تدريب على شهادة CISSP الأمنية

تدرّب على 60 سؤالًا من CISSP تغطي الحوكمة والمخاطر وأمن الأصول والهندسة وأمن الشبكات وإدارة الهوية والعمليات والتطوير الآمن.

المستوى: CISSP الصعوبة: advanced 60 سؤال 60 دقيقة
أجب عن كل سؤال في CISSP، واختر أو اكتب إجابتك ثم راجع الشرح. تُحفظ الأخطاء محليًا للمراجعة.
أيام متتالية: 0 أيام محفوظ على هذا الجهاز فقط
التقدم 0 / 60
سؤال 1

Which CISSP domain covers security governance, risk management, and legal compliance?

اختر إجابة
سؤال 2

Which access principle means users receive only the permissions required for their role?

اختر إجابة
سؤال 3

Which type of security control detects and reports a security incident?

اختر إجابة
سؤال 4

What is the primary purpose of a risk assessment?

اختر إجابة
سؤال 5

What is residual risk?

اختر إجابة
سؤال 6

Which security document states management expectations and is typically high-level?

اختر إجابة
سؤال 7

What is separation of duties designed to prevent?

اختر إجابة
سؤال 8

What is defense in depth?

اختر إجابة
سؤال 9

Which security goal protects data from unauthorized disclosure?

اختر إجابة
سؤال 10

Which security goal ensures data is not modified without authorization?

اختر إجابة
سؤال 11

Which security goal ensures systems remain accessible to authorized users?

اختر إجابة
سؤال 12

What is authentication?

اختر إجابة
سؤال 13

What is authorization?

اختر إجابة
سؤال 14

Which mechanism provides non-repudiation?

اختر إجابة
سؤال 15

What is the main purpose of cryptography?

اختر إجابة
سؤال 16

Which encryption type uses the same key for encryption and decryption?

اختر إجابة
سؤال 17

In public-key cryptography, which key is used to encrypt a message sent to a recipient?

اختر إجابة
سؤال 18

What is a cryptographic hash primarily used for?

اختر إجابة
سؤال 19

Which network device filters traffic based on rules?

اختر إجابة
سؤال 20

What is a VLAN used for?

اختر إجابة
سؤال 21

Which protocol provides encrypted communication for web traffic?

اختر إجابة
سؤال 22

Which technology creates an encrypted tunnel for remote network access?

اختر إجابة
سؤال 23

What is a DMZ?

اختر إجابة
سؤال 24

Which concept describes classifying data and applying protection based on its sensitivity?

اختر إجابة
سؤال 25

What is Identity and Access Management (IAM)?

اختر إجابة
سؤال 26

What is a directory service?

اختر إجابة
سؤال 27

Which authentication factor is described as something the user knows?

اختر إجابة
سؤال 28

Which authentication factor is described as something the user has?

اختر إجابة
سؤال 29

Which authentication factor is described as something the user is?

اختر إجابة
سؤال 30

What is single sign-on (SSO)?

اختر إجابة
سؤال 31

What is multi-factor authentication?

اختر إجابة
سؤال 32

What is privileged access management?

اختر إجابة
سؤال 33

What does SIEM provide?

اختر إجابة
سؤال 34

What does SOAR stand for?

اختر إجابة
سؤال 35

What is a vulnerability scan?

اختر إجابة
سؤال 36

What is a penetration test?

اختر إجابة
سؤال 37

Which incident response activity limits the scope of an incident?

اختر إجابة
سؤال 38

What is the purpose of a business continuity plan (BCP)?

اختر إجابة
سؤال 39

What is a disaster recovery plan (DRP)?

اختر إجابة
سؤال 40

Which secure coding practice prevents injection attacks?

اختر إجابة
سؤال 41

Which of the following are core security objectives in the CIA triad? Select all that apply.

اختر إجابة
سؤال 42

Which of the following are access control models? Select all that apply.

اختر إجابة
سؤال 43

Which of the following are authentication factors? Select all that apply.

اختر إجابة
سؤال 44

Which of the following are symmetric encryption algorithms? Select all that apply.

اختر إجابة
سؤال 45

Which of the following are asymmetric cryptography algorithms? Select all that apply.

اختر إجابة
سؤال 46

Which of the following are phases of incident response? Select all that apply.

اختر إجابة
سؤال 47

Which of the following are secure development practices? Select all that apply.

اختر إجابة
سؤال 48

Confidentiality means information is available to everyone at all times.

اختر إجابة
سؤال 49

A vulnerability is the same thing as an exploit.

اختر إجابة
سؤال 50

Data remanence is a concern when decommissioning storage media.

اختر إجابة
سؤال 51

Symmetric encryption is generally faster than asymmetric encryption.

اختر إجابة
سؤال 52

The principle of least privilege means granting all users administrator access by default.

اختر إجابة
سؤال 53

The security goal that protects data from unauthorized modification is ___.

سؤال 54

The process of confirming a user claimed identity is ___.

سؤال 55

A ___ encrypts traffic between a user and a remote network.

سؤال 56

The access control model that grants rights based on user roles is ___.

سؤال 57

A documented plan to restore IT systems after a disaster is the ___ recovery plan.

سؤال 58

Match each security control type to its example.

سؤال 59

Match each cryptography concept to its purpose.

سؤال 60

Match each IAM concept to its meaning.