Browse all practice questions for the Certiport CyberSecurity Certification Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Certiport CyberSecurity Certification Practice Exam 2026 - Free CyberSecurity Practice Questions and Study Guide course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What is the primary purpose of Mobile Device Management (MDM)?
  • How does an Intrusion Detection System (IDS) primarily function?
  • What is a characteristic of a managed switch?
  • What is the primary purpose of establishing a chain of custody in forensics?
  • What is the main function of the Data Link Layer in the OSI model?
  • What ensures that only authorized users can modify data according to cybersecurity principles?
  • What is included in the infrastructure of a cyber threat?
  • What information does Nbtstat display?
  • PCI DSS is essential for protecting which type of data?
  • Which layer of the OSI model is responsible for routing data?
  • Which of the following describes Mobile Application Management (MAM)?
  • How does an attacker typically execute a DNS attack?
  • Which command would you use to list all active connections on your PC?
  • What function does the arp -a command provide?
  • What does RAID 5 utilize to achieve fault tolerance?
  • What is the primary function of a host-based intrusion detection system (HIDS)?
  • What function does Network Address Translation (NAT) serve?
  • What do preventive controls focus on?
  • Which strategy enforces corporate policies for applications on mobile devices?
  • What is an Advanced Persistent Threat (APT)?
  • Dynamic routing allows a router to do what without administrative intervention?
  • Which of the following best describes the concept of chain of custody?
  • What is a host-based firewall?
  • Which port is used by Telnet for remote communication?
  • What is the primary focus of the Gramm-Leach-Bliley Act (GLBA)?
  • Why is it important to hide the SSID in a Wi-Fi network?
  • How does a proxy server contribute to online privacy?
  • How can evidence be best secured during an investigation?
  • What does NAC (Network Access Control) do?
  • What does Common Vulnerabilities and Exposures (CVE) identify?
  • What is the primary requirement by NIST for BYOD devices in a HIPAA compliant environment?
  • What type of phishing attack utilizes voice communication?
  • What is the key limitation of a Network-Based Intrusion Detection System (NIDS)?
  • Which protocol is used to test and verify network connectivity?
  • What is meant by the term 'At Rest' in cybersecurity?
  • What is the main function of a firewall in network security?
  • An example of an insider hacker is:
  • What common outcome can be caused by substituting an invalid MAC address?
  • Which of the following best describes a VPN's function?
  • Which of the following is vital for ensuring the admissibility of evidence in court?
  • What layer of the OSI model is responsible for generating and detecting signals for data transmission?
  • Which group is most likely responsible for attacks from within a company?
  • What legal protection does HIPAA provide?
  • What does a Disaster Recovery Plan (DRP) primarily concentrate on?
  • Which RAID configuration provides fault tolerance through data mirroring?
  • What do corrective controls aim to achieve?
  • What is the main goal of physical controls in cybersecurity?
  • What characterizes a hot site?
  • Which control type is aimed at preventing problems before they occur?
  • What does the protocol HTTPS indicate?
  • How does a host-based detection system signal an intrusion?
  • What is recommended as a security practice regarding the SSID?
  • What term describes tools used for delivering capability in cyber threats?
  • What is the risk associated with a cyber threat?
  • Why might hackers target PowerShell?
  • What security measure is recommended for unused ports?
  • What is a common goal of ransomware?
  • Which of the following is NOT listed as a reason for successful cyber attacks?
  • What key feature differentiates a managed switch from an unmanaged switch?
  • What is the primary risk associated with not using multi-factor authentication for BYOD devices?
  • What does 'In Processing' refer to in the realm of information security?
  • What does the ipconfig/ifconfig command display?
  • What is PowerShell primarily known for?
  • Which of the following actions violates the chain of custody?
  • Which type of threat actor is typically motivated by financial gain?
  • Which act focuses on the privacy of college student records?
  • What are botnets?
  • Who might be included in the definition of a victim in cyber threats?
  • What is NOT a valid method of backing up data daily?
  • What is nonrepudiation in the context of cybersecurity?
  • What encryption standard does WPA2 utilize?
  • Which protocol is associated with port 161?
  • Which of the following is an example of a physical control in cybersecurity?
  • What does DNS hijacking intend to accomplish?
  • Which system continuously monitors a network and can take action to prevent malicious activity?
  • Which tools can be utilized to see IP addresses within a network?
  • What does passive reconnaissance primarily involve?
  • What are detective controls designed to do?
  • What is the role of DHCP (Dynamic Host Configuration Protocol)?
  • What is the main function of Virtual Desktop Infrastructure (VDI)?
  • What does SSID stand for in a Wi-Fi network?
  • What do suspicious logins or repetitive bad logins in Security logs typically indicate?
  • What is the purpose of authentication in cybersecurity?
  • Why might competitors launch attacks against an opponent's system?
  • What is the function of SMTP (Simple Mail Transfer Protocol)?
  • What is the role of SIEM in cybersecurity?
  • What protocol is designed for network management?
  • Which of the following protocols operates at speeds of 1000 Mbps?
  • What services are provided by the Transport Layer?
  • What does the Netstat command provide information about?
  • What is the definition of malware?
  • What does the General Data Protection Regulation (GDPR) aim to protect?
  • What does IMAP (Internet Message Access Protocol) allow users to do?
  • What type of protocol is UDP?
  • Which type of reconnaissance involves actively probing for vulnerabilities?
  • What type of documentation is essential for maintaining the chain of custody?
  • What is the main characteristic of APT attacks?
  • Forensics relies on which fundamental concept to maintain evidence authenticity?
  • Why are botnets particularly dangerous?
  • Which term describes data that is preserved on a storage device?
  • In terms of cybersecurity, what does the term "nonrepudiation" mean?
  • Which protocol is associated with the Session Layer of the OSI model?
  • What type of hacker is classified as a hacktivist?
  • What type of attack identifies a specific individual as the target using personalized information?
  • What is war flying primarily used for in reconnaissance?
  • What is the primary purpose of SSH (Secure Shell)?
  • What is a potential risk of not using proper Mobile Device Management?
  • What port is used by the Remote Desktop Protocol (RDP)?
  • Which OSI layer manages the encryption and decryption of data?
  • What is a critical benefit of utilizing cloud computing services for data security?
  • Which of the following is a characteristic of criminal syndicates in the context of cyber threats?
  • Which layer of the OSI model is referred to as the Application Layer?
  • What is the main use of port 80?
  • What does integrity in information security guarantee?
  • What is the concept of Shadow IT?
  • What is a cold site?
  • What is the purpose of HTTP (Hypertext Transfer Protocol)?
  • What is privilege escalation in the context of IT systems?
  • What does a differential backup do?
  • Which type of WPA is designed for business environments?
  • Which Act regulates the privacy of consumer financial information?
  • What are social engineering attacks designed to do?
  • In cybersecurity, what does the term 'capability' refer to?
  • What does the Diamond Model of Intrusion Analysis help information security professionals to do?
  • Which of the following could be a consequence of not maintaining the chain of custody?
  • Why is RAID not used as a method of backup?
  • What does FileVault do on a MAC system?
  • Which RAID configuration requires only one additional disk for redundancy and provides fault tolerance?
  • Which port is associated with the Lightweight Directory Access Protocol (LDAP)?
  • What kind of backups does the term 'Sneakernet' refer to?
  • What does the tracert/traceroute command display?
  • What does the risk of a data breach often include?
  • What type of information is primarily found in system logs within the event viewer?
  • What characterizes an insider threat?
  • When does the chain of custody begin?
  • What is a key characteristic of spear phishing attacks?
  • What function does the Syslog protocol serve in IT environments?
  • What is the key element in preserving the integrity of evidence during an investigation?
  • What is the main characteristic of RAID 0?
  • What is a key role of the Presentation Layer in the OSI model?
  • What is the objective of a Business Continuity Plan (BCP)?
  • What aspect does technical control primarily cover in a cybersecurity framework?
  • What is the goal of Information Assurance?
  • What is the Principle of Least Privilege?
  • Which type of backup allows for the most efficient storage use?
  • To ensure data safety, what is a recommended backup practice?
  • What are containers for phones used for?
  • What does error code 513 CAP12 indicate?
  • Which type of device is classified as corporate-owned?
  • What kind of security does 'defense in depth' provide?
  • What is an incremental backup?
  • What defines a DDoS (Distributed Denial of Service) attack?
  • What is the main goal of limiting user access rights according to the Principle of Least Privilege?
  • Which example illustrates the consequence of a successful threat?
  • Why is availability important in an information system?
  • What is the purpose of a Demilitarized Zone (DMZ) in network security?
  • Which type of attack is characterized by leaving unsecured connections open?
  • In the COPE strategy, what is offered to employees?
  • What is the primary objective of a DNS-based attack?
  • What does multi-factor authentication (MFA) provide in a BYOD environment?
  • What does Mobile Content Management (MCM) primarily assist IT admins with?
  • Which protocol is NOT part of the Transport Layer?
  • Which protocol operates on port 110 for email retrieval?
  • What does a Host-Based Intrusion Prevention System (HIPS) primarily do?
  • Which of the following is NOT an example of a corrective control?
  • Who can be considered a victim in a cyber attack?
  • Which method can help prevent spoofing in cybersecurity?
  • Which of the following is an added benefit of using a VPN?
  • In terms of cybersecurity, what does DRP stand for?
  • Which form of backup is considered a valid daily method for protecting data?
  • What is the main purpose of VPN authentication?
  • Which of the following describes a threat in cybersecurity?
  • In what way can an attacker steal data from another device?
  • What ports are commonly associated with File Transfer Protocol (FTP)?
  • What does social engineering rely on to be successful?
  • What does the term 'Defense in Depth' refer to in cybersecurity?
  • What is the primary function of a Multi Layer Switch (Layer 3 switch)?
  • Which technology allows a computer to run multiple operating systems at the same time?
  • What is the main focus of a Business Continuity Plan (BCP)?
  • Which characteristic defines script kiddies?
  • What is an example of Shadow IT?
  • Which of the following layers is included in the acronym "All People Seem To Need Data Processing"?
  • Which of the following best describes the purpose of error monitoring in the Physical Layer?
  • Which protocol guarantees delivery of data through a connection-based approach?
  • What does the term 'data at rest' encompass?
  • What do technical controls in cybersecurity encompass?
  • Which of the following devices operates at the Physical Layer of the OSI model?
  • Which wireless security is considered the best for personal use?
  • Who is referred to as an adversary in the context of cybersecurity?
  • Which tool is widely used for network management and system security courses to troubleshoot?
  • What types of data does SIEM typically ingest?
  • What defines a threat actor?
  • What is the implication of turning off unused ports in a network?
  • What is the purpose of the CVE list?
  • What is the main characteristic of a man-in-the-middle (MITM) attack?
  • What does SOAR primarily focus on in a security environment?
  • What does data in motion refer to?
  • What is the purpose of the nslookup/dig command?
  • What does an Acceptable Use Policy (AUP) define?
  • What describes insiders in a cybersecurity context?
  • Which of the following represents a typical method of an insider threat?
  • What is the primary goal of a warmsite?
  • What is one significant advantage of cloud computing regarding maintenance?
  • In legal cases, what consequence could result from a broken chain of custody?
  • Which protocol uses port 53 for its operations?
  • In cybersecurity, what is considered worse: a false positive or a false negative?
  • Which method is used in smishing attacks?
  • Which command is useful for determining the IP address of a target hostname?
  • What aspect of a dynamic routing technique helps in route selection?
  • What is the primary function of a warmsite in disaster recovery?
  • What role does documentation play in the chain of custody?
  • What is the purpose of a honeypot in cybersecurity?
  • What type of data is considered 'data in transit'?
  • Which principle is NOT a component of Information Assurance?
  • Which aspect is NOT part of maintaining a chain of custody?
  • What is TCPDump used for?
  • What does the Session Layer manage between two nodes?
  • Unified Equipment Management (UEM) combines which of the following?
  • What does BYOD stand for in a cybersecurity context?
  • What type of software is ransomware?
  • What is a Man-in-the-Middle Attack (MITM)?
  • What is the primary function of Wireshark in network management?
  • What does Nmap primarily do?
  • What does a full backup entail?
  • Who are considered Nation State Actors in cybersecurity?
  • What characterizes a half-open attack or SYN flood?
  • What defines a Zero Day Attack?
  • What are administrative controls primarily focused on?
  • War driving is an example of what type of reconnaissance?
  • What type of information can application logs in the event viewer provide?
  • How often should the Principle of Least Privilege be reviewed in a business setting?
  • What vital role does a hypervisor play in computing?
  • What does availability in cybersecurity ensure?
  • What action can an attacker take to prevent internet access to users?
  • FISMA is aimed at ensuring what type of information protection?
  • What does confidentiality in cybersecurity focus on?
  • What does the command ipconfig/ifconfig NOT provide information about?
  • What is the purpose of MAC control on a Wi-Fi network?
  • What does the command 'ls -l' do in a Linux environment?
  • Which of these statements accurately describes NAT’s capability?
  • Which of the following is a common reason for successful cyber attacks?
  • What is meant by data in processing or in use?
  • What type of reconnaissance involves actively probing a network or system?
  • What do vulnerabilities expose an organization to?
  • What can be inferred from the overall CVSS score assigned to a vulnerability?
  • What is the primary goal of information security?
  • Which of the following is a valid range for Private IP Addresses?
  • Which protocol is primarily used for querying DNS?
  • Which of the following is NOT a characteristic of a cold site?
  • Who is responsible for the upfront cost of the device in a CYOD model?
  • Where is a Network-Based Intrusion Prevention System (NIPS) typically located?
  • What is essential for performing audits and monitoring in IT operations?
  • Which term refers to the act of scanning for open ports and vulnerabilities?
  • What technology is primarily used to detect vulnerabilities against applications or computers?
  • What does the National Vulnerability Database (NVD) maintain?
  • What is a Disaster Recovery Plan (DRP) primarily concerned with?
  • Which protocol typically uses port 443?
  • What capability does PowerShell provide to attackers regarding code injection?
  • Hacktivists mainly perform attacks for what purpose?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy