[1/29] What is a common asymmetric key encryption algorithm?
All of them
[2/29] Your AT-TLS policy can specify which of the following?
Time of day
All of these and more
[3/29] Which is a way to access and modify RACF data from the network?
IBM Tivoli Directory Server for z/OS
[4/29] Which keyword determines whether an unauthorized requester can invoke the PC?
[5/29] What is the recommended method for assigning superuser authority?
Assigning a uid of 0
Using UNIXPRIV profiles
Using the BPX.SUPERUSER resource in the FACILITY class
Using the BPX.DAEMON resource in the FACILITY class
[6/29] Why should I subscribe to the IBM Z Security Portal?
To gain access to CVSS data
To review all CVEs
To get notified of the latest security information
To hack z/OS applications
[7/29] Which of the following is not found in the z/OS CVSS Data file available from the IBM Z Security Portal?
[8/29] Which of the below functions can a PKI Services administrator not perform?
Modify a certificate
Update a request
Approve a request
Revoke a certificate
[9/29] After you are done reading and writing your data securely using System SSL APIs, what is the first step you should take?
Close the connection
Shutdown the environment
Shutdown the connection
Close the environment
[10/29] Which of the following is an attack where a malicious user attempts to either guess or confirm valid users in a system?
user enumeration attack
[11/29] How can a user configure the default priority of security providers?
Change the order of the provider jar files in the classpath
Change the order of the provider list in the java.security file
Change the order of the provider list in the java.policy file
A user cannot change the priority of security providers
[12/29] What is “privilege creep”?
A gradual accumulation of access rights beyond what an individual needs to do his job
When a system admin spies on other users without their knowledge
When the process to grant system access is really slow
A condition when access failures generate a large number of alerts
[13/29] Which of the following is not a type of KDS?
[14/29] Which of the following ENQ QNames is most appropriate for an authorized program?
[15/29] Which of the following algorithms is NOT specified in a cipher suite definition?
[16/29] In what security immune system domain does Data Set Encryption reside?
Identity and Access
[17/29] The ability to eliminate the storage administrator from the compliance scope is found at what layer of encryption?
File or data set
Full disk & tape
[18/29] What is the best way to verify the address of a control block provided by an untrusted requester?
Run an independent chain to match the address
Check the eye catcher
Make a safe copy
Test the storage key
[19/29] What is the most important part of symmetric key encryption?
There is no key for this type of encryption
Each encryption creates a unique key
A different key is used for encrypt and decrypt operations
The same key is used for encrypt and decrypt operations
[20/29] Which General Register might be trusted on entry to a PC routine?
[21/29] How many levels of indirect parameters are trusted on entry to a PC available to unauthorized callers?
None of them
All of them
The first one
The first three
[22/29] Which of the following fields is not in a digital certificate?
[23/29] Which information is NOT collected by zERT?
[24/29] Which of the following could be susceptible to a buffer overflow if left unchecked?
Null terminated strings
PC routines with variable length parameters
All of them
Web servers with variable length interfaces
[25/29] Resource managers make security requests through the set of interfaces called the ____
TCB: Trusted computing base
ESM: External Security Manager
SAF: System Authorization Facility
CIA: Confidentiality Integrity and Availability subsystem
[26/29] When an authorized user requests data from Db2 using SQL that is encrypted on disk they will see...
No data will be returned
Data in the clear
An SQL Error code
[27/29] Which of the following is not a property of authorization?
[28/29] Which of the following is not considered a sensitive resource to RACF's health check of the same name?
System Rexx dataset
[29/29] What is the name of the encryption hardware accelerator available on each microprocessor of the z14 providing up to 7x performance?
Badge Certification Score