South Carolina Cybersecurity Analyst
Certification License Exam Practice
Questions And Correct Answers
(Verified Answers) Plus Rationale 2026
Q&A| Instant Download Pdf
1. Which of the following best describes the CIA Triad in cybersecurity?
A. Confidentiality, Integrity, Availability
B. Control, Inspection, Authorization
C. Compliance, Intelligence, Access
D. Cryptography, Identity, Analytics
The CIA Triad stands for Confidentiality, Integrity, and Availability, which
are core principles protecting information systems.
2. What is the primary purpose of a firewall?
A. To encrypt network traffic
B. To monitor application performance
C. To control incoming and outgoing network traffic based on security
rules
D. To provide user authentication
Firewalls are designed to filter traffic between networks according to
defined security policies.
3. Which type of attack involves overwhelming a system with traffic to
make it unavailable?
, A. Man-in-the-middle
B. Denial of Service (DoS)
C. SQL Injection
D. Phishing
DoS attacks flood targets with traffic to exhaust resources and disrupt
availability.
4. What does phishing typically aim to do?
A. Spread malware automatically
B. Trick users into revealing sensitive information
C. Intercept encrypted traffic
D. Perform brute force attacks
Phishing relies on social engineering to deceive users into disclosing
credentials or personal data.
5. In access control models, RBAC stands for:
A. Randomized Binary Authentication Control
B. Role-Based Access Control
C. Role-Based Access Control
D. Restricted Boundary Authorization Code
RBAC assigns permissions to roles and users gain access through role
assignments.
6. What’s the main function of Intrusion Detection Systems (IDS)?
A. To block all traffic from untrusted sources
B. To encrypt sensitive data only
C. To detect and alert on potential security breaches
D. To authenticate legitimate users
IDS identifies suspicious patterns and alerts administrators but doesn’t
typically block traffic.
, 7. Which protocol is used to securely access remote systems?
A. Telnet
B. FTP
C. HTTP
D. SSH
SSH provides encrypted remote command-line access to systems.
8. What does VPN stand for?
A. Verified Private Network
B. Virtual Public Network
C. Virtual Private Network
D. Virtual Protected Node
VPNs create encrypted connections over public networks to protect data in
transit.
9. Which malware type disguises itself as legitimate software?
A. Worm
B. Trojan
C. Rootkit
D. Trojan
Trojans appear benign to trick users into installing malicious code.
10. A zero-day vulnerability refers to:
A. A patch released immediately
B. A vulnerability with no exploit
C. A flaw unknown to defenders and unpatched
D. A deprecated protocol
Zero-day vulnerabilities are exploited before vendors can provide fixes.
11. What is the purpose of encryption?
A. To speed up network traffic
Certification License Exam Practice
Questions And Correct Answers
(Verified Answers) Plus Rationale 2026
Q&A| Instant Download Pdf
1. Which of the following best describes the CIA Triad in cybersecurity?
A. Confidentiality, Integrity, Availability
B. Control, Inspection, Authorization
C. Compliance, Intelligence, Access
D. Cryptography, Identity, Analytics
The CIA Triad stands for Confidentiality, Integrity, and Availability, which
are core principles protecting information systems.
2. What is the primary purpose of a firewall?
A. To encrypt network traffic
B. To monitor application performance
C. To control incoming and outgoing network traffic based on security
rules
D. To provide user authentication
Firewalls are designed to filter traffic between networks according to
defined security policies.
3. Which type of attack involves overwhelming a system with traffic to
make it unavailable?
, A. Man-in-the-middle
B. Denial of Service (DoS)
C. SQL Injection
D. Phishing
DoS attacks flood targets with traffic to exhaust resources and disrupt
availability.
4. What does phishing typically aim to do?
A. Spread malware automatically
B. Trick users into revealing sensitive information
C. Intercept encrypted traffic
D. Perform brute force attacks
Phishing relies on social engineering to deceive users into disclosing
credentials or personal data.
5. In access control models, RBAC stands for:
A. Randomized Binary Authentication Control
B. Role-Based Access Control
C. Role-Based Access Control
D. Restricted Boundary Authorization Code
RBAC assigns permissions to roles and users gain access through role
assignments.
6. What’s the main function of Intrusion Detection Systems (IDS)?
A. To block all traffic from untrusted sources
B. To encrypt sensitive data only
C. To detect and alert on potential security breaches
D. To authenticate legitimate users
IDS identifies suspicious patterns and alerts administrators but doesn’t
typically block traffic.
, 7. Which protocol is used to securely access remote systems?
A. Telnet
B. FTP
C. HTTP
D. SSH
SSH provides encrypted remote command-line access to systems.
8. What does VPN stand for?
A. Verified Private Network
B. Virtual Public Network
C. Virtual Private Network
D. Virtual Protected Node
VPNs create encrypted connections over public networks to protect data in
transit.
9. Which malware type disguises itself as legitimate software?
A. Worm
B. Trojan
C. Rootkit
D. Trojan
Trojans appear benign to trick users into installing malicious code.
10. A zero-day vulnerability refers to:
A. A patch released immediately
B. A vulnerability with no exploit
C. A flaw unknown to defenders and unpatched
D. A deprecated protocol
Zero-day vulnerabilities are exploited before vendors can provide fixes.
11. What is the purpose of encryption?
A. To speed up network traffic