信管网每日一练
信息安全工程师 - 每日一练 导航

信息安全工程师每日一练试题(2025/7/21)

2025年07月22日来源:信管网 作者:cnitpm

信息安全工程师当天每日一练试题地址:www.cnitpm.com/exam/ExamDay.aspx?t1=6

往期信息安全工程师每日一练试题汇总:www.cnitpm.com/class/27/e6_1.html

信息安全工程师每日一练试题(2025/7/21)在线测试:www.cnitpm.com/exam/ExamDay.aspx?t1=6&day=2025/7/21

点击查看:更多信息安全工程师习题与指导

信息安全工程师每日一练试题内容(2025/7/21)

  • 试题1

    信息通过网络进行传输的过程中,存在着被篡改的风险,为了解决这一安全问题,通常采用的安全防护技术是()
    A、加密技术
    B、匿名技术
    C、消息认证技术
    D、数据备份技术

    查看答案

    试题参考答案:C

    试题解析与讨论:www.cnitpm.com/exam/ExamDay.aspx?t1=6&day=2025/7/21

  • 试题2

    Perhaps the most obvious difference between private-key and public-key encryption is that the former assumes complete secrecy of all cry to graphic keys, whereas the latter requires secrecy for only the private key.Although this may seem like a minor distinction ,the ramifications are huge: in the private-key setting the communicating parties must somehow be able to share the (71) key without allowing any third party to learn it, whereas in the public-key setting the (72) key can be sent from one party to the other over a public channel without compromising security.For parties shouting across a room or, more realistically , communicating over a public network like a phone line or then ternet, public-key encryption is the only option.
    Another important distinction is that private-key encryption sch emesuse the (73) key for both encryption and decryption, whereas public key encryption schemes use (74) keys for each operation.That is public-key encryption is inherently as ymmetri C.This asymmetry in the public-key setting means that the roles of sender and receiver are not interchangeable as they are in the private-key setting; a single key-pair allows communication in one direction only.(Bidirectional communication can be achieved in a number of ways; the point is that a single invocation of a public-key encryption scheme forces ad is tinction between one user who acts as a receiver and other users who act as senders.)。In addition, a single instance of a (75) encryption scheme enables multiple senders to communicate privately with a single receiver,in contrast to the private-key case where a secret key shared between two parties enables private communication only between those two parties.
    (1) A.main
    B.same
    C.public
    D.secret
    (2) A.stream
    B.different
    C.public
    D.secret
    (3) A.different
    B.same
    C.public
    D.private
    (4) A.different
    B.same
    C.public
    D.private
    (5) A.private-key
    B.public-key
    C.stream
    D.Hash


    查看答案

    试题参考答案:D、C、B、A、B

    试题解析与讨论:www.cnitpm.com/exam/ExamDay.aspx?t1=6&day=2025/7/21

  • 试题3

    以下(  )是对基于异常事件访问控制规则的应用。
    A.下班时间不允许远程访问服务器
    B.重要的服务器只可以本地访问
    C.当用户登录失败多次后,冻结账户
    D.网站的服务能力接近某个阈值时,禁止访问

    查看答案

    试题参考答案:C

    试题解析与讨论:www.cnitpm.com/exam/ExamDay.aspx?t1=6&day=2025/7/21

  • 试题4

    There are different ways to perform IP based DoS Attacks. The most common IP based DoS attack is that an attacker sends an extensive amount of connection establishment (1)(e.g. TCP SYN requests) to establish hanging connections with the controller or a DPS. Such a way, the attacker can consume the network resources which should be available for legitimate users. In other (2), the attacker inserts a large amount of (3)packets to the data plane by spoofing all or part of the header fields with random values. These incoming packets will trigger table-misses and send lots of packet-in flow request messages to the network controller to saturate the controller resources. In some cases, an (4)who gains access to DPS can artificially generate lots of random packet-in flow request messages to saturate the control channel and the controller resources. Moreover, the lack of diversity among DPSs fuels fuels the fast propagation of such attacks.
    Legacy mobile backhaul devices are inherently protected against the propagation of attacks due to complex and vendor specific equipment. Moreover, legacy backhaul devices do not require frequent communication with core control devices in a manner similar to DPSs communicating with the centralized controller. These features minimize both the impact and propagation of DoS attacks. Moreover, the legacy backhaul devices are controlled as a joint effort of multiple network element. For instance, a single Long Term Evilution(LTE)eNodeB  is connected up to 32 MMEs. Therefore, DoS/DDoS attack on a single core element will not terminate the entire operation of a backhaul device(5)the net work.

    (1)A.message  B、information  C、requests  D、data
    (2)A.methods  B、cases       C、hands    D、sections
    (3)A.bad      B、real        C、fake      D、new
    (4)A.user     B、administrator  C、editor   D、attacker
    (5)A.or       B、of          C、in        D、to

    查看答案

    试题参考答案:C、B、C、D、A

    试题解析与讨论:www.cnitpm.com/exam/ExamDay.aspx?t1=6&day=2025/7/21

  • 试题5

    (   )保护IP包的保密性,(   )保护IP包的完整性和提供数据源认证。
    A.IP AH,IP ESP
    B.IP AH,密钥交换协议
    C.IP ESP,密钥交换协议
    D.IP ESP,IP AH

    查看答案

    试题参考答案:D

    试题解析与讨论:www.cnitpm.com/exam/ExamDay.aspx?t1=6&day=2025/7/21

  • 试题6

    下列报告中,不属于信息安全风险评估识别阶段的是()
    A、资产价值分析报告
    B、风险评估报告
    C、威胁分析报告
    D、已有安全威胁分析报告

    查看答案

    试题参考答案:B

    试题解析与讨论:www.cnitpm.com/exam/ExamDay.aspx?t1=6&day=2025/7/21

  • 试题7

    工控系统广泛应用于电力、石化、医药、航天等领域,已经成为国家关键基础设施的重要组成部分。作为信息基础设施的基础,电力工控系统安全面临的主要威胁不包括()
    A.内部人为风险
    B.黑客攻击
    C.设备损耗
    D.病毒破坏

    查看答案

    试题参考答案:C

    试题解析与讨论:www.cnitpm.com/exam/ExamDay.aspx?t1=6&day=2025/7/21

  • 试题8

    关于SYN Flood,一下,描述错误的是(   )
    A.SYN Flood攻击是在TCP三次握手过程中产生的
    B.这种攻击方式会使目标服务器连接资源耗尽、链路堵塞
    C.管理员不可以通过调整TCP堆栈以减缓SYN泛洪攻击的影响。
    D.管理员可以在内存中为每个SYN请求创建一个小索引,而不必把整个连接对象存入内存

    查看答案

    试题参考答案:C

    试题解析与讨论:www.cnitpm.com/exam/ExamDay.aspx?t1=6&day=2025/7/21

  • 试题9

    Stuxnet(震网病毒)主要攻击了(   )公司的工业控制系统。
    A.微软
    B.西门子
    C.通用电气
    D.霍尼韦尔

    查看答案

    试题参考答案:B

    试题解析与讨论:www.cnitpm.com/exam/ExamDay.aspx?t1=6&day=2025/7/21

  • 试题10

    在乌克兰电厂停电时间中,黑客发动(   )攻击电力客服中心,致使电厂工作人员无法立即进行电力维修工作。
    A.DDoS攻击
    B.SQL注入
    C.代理技术
    D.漏洞扫描

    查看答案

    试题参考答案:A

    试题解析与讨论:www.cnitpm.com/exam/ExamDay.aspx?t1=6&day=2025/7/21

温馨提示:因考试政策、内容不断变化与调整,信管网提供的以上信息仅供参考,如有异议,请考生以权威部门公布的内容为准!

分享至:

信管网 - 信息系统项目管理专业网站

下载APP-在线学习