CompTIA Security+ 练习题

通过 80 道原创题练习 CompTIA Security+,覆盖威胁、漏洞、架构、身份、运营与治理。

等级: CompTIA Security+ 难度: intermediate 80 道题 60 分钟
回答每道安全题,然后查看得分。错题会保存在本机供复习。
连续学习: 0 天 仅保存在此设备
进度 0 / 80
题目 1

A payroll file is silently changed so an employee receives a higher salary. Which security goal is violated?

选择一个答案
题目 2

An employee receives an email that appears to come from IT and asks for a password due to "urgent account verification." Which attack is this?

选择一个答案
题目 3

An attacker calls an employee, pretends to be from the help desk, and asks for a verification code. Which attack is this?

选择一个答案
题目 4

A user receives a text message with a link to a fake package tracking page. Which attack is this?

选择一个答案
题目 5

A campaign sends personalized emails to selected employees using their names, roles, and job context. Which attack is this?

选择一个答案
题目 6

An attacker leaves a USB drive labeled "Salary Data" in a parking lot where employees will find it. Which social engineering technique is this?

选择一个答案
题目 7

An attacker follows an employee through a badge-controlled door without using a badge. Which technique is this?

选择一个答案
题目 8

An attacker watches a user type a PIN at an ATM. Which technique is this?

选择一个答案
题目 9

A person recovers discarded documents containing account details from a trash bin. Which technique is this?

选择一个答案
题目 10

An attacker compromises a website that employees of a target company visit frequently. Which technique is this?

选择一个答案
题目 11

Malware encrypts files on a workstation and demands payment to restore them. Which type of malware is this?

选择一个答案
题目 12

Malware appears to be a legitimate utility but installs a backdoor when executed. Which type of malware is this?

选择一个答案
题目 13

Which malware can spread automatically across networks without requiring user interaction?

选择一个答案
题目 14

Which malware hides deep inside the operating system to maintain privileged access and evade detection?

选择一个答案
题目 15

A large group of compromised devices is used together to launch DDoS attacks. What is the group called?

选择一个答案
题目 16

Which symptoms may indicate malware infection? Select all that apply.

选择一个答案
题目 17

Which are social engineering techniques? Select all that apply.

选择一个答案
题目 18

An email-based attack that targets a specific person using their name and context is called ___ phishing.

选择一个答案
题目 19

Match each social engineering attack to its channel.

题目 20

Match each malware type to its behavior.

题目 21

A vulnerability exists in software, no vendor patch is available, and an attacker exploits it the same day it becomes known. What is this called?

选择一个答案
题目 22

Which standardized scoring system measures the severity of a vulnerability?

选择一个答案
题目 23

What is the main difference between a vulnerability scan and a penetration test?

选择一个答案
题目 24

Why is a patch management process important?

选择一个答案
题目 25

Which control best prevents SQL injection?

选择一个答案
题目 26

An attacker injects a script that executes in another user browser. What should the developer apply to prevent this?

选择一个答案
题目 27

Writing more data than a buffer can hold is known as what?

选择一个答案
题目 28

An attacker forces a running process to load a malicious library. Which technique is this?

选择一个答案
题目 29

Which encryption method uses the same key to encrypt and decrypt data?

选择一个答案
题目 30

RSA uses which cryptographic model?

选择一个答案
题目 31

Which cryptographic function provides integrity by producing a fixed-size digest?

选择一个答案
题目 32

A document is signed with the sender private key. What does the recipient verify using the sender public key?

选择一个答案
题目 33

What is the purpose of a digital certificate in PKI?

选择一个答案
题目 34

A certificate is compromised before it expires. Which mechanisms allow clients to check its current status?

选择一个答案
题目 35

Sending a secret key by email is unsafe because it travels in ___ text.

题目 36

Which controls help verify data integrity? Select all that apply.

选择一个答案
题目 37

Which practices reduce the risk of password cracking? Select all that apply.

选择一个答案
题目 38

Match each cryptographic concept to its role.

题目 39

The protocol that provides real-time certificate status checks is abbreviated ___.

题目 40

Match each cryptographic technology to its typical use.

题目 41

What does multi-factor authentication (MFA) require?

选择一个答案
题目 42

Which authentication factor is "something you have"?

选择一个答案
题目 43

Access is granted based on the user job role. Which access control model is this?

选择一个答案
题目 44

Users should have only the permissions needed to perform their job. Which principle does this describe?

选择一个答案
题目 45

Which system is designed to protect, rotate, and audit administrative account credentials?

选择一个答案
题目 46

What is a key benefit of using a password manager?

选择一个答案
题目 47

A user signs in once and can access multiple applications without signing in again. Which technology is this?

选择一个答案
题目 48

Which device filters traffic based on a defined set of security rules?

选择一个答案
题目 49

What distinguishes an intrusion prevention system (IPS) from an intrusion detection system (IDS)?

选择一个答案
题目 50

How does network segmentation limit the impact of an attack?

选择一个答案
题目 51

Which network zone is designed to host public-facing services while protecting the internal network?

选择一个答案
题目 52

Which control inspects web traffic and protects applications from attacks such as XSS and SQL injection?

选择一个答案
题目 53

What is a VPN primarily used for?

选择一个答案
题目 54

A security model assumes no user or device is trusted by default, even inside the network. Which model is this?

选择一个答案
题目 55

Which technology monitors endpoints and automatically responds to threats using behavioral detection?

选择一个答案
题目 56

In the cloud shared responsibility model, which tasks typically remain the customer responsibility? Select all that apply.

选择一个答案
题目 57

Which controls can help prevent lateral movement inside a network? Select all that apply.

选择一个答案
题目 58

A security model that verifies every request before granting access is called ___ trust.

题目 59

A hardware appliance that securely stores cryptographic keys and performs signing operations is called a hardware security ___.

题目 60

Match each security control to where it primarily operates.

题目 61

What should an incident response team do first during an active security incident?

选择一个答案
题目 62

During an active ransomware outbreak, what is the first containment step?

选择一个答案
题目 63

Why is chain of custody important in digital forensics?

选择一个答案
题目 64

What should an investigator do before analyzing a forensic drive?

选择一个答案
题目 65

Which system collects and correlates logs from many sources for alerting and analysis?

选择一个答案
题目 66

Which log is most useful for detecting unauthorized account access?

选择一个答案
题目 67

What does a data retention policy define?

选择一个答案
题目 68

Which regulation focuses on personal data protection for individuals in the European Union?

选择一个答案
题目 69

Which standard specifically addresses the protection of cardholder data?

选择一个答案
题目 70

How is risk typically calculated?

选择一个答案
题目 71

An organization purchases cyber insurance to handle potential financial losses. Which risk strategy is this?

选择一个答案
题目 72

What is the main purpose of a business continuity plan (BCP)?

选择一个答案
题目 73

Which metric defines the maximum tolerable data loss, measured in time?

选择一个答案
题目 74

Which metric defines the maximum time allowed to restore operations after a disaster?

选择一个答案
题目 75

A team walks through a scenario to review incident procedures without deploying changes. Which exercise is this?

选择一个答案
题目 76

Which practices support forensic evidence integrity? Select all that apply.

选择一个答案
题目 77

Which controls reduce insider threat risk? Select all that apply.

选择一个答案
题目 78

The maximum acceptable data loss measured in time is the recovery point ___.

题目 79

The documented sequence of evidence custody is called the chain of ___.

题目 80

Match each incident response phase to its main action.