Cyber Security Jobs Cyber Security Career Paths 2 — Questions and Answers
Question 1: Which US government agency is a major employer of cyber security professionals and operates the National Cybersecurity and Communications Integration Center?
- CISA (Correct answer)
- FDA
- DOT
- FTC
Correct answer: CISA
CISA (Cybersecurity and Infrastructure Security Agency) runs NCCIC and is one of the largest federal employers of cyber security professionals.
Question 2: What is a common salary range for a mid-level cyber security analyst in the US as of recent surveys?
- $80,000–$120,000 per year (Correct answer)
- $25,000–$40,000 per year
- $200,000–$300,000 per year
- $45,000–$55,000 per year
Correct answer: $80,000–$120,000 per year
Mid-level cyber security analysts in the US typically earn between $80,000 and $120,000 annually according to BLS and industry surveys.
Question 3: Which skill is increasingly listed as 'required' in US cloud security job postings?
- Experience with AWS, Azure, or GCP (Correct answer)
- Proficiency in COBOL programming
- Knowledge of physical lock mechanisms
- Expertise in analog telephony
Correct answer: Experience with AWS, Azure, or GCP
Cloud platform experience (AWS, Azure, or GCP) is now a standard requirement in US cloud security roles.
Question 4: What does a Threat Intelligence Analyst primarily produce?
- Reports on emerging threats and attacker tactics (Correct answer)
- Hardware firewall configurations
- Employee onboarding documentation
- Annual financial audits
Correct answer: Reports on emerging threats and attacker tactics
Threat Intelligence Analysts research adversary behavior and produce actionable reports to help organizations defend against emerging threats.
Question 5: Which framework is commonly used by US employers to define cyber security roles and skill requirements?
- NICE Cybersecurity Workforce Framework (Correct answer)
- GAAP Accounting Standards
- ISO 9001 Quality Management
- PCI DSS Payment Standards
Correct answer: NICE Cybersecurity Workforce Framework
The NICE (National Initiative for Cybersecurity Education) Workforce Framework defines standardized roles, skills, and tasks for cyber security jobs.
Question 6: What is 'purple teaming' in a cyber security job context?
- Collaborative exercises where red and blue teams work together (Correct answer)
- A certification program for government contractors
- A color-coded phishing simulation
- A type of malware analysis technique
Correct answer: Collaborative exercises where red and blue teams work together
Purple teaming combines offensive (red) and defensive (blue) teams working jointly to improve detection and response capabilities.
Which US government agency is a major employer of cyber security professionals and operates the National Cybersecurity and Communications Integration Center?