اختبار تحديد المستوى في الأمن السيبراني

اختبار مجاني بدون إنشاء حساب
أجب عن جميع الأسئلة بأفضل ما تستطيع. النتيجة تساعدنا على تقدير مستواك واقتراح المسار المناسب لك.
السؤال 1 من 40

What is the primary role of an operating system?

يرجى اختيار إجابة قبل المتابعة.
السؤال 2 من 40

What is an IP address primarily used for?

يرجى اختيار إجابة قبل المتابعة.
السؤال 3 من 40

What is the main function of a router?

يرجى اختيار إجابة قبل المتابعة.
السؤال 4 من 40

What does DNS commonly do?

يرجى اختيار إجابة قبل المتابعة.
السؤال 5 من 40

Which statement best describes TCP?

يرجى اختيار إجابة قبل المتابعة.
السؤال 6 من 40

What is a firewall primarily designed to do?

يرجى اختيار إجابة قبل المتابعة.
السؤال 7 من 40

Which term describes software intentionally designed to cause harm, steal information, or perform unauthorized actions?

يرجى اختيار إجابة قبل المتابعة.
السؤال 8 من 40

A message pretending to be from a trusted organization asks you to click a link and enter your password. What type of attack is this most likely?

يرجى اختيار إجابة قبل المتابعة.
السؤال 9 من 40

What is the main security benefit of multi-factor authentication (MFA)?

يرجى اختيار إجابة قبل المتابعة.
السؤال 10 من 40

Which password practice is generally the most secure?

يرجى اختيار إجابة قبل المتابعة.
السؤال 11 من 40

What is the primary purpose of encryption?

يرجى اختيار إجابة قبل المتابعة.
السؤال 12 من 40

Which statement best describes cryptographic hashing?

يرجى اختيار إجابة قبل المتابعة.
السؤال 13 من 40

In cybersecurity, what is a vulnerability?

يرجى اختيار إجابة قبل المتابعة.
السؤال 14 من 40

Why are security patches important?

يرجى اختيار إجابة قبل المتابعة.
السؤال 15 من 40

What does the principle of least privilege mean?

يرجى اختيار إجابة قبل المتابعة.
السؤال 16 من 40

In the CIA security triad, what does confidentiality focus on?

يرجى اختيار إجابة قبل المتابعة.
السؤال 17 من 40

In information security, integrity primarily means:

يرجى اختيار إجابة قبل المتابعة.
السؤال 18 من 40

Why are tested backups important in cybersecurity?

يرجى اختيار إجابة قبل المتابعة.
السؤال 19 من 40

You suspect that a workstation has been compromised. Which action is generally most appropriate?

يرجى اختيار إجابة قبل المتابعة.
السؤال 20 من 40

What is social engineering in cybersecurity?

يرجى اختيار إجابة قبل المتابعة.
السؤال 21 من 40

A host has the address 192.168.10.130/26. Which network address contains this host?

يرجى اختيار إجابة قبل المتابعة.
السؤال 22 من 40

During a normal TCP connection establishment, which sequence represents the three-way handshake?

يرجى اختيار إجابة قبل المتابعة.
السؤال 23 من 40

A browser receives a TLS certificate whose hostname does not match the website being visited. What security property has primarily failed?

يرجى اختيار إجابة قبل المتابعة.
السؤال 24 من 40

A web application safely parameterizes all SQL queries, but places untrusted user input directly into HTML responses without context-appropriate output encoding. Which vulnerability remains most relevant?

يرجى اختيار إجابة قبل المتابعة.
السؤال 25 من 40

A SIEM observes a successful login immediately after hundreds of failed authentication attempts against the same account from one external source. What should an analyst investigate first?

يرجى اختيار إجابة قبل المتابعة.
السؤال 26 من 40

EDR detects a suspicious process spawning PowerShell with an encoded command followed by outbound communication to an unusual host. What is the most appropriate immediate defensive action when organizational procedures allow it?

يرجى اختيار إجابة قبل المتابعة.
السؤال 27 من 40

Why is membership in a highly privileged Active Directory administrative group particularly sensitive?

يرجى اختيار إجابة قبل المتابعة.
السؤال 28 من 40

An attacker compromises a standard user account and then exploits a local misconfiguration to obtain SYSTEM-level privileges. Which stage best describes the second action?

يرجى اختيار إجابة قبل المتابعة.
السؤال 29 من 40

A security analyst observes unusually large numbers of Kerberos service-ticket requests for many service accounts from a single workstation. Which activity should be considered during investigation?

يرجى اختيار إجابة قبل المتابعة.
السؤال 30 من 40

After compromising one workstation, an attacker uses stolen credentials to authenticate to additional internal systems. Which term best describes this behavior?

يرجى اختيار إجابة قبل المتابعة.
السؤال 31 من 40

Two vulnerabilities have similar CVSS scores. One is Internet-exposed, has reliable exploitation observed in the wild, and affects a critical authentication server. The other exists only on an isolated test system. Which should normally receive higher remediation priority?

يرجى اختيار إجابة قبل المتابعة.
السؤال 32 من 40

An internal workstation makes small encrypted outbound connections to the same uncommon external host at highly regular intervals, including when no user is active. Which hypothesis deserves investigation?

يرجى اختيار إجابة قبل المتابعة.
السؤال 33 من 40

A threat hunter has an indicator for one malicious domain but wants to identify related activity even if the adversary changes domains. Which approach is generally more resilient?

يرجى اختيار إجابة قبل المتابعة.
السؤال 34 من 40

During incident response, malware is suspected of injecting code into another running process without leaving a clear executable on disk. Which evidence source is especially valuable?

يرجى اختيار إجابة قبل المتابعة.
السؤال 35 من 40

A cloud workload normally reads objects from one storage bucket. Its identity suddenly receives a broad wildcard permission across multiple services. What is the strongest security concern?

يرجى اختيار إجابة قبل المتابعة.
السؤال 36 من 40

An enterprise root certificate authority private key is confirmed compromised. Why is this a severe incident?

يرجى اختيار إجابة قبل المتابعة.
السؤال 37 من 40

A workstation shows a burst of Kerberos service-ticket requests for privileged service accounts, followed shortly by successful remote logons to several servers using one of those accounts. Which interpretation best connects the evidence?

يرجى اختيار إجابة قبل المتابعة.
السؤال 38 من 40

A compromised endpoint may contain fileless malware, active network sessions, injected processes, and short-lived credentials. The system must eventually be rebuilt. Which evidence collection priority best preserves volatile investigative value?

يرجى اختيار إجابة قبل المتابعة.
السؤال 39 من 40

An adversary frequently changes filenames, hashes, IP addresses, and domains but repeatedly uses the same unusual parent-child process chain and credential-access behavior. Which detection strategy is likely to remain effective longest?

يرجى اختيار إجابة قبل المتابعة.
السؤال 40 من 40

An organization observes a suspicious document spawning a script interpreter, credential-access alerts on the endpoint, unusual privileged authentication to multiple servers, and periodic encrypted outbound connections from those servers. Which response best reflects expert incident handling?

يرجى اختيار إجابة قبل المتابعة.
لا يتم إنشاء حساب طالب ولا تسجيل هذه المحاولة في سجل درجات Moodle.