CISSP 安全认证练习

通过 60 道 CISSP 题练习治理、风险、资产安全、架构、网络安全、IAM、安全运营和安全开发。

等级: CISSP 难度: advanced 60 道题 60 分钟
回答每道 CISSP 题,选择或输入答案,然后查看解析。错题会保存在本机供复习。
连续学习: 0 天 仅保存在此设备
进度 0 / 60
题目 1

Which CISSP domain covers security governance, risk management, and legal compliance?

选择一个答案
题目 2

Which access principle means users receive only the permissions required for their role?

选择一个答案
题目 3

Which type of security control detects and reports a security incident?

选择一个答案
题目 4

What is the primary purpose of a risk assessment?

选择一个答案
题目 5

What is residual risk?

选择一个答案
题目 6

Which security document states management expectations and is typically high-level?

选择一个答案
题目 7

What is separation of duties designed to prevent?

选择一个答案
题目 8

What is defense in depth?

选择一个答案
题目 9

Which security goal protects data from unauthorized disclosure?

选择一个答案
题目 10

Which security goal ensures data is not modified without authorization?

选择一个答案
题目 11

Which security goal ensures systems remain accessible to authorized users?

选择一个答案
题目 12

What is authentication?

选择一个答案
题目 13

What is authorization?

选择一个答案
题目 14

Which mechanism provides non-repudiation?

选择一个答案
题目 15

What is the main purpose of cryptography?

选择一个答案
题目 16

Which encryption type uses the same key for encryption and decryption?

选择一个答案
题目 17

In public-key cryptography, which key is used to encrypt a message sent to a recipient?

选择一个答案
题目 18

What is a cryptographic hash primarily used for?

选择一个答案
题目 19

Which network device filters traffic based on rules?

选择一个答案
题目 20

What is a VLAN used for?

选择一个答案
题目 21

Which protocol provides encrypted communication for web traffic?

选择一个答案
题目 22

Which technology creates an encrypted tunnel for remote network access?

选择一个答案
题目 23

What is a DMZ?

选择一个答案
题目 24

Which concept describes classifying data and applying protection based on its sensitivity?

选择一个答案
题目 25

What is Identity and Access Management (IAM)?

选择一个答案
题目 26

What is a directory service?

选择一个答案
题目 27

Which authentication factor is described as something the user knows?

选择一个答案
题目 28

Which authentication factor is described as something the user has?

选择一个答案
题目 29

Which authentication factor is described as something the user is?

选择一个答案
题目 30

What is single sign-on (SSO)?

选择一个答案
题目 31

What is multi-factor authentication?

选择一个答案
题目 32

What is privileged access management?

选择一个答案
题目 33

What does SIEM provide?

选择一个答案
题目 34

What does SOAR stand for?

选择一个答案
题目 35

What is a vulnerability scan?

选择一个答案
题目 36

What is a penetration test?

选择一个答案
题目 37

Which incident response activity limits the scope of an incident?

选择一个答案
题目 38

What is the purpose of a business continuity plan (BCP)?

选择一个答案
题目 39

What is a disaster recovery plan (DRP)?

选择一个答案
题目 40

Which secure coding practice prevents injection attacks?

选择一个答案
题目 41

Which of the following are core security objectives in the CIA triad? Select all that apply.

选择一个答案
题目 42

Which of the following are access control models? Select all that apply.

选择一个答案
题目 43

Which of the following are authentication factors? Select all that apply.

选择一个答案
题目 44

Which of the following are symmetric encryption algorithms? Select all that apply.

选择一个答案
题目 45

Which of the following are asymmetric cryptography algorithms? Select all that apply.

选择一个答案
题目 46

Which of the following are phases of incident response? Select all that apply.

选择一个答案
题目 47

Which of the following are secure development practices? Select all that apply.

选择一个答案
题目 48

Confidentiality means information is available to everyone at all times.

选择一个答案
题目 49

A vulnerability is the same thing as an exploit.

选择一个答案
题目 50

Data remanence is a concern when decommissioning storage media.

选择一个答案
题目 51

Symmetric encryption is generally faster than asymmetric encryption.

选择一个答案
题目 52

The principle of least privilege means granting all users administrator access by default.

选择一个答案
题目 53

The security goal that protects data from unauthorized modification is ___.

题目 54

The process of confirming a user claimed identity is ___.

题目 55

A ___ encrypts traffic between a user and a remote network.

题目 56

The access control model that grants rights based on user roles is ___.

题目 57

A documented plan to restore IT systems after a disaster is the ___ recovery plan.

题目 58

Match each security control type to its example.

题目 59

Match each cryptography concept to its purpose.

题目 60

Match each IAM concept to its meaning.