Cybersecurity-Einstufungstest

Kostenloser Test — kein Konto erforderlich
Beantworten Sie alle Fragen nach bestem Wissen. Das Ergebnis hilft dabei, Ihr aktuelles Niveau einzuschätzen und einen geeigneten Lernweg zu empfehlen.
Frage 1 von 40

What is the primary role of an operating system?

Bitte wählen Sie eine Antwort aus.
Frage 2 von 40

What is an IP address primarily used for?

Bitte wählen Sie eine Antwort aus.
Frage 3 von 40

What is the main function of a router?

Bitte wählen Sie eine Antwort aus.
Frage 4 von 40

What does DNS commonly do?

Bitte wählen Sie eine Antwort aus.
Frage 5 von 40

Which statement best describes TCP?

Bitte wählen Sie eine Antwort aus.
Frage 6 von 40

What is a firewall primarily designed to do?

Bitte wählen Sie eine Antwort aus.
Frage 7 von 40

Which term describes software intentionally designed to cause harm, steal information, or perform unauthorized actions?

Bitte wählen Sie eine Antwort aus.
Frage 8 von 40

A message pretending to be from a trusted organization asks you to click a link and enter your password. What type of attack is this most likely?

Bitte wählen Sie eine Antwort aus.
Frage 9 von 40

What is the main security benefit of multi-factor authentication (MFA)?

Bitte wählen Sie eine Antwort aus.
Frage 10 von 40

Which password practice is generally the most secure?

Bitte wählen Sie eine Antwort aus.
Frage 11 von 40

What is the primary purpose of encryption?

Bitte wählen Sie eine Antwort aus.
Frage 12 von 40

Which statement best describes cryptographic hashing?

Bitte wählen Sie eine Antwort aus.
Frage 13 von 40

In cybersecurity, what is a vulnerability?

Bitte wählen Sie eine Antwort aus.
Frage 14 von 40

Why are security patches important?

Bitte wählen Sie eine Antwort aus.
Frage 15 von 40

What does the principle of least privilege mean?

Bitte wählen Sie eine Antwort aus.
Frage 16 von 40

In the CIA security triad, what does confidentiality focus on?

Bitte wählen Sie eine Antwort aus.
Frage 17 von 40

In information security, integrity primarily means:

Bitte wählen Sie eine Antwort aus.
Frage 18 von 40

Why are tested backups important in cybersecurity?

Bitte wählen Sie eine Antwort aus.
Frage 19 von 40

You suspect that a workstation has been compromised. Which action is generally most appropriate?

Bitte wählen Sie eine Antwort aus.
Frage 20 von 40

What is social engineering in cybersecurity?

Bitte wählen Sie eine Antwort aus.
Frage 21 von 40

A host has the address 192.168.10.130/26. Which network address contains this host?

Bitte wählen Sie eine Antwort aus.
Frage 22 von 40

During a normal TCP connection establishment, which sequence represents the three-way handshake?

Bitte wählen Sie eine Antwort aus.
Frage 23 von 40

A browser receives a TLS certificate whose hostname does not match the website being visited. What security property has primarily failed?

Bitte wählen Sie eine Antwort aus.
Frage 24 von 40

A web application safely parameterizes all SQL queries, but places untrusted user input directly into HTML responses without context-appropriate output encoding. Which vulnerability remains most relevant?

Bitte wählen Sie eine Antwort aus.
Frage 25 von 40

A SIEM observes a successful login immediately after hundreds of failed authentication attempts against the same account from one external source. What should an analyst investigate first?

Bitte wählen Sie eine Antwort aus.
Frage 26 von 40

EDR detects a suspicious process spawning PowerShell with an encoded command followed by outbound communication to an unusual host. What is the most appropriate immediate defensive action when organizational procedures allow it?

Bitte wählen Sie eine Antwort aus.
Frage 27 von 40

Why is membership in a highly privileged Active Directory administrative group particularly sensitive?

Bitte wählen Sie eine Antwort aus.
Frage 28 von 40

An attacker compromises a standard user account and then exploits a local misconfiguration to obtain SYSTEM-level privileges. Which stage best describes the second action?

Bitte wählen Sie eine Antwort aus.
Frage 29 von 40

A security analyst observes unusually large numbers of Kerberos service-ticket requests for many service accounts from a single workstation. Which activity should be considered during investigation?

Bitte wählen Sie eine Antwort aus.
Frage 30 von 40

After compromising one workstation, an attacker uses stolen credentials to authenticate to additional internal systems. Which term best describes this behavior?

Bitte wählen Sie eine Antwort aus.
Frage 31 von 40

Two vulnerabilities have similar CVSS scores. One is Internet-exposed, has reliable exploitation observed in the wild, and affects a critical authentication server. The other exists only on an isolated test system. Which should normally receive higher remediation priority?

Bitte wählen Sie eine Antwort aus.
Frage 32 von 40

An internal workstation makes small encrypted outbound connections to the same uncommon external host at highly regular intervals, including when no user is active. Which hypothesis deserves investigation?

Bitte wählen Sie eine Antwort aus.
Frage 33 von 40

A threat hunter has an indicator for one malicious domain but wants to identify related activity even if the adversary changes domains. Which approach is generally more resilient?

Bitte wählen Sie eine Antwort aus.
Frage 34 von 40

During incident response, malware is suspected of injecting code into another running process without leaving a clear executable on disk. Which evidence source is especially valuable?

Bitte wählen Sie eine Antwort aus.
Frage 35 von 40

A cloud workload normally reads objects from one storage bucket. Its identity suddenly receives a broad wildcard permission across multiple services. What is the strongest security concern?

Bitte wählen Sie eine Antwort aus.
Frage 36 von 40

An enterprise root certificate authority private key is confirmed compromised. Why is this a severe incident?

Bitte wählen Sie eine Antwort aus.
Frage 37 von 40

A workstation shows a burst of Kerberos service-ticket requests for privileged service accounts, followed shortly by successful remote logons to several servers using one of those accounts. Which interpretation best connects the evidence?

Bitte wählen Sie eine Antwort aus.
Frage 38 von 40

A compromised endpoint may contain fileless malware, active network sessions, injected processes, and short-lived credentials. The system must eventually be rebuilt. Which evidence collection priority best preserves volatile investigative value?

Bitte wählen Sie eine Antwort aus.
Frage 39 von 40

An adversary frequently changes filenames, hashes, IP addresses, and domains but repeatedly uses the same unusual parent-child process chain and credential-access behavior. Which detection strategy is likely to remain effective longest?

Bitte wählen Sie eine Antwort aus.
Frage 40 von 40

An organization observes a suspicious document spawning a script interpreter, credential-access alerts on the endpoint, unusual privileged authentication to multiple servers, and periodic encrypted outbound connections from those servers. Which response best reflects expert incident handling?

Bitte wählen Sie eine Antwort aus.
Es wird kein Studentenkonto erstellt und dieser Versuch wird nicht im Moodle-Notenbuch gespeichert.