Luyện CompTIA Security+

Luyện 80 câu hỏi gốc về CompTIA Security+, bao gồm mối đe dọa, lỗ hổng, kiến trúc, danh tính, vận hành và quản trị.

Cấp độ: CompTIA Security+ Độ khó: intermediate 80 câu hỏi 60 phút
Trả lời từng câu bảo mật rồi kiểm tra điểm. Câu sai được lưu cục bộ để ôn lại.
Chuỗi ngày: 0 ngày Chỉ lưu trên thiết bị này
Tiến độ 0 / 80
Câu hỏi 1

A payroll file is silently changed so an employee receives a higher salary. Which security goal is violated?

Chọn một đáp án
Câu hỏi 2

An employee receives an email that appears to come from IT and asks for a password due to "urgent account verification." Which attack is this?

Chọn một đáp án
Câu hỏi 3

An attacker calls an employee, pretends to be from the help desk, and asks for a verification code. Which attack is this?

Chọn một đáp án
Câu hỏi 4

A user receives a text message with a link to a fake package tracking page. Which attack is this?

Chọn một đáp án
Câu hỏi 5

A campaign sends personalized emails to selected employees using their names, roles, and job context. Which attack is this?

Chọn một đáp án
Câu hỏi 6

An attacker leaves a USB drive labeled "Salary Data" in a parking lot where employees will find it. Which social engineering technique is this?

Chọn một đáp án
Câu hỏi 7

An attacker follows an employee through a badge-controlled door without using a badge. Which technique is this?

Chọn một đáp án
Câu hỏi 8

An attacker watches a user type a PIN at an ATM. Which technique is this?

Chọn một đáp án
Câu hỏi 9

A person recovers discarded documents containing account details from a trash bin. Which technique is this?

Chọn một đáp án
Câu hỏi 10

An attacker compromises a website that employees of a target company visit frequently. Which technique is this?

Chọn một đáp án
Câu hỏi 11

Malware encrypts files on a workstation and demands payment to restore them. Which type of malware is this?

Chọn một đáp án
Câu hỏi 12

Malware appears to be a legitimate utility but installs a backdoor when executed. Which type of malware is this?

Chọn một đáp án
Câu hỏi 13

Which malware can spread automatically across networks without requiring user interaction?

Chọn một đáp án
Câu hỏi 14

Which malware hides deep inside the operating system to maintain privileged access and evade detection?

Chọn một đáp án
Câu hỏi 15

A large group of compromised devices is used together to launch DDoS attacks. What is the group called?

Chọn một đáp án
Câu hỏi 16

Which symptoms may indicate malware infection? Select all that apply.

Chọn một đáp án
Câu hỏi 17

Which are social engineering techniques? Select all that apply.

Chọn một đáp án
Câu hỏi 18

An email-based attack that targets a specific person using their name and context is called ___ phishing.

Chọn một đáp án
Câu hỏi 19

Match each social engineering attack to its channel.

Câu hỏi 20

Match each malware type to its behavior.

Câu hỏi 21

A vulnerability exists in software, no vendor patch is available, and an attacker exploits it the same day it becomes known. What is this called?

Chọn một đáp án
Câu hỏi 22

Which standardized scoring system measures the severity of a vulnerability?

Chọn một đáp án
Câu hỏi 23

What is the main difference between a vulnerability scan and a penetration test?

Chọn một đáp án
Câu hỏi 24

Why is a patch management process important?

Chọn một đáp án
Câu hỏi 25

Which control best prevents SQL injection?

Chọn một đáp án
Câu hỏi 26

An attacker injects a script that executes in another user browser. What should the developer apply to prevent this?

Chọn một đáp án
Câu hỏi 27

Writing more data than a buffer can hold is known as what?

Chọn một đáp án
Câu hỏi 28

An attacker forces a running process to load a malicious library. Which technique is this?

Chọn một đáp án
Câu hỏi 29

Which encryption method uses the same key to encrypt and decrypt data?

Chọn một đáp án
Câu hỏi 30

RSA uses which cryptographic model?

Chọn một đáp án
Câu hỏi 31

Which cryptographic function provides integrity by producing a fixed-size digest?

Chọn một đáp án
Câu hỏi 32

A document is signed with the sender private key. What does the recipient verify using the sender public key?

Chọn một đáp án
Câu hỏi 33

What is the purpose of a digital certificate in PKI?

Chọn một đáp án
Câu hỏi 34

A certificate is compromised before it expires. Which mechanisms allow clients to check its current status?

Chọn một đáp án
Câu hỏi 35

Sending a secret key by email is unsafe because it travels in ___ text.

Câu hỏi 36

Which controls help verify data integrity? Select all that apply.

Chọn một đáp án
Câu hỏi 37

Which practices reduce the risk of password cracking? Select all that apply.

Chọn một đáp án
Câu hỏi 38

Match each cryptographic concept to its role.

Câu hỏi 39

The protocol that provides real-time certificate status checks is abbreviated ___.

Câu hỏi 40

Match each cryptographic technology to its typical use.

Câu hỏi 41

What does multi-factor authentication (MFA) require?

Chọn một đáp án
Câu hỏi 42

Which authentication factor is "something you have"?

Chọn một đáp án
Câu hỏi 43

Access is granted based on the user job role. Which access control model is this?

Chọn một đáp án
Câu hỏi 44

Users should have only the permissions needed to perform their job. Which principle does this describe?

Chọn một đáp án
Câu hỏi 45

Which system is designed to protect, rotate, and audit administrative account credentials?

Chọn một đáp án
Câu hỏi 46

What is a key benefit of using a password manager?

Chọn một đáp án
Câu hỏi 47

A user signs in once and can access multiple applications without signing in again. Which technology is this?

Chọn một đáp án
Câu hỏi 48

Which device filters traffic based on a defined set of security rules?

Chọn một đáp án
Câu hỏi 49

What distinguishes an intrusion prevention system (IPS) from an intrusion detection system (IDS)?

Chọn một đáp án
Câu hỏi 50

How does network segmentation limit the impact of an attack?

Chọn một đáp án
Câu hỏi 51

Which network zone is designed to host public-facing services while protecting the internal network?

Chọn một đáp án
Câu hỏi 52

Which control inspects web traffic and protects applications from attacks such as XSS and SQL injection?

Chọn một đáp án
Câu hỏi 53

What is a VPN primarily used for?

Chọn một đáp án
Câu hỏi 54

A security model assumes no user or device is trusted by default, even inside the network. Which model is this?

Chọn một đáp án
Câu hỏi 55

Which technology monitors endpoints and automatically responds to threats using behavioral detection?

Chọn một đáp án
Câu hỏi 56

In the cloud shared responsibility model, which tasks typically remain the customer responsibility? Select all that apply.

Chọn một đáp án
Câu hỏi 57

Which controls can help prevent lateral movement inside a network? Select all that apply.

Chọn một đáp án
Câu hỏi 58

A security model that verifies every request before granting access is called ___ trust.

Câu hỏi 59

A hardware appliance that securely stores cryptographic keys and performs signing operations is called a hardware security ___.

Câu hỏi 60

Match each security control to where it primarily operates.

Câu hỏi 61

What should an incident response team do first during an active security incident?

Chọn một đáp án
Câu hỏi 62

During an active ransomware outbreak, what is the first containment step?

Chọn một đáp án
Câu hỏi 63

Why is chain of custody important in digital forensics?

Chọn một đáp án
Câu hỏi 64

What should an investigator do before analyzing a forensic drive?

Chọn một đáp án
Câu hỏi 65

Which system collects and correlates logs from many sources for alerting and analysis?

Chọn một đáp án
Câu hỏi 66

Which log is most useful for detecting unauthorized account access?

Chọn một đáp án
Câu hỏi 67

What does a data retention policy define?

Chọn một đáp án
Câu hỏi 68

Which regulation focuses on personal data protection for individuals in the European Union?

Chọn một đáp án
Câu hỏi 69

Which standard specifically addresses the protection of cardholder data?

Chọn một đáp án
Câu hỏi 70

How is risk typically calculated?

Chọn một đáp án
Câu hỏi 71

An organization purchases cyber insurance to handle potential financial losses. Which risk strategy is this?

Chọn một đáp án
Câu hỏi 72

What is the main purpose of a business continuity plan (BCP)?

Chọn một đáp án
Câu hỏi 73

Which metric defines the maximum tolerable data loss, measured in time?

Chọn một đáp án
Câu hỏi 74

Which metric defines the maximum time allowed to restore operations after a disaster?

Chọn một đáp án
Câu hỏi 75

A team walks through a scenario to review incident procedures without deploying changes. Which exercise is this?

Chọn một đáp án
Câu hỏi 76

Which practices support forensic evidence integrity? Select all that apply.

Chọn một đáp án
Câu hỏi 77

Which controls reduce insider threat risk? Select all that apply.

Chọn một đáp án
Câu hỏi 78

The maximum acceptable data loss measured in time is the recovery point ___.

Câu hỏi 79

The documented sequence of evidence custody is called the chain of ___.

Câu hỏi 80

Match each incident response phase to its main action.