ฝึกข้อสอบ CISSP Security

ฝึกข้อสอบ CISSP 60 ข้อครอบคลุมการกำกับดูแล ความเสี่ยง ความปลอดภัยของสินทรัพย์ สถาปัตยกรรม เครือข่าย IAM การปฏิบัติการ และการพัฒนาที่ปลอดภัย

ระดับ: CISSP ความยาก: advanced 60 ข้อ 60 นาที
ตอบข้อสอบ CISSP แต่ละข้อ เลือกหรือพิมพ์คำตอบ แล้วตรวจคำอธิบาย ข้อที่ผิดจะถูกบันทึกไว้ในเครื่อง
จำนวนวันต่อเนื่อง: 0 วัน บันทึกเฉพาะอุปกรณ์นี้
ความคืบหน้า 0 / 60
ข้อ 1

Which CISSP domain covers security governance, risk management, and legal compliance?

เลือกคำตอบ
ข้อ 2

Which access principle means users receive only the permissions required for their role?

เลือกคำตอบ
ข้อ 3

Which type of security control detects and reports a security incident?

เลือกคำตอบ
ข้อ 4

What is the primary purpose of a risk assessment?

เลือกคำตอบ
ข้อ 5

What is residual risk?

เลือกคำตอบ
ข้อ 6

Which security document states management expectations and is typically high-level?

เลือกคำตอบ
ข้อ 7

What is separation of duties designed to prevent?

เลือกคำตอบ
ข้อ 8

What is defense in depth?

เลือกคำตอบ
ข้อ 9

Which security goal protects data from unauthorized disclosure?

เลือกคำตอบ
ข้อ 10

Which security goal ensures data is not modified without authorization?

เลือกคำตอบ
ข้อ 11

Which security goal ensures systems remain accessible to authorized users?

เลือกคำตอบ
ข้อ 12

What is authentication?

เลือกคำตอบ
ข้อ 13

What is authorization?

เลือกคำตอบ
ข้อ 14

Which mechanism provides non-repudiation?

เลือกคำตอบ
ข้อ 15

What is the main purpose of cryptography?

เลือกคำตอบ
ข้อ 16

Which encryption type uses the same key for encryption and decryption?

เลือกคำตอบ
ข้อ 17

In public-key cryptography, which key is used to encrypt a message sent to a recipient?

เลือกคำตอบ
ข้อ 18

What is a cryptographic hash primarily used for?

เลือกคำตอบ
ข้อ 19

Which network device filters traffic based on rules?

เลือกคำตอบ
ข้อ 20

What is a VLAN used for?

เลือกคำตอบ
ข้อ 21

Which protocol provides encrypted communication for web traffic?

เลือกคำตอบ
ข้อ 22

Which technology creates an encrypted tunnel for remote network access?

เลือกคำตอบ
ข้อ 23

What is a DMZ?

เลือกคำตอบ
ข้อ 24

Which concept describes classifying data and applying protection based on its sensitivity?

เลือกคำตอบ
ข้อ 25

What is Identity and Access Management (IAM)?

เลือกคำตอบ
ข้อ 26

What is a directory service?

เลือกคำตอบ
ข้อ 27

Which authentication factor is described as something the user knows?

เลือกคำตอบ
ข้อ 28

Which authentication factor is described as something the user has?

เลือกคำตอบ
ข้อ 29

Which authentication factor is described as something the user is?

เลือกคำตอบ
ข้อ 30

What is single sign-on (SSO)?

เลือกคำตอบ
ข้อ 31

What is multi-factor authentication?

เลือกคำตอบ
ข้อ 32

What is privileged access management?

เลือกคำตอบ
ข้อ 33

What does SIEM provide?

เลือกคำตอบ
ข้อ 34

What does SOAR stand for?

เลือกคำตอบ
ข้อ 35

What is a vulnerability scan?

เลือกคำตอบ
ข้อ 36

What is a penetration test?

เลือกคำตอบ
ข้อ 37

Which incident response activity limits the scope of an incident?

เลือกคำตอบ
ข้อ 38

What is the purpose of a business continuity plan (BCP)?

เลือกคำตอบ
ข้อ 39

What is a disaster recovery plan (DRP)?

เลือกคำตอบ
ข้อ 40

Which secure coding practice prevents injection attacks?

เลือกคำตอบ
ข้อ 41

Which of the following are core security objectives in the CIA triad? Select all that apply.

เลือกคำตอบ
ข้อ 42

Which of the following are access control models? Select all that apply.

เลือกคำตอบ
ข้อ 43

Which of the following are authentication factors? Select all that apply.

เลือกคำตอบ
ข้อ 44

Which of the following are symmetric encryption algorithms? Select all that apply.

เลือกคำตอบ
ข้อ 45

Which of the following are asymmetric cryptography algorithms? Select all that apply.

เลือกคำตอบ
ข้อ 46

Which of the following are phases of incident response? Select all that apply.

เลือกคำตอบ
ข้อ 47

Which of the following are secure development practices? Select all that apply.

เลือกคำตอบ
ข้อ 48

Confidentiality means information is available to everyone at all times.

เลือกคำตอบ
ข้อ 49

A vulnerability is the same thing as an exploit.

เลือกคำตอบ
ข้อ 50

Data remanence is a concern when decommissioning storage media.

เลือกคำตอบ
ข้อ 51

Symmetric encryption is generally faster than asymmetric encryption.

เลือกคำตอบ
ข้อ 52

The principle of least privilege means granting all users administrator access by default.

เลือกคำตอบ
ข้อ 53

The security goal that protects data from unauthorized modification is ___.

ข้อ 54

The process of confirming a user claimed identity is ___.

ข้อ 55

A ___ encrypts traffic between a user and a remote network.

ข้อ 56

The access control model that grants rights based on user roles is ___.

ข้อ 57

A documented plan to restore IT systems after a disaster is the ___ recovery plan.

ข้อ 58

Match each security control type to its example.

ข้อ 59

Match each cryptography concept to its purpose.

ข้อ 60

Match each IAM concept to its meaning.