แบบฝึก CompTIA Security+

ฝึกข้อสอบ CompTIA Security+ ต้นฉบับ 80 ข้อครอบคลุมภัยคุกคาม ช่องโหว่ สถาปัตยกรรม อัตลักษณ์ การปฏิบัติการ และการกำกับดูแล

ระดับ: CompTIA Security+ ความยาก: intermediate 80 ข้อ 60 นาที
ตอบข้อสอบความปลอดภัยแต่ละข้อ แล้วตรวจคะแนน ข้อที่ผิดจะถูกบันทึกไว้ในเครื่องเพื่อทบทวน
จำนวนวันต่อเนื่อง: 0 วัน บันทึกเฉพาะอุปกรณ์นี้
ความคืบหน้า 0 / 80
ข้อ 1

A payroll file is silently changed so an employee receives a higher salary. Which security goal is violated?

เลือกคำตอบ
ข้อ 2

An employee receives an email that appears to come from IT and asks for a password due to "urgent account verification." Which attack is this?

เลือกคำตอบ
ข้อ 3

An attacker calls an employee, pretends to be from the help desk, and asks for a verification code. Which attack is this?

เลือกคำตอบ
ข้อ 4

A user receives a text message with a link to a fake package tracking page. Which attack is this?

เลือกคำตอบ
ข้อ 5

A campaign sends personalized emails to selected employees using their names, roles, and job context. Which attack is this?

เลือกคำตอบ
ข้อ 6

An attacker leaves a USB drive labeled "Salary Data" in a parking lot where employees will find it. Which social engineering technique is this?

เลือกคำตอบ
ข้อ 7

An attacker follows an employee through a badge-controlled door without using a badge. Which technique is this?

เลือกคำตอบ
ข้อ 8

An attacker watches a user type a PIN at an ATM. Which technique is this?

เลือกคำตอบ
ข้อ 9

A person recovers discarded documents containing account details from a trash bin. Which technique is this?

เลือกคำตอบ
ข้อ 10

An attacker compromises a website that employees of a target company visit frequently. Which technique is this?

เลือกคำตอบ
ข้อ 11

Malware encrypts files on a workstation and demands payment to restore them. Which type of malware is this?

เลือกคำตอบ
ข้อ 12

Malware appears to be a legitimate utility but installs a backdoor when executed. Which type of malware is this?

เลือกคำตอบ
ข้อ 13

Which malware can spread automatically across networks without requiring user interaction?

เลือกคำตอบ
ข้อ 14

Which malware hides deep inside the operating system to maintain privileged access and evade detection?

เลือกคำตอบ
ข้อ 15

A large group of compromised devices is used together to launch DDoS attacks. What is the group called?

เลือกคำตอบ
ข้อ 16

Which symptoms may indicate malware infection? Select all that apply.

เลือกคำตอบ
ข้อ 17

Which are social engineering techniques? Select all that apply.

เลือกคำตอบ
ข้อ 18

An email-based attack that targets a specific person using their name and context is called ___ phishing.

เลือกคำตอบ
ข้อ 19

Match each social engineering attack to its channel.

ข้อ 20

Match each malware type to its behavior.

ข้อ 21

A vulnerability exists in software, no vendor patch is available, and an attacker exploits it the same day it becomes known. What is this called?

เลือกคำตอบ
ข้อ 22

Which standardized scoring system measures the severity of a vulnerability?

เลือกคำตอบ
ข้อ 23

What is the main difference between a vulnerability scan and a penetration test?

เลือกคำตอบ
ข้อ 24

Why is a patch management process important?

เลือกคำตอบ
ข้อ 25

Which control best prevents SQL injection?

เลือกคำตอบ
ข้อ 26

An attacker injects a script that executes in another user browser. What should the developer apply to prevent this?

เลือกคำตอบ
ข้อ 27

Writing more data than a buffer can hold is known as what?

เลือกคำตอบ
ข้อ 28

An attacker forces a running process to load a malicious library. Which technique is this?

เลือกคำตอบ
ข้อ 29

Which encryption method uses the same key to encrypt and decrypt data?

เลือกคำตอบ
ข้อ 30

RSA uses which cryptographic model?

เลือกคำตอบ
ข้อ 31

Which cryptographic function provides integrity by producing a fixed-size digest?

เลือกคำตอบ
ข้อ 32

A document is signed with the sender private key. What does the recipient verify using the sender public key?

เลือกคำตอบ
ข้อ 33

What is the purpose of a digital certificate in PKI?

เลือกคำตอบ
ข้อ 34

A certificate is compromised before it expires. Which mechanisms allow clients to check its current status?

เลือกคำตอบ
ข้อ 35

Sending a secret key by email is unsafe because it travels in ___ text.

ข้อ 36

Which controls help verify data integrity? Select all that apply.

เลือกคำตอบ
ข้อ 37

Which practices reduce the risk of password cracking? Select all that apply.

เลือกคำตอบ
ข้อ 38

Match each cryptographic concept to its role.

ข้อ 39

The protocol that provides real-time certificate status checks is abbreviated ___.

ข้อ 40

Match each cryptographic technology to its typical use.

ข้อ 41

What does multi-factor authentication (MFA) require?

เลือกคำตอบ
ข้อ 42

Which authentication factor is "something you have"?

เลือกคำตอบ
ข้อ 43

Access is granted based on the user job role. Which access control model is this?

เลือกคำตอบ
ข้อ 44

Users should have only the permissions needed to perform their job. Which principle does this describe?

เลือกคำตอบ
ข้อ 45

Which system is designed to protect, rotate, and audit administrative account credentials?

เลือกคำตอบ
ข้อ 46

What is a key benefit of using a password manager?

เลือกคำตอบ
ข้อ 47

A user signs in once and can access multiple applications without signing in again. Which technology is this?

เลือกคำตอบ
ข้อ 48

Which device filters traffic based on a defined set of security rules?

เลือกคำตอบ
ข้อ 49

What distinguishes an intrusion prevention system (IPS) from an intrusion detection system (IDS)?

เลือกคำตอบ
ข้อ 50

How does network segmentation limit the impact of an attack?

เลือกคำตอบ
ข้อ 51

Which network zone is designed to host public-facing services while protecting the internal network?

เลือกคำตอบ
ข้อ 52

Which control inspects web traffic and protects applications from attacks such as XSS and SQL injection?

เลือกคำตอบ
ข้อ 53

What is a VPN primarily used for?

เลือกคำตอบ
ข้อ 54

A security model assumes no user or device is trusted by default, even inside the network. Which model is this?

เลือกคำตอบ
ข้อ 55

Which technology monitors endpoints and automatically responds to threats using behavioral detection?

เลือกคำตอบ
ข้อ 56

In the cloud shared responsibility model, which tasks typically remain the customer responsibility? Select all that apply.

เลือกคำตอบ
ข้อ 57

Which controls can help prevent lateral movement inside a network? Select all that apply.

เลือกคำตอบ
ข้อ 58

A security model that verifies every request before granting access is called ___ trust.

ข้อ 59

A hardware appliance that securely stores cryptographic keys and performs signing operations is called a hardware security ___.

ข้อ 60

Match each security control to where it primarily operates.

ข้อ 61

What should an incident response team do first during an active security incident?

เลือกคำตอบ
ข้อ 62

During an active ransomware outbreak, what is the first containment step?

เลือกคำตอบ
ข้อ 63

Why is chain of custody important in digital forensics?

เลือกคำตอบ
ข้อ 64

What should an investigator do before analyzing a forensic drive?

เลือกคำตอบ
ข้อ 65

Which system collects and correlates logs from many sources for alerting and analysis?

เลือกคำตอบ
ข้อ 66

Which log is most useful for detecting unauthorized account access?

เลือกคำตอบ
ข้อ 67

What does a data retention policy define?

เลือกคำตอบ
ข้อ 68

Which regulation focuses on personal data protection for individuals in the European Union?

เลือกคำตอบ
ข้อ 69

Which standard specifically addresses the protection of cardholder data?

เลือกคำตอบ
ข้อ 70

How is risk typically calculated?

เลือกคำตอบ
ข้อ 71

An organization purchases cyber insurance to handle potential financial losses. Which risk strategy is this?

เลือกคำตอบ
ข้อ 72

What is the main purpose of a business continuity plan (BCP)?

เลือกคำตอบ
ข้อ 73

Which metric defines the maximum tolerable data loss, measured in time?

เลือกคำตอบ
ข้อ 74

Which metric defines the maximum time allowed to restore operations after a disaster?

เลือกคำตอบ
ข้อ 75

A team walks through a scenario to review incident procedures without deploying changes. Which exercise is this?

เลือกคำตอบ
ข้อ 76

Which practices support forensic evidence integrity? Select all that apply.

เลือกคำตอบ
ข้อ 77

Which controls reduce insider threat risk? Select all that apply.

เลือกคำตอบ
ข้อ 78

The maximum acceptable data loss measured in time is the recovery point ___.

ข้อ 79

The documented sequence of evidence custody is called the chain of ___.

ข้อ 80

Match each incident response phase to its main action.