PCES – Certified Entry-Level Security Specialist with Python Free Sample Questions

Create a free account to browse all 12 sample questions. The full practice test includes 150 questions. Use the simulator for timed and flashcard mode.

Try Simulator

PCES-30-01 Sample Questions

  1. Question 1

    Q1

    A regional hospital recently upgraded its electronic health record (EHR) system. The new system requires doctors to use a smart card and a PIN to log in, and it permanently records every patient file accessed, modified, or printed, linking these actions directly to the doctor's unique ID. While Confidentiality, Integrity, and Availability are maintained, which specific security concept is primarily enforced by the permanent recording of these actions?

    Show answer & explanation

    Correct answer: B

    Accountability extends the CIA triad by ensuring that actions within a system can be traced back to a specific user or entity. By permanently recording every action linked to a doctor's unique ID, the hospital ensures that users are held responsible for their actions.

  2. Question 2

    Q2Multiple answers

    A financial services organization is reviewing its risk management framework. During a tabletop exercise, the incident response team analyzes a scenario where a threat actor sends a deceptive email appearing to be from the CEO, tricking a junior accountant into transferring funds to an offshore account. Which TWO of the following classifications best describe this threat and the appropriate layered defense measure? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    The scenario describes a Business Email Compromise (BEC), which is a form of phishing and social engineering where attackers manipulate employees into performing actions.

    Layered defenses (defense in depth) for social engineering include combining technical controls like MFA for sensitive transactions with administrative controls like employee training.

  3. Question 3

    Q3

    A logistics company relies heavily on a centralized database to route delivery trucks efficiently. A malicious insider gains access to the system and alters the GPS coordinates for 500 delivery destinations, changing them slightly so the trucks are sent to incorrect, remote locations. What is the primary consequence of this specific type of data manipulation?

    Show answer & explanation

    Correct answer: B

    Data manipulation directly attacks the integrity of the data. In a logistics context, altering GPS coordinates leads to incorrect routing decisions, causing severe operational disruptions, wasted fuel, and delayed deliveries.

  4. Question 4

    Q4

    True or False: In the context of data protection regulations, a company that suffers a data breach exposing user passwords and emails can typically wait up to 6 months before notifying regulatory authorities, provided they are actively investigating the incident.

    Show answer & explanation

    Correct answer: B

    False. Major data protection regulations like GDPR impose strict timelines for reporting breaches (e.g., within 72 hours of becoming aware of the breach). Waiting 6 months would violate reporting obligations and invite severe regulatory fines.

  5. Question 5

    Q5

    An e-commerce retailer experiences a catastrophic database failure during the 'Black Friday' peak sales period. The website remains offline for 14 hours. Beyond the direct loss of sales revenue during the outage, which of the following represents an indirect operational impact of this system unavailability?

    Show answer & explanation

    Correct answer: B

    System unavailability causes direct financial losses (lost sales during the outage) as well as indirect impacts, such as abandoned shopping carts, long-term brand damage, and customers moving to competitors for future purchases.

  6. Question 6

    Q6

    A software development firm is drafting a new employment contract. The legal team includes a clause specifically protecting the company's proprietary algorithms and source code, which give them a competitive advantage in the market. Which legal instrument is specifically designed to protect this type of confidential information from being shared with competitors by former employees?

    Show answer & explanation

    Correct answer: C

    A Non-Disclosure Agreement (NDA) is a legal contract that outlines confidential material, knowledge, or information (like trade secrets and proprietary algorithms) that the parties wish to share with one another but wish to restrict access to or by third parties.

Register free to unlock 6 more sample questions

Create a free account to continue with the rest of the PCES-30-01 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 150 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon