Browse all practice questions for the Certiport CyberSecurity Certification Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Ace the Certiport CyberSecurity Exam 2026 – Secure Your Spot as a Cyber Pro! course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What is the main goal of physical controls in cybersecurity?
  • What defines a DDoS (Distributed Denial of Service) attack?
  • Who is responsible for the upfront cost of the device in a CYOD model?
  • What is the main function of the Data Link Layer in the OSI model?
  • What are administrative controls primarily focused on?
  • What is a cold site?
  • What does the command ipconfig/ifconfig NOT provide information about?
  • Which of the following best describes the purpose of error monitoring in the Physical Layer?
  • What does data in motion refer to?
  • What characterizes an insider threat?
  • Why are botnets particularly dangerous?
  • What protocol is designed for network management?
  • What does the term 'Defense in Depth' refer to in cybersecurity?
  • Which control type is aimed at preventing problems before they occur?
  • Why is availability important in an information system?
  • What is the Principle of Least Privilege?
  • What is included in the infrastructure of a cyber threat?
  • What are detective controls designed to do?
  • What term describes tools used for delivering capability in cyber threats?
  • How does an Intrusion Detection System (IDS) primarily function?
  • What does DNS hijacking intend to accomplish?
  • What does multi-factor authentication (MFA) provide in a BYOD environment?
  • Which wireless security is considered the best for personal use?
  • Which example illustrates the consequence of a successful threat?
  • What does the command 'ls -l' do in a Linux environment?
  • Who might be included in the definition of a victim in cyber threats?
  • What is a key role of the Presentation Layer in the OSI model?
  • What function does the arp -a command provide?
  • Which term describes data that is preserved on a storage device?
  • What kind of backups does the term 'Sneakernet' refer to?
  • What capability does PowerShell provide to attackers regarding code injection?
  • In the COPE strategy, what is offered to employees?
  • What encryption standard does WPA2 utilize?
  • What type of information can application logs in the event viewer provide?
  • In cybersecurity, what is considered worse: a false positive or a false negative?
  • What does IMAP (Internet Message Access Protocol) allow users to do?
  • What does RAID 5 utilize to achieve fault tolerance?
  • In legal cases, what consequence could result from a broken chain of custody?
  • What port is used by the Remote Desktop Protocol (RDP)?
  • Which act focuses on the privacy of college student records?
  • What is the role of DHCP (Dynamic Host Configuration Protocol)?
  • What is a Disaster Recovery Plan (DRP) primarily concerned with?
  • Which protocol is used to test and verify network connectivity?
  • Which protocol uses port 53 for its operations?
  • Which protocol guarantees delivery of data through a connection-based approach?
  • Which type of device is classified as corporate-owned?
  • Which characteristic defines script kiddies?
  • What type of reconnaissance involves actively probing a network or system?
  • Which RAID configuration provides fault tolerance through data mirroring?
  • What is the primary objective of a DNS-based attack?
  • What does SSID stand for in a Wi-Fi network?
  • What do preventive controls focus on?
  • What does the ipconfig/ifconfig command display?
  • What is the primary function of a host-based intrusion detection system (HIDS)?
  • What is nonrepudiation in the context of cybersecurity?
  • What does the Diamond Model of Intrusion Analysis help information security professionals to do?
  • What is a common goal of ransomware?
  • What is the primary purpose of Mobile Device Management (MDM)?
  • Which of the following layers is included in the acronym "All People Seem To Need Data Processing"?
  • What is a host-based firewall?
  • Where is a Network-Based Intrusion Prevention System (NIPS) typically located?
  • What type of information is primarily found in system logs within the event viewer?
  • What is an incremental backup?
  • What is the primary requirement by NIST for BYOD devices in a HIPAA compliant environment?
  • Which of the following is a valid range for Private IP Addresses?
  • What is the primary function of a warmsite in disaster recovery?
  • What legal protection does HIPAA provide?
  • What is the purpose of authentication in cybersecurity?
  • What action can an attacker take to prevent internet access to users?
  • What aspect does technical control primarily cover in a cybersecurity framework?
  • What characterizes a hot site?
  • Which strategy enforces corporate policies for applications on mobile devices?
  • Which protocol is primarily used for querying DNS?
  • Which protocol is associated with port 161?
  • What type of protocol is UDP?
  • What is the main purpose of VPN authentication?
  • What does an Acceptable Use Policy (AUP) define?
  • What are social engineering attacks designed to do?
  • What does the risk of a data breach often include?
  • Why is RAID not used as a method of backup?
  • What vital role does a hypervisor play in computing?
  • Which form of backup is considered a valid daily method for protecting data?
  • What characterizes a half-open attack or SYN flood?
  • An example of an insider hacker is:
  • Which protocol operates on port 110 for email retrieval?
  • What does Common Vulnerabilities and Exposures (CVE) identify?
  • What is privilege escalation in the context of IT systems?
  • Which RAID configuration requires only one additional disk for redundancy and provides fault tolerance?
  • What is the primary purpose of establishing a chain of custody in forensics?
  • Which of the following represents a typical method of an insider threat?
  • Which protocol is associated with the Session Layer of the OSI model?
  • Which of the following could be a consequence of not maintaining the chain of custody?
  • What role does documentation play in the chain of custody?
  • What is the primary function of Wireshark in network management?
  • What does error code 513 CAP12 indicate?
  • What is a critical benefit of utilizing cloud computing services for data security?
  • In cybersecurity, what does the term 'capability' refer to?
  • PCI DSS is essential for protecting which type of data?
  • What is the role of SIEM in cybersecurity?
  • Why is it important to hide the SSID in a Wi-Fi network?
  • What is NOT a valid method of backing up data daily?
  • What is the purpose of a Demilitarized Zone (DMZ) in network security?
  • Which port is associated with the Lightweight Directory Access Protocol (LDAP)?
  • What is an Advanced Persistent Threat (APT)?
  • Which of the following describes a threat in cybersecurity?
  • What is the primary function of a Multi Layer Switch (Layer 3 switch)?
  • How does an attacker typically execute a DNS attack?
  • What is the key limitation of a Network-Based Intrusion Detection System (NIDS)?
  • Which term refers to the act of scanning for open ports and vulnerabilities?
  • Which of the following is NOT an example of a corrective control?
  • What does passive reconnaissance primarily involve?
  • Which principle is NOT a component of Information Assurance?
  • Which tool is widely used for network management and system security courses to troubleshoot?
  • What does the Session Layer manage between two nodes?
  • Which of the following is a common reason for successful cyber attacks?
  • What type of phishing attack utilizes voice communication?
  • What does social engineering rely on to be successful?
  • What is meant by data in processing or in use?
  • What is the primary goal of a warmsite?
  • Which of the following protocols operates at speeds of 1000 Mbps?
  • What security measure is recommended for unused ports?
  • What aspect of a dynamic routing technique helps in route selection?
  • What is one significant advantage of cloud computing regarding maintenance?
  • What is recommended as a security practice regarding the SSID?
  • Which method is used in smishing attacks?
  • Which aspect is NOT part of maintaining a chain of custody?
  • What are containers for phones used for?
  • Which of the following devices operates at the Physical Layer of the OSI model?
  • Which of the following best describes the concept of chain of custody?
  • Forensics relies on which fundamental concept to maintain evidence authenticity?
  • What key feature differentiates a managed switch from an unmanaged switch?
  • What is the function of SMTP (Simple Mail Transfer Protocol)?
  • What type of attack identifies a specific individual as the target using personalized information?
  • Which of the following is an added benefit of using a VPN?
  • What types of data does SIEM typically ingest?
  • Which OSI layer manages the encryption and decryption of data?
  • What is the implication of turning off unused ports in a network?
  • What does availability in cybersecurity ensure?
  • What is TCPDump used for?
  • What does SOAR primarily focus on in a security environment?
  • Which command would you use to list all active connections on your PC?
  • What does the tracert/traceroute command display?
  • Which group is most likely responsible for attacks from within a company?
  • Which layer of the OSI model is referred to as the Application Layer?
  • Why might competitors launch attacks against an opponent's system?
  • What is a key characteristic of spear phishing attacks?
  • Which of the following best describes a VPN's function?
  • Which Act regulates the privacy of consumer financial information?
  • What is an example of Shadow IT?
  • Who can be considered a victim in a cyber attack?
  • What does a differential backup do?
  • What is the primary risk associated with not using multi-factor authentication for BYOD devices?
  • What do vulnerabilities expose an organization to?
  • What is the purpose of MAC control on a Wi-Fi network?
  • What is the main focus of a Business Continuity Plan (BCP)?
  • Who are considered Nation State Actors in cybersecurity?
  • Which of the following is vital for ensuring the admissibility of evidence in court?
  • What type of software is ransomware?
  • What is the risk associated with a cyber threat?
  • What is the definition of malware?
  • What is the primary goal of information security?
  • What does a full backup entail?
  • What does the Netstat command provide information about?
  • How can evidence be best secured during an investigation?
  • What ports are commonly associated with File Transfer Protocol (FTP)?
  • What is the main characteristic of RAID 0?
  • To ensure data safety, what is a recommended backup practice?
  • Which of these statements accurately describes NAT’s capability?
  • What is the key element in preserving the integrity of evidence during an investigation?
  • What describes insiders in a cybersecurity context?
  • What is the goal of Information Assurance?
  • Which type of reconnaissance involves actively probing for vulnerabilities?
  • What defines a threat actor?
  • Which type of WPA is designed for business environments?
  • What services are provided by the Transport Layer?
  • What is meant by the term 'At Rest' in cybersecurity?
  • What does Mobile Content Management (MCM) primarily assist IT admins with?
  • Which method can help prevent spoofing in cybersecurity?
  • What does BYOD stand for in a cybersecurity context?
  • What is the objective of a Business Continuity Plan (BCP)?
  • How often should the Principle of Least Privilege be reviewed in a business setting?
  • What function does Network Address Translation (NAT) serve?
  • Which type of backup allows for the most efficient storage use?
  • What function does the Syslog protocol serve in IT environments?
  • What common outcome can be caused by substituting an invalid MAC address?
  • What can be inferred from the overall CVSS score assigned to a vulnerability?
  • What does integrity in information security guarantee?
  • What does Nmap primarily do?
  • What defines a Zero Day Attack?
  • Which command is useful for determining the IP address of a target hostname?
  • What does confidentiality in cybersecurity focus on?
  • What are botnets?
  • Which system continuously monitors a network and can take action to prevent malicious activity?
  • What layer of the OSI model is responsible for generating and detecting signals for data transmission?
  • What is the purpose of the CVE list?
  • What does a Host-Based Intrusion Prevention System (HIPS) primarily do?
  • Which port is used by Telnet for remote communication?
  • Which type of attack is characterized by leaving unsecured connections open?
  • When does the chain of custody begin?
  • Which of the following actions violates the chain of custody?
  • What do corrective controls aim to achieve?
  • In terms of cybersecurity, what does the term "nonrepudiation" mean?
  • What type of documentation is essential for maintaining the chain of custody?
  • What is a characteristic of a managed switch?
  • In terms of cybersecurity, what does DRP stand for?
  • Which of the following is NOT listed as a reason for successful cyber attacks?
  • What does the protocol HTTPS indicate?
  • What is the main characteristic of APT attacks?
  • Which of the following is an example of a physical control in cybersecurity?
  • What is essential for performing audits and monitoring in IT operations?
  • Which technology allows a computer to run multiple operating systems at the same time?
  • What is the main characteristic of a man-in-the-middle (MITM) attack?
  • What does NAC (Network Access Control) do?
  • What type of data is considered 'data in transit'?
  • What is the purpose of the nslookup/dig command?
  • Which of the following is NOT a characteristic of a cold site?
  • What information does Nbtstat display?
  • FISMA is aimed at ensuring what type of information protection?
  • Dynamic routing allows a router to do what without administrative intervention?
  • Which layer of the OSI model is responsible for routing data?
  • What kind of security does 'defense in depth' provide?
  • Which of the following is a characteristic of criminal syndicates in the context of cyber threats?
  • What is the concept of Shadow IT?
  • What is the purpose of HTTP (Hypertext Transfer Protocol)?
  • Which of the following describes Mobile Application Management (MAM)?
  • What is the main goal of limiting user access rights according to the Principle of Least Privilege?
  • What does the National Vulnerability Database (NVD) maintain?
  • Which type of threat actor is typically motivated by financial gain?
  • What does the term 'data at rest' encompass?
  • What do technical controls in cybersecurity encompass?
  • War driving is an example of what type of reconnaissance?
  • What does 'In Processing' refer to in the realm of information security?
  • What is the primary focus of the Gramm-Leach-Bliley Act (GLBA)?
  • What type of hacker is classified as a hacktivist?
  • Which protocol typically uses port 443?
  • Which protocol is NOT part of the Transport Layer?
  • Who is referred to as an adversary in the context of cybersecurity?
  • What does a Disaster Recovery Plan (DRP) primarily concentrate on?
  • What does FileVault do on a MAC system?
  • What is a potential risk of not using proper Mobile Device Management?
  • What is the main use of port 80?
  • What do suspicious logins or repetitive bad logins in Security logs typically indicate?
  • How does a proxy server contribute to online privacy?
  • What ensures that only authorized users can modify data according to cybersecurity principles?
  • How does a host-based detection system signal an intrusion?
  • What is PowerShell primarily known for?
  • Unified Equipment Management (UEM) combines which of the following?
  • In what way can an attacker steal data from another device?
  • Which tools can be utilized to see IP addresses within a network?
  • What is the main function of Virtual Desktop Infrastructure (VDI)?
  • What technology is primarily used to detect vulnerabilities against applications or computers?
  • What is the primary purpose of SSH (Secure Shell)?
  • What is the main function of a firewall in network security?
  • What does the General Data Protection Regulation (GDPR) aim to protect?
  • What is war flying primarily used for in reconnaissance?
  • What is the purpose of a honeypot in cybersecurity?
  • What is a Man-in-the-Middle Attack (MITM)?
  • Why might hackers target PowerShell?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy