تدريب CompTIA Security+

تدرّب على 80 سؤالًا أصليًا لـ CompTIA Security+ تغطي التهديدات والثغرات والبنية والهوية والعمليات والحوكمة.

المستوى: CompTIA Security+ الصعوبة: intermediate 80 سؤال 60 دقيقة
أجب عن كل سؤال أمني ثم تحقق من نتيجتك. تُحفظ الأخطاء محليًا للمراجعة.
أيام متتالية: 0 أيام محفوظ على هذا الجهاز فقط
التقدم 0 / 80
سؤال 1

A payroll file is silently changed so an employee receives a higher salary. Which security goal is violated?

اختر إجابة
سؤال 2

An employee receives an email that appears to come from IT and asks for a password due to "urgent account verification." Which attack is this?

اختر إجابة
سؤال 3

An attacker calls an employee, pretends to be from the help desk, and asks for a verification code. Which attack is this?

اختر إجابة
سؤال 4

A user receives a text message with a link to a fake package tracking page. Which attack is this?

اختر إجابة
سؤال 5

A campaign sends personalized emails to selected employees using their names, roles, and job context. Which attack is this?

اختر إجابة
سؤال 6

An attacker leaves a USB drive labeled "Salary Data" in a parking lot where employees will find it. Which social engineering technique is this?

اختر إجابة
سؤال 7

An attacker follows an employee through a badge-controlled door without using a badge. Which technique is this?

اختر إجابة
سؤال 8

An attacker watches a user type a PIN at an ATM. Which technique is this?

اختر إجابة
سؤال 9

A person recovers discarded documents containing account details from a trash bin. Which technique is this?

اختر إجابة
سؤال 10

An attacker compromises a website that employees of a target company visit frequently. Which technique is this?

اختر إجابة
سؤال 11

Malware encrypts files on a workstation and demands payment to restore them. Which type of malware is this?

اختر إجابة
سؤال 12

Malware appears to be a legitimate utility but installs a backdoor when executed. Which type of malware is this?

اختر إجابة
سؤال 13

Which malware can spread automatically across networks without requiring user interaction?

اختر إجابة
سؤال 14

Which malware hides deep inside the operating system to maintain privileged access and evade detection?

اختر إجابة
سؤال 15

A large group of compromised devices is used together to launch DDoS attacks. What is the group called?

اختر إجابة
سؤال 16

Which symptoms may indicate malware infection? Select all that apply.

اختر إجابة
سؤال 17

Which are social engineering techniques? Select all that apply.

اختر إجابة
سؤال 18

An email-based attack that targets a specific person using their name and context is called ___ phishing.

اختر إجابة
سؤال 19

Match each social engineering attack to its channel.

سؤال 20

Match each malware type to its behavior.

سؤال 21

A vulnerability exists in software, no vendor patch is available, and an attacker exploits it the same day it becomes known. What is this called?

اختر إجابة
سؤال 22

Which standardized scoring system measures the severity of a vulnerability?

اختر إجابة
سؤال 23

What is the main difference between a vulnerability scan and a penetration test?

اختر إجابة
سؤال 24

Why is a patch management process important?

اختر إجابة
سؤال 25

Which control best prevents SQL injection?

اختر إجابة
سؤال 26

An attacker injects a script that executes in another user browser. What should the developer apply to prevent this?

اختر إجابة
سؤال 27

Writing more data than a buffer can hold is known as what?

اختر إجابة
سؤال 28

An attacker forces a running process to load a malicious library. Which technique is this?

اختر إجابة
سؤال 29

Which encryption method uses the same key to encrypt and decrypt data?

اختر إجابة
سؤال 30

RSA uses which cryptographic model?

اختر إجابة
سؤال 31

Which cryptographic function provides integrity by producing a fixed-size digest?

اختر إجابة
سؤال 32

A document is signed with the sender private key. What does the recipient verify using the sender public key?

اختر إجابة
سؤال 33

What is the purpose of a digital certificate in PKI?

اختر إجابة
سؤال 34

A certificate is compromised before it expires. Which mechanisms allow clients to check its current status?

اختر إجابة
سؤال 35

Sending a secret key by email is unsafe because it travels in ___ text.

سؤال 36

Which controls help verify data integrity? Select all that apply.

اختر إجابة
سؤال 37

Which practices reduce the risk of password cracking? Select all that apply.

اختر إجابة
سؤال 38

Match each cryptographic concept to its role.

سؤال 39

The protocol that provides real-time certificate status checks is abbreviated ___.

سؤال 40

Match each cryptographic technology to its typical use.

سؤال 41

What does multi-factor authentication (MFA) require?

اختر إجابة
سؤال 42

Which authentication factor is "something you have"?

اختر إجابة
سؤال 43

Access is granted based on the user job role. Which access control model is this?

اختر إجابة
سؤال 44

Users should have only the permissions needed to perform their job. Which principle does this describe?

اختر إجابة
سؤال 45

Which system is designed to protect, rotate, and audit administrative account credentials?

اختر إجابة
سؤال 46

What is a key benefit of using a password manager?

اختر إجابة
سؤال 47

A user signs in once and can access multiple applications without signing in again. Which technology is this?

اختر إجابة
سؤال 48

Which device filters traffic based on a defined set of security rules?

اختر إجابة
سؤال 49

What distinguishes an intrusion prevention system (IPS) from an intrusion detection system (IDS)?

اختر إجابة
سؤال 50

How does network segmentation limit the impact of an attack?

اختر إجابة
سؤال 51

Which network zone is designed to host public-facing services while protecting the internal network?

اختر إجابة
سؤال 52

Which control inspects web traffic and protects applications from attacks such as XSS and SQL injection?

اختر إجابة
سؤال 53

What is a VPN primarily used for?

اختر إجابة
سؤال 54

A security model assumes no user or device is trusted by default, even inside the network. Which model is this?

اختر إجابة
سؤال 55

Which technology monitors endpoints and automatically responds to threats using behavioral detection?

اختر إجابة
سؤال 56

In the cloud shared responsibility model, which tasks typically remain the customer responsibility? Select all that apply.

اختر إجابة
سؤال 57

Which controls can help prevent lateral movement inside a network? Select all that apply.

اختر إجابة
سؤال 58

A security model that verifies every request before granting access is called ___ trust.

سؤال 59

A hardware appliance that securely stores cryptographic keys and performs signing operations is called a hardware security ___.

سؤال 60

Match each security control to where it primarily operates.

سؤال 61

What should an incident response team do first during an active security incident?

اختر إجابة
سؤال 62

During an active ransomware outbreak, what is the first containment step?

اختر إجابة
سؤال 63

Why is chain of custody important in digital forensics?

اختر إجابة
سؤال 64

What should an investigator do before analyzing a forensic drive?

اختر إجابة
سؤال 65

Which system collects and correlates logs from many sources for alerting and analysis?

اختر إجابة
سؤال 66

Which log is most useful for detecting unauthorized account access?

اختر إجابة
سؤال 67

What does a data retention policy define?

اختر إجابة
سؤال 68

Which regulation focuses on personal data protection for individuals in the European Union?

اختر إجابة
سؤال 69

Which standard specifically addresses the protection of cardholder data?

اختر إجابة
سؤال 70

How is risk typically calculated?

اختر إجابة
سؤال 71

An organization purchases cyber insurance to handle potential financial losses. Which risk strategy is this?

اختر إجابة
سؤال 72

What is the main purpose of a business continuity plan (BCP)?

اختر إجابة
سؤال 73

Which metric defines the maximum tolerable data loss, measured in time?

اختر إجابة
سؤال 74

Which metric defines the maximum time allowed to restore operations after a disaster?

اختر إجابة
سؤال 75

A team walks through a scenario to review incident procedures without deploying changes. Which exercise is this?

اختر إجابة
سؤال 76

Which practices support forensic evidence integrity? Select all that apply.

اختر إجابة
سؤال 77

Which controls reduce insider threat risk? Select all that apply.

اختر إجابة
سؤال 78

The maximum acceptable data loss measured in time is the recovery point ___.

سؤال 79

The documented sequence of evidence custody is called the chain of ___.

سؤال 80

Match each incident response phase to its main action.