PCES-30-01 Sample Questions & Answers
Emphasizes Python-based defensive and ethical security assessments plus event correlation, the single biggest weight, then covers system hardening and network security basics, secure coding and data integrity practices, and the CIA triad with common IT threats.
Launch the full PCES-30-01 simulator →Showing 6 of 12 free samples.
- Question 1Beginner
Security Essentials · Understand the legal requirements, penalties, and business impacts related to the unauthorized disclosure of personal data
True or False: In the context of data protection regulations, a company that suffers a data breach exposing user passwords and emails can typically wait up to 6 months before notifying regulatory authorities, provided they are actively investigating the incident.
Show answer & explanation
Correct answer: B
False. Major data protection regulations like GDPR impose strict timelines for reporting breaches (e.g., within 72 hours of becoming aware of the breach). Waiting 6 months would violate reporting obligations and invite severe regulatory fines.
- Question 2Intermediate
Security Essentials · Analyze the operational, financial, and safety impacts of system downtime in critical environments
An e-commerce retailer experiences a catastrophic database failure during the 'Black Friday' peak sales period. The website remains offline for 14 hours. Beyond the direct loss of sales revenue during the outage, which of the following represents an indirect operational impact of this system unavailability?
Show answer & explanation
Correct answer: B
System unavailability causes direct financial losses (lost sales during the outage) as well as indirect impacts, such as abandoned shopping carts, long-term brand damage, and customers moving to competitors for future purchases.
- Question 3Intermediate
Security Essentials · Understand the legal requirements, penalties, and business impacts related to the unauthorized disclosure of personal data or trade secrets
A software development firm is drafting a new employment contract. The legal team includes a clause specifically protecting the company's proprietary algorithms and source code, which give them a competitive advantage in the market. Which legal instrument is specifically designed to protect this type of confidential information from being shared with competitors by former employees?
Show answer & explanation
Correct answer: B
A Non-Disclosure Agreement (NDA) is a legal contract that outlines confidential material, knowledge, or information (like trade secrets and proprietary algorithms) that the parties wish to share with one another but wish to restrict access to or by third parties.
- Question 4Advanced
Security Essentials · Identify and classify threats and risks to IT systems
Background:
TechNova Solutions is a mid-sized software vendor. Recently, their support desk received multiple calls from employees stating that their workstation screens were locked, displaying a red countdown timer and demanding payment in Monero to decrypt their files.Investigation:
The Incident Response Team (IRT) discovers that the initial infection vector was a malicious email attachment disguised as a Q3 Financial Report. An employee in the accounting department opened the attachment, which executed a payload that rapidly spread across the internal network, encrypting shared drives.Response:
The IRT isolates the affected network segments and begins restoring data from offline backups taken 24 hours prior.Based on the scenario, which of the following statements correctly identifies the malware type and the most effective layered defense strategy that could have prevented or mitigated this specific incident?
Show answer & explanation
Correct answer: A
The scenario describes ransomware (encrypting files and demanding payment). A layered defense against this includes technical controls (email filtering), administrative controls (user training), and resilience controls (regular, isolated backups to restore data without paying the ransom).
flowchart LR A[Phishing Email] -->|Filtered?| B{Email Gateway} B -->|Yes| C[Blocked] B -->|No| D[User Inbox] D -->|User Trained?| E{User Action} E -->|Yes| F[Reported to IT] E -->|No| G[Ransomware Executes] G --> H[Restore from Backups] - Question 5Beginner
Security Essentials · Understand the importance of communication in IT security
During a post-incident review, a security analyst notes that the initial reporting of a suspected breach was delayed by 14 hours because the junior administrator emailed a technical log file directly to the CEO instead of the Security Operations Center (SOC). This resulted in the malware spreading further. What is the primary lesson regarding communication in IT security highlighted by this event?
Show answer & explanation
Correct answer: A
Effective security relies on timely and accurate reporting to the correct personnel following an escalation chain. Sending raw technical logs to a non-technical executive (CEO) instead of the SOC is a failure of communication that directly increases response times and potential damage.
- Question 6Beginner
Security Essentials · Explain why security is a continuous process
A systems administrator is configuring a new web server. To ensure the server is resilient against emerging threats, the administrator configures a daily cron job to check for and apply security patches automatically. This practice best exemplifies which core security principle?
Show answer & explanation
Correct answer: D
Security is not a "set it and forget it" endeavor. Because threats continually evolve, systems must be continuously monitored and updated (patched) to mitigate risks from newly discovered vulnerabilities.
Ready for the real thing?
The full PCES-30-01 simulator has every exam-style question, timed mode, and instant scoring.