Latihan Keselamatan CISSP

Latih 60 soalan CISSP merangkumi tadbir urus, risiko, keselamatan aset, seni bina, rangkaian, IAM, operasi dan pembangunan selamat.

Tahap: CISSP Kesukaran: advanced 60 soalan 60 min
Jawab setiap soalan CISSP, pilih atau taip jawapan, kemudian semak penerangan. Jawapan salah disimpan setempat.
Hari berturut-turut: 0 hari Disimpan hanya pada peranti ini
Kemajuan 0 / 60
Soalan 1

Which CISSP domain covers security governance, risk management, and legal compliance?

Pilih jawapan
Soalan 2

Which access principle means users receive only the permissions required for their role?

Pilih jawapan
Soalan 3

Which type of security control detects and reports a security incident?

Pilih jawapan
Soalan 4

What is the primary purpose of a risk assessment?

Pilih jawapan
Soalan 5

What is residual risk?

Pilih jawapan
Soalan 6

Which security document states management expectations and is typically high-level?

Pilih jawapan
Soalan 7

What is separation of duties designed to prevent?

Pilih jawapan
Soalan 8

What is defense in depth?

Pilih jawapan
Soalan 9

Which security goal protects data from unauthorized disclosure?

Pilih jawapan
Soalan 10

Which security goal ensures data is not modified without authorization?

Pilih jawapan
Soalan 11

Which security goal ensures systems remain accessible to authorized users?

Pilih jawapan
Soalan 12

What is authentication?

Pilih jawapan
Soalan 13

What is authorization?

Pilih jawapan
Soalan 14

Which mechanism provides non-repudiation?

Pilih jawapan
Soalan 15

What is the main purpose of cryptography?

Pilih jawapan
Soalan 16

Which encryption type uses the same key for encryption and decryption?

Pilih jawapan
Soalan 17

In public-key cryptography, which key is used to encrypt a message sent to a recipient?

Pilih jawapan
Soalan 18

What is a cryptographic hash primarily used for?

Pilih jawapan
Soalan 19

Which network device filters traffic based on rules?

Pilih jawapan
Soalan 20

What is a VLAN used for?

Pilih jawapan
Soalan 21

Which protocol provides encrypted communication for web traffic?

Pilih jawapan
Soalan 22

Which technology creates an encrypted tunnel for remote network access?

Pilih jawapan
Soalan 23

What is a DMZ?

Pilih jawapan
Soalan 24

Which concept describes classifying data and applying protection based on its sensitivity?

Pilih jawapan
Soalan 25

What is Identity and Access Management (IAM)?

Pilih jawapan
Soalan 26

What is a directory service?

Pilih jawapan
Soalan 27

Which authentication factor is described as something the user knows?

Pilih jawapan
Soalan 28

Which authentication factor is described as something the user has?

Pilih jawapan
Soalan 29

Which authentication factor is described as something the user is?

Pilih jawapan
Soalan 30

What is single sign-on (SSO)?

Pilih jawapan
Soalan 31

What is multi-factor authentication?

Pilih jawapan
Soalan 32

What is privileged access management?

Pilih jawapan
Soalan 33

What does SIEM provide?

Pilih jawapan
Soalan 34

What does SOAR stand for?

Pilih jawapan
Soalan 35

What is a vulnerability scan?

Pilih jawapan
Soalan 36

What is a penetration test?

Pilih jawapan
Soalan 37

Which incident response activity limits the scope of an incident?

Pilih jawapan
Soalan 38

What is the purpose of a business continuity plan (BCP)?

Pilih jawapan
Soalan 39

What is a disaster recovery plan (DRP)?

Pilih jawapan
Soalan 40

Which secure coding practice prevents injection attacks?

Pilih jawapan
Soalan 41

Which of the following are core security objectives in the CIA triad? Select all that apply.

Pilih jawapan
Soalan 42

Which of the following are access control models? Select all that apply.

Pilih jawapan
Soalan 43

Which of the following are authentication factors? Select all that apply.

Pilih jawapan
Soalan 44

Which of the following are symmetric encryption algorithms? Select all that apply.

Pilih jawapan
Soalan 45

Which of the following are asymmetric cryptography algorithms? Select all that apply.

Pilih jawapan
Soalan 46

Which of the following are phases of incident response? Select all that apply.

Pilih jawapan
Soalan 47

Which of the following are secure development practices? Select all that apply.

Pilih jawapan
Soalan 48

Confidentiality means information is available to everyone at all times.

Pilih jawapan
Soalan 49

A vulnerability is the same thing as an exploit.

Pilih jawapan
Soalan 50

Data remanence is a concern when decommissioning storage media.

Pilih jawapan
Soalan 51

Symmetric encryption is generally faster than asymmetric encryption.

Pilih jawapan
Soalan 52

The principle of least privilege means granting all users administrator access by default.

Pilih jawapan
Soalan 53

The security goal that protects data from unauthorized modification is ___.

Soalan 54

The process of confirming a user claimed identity is ___.

Soalan 55

A ___ encrypts traffic between a user and a remote network.

Soalan 56

The access control model that grants rights based on user roles is ___.

Soalan 57

A documented plan to restore IT systems after a disaster is the ___ recovery plan.

Soalan 58

Match each security control type to its example.

Soalan 59

Match each cryptography concept to its purpose.

Soalan 60

Match each IAM concept to its meaning.