Práctica de seguridad CISSP

Practica 60 preguntas CISSP sobre gobernanza, riesgo, seguridad de activos, arquitectura, red, IAM, operaciones y desarrollo seguro.

Nivel: CISSP Dificultad: advanced 60 preguntas 60 min
Responde cada pregunta CISSP, elige o escribe tu respuesta y revisa la explicación. Los errores se guardan localmente.
Racha de días: 0 días Guardado solo en este dispositivo
Progreso 0 / 60
Pregunta 1

Which CISSP domain covers security governance, risk management, and legal compliance?

Selecciona una respuesta
Pregunta 2

Which access principle means users receive only the permissions required for their role?

Selecciona una respuesta
Pregunta 3

Which type of security control detects and reports a security incident?

Selecciona una respuesta
Pregunta 4

What is the primary purpose of a risk assessment?

Selecciona una respuesta
Pregunta 5

What is residual risk?

Selecciona una respuesta
Pregunta 6

Which security document states management expectations and is typically high-level?

Selecciona una respuesta
Pregunta 7

What is separation of duties designed to prevent?

Selecciona una respuesta
Pregunta 8

What is defense in depth?

Selecciona una respuesta
Pregunta 9

Which security goal protects data from unauthorized disclosure?

Selecciona una respuesta
Pregunta 10

Which security goal ensures data is not modified without authorization?

Selecciona una respuesta
Pregunta 11

Which security goal ensures systems remain accessible to authorized users?

Selecciona una respuesta
Pregunta 12

What is authentication?

Selecciona una respuesta
Pregunta 13

What is authorization?

Selecciona una respuesta
Pregunta 14

Which mechanism provides non-repudiation?

Selecciona una respuesta
Pregunta 15

What is the main purpose of cryptography?

Selecciona una respuesta
Pregunta 16

Which encryption type uses the same key for encryption and decryption?

Selecciona una respuesta
Pregunta 17

In public-key cryptography, which key is used to encrypt a message sent to a recipient?

Selecciona una respuesta
Pregunta 18

What is a cryptographic hash primarily used for?

Selecciona una respuesta
Pregunta 19

Which network device filters traffic based on rules?

Selecciona una respuesta
Pregunta 20

What is a VLAN used for?

Selecciona una respuesta
Pregunta 21

Which protocol provides encrypted communication for web traffic?

Selecciona una respuesta
Pregunta 22

Which technology creates an encrypted tunnel for remote network access?

Selecciona una respuesta
Pregunta 23

What is a DMZ?

Selecciona una respuesta
Pregunta 24

Which concept describes classifying data and applying protection based on its sensitivity?

Selecciona una respuesta
Pregunta 25

What is Identity and Access Management (IAM)?

Selecciona una respuesta
Pregunta 26

What is a directory service?

Selecciona una respuesta
Pregunta 27

Which authentication factor is described as something the user knows?

Selecciona una respuesta
Pregunta 28

Which authentication factor is described as something the user has?

Selecciona una respuesta
Pregunta 29

Which authentication factor is described as something the user is?

Selecciona una respuesta
Pregunta 30

What is single sign-on (SSO)?

Selecciona una respuesta
Pregunta 31

What is multi-factor authentication?

Selecciona una respuesta
Pregunta 32

What is privileged access management?

Selecciona una respuesta
Pregunta 33

What does SIEM provide?

Selecciona una respuesta
Pregunta 34

What does SOAR stand for?

Selecciona una respuesta
Pregunta 35

What is a vulnerability scan?

Selecciona una respuesta
Pregunta 36

What is a penetration test?

Selecciona una respuesta
Pregunta 37

Which incident response activity limits the scope of an incident?

Selecciona una respuesta
Pregunta 38

What is the purpose of a business continuity plan (BCP)?

Selecciona una respuesta
Pregunta 39

What is a disaster recovery plan (DRP)?

Selecciona una respuesta
Pregunta 40

Which secure coding practice prevents injection attacks?

Selecciona una respuesta
Pregunta 41

Which of the following are core security objectives in the CIA triad? Select all that apply.

Selecciona una respuesta
Pregunta 42

Which of the following are access control models? Select all that apply.

Selecciona una respuesta
Pregunta 43

Which of the following are authentication factors? Select all that apply.

Selecciona una respuesta
Pregunta 44

Which of the following are symmetric encryption algorithms? Select all that apply.

Selecciona una respuesta
Pregunta 45

Which of the following are asymmetric cryptography algorithms? Select all that apply.

Selecciona una respuesta
Pregunta 46

Which of the following are phases of incident response? Select all that apply.

Selecciona una respuesta
Pregunta 47

Which of the following are secure development practices? Select all that apply.

Selecciona una respuesta
Pregunta 48

Confidentiality means information is available to everyone at all times.

Selecciona una respuesta
Pregunta 49

A vulnerability is the same thing as an exploit.

Selecciona una respuesta
Pregunta 50

Data remanence is a concern when decommissioning storage media.

Selecciona una respuesta
Pregunta 51

Symmetric encryption is generally faster than asymmetric encryption.

Selecciona una respuesta
Pregunta 52

The principle of least privilege means granting all users administrator access by default.

Selecciona una respuesta
Pregunta 53

The security goal that protects data from unauthorized modification is ___.

Pregunta 54

The process of confirming a user claimed identity is ___.

Pregunta 55

A ___ encrypts traffic between a user and a remote network.

Pregunta 56

The access control model that grants rights based on user roles is ___.

Pregunta 57

A documented plan to restore IT systems after a disaster is the ___ recovery plan.

Pregunta 58

Match each security control type to its example.

Pregunta 59

Match each cryptography concept to its purpose.

Pregunta 60

Match each IAM concept to its meaning.