Luyện tập chứng chỉ bảo mật CISSP

Luyện tập 60 câu hỏi CISSP về quản trị, rủi ro, bảo mật tài sản, kiến trúc, mạng, IAM, vận hành và phát triển an toàn.

Cấp độ: CISSP Độ khó: advanced 60 câu hỏi 60 phút
Trả lời từng câu hỏi CISSP, chọn hoặc nhập câu trả lời, sau đó xem lời giải. Câu trả lời sai được lưu cục bộ.
Chuỗi ngày: 0 ngày Chỉ lưu trên thiết bị này
Tiến độ 0 / 60
Câu hỏi 1

Which CISSP domain covers security governance, risk management, and legal compliance?

Chọn một đáp án
Câu hỏi 2

Which access principle means users receive only the permissions required for their role?

Chọn một đáp án
Câu hỏi 3

Which type of security control detects and reports a security incident?

Chọn một đáp án
Câu hỏi 4

What is the primary purpose of a risk assessment?

Chọn một đáp án
Câu hỏi 5

What is residual risk?

Chọn một đáp án
Câu hỏi 6

Which security document states management expectations and is typically high-level?

Chọn một đáp án
Câu hỏi 7

What is separation of duties designed to prevent?

Chọn một đáp án
Câu hỏi 8

What is defense in depth?

Chọn một đáp án
Câu hỏi 9

Which security goal protects data from unauthorized disclosure?

Chọn một đáp án
Câu hỏi 10

Which security goal ensures data is not modified without authorization?

Chọn một đáp án
Câu hỏi 11

Which security goal ensures systems remain accessible to authorized users?

Chọn một đáp án
Câu hỏi 12

What is authentication?

Chọn một đáp án
Câu hỏi 13

What is authorization?

Chọn một đáp án
Câu hỏi 14

Which mechanism provides non-repudiation?

Chọn một đáp án
Câu hỏi 15

What is the main purpose of cryptography?

Chọn một đáp án
Câu hỏi 16

Which encryption type uses the same key for encryption and decryption?

Chọn một đáp án
Câu hỏi 17

In public-key cryptography, which key is used to encrypt a message sent to a recipient?

Chọn một đáp án
Câu hỏi 18

What is a cryptographic hash primarily used for?

Chọn một đáp án
Câu hỏi 19

Which network device filters traffic based on rules?

Chọn một đáp án
Câu hỏi 20

What is a VLAN used for?

Chọn một đáp án
Câu hỏi 21

Which protocol provides encrypted communication for web traffic?

Chọn một đáp án
Câu hỏi 22

Which technology creates an encrypted tunnel for remote network access?

Chọn một đáp án
Câu hỏi 23

What is a DMZ?

Chọn một đáp án
Câu hỏi 24

Which concept describes classifying data and applying protection based on its sensitivity?

Chọn một đáp án
Câu hỏi 25

What is Identity and Access Management (IAM)?

Chọn một đáp án
Câu hỏi 26

What is a directory service?

Chọn một đáp án
Câu hỏi 27

Which authentication factor is described as something the user knows?

Chọn một đáp án
Câu hỏi 28

Which authentication factor is described as something the user has?

Chọn một đáp án
Câu hỏi 29

Which authentication factor is described as something the user is?

Chọn một đáp án
Câu hỏi 30

What is single sign-on (SSO)?

Chọn một đáp án
Câu hỏi 31

What is multi-factor authentication?

Chọn một đáp án
Câu hỏi 32

What is privileged access management?

Chọn một đáp án
Câu hỏi 33

What does SIEM provide?

Chọn một đáp án
Câu hỏi 34

What does SOAR stand for?

Chọn một đáp án
Câu hỏi 35

What is a vulnerability scan?

Chọn một đáp án
Câu hỏi 36

What is a penetration test?

Chọn một đáp án
Câu hỏi 37

Which incident response activity limits the scope of an incident?

Chọn một đáp án
Câu hỏi 38

What is the purpose of a business continuity plan (BCP)?

Chọn một đáp án
Câu hỏi 39

What is a disaster recovery plan (DRP)?

Chọn một đáp án
Câu hỏi 40

Which secure coding practice prevents injection attacks?

Chọn một đáp án
Câu hỏi 41

Which of the following are core security objectives in the CIA triad? Select all that apply.

Chọn một đáp án
Câu hỏi 42

Which of the following are access control models? Select all that apply.

Chọn một đáp án
Câu hỏi 43

Which of the following are authentication factors? Select all that apply.

Chọn một đáp án
Câu hỏi 44

Which of the following are symmetric encryption algorithms? Select all that apply.

Chọn một đáp án
Câu hỏi 45

Which of the following are asymmetric cryptography algorithms? Select all that apply.

Chọn một đáp án
Câu hỏi 46

Which of the following are phases of incident response? Select all that apply.

Chọn một đáp án
Câu hỏi 47

Which of the following are secure development practices? Select all that apply.

Chọn một đáp án
Câu hỏi 48

Confidentiality means information is available to everyone at all times.

Chọn một đáp án
Câu hỏi 49

A vulnerability is the same thing as an exploit.

Chọn một đáp án
Câu hỏi 50

Data remanence is a concern when decommissioning storage media.

Chọn một đáp án
Câu hỏi 51

Symmetric encryption is generally faster than asymmetric encryption.

Chọn một đáp án
Câu hỏi 52

The principle of least privilege means granting all users administrator access by default.

Chọn một đáp án
Câu hỏi 53

The security goal that protects data from unauthorized modification is ___.

Câu hỏi 54

The process of confirming a user claimed identity is ___.

Câu hỏi 55

A ___ encrypts traffic between a user and a remote network.

Câu hỏi 56

The access control model that grants rights based on user roles is ___.

Câu hỏi 57

A documented plan to restore IT systems after a disaster is the ___ recovery plan.

Câu hỏi 58

Match each security control type to its example.

Câu hỏi 59

Match each cryptography concept to its purpose.

Câu hỏi 60

Match each IAM concept to its meaning.