CertSafari

    Free CompTIA Security+ Sample Questions

    35 free sample questions from our bank of 346+, covering every exam domain, with answers and detailed explanations. Updated October 2026.

    Domain 1: General Security Concepts

    Subdomain 1.1: Compare and contrast various types of security controls.

    1.Which TWO classifications apply to a board-approved information security policy that tells employees which behavior is required?(Select 2)

    1. A.Managerial category
    2. B.Physical category
    3. C.Directive control type
    4. D.Corrective control type
    5. E.Technical category
    Show answer & explanation

    Correct answers: A, C — Managerial category; Directive control type

    • A. Managerial controls govern the security program through policy, risk management, and oversight. A leadership-approved policy is a textbook managerial control.
    • B. Physical controls protect facilities and equipment, such as fences and badge readers. A written policy document does not restrict physical access.
    • C. Directive controls state what is required or prohibited, and a policy that sets mandatory employee behavior is the standard example.
    • D. Corrective controls limit impact or restore normal operation after an incident. A policy that states required behavior in advance is not a recovery measure.
    • E. Technical controls are enforced by hardware or software, such as firewalls and encryption. A policy document relies on people to follow it, so it is not technical.

    Subdomain 1.4: Explain the importance of using appropriate cryptographic solutions.

    2.An administrator installs a certificate issued for *.example.com on a load balancer that serves shop.example.com, api.example.com and a.dev.example.com. Which result should the administrator expect?

    1. A.Hosts under any other domain owned by the same company validate too, because the CA verified the organization when it issued the certificate
    2. B.Only example.com itself validates, because wildcard characters are accepted solely in the organization field of the subject name
    3. C.shop.example.com and a.dev.example.com validate, because the wildcard matches any number of labels to the left of the domain
    4. D.shop.example.com and api.example.com validate, but a.dev.example.com fails, because the wildcard matches only a single label
    Show answer & explanation

    Correct answer: D — shop.example.com and api.example.com validate, but a.dev.example.com fails, because the wildcard matches only a single label

    • A. Incorrect. A wildcard certificate is bound to the names it lists, and validating the organization does not extend coverage to other domains.
    • B. Incorrect. The wildcard appears in the name field, and it matches subdomains, so shop.example.com and api.example.com are covered.
    • C. Incorrect. A wildcard replaces exactly one DNS label, so a multi-level name such as a.dev.example.com is not matched.
    • D. Correct. The asterisk stands for one label, so single-level subdomains are covered, while a two-level name needs its own entry or a second wildcard such as *.dev.example.com.

    Subdomain 1.3: Explain the importance of change management processes and the impact to security.

    3.What benefit does storing firewall and server configuration files in a version control system provide for change management?

    1. A.Removal of the need for approvals, because every commit is tracked and any earlier revision can be redeployed later
    2. B.A history of who changed what and when, plus the ability to compare revisions and restore a known-good configuration
    3. C.Automatic blocking of any configuration that violates the allow list before it can ever reach the production devices
    4. D.Automatic encryption of every stored file at rest, which removes the need for access controls on the configuration repository
    Show answer & explanation

    Correct answer: B — A history of who changed what and when, plus the ability to compare revisions and restore a known-good configuration

    • A. Incorrect. Tracking commits supports accountability but does not replace the approval process that authorizes changes.
    • B. Correct. Version control records authorship and timing, supports diffing between versions, and makes rollback to a known-good state straightforward.
    • C. Incorrect. Version control stores and tracks files; it does not enforce allow list policy on devices unless separate tooling is added.
    • D. Incorrect. Encryption at rest is a separate storage feature, and repositories still need access controls to prevent unauthorized edits.

    Subdomain 1.2: Summarize fundamental security concepts.

    4.Which AAA function records session start and stop times and the commands an administrator ran on a network device so that activity can be reviewed later?

    1. A.Authorization, which checks the user's group membership to decide which commands the account may run on the device
    2. B.Accounting, which logs the user's activity during the session so that it can be audited and attributed afterward
    3. C.Federation, which lets the device trust identity assertions issued by a partner organization's identity provider
    4. D.Authentication, which validates the supplied credentials against the directory before any session is allowed to begin
    Show answer & explanation

    Correct answer: B — Accounting, which logs the user's activity during the session so that it can be audited and attributed afterward

    • A. Authorization decides what an authenticated user is permitted to do, but it produces a permit or deny decision rather than a record of the activity that took place.
    • B. Accounting is the AAA function that tracks what an authenticated user did, including session timing and commands, which supports auditing, billing, and forensics.
    • C. Federation extends trust across identity providers so users can sign in with external identities. It is not one of the three AAA functions and records nothing about commands.
    • D. Authentication proves who the user is at the start of the session; it does not keep a running record of the commands executed after login.

    Subdomain 1.2: Summarize fundamental security concepts.

    5.A warehouse is unlit at night and the security team wants an alarm when a person walks through. The sensor must detect the intruder's emitted body heat and must not transmit any signal of its own. Which sensor fits?

    1. A.Infrared sensor, which detects the thermal radiation of a warm body passing through its field of view
    2. B.Pressure sensor, which triggers when weight is applied to a mat or floor tile in the monitored area
    3. C.Ultrasonic sensor, which emits high-frequency sound and detects changes in the echo caused by movement
    4. D.Microwave sensor, which sends out microwave pulses and watches the reflections for signs of motion
    Show answer & explanation

    Correct answer: A — Infrared sensor, which detects the thermal radiation of a warm body passing through its field of view

    • A. A passive infrared sensor detects the heat a person radiates, works in total darkness, and transmits nothing, which matches every requirement.
    • B. A pressure sensor reacts to weight, not heat, and a person could avoid the mat. It also does not rely on thermal radiation as the stem requires.
    • C. An ultrasonic sensor is also active, since it emits sound waves and listens for echo changes. It detects motion rather than body heat.
    • D. A microwave sensor is active: it transmits pulses and measures their reflection. That contradicts the requirement that the sensor emits nothing.

    Domain 2: Threats, Vulnerabilities, and Mitigations

    Subdomain 2.1: Compare and contrast common threat actors and motivations.

    6.A marketing team, frustrated by slow IT approvals, begins sharing customer lists through a personal cloud storage account and a free project-tracking app the security team has never reviewed. What does this behavior represent?

    1. A.Organized crime, an external source of risk because the cloud provider resells the customer lists for profit
    2. B.A nation-state operation, an internal source of risk because foreign agents recruited the team for collection
    3. C.Shadow IT, an internal source of risk because unapproved services sit outside security controls
    4. D.Hacktivism, an external source of risk because the team protests IT policy by exposing company data
    Show answer & explanation

    Correct answer: C — Shadow IT, an internal source of risk because unapproved services sit outside security controls

    • A. Incorrect. Nothing shows a criminal party involved, and the risk comes from the team's own unsanctioned adoption of the services.
    • B. Incorrect. The scenario describes convenience-driven workarounds, not a recruited insider or a directed intelligence operation.
    • C. Correct. Shadow IT is the use of hardware, software or services without IT approval, which leaves data outside logging, DLP and access governance.
    • D. Incorrect. The team is not attacking for a cause and is not external; it is simply working around controls to get work done.

    Subdomain 2.1: Compare and contrast common threat actors and motivations.

    7.A third-party contractor is given a VPN account and read access to the finance share for a six-month audit. Security reviews are scoping the threat model. How should the contractor be treated under the internal/external attribute of threat actors?

    1. A.As an external actor, because the contractor is not on the payroll and works for a different company
    2. B.As an unskilled actor, because auditors typically lack the technical expertise to exploit systems
    3. C.As an external actor, because VPN connections originate outside the corporate network address space
    4. D.As an internal actor, because the account grants trusted access inside the perimeter
    Show answer & explanation

    Correct answer: D — As an internal actor, because the account grants trusted access inside the perimeter

    • A. Incorrect. Payroll status is not the deciding factor; the contractor's authorized access gives insider-level reach to the finance share.
    • B. Incorrect. Sophistication is a separate attribute from internal/external, and it cannot be inferred from the contractor's job title.
    • C. Incorrect. Connecting remotely does not make someone external once credentials authenticate them into trusted resources.
    • D. Correct. The internal/external attribute depends on access and trust, so a contractor with valid credentials is modeled like an insider even though not an employee.

    Subdomain 2.2: Explain common threat vectors and attack surfaces.

    8.During a physical walkthrough, an auditor plugs a laptop into an unused wall jack in a ground-floor meeting room and immediately receives an internal IP address with reachability to file servers. Which control best closes this unsecure wired network exposure?

    1. A.Shorten the DHCP lease time so that unknown clients lose their addresses within minutes
    2. B.Enforce 802.1X port-based authentication on access switches and shut down unused ports
    3. C.Enable WPA3 on the wireless controller so visitors cannot reach any of the wired VLANs
    4. D.Install host-based IDS agents on the file servers to log every connection from new clients
    Show answer & explanation

    Correct answer: B — Enforce 802.1X port-based authentication on access switches and shut down unused ports

    • A. A shorter lease only changes how quickly an address expires. The rogue laptop can simply request a new lease and stay connected.
    • B. 802.1X requires a device to authenticate before the switch port passes traffic, and disabling idle ports removes the open jack altogether. Together they stop unauthorized wired access.
    • C. WPA3 protects wireless associations. The auditor connected by cable, so wireless encryption has no effect on this wall jack.
    • D. Host-based IDS logging is detective and sits on the servers. The rogue client is still granted network access instead of being blocked at the port.

    Subdomain 2.3: Explain various types of vulnerabilities.

    9.Which condition is the root cause of a classic stack-based buffer overflow?

    1. A.A program that checks a file's permissions and opens it later lets another process swap the file between the two operations
    2. B.A program that concatenates a user-supplied filename into a path allows traversal outside the intended directory with dot-dot sequences
    3. C.A program that stores secrets in plaintext memory lets other processes read them through shared page mappings without an access check
    4. D.A program copies input into a fixed-length buffer without verifying its size, overwriting adjacent memory including the return address
    Show answer & explanation

    Correct answer: D — A program copies input into a fixed-length buffer without verifying its size, overwriting adjacent memory including the return address

    • A. Checking permissions and then opening the file later is the time-of-check to time-of-use race condition, a timing flaw rather than a memory-bounds flaw.
    • B. Concatenating filenames into paths enables directory traversal, an input-validation weakness unrelated to overrunning a memory buffer.
    • C. Plaintext secrets readable across processes describe a data-exposure weakness, not corruption of memory beyond a buffer's boundary.
    • D. Copying unchecked input into a fixed-size buffer is the defining cause of a buffer overflow. The excess data overwrites neighbouring memory such as the saved return address, letting an attacker redirect execution.

    Subdomain 2.3: Explain various types of vulnerabilities.

    10.After a breach, a company learns that its legacy application stored user passwords as unsalted MD5 digests, and attackers recovered most of them within hours using precomputed tables. Which remediation best addresses this cryptographic weakness?

    1. A.Re-encrypt the password column with AES-256 using a key kept in the application's configuration file on the web server
    2. B.Migrate to a slow, salted password hash such as bcrypt or Argon2 and require users to reset their passwords
    3. C.Replace MD5 with unsalted SHA-256 so identical passwords still map to a single digest and can be looked up quickly
    4. D.Truncate each stored hash to its first sixteen characters so that a stolen database exposes less of every digest
    Show answer & explanation

    Correct answer: B — Migrate to a slow, salted password hash such as bcrypt or Argon2 and require users to reset their passwords

    • A. Encrypting with a key stored beside the application is weak, because anyone who reaches the server can recover the key and decrypt everything. Passwords should be hashed, not reversibly encrypted.
    • B. A deliberately slow, salted password hash defeats precomputed tables and makes brute force expensive per account. Forcing resets is needed because the old digests are already compromised.
    • C. Unsalted SHA-256 still allows rainbow table and bulk lookup attacks, and the speed of the algorithm favors the attacker. It is only a marginal improvement over MD5.
    • D. Truncating digests increases collisions and does not stop offline guessing of the shortened values. It also leaves the same unsalted weakness in place.

    Subdomain 2.5: Explain the purpose of mitigation techniques used to secure the enterprise.

    11.What distinguishes a host-based intrusion prevention system (HIPS) from a host-based intrusion detection system (HIDS)?

    1. A.It can block or terminate a malicious process or connection on the endpoint in real time, not just raise an alert
    2. B.It inspects only traffic crossing the network perimeter by reading mirrored packets from a SPAN port on the core switch
    3. C.It encrypts every file on the host so that unauthorized processes cannot read content without possessing the correct key
    4. D.It compares executables to a list of approved hashes and refuses to launch any program that is not on that list
    Show answer & explanation

    Correct answer: A — It can block or terminate a malicious process or connection on the endpoint in real time, not just raise an alert

    • A. The defining feature of a HIPS is active prevention: it takes action on the host such as stopping a process or dropping traffic. A HIDS only monitors and reports.
    • B. Reading mirrored perimeter traffic describes a network-based sensor, not a host-based product. A HIPS runs on the endpoint itself.
    • C. File encryption is a data-protection control and does not detect or block malicious behaviour. Intrusion prevention is behavioural, not cryptographic.
    • D. That is an application allow list. A HIPS evaluates behaviour and signatures of running activity rather than gating launches by an approved list.

    Subdomain 2.4: Given a scenario, analyze indicators of malicious activity.

    12.Within minutes, hundreds of workstations on several VLANs show high CPU use and saturated links. No users opened attachments, and each infected host is scanning TCP port 445 on other hosts. Which malware type is most consistent with this behaviour?

    1. A.Trojan, because it relies on users running a disguised program before any spread can happen
    2. B.Spyware, because it quietly profiles browsing activity and sends the data out to a collector
    3. C.Bloatware, because it ships with the standard image and consumes resources on every workstation
    4. D.Worm, because it replicates itself across hosts by exploiting a vulnerable network service
    Show answer & explanation

    Correct answer: D — Worm, because it replicates itself across hosts by exploiting a vulnerable network service

    • A. Incorrect. A trojan depends on a user running a program that appears legitimate, yet no user interaction occurred in this outbreak.
    • B. Incorrect. Spyware aims at covert data collection and does not scan across the network for other victims at high volume.
    • C. Incorrect. Bloatware is unwanted software that comes with the standard image, which would not scan port 445 on peer hosts or spread.
    • D. Correct. A worm is self-replicating and spreads without user action, here by scanning and exploiting SMB on port 445, which causes the CPU and bandwidth saturation.

    Domain 3: Security Architecture

    Subdomain 3.1: Compare and contrast security implications of different architecture models.

    13.A DevOps team provisions cloud networks from Terraform templates stored in a Git repository. A security engineer wants to catch an overly permissive security group before it reaches production. Which approach best uses the strengths of infrastructure as code?

    1. A.Disable version control for the templates so credentials embedded in earlier commits cannot be recovered, then scan the live environment weekly instead.
    2. B.Store the templates on a shared drive with full write access so any engineer can quickly correct an insecure rule without a formal review step.
    3. C.Allow engineers to edit security groups manually in the console after deployment, then export the state nightly to document whatever changes were made.
    4. D.Run static analysis on the templates in the CI pipeline and require peer-reviewed pull requests, so insecure settings are rejected before deployment.
    Show answer & explanation

    Correct answer: D — Run static analysis on the templates in the CI pipeline and require peer-reviewed pull requests, so insecure settings are rejected before deployment.

    • A. Incorrect. Removing version control destroys change history and rollback ability. Secrets belong in a vault, not in templates, and scanning after deployment is reactive.
    • B. Incorrect. Unrestricted write access removes review and auditability, which are the main security benefits of keeping infrastructure definitions in controlled code.
    • C. Incorrect. Manual console edits create configuration drift away from the templates and are detected only after the exposure already exists in production.
    • D. Correct. IaC makes configuration reviewable code, so policy-as-code scanners and pull-request approval can stop insecure rules and also give repeatable, auditable deployments.

    Subdomain 3.1: Compare and contrast security implications of different architecture models.

    14.A bank splits its monolithic application into dozens of microservices that call each other over the internal network through REST APIs. Which security implication of this architecture should the team address first?

    1. A.A single point of failure in one large codebase, which means one failed deployment will always take the entire application offline for all users.
    2. B.The inability to scale individual components, since all services must be replicated together as one unit to keep the application consistent.
    3. C.An expanded attack surface of many exposed APIs, requiring an API gateway, service-to-service authentication, and encrypted internal traffic.
    4. D.A single shared process memory space across all services, which lets any one flaw read the secrets of every other service on the same host.
    Show answer & explanation

    Correct answer: C — An expanded attack surface of many exposed APIs, requiring an API gateway, service-to-service authentication, and encrypted internal traffic.

    • A. Incorrect. A single codebase and all-or-nothing deployment describe a monolith. Microservices are deployed independently and tend to isolate failures.
    • B. Incorrect. Independent scaling is a core benefit of microservices. Each service can be replicated according to its own load.
    • C. Correct. Every microservice endpoint is a potential entry point, so teams need gateway enforcement, mutual authentication such as mTLS, and authorization between services.
    • D. Incorrect. Microservices run as separate processes or containers, not in one shared memory space. That description fits a monolith or a poorly isolated host.

    Subdomain 3.2: Given a scenario, apply security principles to secure enterprise infrastructure.

    15.A company hosts a public web server that must be reachable from the internet. The security architect wants to limit damage if the server is compromised, so internal hosts are not directly exposed. Which placement is most appropriate?

    1. A.In the internal user VLAN alongside workstations, protected only by a host-based firewall running on the server itself
    2. B.In a screened subnet between the external and internal firewalls, with rules limiting traffic into the internal zone
    3. C.Directly on the internet edge with a public address and no firewall, so inspection devices cannot add latency to requests
    4. D.In the management zone beside the jump server and administrative workstations, so patches are easy to apply and audit
    Show answer & explanation

    Correct answer: B — In a screened subnet between the external and internal firewalls, with rules limiting traffic into the internal zone

    • A. Placing an internet-facing server among workstations gives an attacker a foothold inside the trusted network. A host firewall alone does not provide network-level isolation.
    • B. A screened subnet isolates internet-facing systems in their own security zone. If the web server is compromised, the internal firewall still restricts what it can reach.
    • C. Removing all filtering exposes the host's entire attack surface to the internet. Eliminating inspection latency is not a valid reason for skipping a boundary control.
    • D. The management zone holds the most sensitive administrative systems and should not host a publicly reachable server. Compromise there could give an attacker administrative pivot points.

    Subdomain 3.4: Explain the importance of resilience and recovery in security architecture.

    16.A hospital's electronic health record system has a recovery time objective of 15 minutes and cannot lose more than a few seconds of data. Which alternate-site strategy meets these requirements?

    1. A.Lease a cold site that provides power, cooling, and rack space, then ship replacement servers and backup media there once a disaster has been declared.
    2. B.Lease a warm site with pre-installed hardware and restore the most recent weekly backup before cutover, which normally takes a full day or more.
    3. C.Contract a hot site with duplicate hardware and continuously replicated data so operations resume within minutes of a declared disaster.
    4. D.Sign a reciprocal agreement with a partner hospital to borrow spare data center capacity whenever a regional outage hits, without pre-staging any data.
    Show answer & explanation

    Correct answer: C — Contract a hot site with duplicate hardware and continuously replicated data so operations resume within minutes of a declared disaster.

    • A. Incorrect: a cold site has only utilities and space, so procuring hardware and restoring media takes days or weeks, far beyond a 15-minute recovery time objective.
    • B. Incorrect: a warm site has hardware but stale data from the last backup, so recovery takes hours to a day and loses far more than a few seconds of data.
    • C. Correct: a hot site is a fully equipped, continuously synchronized duplicate facility. It is the only site type that supports minutes-level recovery with near-zero data loss.
    • D. Incorrect: a reciprocal agreement offers no pre-staged data or configuration, so capacity is uncertain and recovery would be slow and unpredictable.

    Subdomain 3.3: Compare and contrast concepts and strategies to protect data.

    17.The security team must confirm that a firmware image downloaded for a plant controller was not altered in transit. The vendor publishes the image's SHA-256 value on its website, which is served over HTTPS. Which action verifies the image's integrity?

    1. A.Encrypt the downloaded image with a local AES key and compare the ciphertext size with the file size listed on the vendor page
    2. B.Place the image in a segmented sandbox network and watch for unexpected outbound connections before approving it for installation
    3. C.Calculate the SHA-256 digest of the downloaded file and compare it with the value the vendor published on its HTTPS site
    4. D.Run the image through a DLP scanner to check whether it contains regulated data patterns such as card numbers or health identifiers
    Show answer & explanation

    Correct answer: C — Calculate the SHA-256 digest of the downloaded file and compare it with the value the vendor published on its HTTPS site

    • A. Encrypting with a local key produces output that depends on that key and says nothing about the original file's integrity. File size alone cannot detect tampering that preserves length.
    • B. Sandbox behavior monitoring may reveal malicious activity, but it is not an integrity check. A subtly modified image could behave normally during observation.
    • C. Hashing produces a fixed-length digest that changes if even one bit of the file changes. Matching the locally computed SHA-256 against the vendor's published value shows that the file was not modified.
    • D. A DLP scanner looks for sensitive data patterns leaving or sitting in the environment. It does not compare a file against a known-good reference value.

    Domain 4: Security Operations

    Subdomain 4.1: Given a scenario, apply common security techniques to computing resources.

    18.A SOC analyst receives an unknown executable that was attached to a phishing email. The team needs to observe its file, registry, and network behavior without risking the production environment. What is the best approach?

    1. A.Open the file on the reporting user's workstation with the EDR agent set to monitor-only mode and watch for alerts.
    2. B.Run it on a domain-joined test server in the production VLAN and revert to a snapshot after the observation is complete.
    3. C.Detonate it in an isolated sandbox VM with no production network access and record the behavior it produces.
    4. D.Check the file hash against a public threat feed and treat the file as safe when no matching report exists.
    Show answer & explanation

    Correct answer: C — Detonate it in an isolated sandbox VM with no production network access and record the behavior it produces.

    • A. Running unknown malware on a real user workstation risks infection, and monitor-only EDR will not contain it. A production endpoint is not an isolated test environment.
    • B. A domain-joined server in the production VLAN can reach internal resources, so malware could spread or steal credentials before a snapshot is restored. A snapshot does not contain network activity.
    • C. This is correct because a sandbox isolates execution from production, and analysts can safely record files, registry changes, and network calls. It is the standard way to analyze suspicious code.
    • D. A new or targeted sample often has no feed entry, so a missing match proves nothing. Hash lookup does not reveal the behavior the team wants to observe.

    Subdomain 4.2: Explain the security implications of proper hardware, software, and data asset management.

    19.During an audit, a company finds 40 cloud virtual machines running for months that nobody can account for, and several are missing patches. Which asset management practice most directly prevents this recurring?

    1. A.Record a named individual or team as owner of every asset in the register, accountable for its classification, patching, and eventual decommissioning.
    2. B.Configure the vulnerability scanner to run twice as often so unpatched virtual machines are reported to the security operations mailbox far sooner each week.
    3. C.Move all virtual machines into a single shared subscription so administrators can see every instance from one billing and management view.
    4. D.Apply a uniform data retention period of seven years to every virtual machine disk so that no workload data is lost during audits.
    Show answer & explanation

    Correct answer: A — Record a named individual or team as owner of every asset in the register, accountable for its classification, patching, and eventual decommissioning.

    • A. Correct. Ownership gives each asset an accountable party, so unpatched or abandoned systems have someone responsible for remediating or retiring them.
    • B. Incorrect. More frequent scanning surfaces findings faster, but with no assigned owner nobody is accountable for acting on those reports.
    • C. Incorrect. Consolidating the subscription improves visibility but still leaves no person responsible for each machine's lifecycle or patch status.
    • D. Incorrect. Retention periods govern how long data is kept, not who is accountable for the system, and would keep forgotten machines' data around longer.

    Subdomain 4.4: Explain security alerting and monitoring concepts and tools.

    20.A SIEM rule that alerts on any single failed login to the VPN generates hundreds of alerts per shift, and analysts have begun ignoring the queue. Past reviews show nearly all of them are users mistyping passwords. What should the team do first?

    1. A.Disable the VPN failed-login rule completely so analysts can concentrate on alerts from other detection content in the SIEM
    2. B.Add more analysts to each shift so that every individual failed-login alert can be opened and closed manually as it arrives
    3. C.Lower the log verbosity on the VPN concentrator so it records fewer authentication events and sends less data to the SIEM
    4. D.Tune the rule to alert only after several failures from one source within a short window, then recheck false positives
    Show answer & explanation

    Correct answer: D — Tune the rule to alert only after several failures from one source within a short window, then recheck false positives

    • A. Incorrect. Disabling the rule creates a blind spot for password guessing and credential stuffing; the problem is the threshold, not the detection goal.
    • B. Incorrect. Scaling manual triage does not fix the noisy rule and still buries true positives among thousands of meaningless alerts.
    • C. Incorrect. Reducing logging removes evidence needed for investigations and compliance, and it does not correct the logic of the alerting rule.
    • D. Correct. Alert tuning raises the threshold and adds context so benign typos stop triggering alerts while real brute-force activity still fires, reducing alert fatigue.

    Subdomain 4.3: Explain various activities associated with vulnerability management.

    21.A quarterly authenticated scan reports no critical findings on a file server. Two weeks later, a penetration tester gains access through an unpatched SMB flaw that the scanner never reported. How should the scanner's result be classified?

    1. A.True positive
    2. B.True negative
    3. C.False positive
    4. D.False negative
    Show answer & explanation

    Correct answer: D — False negative

    • A. A true positive would mean the scanner reported a flaw that really exists, but here it reported nothing at all.
    • B. A true negative means no flaw was reported and none exists, which contradicts the successful exploitation of the SMB flaw.
    • C. A false positive is a reported finding that turns out not to exist; here the problem is a missing finding, not a bogus one.
    • D. A false negative is a real vulnerability that the scanner failed to report, which is exactly what the tester's SMB exploit demonstrated.

    Subdomain 4.3: Explain various activities associated with vulnerability management.

    22.Two findings are open: a CVSS 9.8 flaw on an isolated lab server holding no sensitive data, and a CVSS 7.5 flaw on an internet-facing payment gateway with exploitation already reported in the wild. Which order should the team follow?

    1. A.Fix the payment gateway first, since exposure, asset criticality, and active exploitation raise its real risk
    2. B.Fix the lab server first, since the CVSS base score alone is the value that decides remediation order
    3. C.Fix the lab server first, since any score above 9.0 must be closed before lower-scored findings are scheduled
    4. D.Fix either one first, since the CVSS base score already folds in exposure factor and asset value
    Show answer & explanation

    Correct answer: A — Fix the payment gateway first, since exposure, asset criticality, and active exploitation raise its real risk

    • A. Prioritization combines the base score with environmental variables such as exposure, asset value, and exploit activity, so the internet-facing gateway carries more actual risk.
    • B. The base score measures intrinsic severity only; using it alone ignores that the lab server is isolated and holds no sensitive data.
    • C. No rule makes a score above 9.0 an automatic first priority; organizations weigh context and risk tolerance when ordering fixes.
    • D. The base score does not include a specific asset's exposure or business value; those come from environmental variables, so order does matter.

    Subdomain 4.7: Explain the importance of automation and orchestration related to secure operations.

    23.A team deploys infrastructure code straight to production and recently shipped a template that left a database publicly reachable. Management wants such errors caught before release without slowing delivery. What should the team add?

    1. A.Hold a monthly meeting where engineers read through the week's template changes together and flag anything that looks risky after deployment.
    2. B.Require a security engineer to approve each template change through a ticket, then deploy it by hand during a single weekly release window.
    3. C.Run automated static analysis and policy tests on every commit in the CI pipeline, and fail the build when a template violates the security baseline.
    4. D.Schedule a penetration test of production once a year and have the testers report any exposed databases to the infrastructure team afterward.
    Show answer & explanation

    Correct answer: C — Run automated static analysis and policy tests on every commit in the CI pipeline, and fail the build when a template violates the security baseline.

    • A. Incorrect. A monthly review happens after deployment and depends on people noticing risk, so the exposed database would already have been live for weeks.
    • B. Incorrect. Manual approval plus a weekly window slows delivery, and it still relies on a reviewer spotting the issue by eye rather than testing it consistently.
    • C. Correct. Continuous integration and testing runs the same checks on every change, blocking a failing build before release without adding a manual bottleneck.
    • D. Incorrect. An annual penetration test is far too infrequent and detective only; it cannot prevent a flawed template from reaching production.

    Subdomain 4.5: Given a scenario, modify enterprise capabilities to enhance security.

    24.A security audit finds administrators managing network devices over Telnet and monitoring them with SNMPv2c community strings sent in cleartext. Which TWO changes replace these with encrypted protocols?(Select 2)

    1. A.Change the Telnet daemon to listen on TCP port 2323 and limit access with an ACL so only the management subnet connects.
    2. B.Move SNMP polling from v2c to SNMPv3 using the authPriv level so credentials and payloads are authenticated and encrypted.
    3. C.Switch SNMP transport from UDP to TCP while keeping the community strings, since TCP encrypts the retransmitted payload data.
    4. D.Rename the SNMP community strings to long random values and keep Telnet enabled behind the existing perimeter firewall rules.
    5. E.Replace Telnet with SSH on TCP port 22 for administrative sessions to every router, switch, and firewall in the network.
    Show answer & explanation

    Correct answers: B, E — Move SNMP polling from v2c to SNMPv3 using the authPriv level so credentials and payloads are authenticated and encrypted.; Replace Telnet with SSH on TCP port 22 for administrative sessions to every router, switch, and firewall in the network.

    • A. Incorrect. Moving to a nonstandard port and adding an ACL limits who connects but the session and credentials still travel unencrypted.
    • B. Correct. SNMPv3 with authPriv provides authentication and encryption, unlike v2c community strings that travel in plaintext.
    • C. Incorrect. TCP provides reliable delivery rather than confidentiality, and community strings would still be sent in cleartext.
    • D. Incorrect. Longer strings are still readable on the wire, and leaving Telnet enabled keeps administrator credentials exposed on the internal network.
    • E. Correct. SSH encrypts the session and authenticates the server, which removes the cleartext credentials Telnet exposes.

    Subdomain 4.6: Given a scenario, implement and maintain identity and access management.

    25.A security architect is reviewing sign-in options for administrators. Which TWO of the following combinations provide true multifactor authentication?(Select 2)

    1. A.A PIN followed by a security question answer about the first school the user attended
    2. B.A smart card inserted into the reader together with a PIN typed at the keypad
    3. C.A fingerprint scan combined with a retina scan at the same door controller
    4. D.A hardware FIDO2 security key touched after the user types the account password
    5. E.A password plus a long passphrase entered on two separate login screens
    Show answer & explanation

    Correct answers: B, D — A smart card inserted into the reader together with a PIN typed at the keypad; A hardware FIDO2 security key touched after the user types the account password

    • A. A PIN and a security question answer are both something you know. Two knowledge items are still a single factor, so this is not multifactor.
    • B. Correct. The smart card is something you have and the PIN is something you know, so two distinct factor categories are used.
    • C. A fingerprint and a retina scan are both something you are. Combining two biometrics stays within a single factor category.
    • D. Correct. The security key is something you have and the password is something you know, which gives two distinct factor categories.
    • E. A password and a passphrase are both something you know. Entering them on separate screens does not add a different factor category.

    Subdomain 4.8: Explain appropriate incident response activities.

    26.Which statement best describes e-discovery in the context of digital forensics?

    1. A.Identifying, collecting, and producing electronically stored information in response to a legal or regulatory request or a lawsuit.
    2. B.Scanning enterprise networks to find unmanaged assets and unpatched systems before attackers have a chance to exploit them.
    3. C.Searching telemetry for adversary behaviors that existing detection rules and automated alerts have not yet flagged anywhere.
    4. D.Reconstructing the attack timeline after a breach to identify the vulnerability that allowed the first compromise of a host.
    Show answer & explanation

    Correct answer: A — Identifying, collecting, and producing electronically stored information in response to a legal or regulatory request or a lawsuit.

    • A. E-discovery is the legal process of identifying, collecting, and producing electronically stored information for litigation or regulatory requests. It is closely tied to legal hold and preservation.
    • B. Finding unmanaged assets and unpatched systems is asset discovery and vulnerability management. It is a preventive security activity, not a legal process.
    • C. Looking for undetected adversary behavior in telemetry is threat hunting. It is proactive detection work, not legal production of data.
    • D. Reconstructing the timeline to find how the compromise began is root cause analysis. It supports remediation rather than legal production of information.

    Subdomain 4.9: Given a scenario, use data sources to support an investigation.

    27.NetFlow records show a database server sent 2 GB to an external host over TCP port 21 overnight. The analyst suspects cleartext FTP was used and needs the file names, commands, and any credentials that crossed the wire. Which data source provides this?

    1. A.A full packet capture of the session, which can be reassembled into the FTP control and data streams in a protocol analyzer
    2. B.Firewall allow entries for the session, recording the source, destination, and port along with the rule that permitted it
    3. C.Additional NetFlow exports with a shorter active timeout, giving more granular byte and packet counters for the same session
    4. D.A vulnerability scan of the database server, reporting whether an FTP service banner or weak configuration is exposed
    Show answer & explanation

    Correct answer: A — A full packet capture of the session, which can be reassembled into the FTP control and data streams in a protocol analyzer

    • A. Correct. Packet captures retain the actual payload, so the FTP USER, PASS, STOR, and RETR commands and transferred files can be reassembled and read when the protocol is unencrypted.
    • B. Incorrect. Firewall entries confirm the connection was permitted but record no commands, file names, or credentials from inside the session.
    • C. Incorrect. NetFlow only summarizes conversation metadata such as addresses, ports, and byte counts. Tuning its timeouts never adds payload content.
    • D. Incorrect. A scan describes a service's weaknesses at scan time and cannot show what data actually moved during last night's transfer.

    Domain 5: Security Program Management and Oversight

    Subdomain 5.3: Explain the processes associated with third-party risk assessment and management.

    28.During vendor selection for a managed SOC, the CISO learns that the procurement lead's spouse is a minority owner of the highest-scoring bidder. What is the most appropriate response?

    1. A.Keep the same evaluators because the bidder scored highest on the technical criteria, and note the relationship in the vendor file once the contract is signed
    2. B.Ask the bidder to sign a mutual NDA covering the ownership relationship so that the arrangement stays confidential throughout the whole evaluation process
    3. C.Drop the bidder's security questionnaire answers from scoring so the evaluation relies only on the price quotations that every bidder submitted
    4. D.Have the procurement lead disclose the relationship and recuse from evaluating and awarding, with the committee recording the disclosure
    Show answer & explanation

    Correct answer: D — Have the procurement lead disclose the relationship and recuse from evaluating and awarding, with the committee recording the disclosure

    • A. Waiting until after signing to record the relationship leaves the selection tainted. A conflict of interest must be handled before the decision, not documented afterward.
    • B. An NDA would hide the relationship rather than manage it. Concealing a conflict of interest increases risk and undermines the fairness of the selection.
    • C. Removing questionnaire scoring distorts the evaluation and does not address the conflict. The issue is the evaluator's personal interest, not the type of evidence collected.
    • D. Disclosure and recusal is correct because it removes the conflicted person from the decision and creates an auditable record. This protects the integrity of the vendor selection process.

    Subdomain 5.3: Explain the processes associated with third-party risk assessment and management.

    29.A bank must compare 40 candidate SaaS vendors on encryption, incident response, and subcontractor use before deciding which ones deserve a deeper review. Which approach gives consistent, comparable data most efficiently?

    1. A.Run an unannounced penetration test against each vendor's production environment and rank the vendors by the number of findings reported
    2. B.Send every vendor the same standardized security questionnaire and score the responses against a single set of criteria prepared in advance
    3. C.Collect each vendor's master service agreement template and compare the liability caps and termination clauses across all forty candidates
    4. D.Negotiate an individual service-level agreement with each vendor first so response times are fixed before any control information is collected
    Show answer & explanation

    Correct answer: B — Send every vendor the same standardized security questionnaire and score the responses against a single set of criteria prepared in advance

    • A. Unannounced testing of production systems without agreed rules of engagement is risky and usually unauthorized. It is also impractical to perform across forty vendors at the screening stage.
    • B. A standardized questionnaire is correct because identical questions produce comparable answers that can be scored consistently. It is a low-cost screening step before deeper verification.
    • C. MSA templates describe legal and commercial terms. They reveal little about how each vendor handles encryption, incident response, or subcontractors.
    • D. An SLA covers service performance commitments and is negotiated after selection. Doing it first gathers no information about security controls.

    Subdomain 5.2: Explain elements of the risk management process.

    30.A plant's legacy controller cannot run supported patches. The risk committee approves a request letting it stay out of compliance with the patching standard for 12 months, with network isolation as a compensating control and a scheduled review date. What does this approval represent under the accept strategy?

    1. A.A risk transfer in which the committee shifts responsibility for the legacy controller to the vendor through its support agreement
    2. B.A risk avoidance decision because network isolation removes the controller from every system that handles production data
    3. C.A permanent exemption that removes the controller from the patching standard and from all future risk register reviews
    4. D.A documented exception granting time-bound permission to deviate from the standard, with compensating controls and a review date
    Show answer & explanation

    Correct answer: D — A documented exception granting time-bound permission to deviate from the standard, with compensating controls and a review date

    • A. Transfer would move the consequences to another party, and nothing in the approval does that. The organization still carries the risk of the unpatched controller.
    • B. Avoidance would require retiring or not using the controller. Isolating it only reduces exposure, and the device remains in production use.
    • C. An exemption excuses an asset from a requirement outright. This approval is temporary, conditional on compensating controls, and scheduled for review, so it is not permanent.
    • D. Correct. An exception is a formally approved, time-limited deviation from a standard that is accepted with compensating controls and revisited at a review date.

    Subdomain 5.1: Summarize elements of effective security governance.

    31.A customer database needs someone to set its classification and approve access requests. The DBA team performs backups, patching, and applies the permissions that are approved. Which assignment of roles is correct?

    1. A.The DBA team is the data owner because it holds administrator rights, and the VP of Sales is the custodian
    2. B.The CISO is the custodian of the data because policy lives there, and the VP of Sales is a processor
    3. C.The VP of Sales is the data owner approving access and classification, and the DBA team acts as custodian
    4. D.The customers are the data owners who approve access, and the DBA team is the controller of the database
    Show answer & explanation

    Correct answer: C — The VP of Sales is the data owner approving access and classification, and the DBA team acts as custodian

    • A. Administrative rights do not confer ownership. Technical staff implement controls, while accountability for the data rests with a business owner such as the VP of Sales.
    • B. A CISO oversees the program, but custodian is a hands-on role performing safeguards. A business executive is not a processor, which is an external party handling data for a controller.
    • C. The owner is the accountable business executive who decides classification and access. Custodians carry out technical safeguards like backups, patching, and permission changes.
    • D. Customers are data subjects and do not approve internal access. Controller is a privacy role about purposes of processing, not a name for database administrators.

    Subdomain 5.5: Explain types and purposes of audits and assessments.

    32.Testers are given a standard user account, the external IP ranges and a high-level network diagram for a web application, but no source code and no administrator credentials. Which type of test environment does this describe?

    1. A.A known environment, because the testers receive credentials and have complete documentation of every component
    2. B.An unknown environment, because the testers receive nothing beyond the organization's name and the signed scope
    3. C.A partially known environment, because the testers receive limited details and access similar to an informed insider
    4. D.A defensive environment, because the testers receive information that mainly helps the blue team tune detections
    Show answer & explanation

    Correct answer: C — A partially known environment, because the testers receive limited details and access similar to an informed insider

    • A. A known environment gives testers full details such as source code, architecture and privileged credentials. Here administrator credentials and source code are withheld.
    • B. An unknown environment gives testers essentially no information. A user account, IP ranges and a diagram are well beyond that.
    • C. A partially known environment gives testers some information, such as a low-privilege account and a diagram, to simulate an attacker with limited inside knowledge.
    • D. Defensive describes the focus of the exercise, not how much information the testers are given. The amount of disclosed detail is what defines the environment type.

    Subdomain 5.5: Explain types and purposes of audits and assessments.

    33.A development team has a two-week window to test a new payment application and wants maximum coverage of its internal logic without time spent on discovery. Which testing approach should it choose?

    1. A.An unknown-environment test, because withholding all details forces the testers to find the most realistic attack paths
    2. B.A passive reconnaissance engagement, because gathering public information first reveals every flaw in the application
    3. C.A physical test, because the data center hosting the application is the most likely entry point for attackers
    4. D.A known-environment test, because source code, architecture diagrams and credentials let testers go straight to the logic
    Show answer & explanation

    Correct answer: D — A known-environment test, because source code, architecture diagrams and credentials let testers go straight to the logic

    • A. An unknown-environment test spends much of the window on discovery and gives less coverage of internal logic. It suits realism goals rather than depth in a short window.
    • B. Passive reconnaissance gathers publicly available information only. It cannot reveal flaws in internal application logic.
    • C. A physical test targets buildings and access controls. It does not examine the application's internal logic.
    • D. A known-environment test gives the testers full information, including source code and credentials, so no time is lost on discovery. This yields the deepest coverage in limited time.

    Subdomain 5.4: Summarize elements of effective security compliance.

    34.The database administrator for an HR system performs the nightly backups and applies patches. A new project asks who may approve access to employee salary data and decide its classification level. Who holds that authority?

    1. A.The database administrator, because the person who operates and secures the platform holds authority over every data set that is stored on it
    2. B.The data owner, typically a senior business leader such as the HR director, who is accountable for classifying the data and approving who may use it
    3. C.The employees whose salaries are stored, because each data subject must personally approve every internal access request before it is granted to anyone
    4. D.The external payroll provider, because any vendor that processes the data on the company's behalf controls who is allowed to see it
    Show answer & explanation

    Correct answer: B — The data owner, typically a senior business leader such as the HR director, who is accountable for classifying the data and approving who may use it

    • A. Incorrect: the administrator is a custodian who implements controls under the owner's direction. Operating the platform does not confer authority over classification or access decisions.
    • B. Correct: the data owner is the accountable role that decides classification, acceptable use, and access. Custodians and processors then implement those decisions.
    • C. Incorrect: data subjects hold privacy rights such as access and correction but do not approve internal access. Business accountability rests with the data owner.
    • D. Incorrect: a processor acts on the controller's instructions and does not set access policy. Responsibility for those decisions stays with the organization's data owner.

    Subdomain 5.6: Given a scenario, implement security awareness practices.

    35.A review shows that many employees reuse the same password across work and personal accounts, and some keep passwords in a spreadsheet on their desktop. Which awareness guidance best reduces this risk?

    1. A.Require every password to be changed each 30 days, with users appending a month number to the old password
    2. B.Let each team keep one shared vault login so that credentials are stored in a single central place
    3. C.Have staff write unique passwords in a notebook and keep it in their own unlocked desk drawer at the office
    4. D.Train staff to use the approved password manager with unique generated passphrases, plus MFA on accounts
    Show answer & explanation

    Correct answer: D — Train staff to use the approved password manager with unique generated passphrases, plus MFA on accounts

    • A. Forced frequent rotation pushes users toward predictable patterns such as incrementing a number. It does not address reuse and weakens real password strength.
    • B. A shared team login removes individual accountability and spreads one credential among many people. It also makes offboarding and auditing harder.
    • C. A paper notebook in an unlocked drawer is easily found by anyone with physical access. It trades one weak storage method for another.
    • D. A password manager makes unique, long passwords practical, and MFA limits damage when one credential leaks. This directly targets reuse and insecure storage.

    Want the full experience?

    These are just samples. Practice the full CompTIA Security+ question bank in quiz mode — free, no signup, with domain practice and exam simulation.