Verified Content

CompTIA-SecurityPlus Demo Questions

Get a glimpse of our premium question bank. Practice these highly-curated demo questions to boost your CompTIA-SecurityPlus preparation and identify your weak spots.

Sample Question Bank

In a on-premises data center involving the payment API and admin credentials, A private application checks user identity, device compliance, location, and risk score before each session. Which architecture principle best fits?

+1-0
MCQ
A
Trust internal network by default
B
Authenticate once and allow all apps
C
Disable segmentation after VPN login
D
Never trust, always verify
CompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.2-security-conceptszero-trustdifficulty-2

In a AWS account involving the SIEM rule set and audit logs, A firewall exception for the payment API requires testing, rollback steps, owner approval, and a maintenance window. Which process is this?

+1-0
MCQ
A
Change management
B
Threat hunting
C
Evidence preservation
D
Credential rotation
CompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.3-change-managementchange-controldifficulty-2

In a Kubernetes cluster involving the identity provider and audit logs, A patch causes failed logins in production. Which change-management artifact allows the team to restore service quickly?

+1-0
MCQ
A
Data classification label
B
Password complexity rule
C
Certificate chain
D
Rollback plan
CompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.3-change-managementrollbackdifficulty-2

In a AWS account involving the identity provider and source code, A design review focuses on preventing unauthorized disclosure of admin credentials. Which CIA objective is the review primarily addressing?

+1-0
MCQ
A
Availability
B
Confidentiality
C
Integrity
D
Non-repudiation
CompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.2-security-conceptscia-confidentialitydifficulty-1

In a hybrid cloud involving the identity provider and medical records, A release manager requires signed commits so unauthorized changes to production code can be detected. Which objective is most directly supported?

+1-0
MCQ
A
Privacy by design
B
Availability
C
Integrity
D
Confidentiality
CompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.2-security-conceptscia-integritydifficulty-2

In a manufacturing OT segment involving the patient-record system and customer PII, A private application checks user identity, device compliance, location, and risk score before each session. Which architecture principle best fits?

+1-0
MCQ
A
Disable segmentation after VPN login
B
Trust internal network by default
C
Authenticate once and allow all apps
D
Never trust, always verify
CompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.2-security-conceptszero-trustdifficulty-2

In a hybrid cloud involving the developer CI/CD pipeline and financial reports, A private application checks user identity, device compliance, location, and risk score before each session. Which architecture principle best fits?

+1-0
MCQ
A
Authenticate once and allow all apps
B
Trust internal network by default
C
Never trust, always verify
D
Disable segmentation after VPN login
CompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.2-security-conceptszero-trustdifficulty-2

In a retail branch network involving the identity provider and audit logs, A firewall exception for the SIEM rule set requires testing, rollback steps, owner approval, and a maintenance window. Which process is this?

+1-0
MCQ
A
Change management
B
Evidence preservation
C
Threat hunting
D
Credential rotation
CompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.3-change-managementchange-controldifficulty-2

In a Kubernetes cluster involving the patient-record system and audit logs, A firewall exception for the public web application requires testing, rollback steps, owner approval, and a maintenance window. Which process is this?

+1-0
MCQ
A
Credential rotation
B
Threat hunting
C
Change management
D
Evidence preservation
CompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.3-change-managementchange-controldifficulty-2

In a AWS account involving the container platform and admin credentials, A patch causes failed logins in production. Which change-management artifact allows the team to restore service quickly?

+1-0
MCQ
A
Rollback plan
B
Certificate chain
C
Data classification label
D
Password complexity rule
CompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.3-change-managementrollbackdifficulty-2

In a on-premises data center involving the SIEM rule set and customer PII, A patch causes failed logins in production. Which change-management artifact allows the team to restore service quickly?

+1-0
MCQ
A
Rollback plan
B
Password complexity rule
C
Data classification label
D
Certificate chain
CompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.3-change-managementrollbackdifficulty-2

In a Azure tenant involving the container platform and source code, A vendor publishes a SHA-256 digest for an installer. What should the customer use it for?

+1-0
MCQ
A
Authenticate to Wi-Fi
B
Verify file integrity after download
C
Assign RBAC permissions
D
Decrypt the installer
CompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.4-cryptographyhashingdifficulty-2

In a manufacturing OT segment involving the patient-record system and encryption keys, A server proves its identity using a certificate and private key during TLS negotiation. Which cryptographic approach is involved?

+1-0
MCQ
A
Asymmetric cryptography
B
Disk deduplication
C
Shared local password only
D
Plaintext encoding
CompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.4-cryptographyasymmetricdifficulty-2

In a retail branch network involving the HR portal and medical records, A team stores database encryption keys in a managed HSM instead of application code. What risk is reduced?

+1-0
MCQ
A
DNS cache poisoning
B
Weak physical lighting
C
DDoS bandwidth exhaustion
D
Key exposure through source-code leakage
CompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.4-cryptographykey-managementdifficulty-2

In a on-premises data center involving the branch-office firewall and customer PII, A vendor publishes a SHA-256 digest for an installer. What should the customer use it for?

+1-0
MCQ
A
Assign RBAC permissions
B
Verify file integrity after download
C
Decrypt the installer
D
Authenticate to Wi-Fi
CompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.4-cryptographyhashingdifficulty-2

In a remote workforce involving the patient-record system and audit logs, A vendor publishes a SHA-256 digest for an installer. What should the customer use it for?

+1-0
MCQ
A
Authenticate to Wi-Fi
B
Decrypt the installer
C
Assign RBAC permissions
D
Verify file integrity after download
CompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.4-cryptographyhashingdifficulty-2

In a Kubernetes cluster involving the identity provider and customer PII, A server proves its identity using a certificate and private key during TLS negotiation. Which cryptographic approach is involved?

+1-0
MCQ
A
Asymmetric cryptography
B
Plaintext encoding
C
Shared local password only
D
Disk deduplication
CompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.4-cryptographyasymmetricdifficulty-2

In a remote workforce involving the EDR console and cardholder data, A server proves its identity using a certificate and private key during TLS negotiation. Which cryptographic approach is involved?

+1-0
MCQ
A
Disk deduplication
B
Asymmetric cryptography
C
Shared local password only
D
Plaintext encoding
CompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.4-cryptographyasymmetricdifficulty-2

In a hybrid cloud involving the EDR console and customer PII, A team stores database encryption keys in a managed HSM instead of application code. What risk is reduced?

+1-0
MCQ
A
DDoS bandwidth exhaustion
B
Key exposure through source-code leakage
C
DNS cache poisoning
D
Weak physical lighting
CompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.4-cryptographykey-managementdifficulty-2

In a Kubernetes cluster involving the patient-record system and financial reports, A team stores database encryption keys in a managed HSM instead of application code. What risk is reduced?

+1-0
MCQ
A
DDoS bandwidth exhaustion
B
Weak physical lighting
C
Key exposure through source-code leakage
D
DNS cache poisoning
CompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.4-cryptographykey-managementdifficulty-2

In a retail branch network involving the container platform and medical records, A retail branch network team blocks inbound traffic with a stateful firewall before it reaches the identity provider. Which control type is being used?

+1-0
MCQ
A
Physical corrective control
B
Technical preventive control
C
Managerial compensating control
D
Administrative detective control
CompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.1-security-controlstechnical-preventivedifficulty-1

In a Kubernetes cluster involving the branch-office firewall and audit logs, Security installs lighting, fencing, and warning signs around a data-center loading dock. What is the main purpose of these controls?

+1-0
MCQ
A
Validate software input
B
Deter unauthorized physical access
C
Federate user identities
D
Encrypt data in transit
CompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.1-security-controlsphysical-deterrentdifficulty-1

In a Kubernetes cluster involving the remote-access VPN and medical records, A Kubernetes cluster team blocks inbound traffic with a stateful firewall before it reaches the container platform. Which control type is being used?

+1-0
MCQ
A
Managerial compensating control
B
Physical corrective control
C
Technical preventive control
D
Administrative detective control
CompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.1-security-controlstechnical-preventivedifficulty-1

In a retail branch network involving the public web application and medical records, A Kubernetes cluster team blocks inbound traffic with a stateful firewall before it reaches the public web application. Which control type is being used?

+1-0
MCQ
A
Managerial compensating control
B
Physical corrective control
C
Administrative detective control
D
Technical preventive control
CompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.1-security-controlstechnical-preventivedifficulty-1

In a retail branch network involving the SIEM rule set and financial reports, Security installs lighting, fencing, and warning signs around a data-center loading dock. What is the main purpose of these controls?

+1-0
MCQ
A
Validate software input
B
Deter unauthorized physical access
C
Federate user identities
D
Encrypt data in transit
CompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.1-security-controlsphysical-deterrentdifficulty-1

In a Azure tenant involving the public web application and source code, Security installs lighting, fencing, and warning signs around a data-center loading dock. What is the main purpose of these controls?

+1-0
MCQ
A
Federate user identities
B
Validate software input
C
Deter unauthorized physical access
D
Encrypt data in transit
CompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.1-security-controlsphysical-deterrentdifficulty-1

In a AWS account involving the SIEM rule set and encryption keys, A design review focuses on preventing unauthorized disclosure of customer PII. Which CIA objective is the review primarily addressing?

+1-0
MCQ
A
Integrity
B
Availability
C
Confidentiality
D
Non-repudiation
CompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.2-security-conceptscia-confidentialitydifficulty-1

In a retail branch network involving the payment API and customer PII, A design review focuses on preventing unauthorized disclosure of source code. Which CIA objective is the review primarily addressing?

+1-0
MCQ
A
Non-repudiation
B
Availability
C
Integrity
D
Confidentiality
CompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.2-security-conceptscia-confidentialitydifficulty-1

In a retail branch network involving the EDR console and medical records, A release manager requires signed commits so unauthorized changes to production code can be detected. Which objective is most directly supported?

+1-0
MCQ
A
Confidentiality
B
Availability
C
Privacy by design
D
Integrity
CompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.2-security-conceptscia-integritydifficulty-2

In a Kubernetes cluster involving the cloud storage account and audit logs, A release manager requires signed commits so unauthorized changes to production code can be detected. Which objective is most directly supported?

+1-0
MCQ
A
Privacy by design
B
Confidentiality
C
Integrity
D
Availability
CompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.2-security-conceptscia-integritydifficulty-2

In a Azure tenant involving the HR portal and financial reports, A user logs in, receives access based on group membership, and the action is written to an audit log. Which sequence is represented?

+1-0
MCQ
A
Authentication, authorization, and accounting
B
Identification, compression, and steganography
C
Accounting, federation, and tokenization
D
Authorization, hashing, and encryption
CompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.2-security-conceptsaaadifficulty-2

In a on-premises data center involving the identity provider and admin credentials, A user logs in, receives access based on group membership, and the action is written to an audit log. Which sequence is represented?

+1-0
MCQ
A
Authorization, hashing, and encryption
B
Accounting, federation, and tokenization
C
Identification, compression, and steganography
D
Authentication, authorization, and accounting
CompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.2-security-conceptsaaadifficulty-2

In a on-premises data center involving the HR portal and customer PII, A user logs in, receives access based on group membership, and the action is written to an audit log. Which sequence is represented?

+1-0
MCQ
A
Authorization, hashing, and encryption
B
Accounting, federation, and tokenization
C
Authentication, authorization, and accounting
D
Identification, compression, and steganography
CompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.2-security-conceptsaaadifficulty-2

In a remote workforce involving the payment API and financial reports, A login field accepts input that changes a database query and bypasses authentication. Which flaw exists?

+1-0
MCQ
A
CSRF token reuse only
B
SQL injection
C
ARP inspection
D
Key stretching
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiessql-injectiondifficulty-2

In a remote workforce involving the SIEM rule set and audit logs, A stored product review executes JavaScript in other shoppers’ browsers. What vulnerability is present?

+1-0
MCQ
A
Pass-the-ticket
B
VLAN hopping only
C
Stored cross-site scripting
D
DNSSEC failure
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesxssdifficulty-2

In a remote workforce involving the SIEM rule set and medical records, A storage bucket containing encryption keys is readable without authentication. What is the root issue?

+1-0
MCQ
A
Cloud access misconfiguration
B
Strong certificate validation
C
Secure boot enforcement
D
Offline backup retention
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiescloud-public-bucketdifficulty-2

In a hybrid cloud involving the developer CI/CD pipeline and source code, A login field accepts input that changes a database query and bypasses authentication. Which flaw exists?

+1-0
MCQ
A
Key stretching
B
ARP inspection
C
CSRF token reuse only
D
SQL injection
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiessql-injectiondifficulty-2

In a AWS account involving the remote-access VPN and medical records, A login field accepts input that changes a database query and bypasses authentication. Which flaw exists?

+1-0
MCQ
A
Key stretching
B
SQL injection
C
CSRF token reuse only
D
ARP inspection
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiessql-injectiondifficulty-2

In a remote workforce involving the identity provider and source code, A stored product review executes JavaScript in other shoppers’ browsers. What vulnerability is present?

+1-0
MCQ
A
VLAN hopping only
B
Pass-the-ticket
C
Stored cross-site scripting
D
DNSSEC failure
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesxssdifficulty-2

In a hybrid cloud involving the cloud storage account and admin credentials, A stored product review executes JavaScript in other shoppers’ browsers. What vulnerability is present?

+1-0
MCQ
A
Stored cross-site scripting
B
DNSSEC failure
C
VLAN hopping only
D
Pass-the-ticket
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesxssdifficulty-2

In a AWS account involving the public web application and audit logs, A storage bucket containing customer PII is readable without authentication. What is the root issue?

+1-0
MCQ
A
Cloud access misconfiguration
B
Secure boot enforcement
C
Strong certificate validation
D
Offline backup retention
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiescloud-public-bucketdifficulty-2

In a AWS account involving the HR portal and source code, A storage bucket containing customer PII is readable without authentication. What is the root issue?

+1-0
MCQ
A
Cloud access misconfiguration
B
Offline backup retention
C
Secure boot enforcement
D
Strong certificate validation
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiescloud-public-bucketdifficulty-2

In a hybrid cloud involving the developer CI/CD pipeline and admin credentials, File servers begin renaming files with a new extension and leave payment instructions. Which activity is indicated?

+1-0
MCQ
A
Ransomware encryption
B
Normal deduplication
C
Certificate renewal
D
Federated logout
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activityransomwaredifficulty-2

In a remote workforce involving the payment API and financial reports, EDR alerts on a tool reading LSASS memory shortly after admin login. Which activity should be suspected?

+1-0
MCQ
A
Credential dumping
B
Clean desk audit
C
Data classification
D
RAID rebuild
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitycredential-dumpingdifficulty-3

In a Azure tenant involving the developer CI/CD pipeline and financial reports, DNS logs show long random-looking subdomains leaving the network at high volume. What should analysts investigate?

+1-0
MCQ
A
Normal DHCP renewal
B
DNS tunneling or exfiltration
C
Disk encryption
D
Certificate stapling
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitydns-tunnelingdifficulty-3

In a AWS account involving the identity provider and audit logs, File servers begin renaming files with a new extension and leave payment instructions. Which activity is indicated?

+1-0
MCQ
A
Normal deduplication
B
Federated logout
C
Ransomware encryption
D
Certificate renewal
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activityransomwaredifficulty-2

In a on-premises data center involving the remote-access VPN and cardholder data, File servers begin renaming files with a new extension and leave payment instructions. Which activity is indicated?

+1-0
MCQ
A
Certificate renewal
B
Federated logout
C
Ransomware encryption
D
Normal deduplication
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activityransomwaredifficulty-2

In a manufacturing OT segment involving the developer CI/CD pipeline and financial reports, EDR alerts on a tool reading LSASS memory shortly after admin login. Which activity should be suspected?

+1-0
MCQ
A
Data classification
B
RAID rebuild
C
Credential dumping
D
Clean desk audit
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitycredential-dumpingdifficulty-3

In a retail branch network involving the HR portal and source code, EDR alerts on a tool reading LSASS memory shortly after admin login. Which activity should be suspected?

+1-0
MCQ
A
RAID rebuild
B
Clean desk audit
C
Credential dumping
D
Data classification
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitycredential-dumpingdifficulty-3

In a AWS account involving the identity provider and source code, Changing an order ID in an API URL returns another customer’s order. Which vulnerability is most likely?

+1-0
MCQ
A
Secure cookie flag
B
Certificate transparency
C
Broken object-level authorization
D
Port security
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesinsecure-apidifficulty-3

In a on-premises data center involving the container platform and cardholder data, DNS logs show long random-looking subdomains leaving the network at high volume. What should analysts investigate?

+1-0
MCQ
A
Certificate stapling
B
Normal DHCP renewal
C
DNS tunneling or exfiltration
D
Disk encryption
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitydns-tunnelingdifficulty-3

In a AWS account involving the branch-office firewall and source code, DNS logs show long random-looking subdomains leaving the network at high volume. What should analysts investigate?

+1-0
MCQ
A
DNS tunneling or exfiltration
B
Normal DHCP renewal
C
Disk encryption
D
Certificate stapling
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitydns-tunnelingdifficulty-3

In a on-premises data center involving the patient-record system and admin credentials, One password is attempted once against hundreds of user accounts. Which attack pattern is this?

+1-0
MCQ
A
Tailgating
B
Birthday attack
C
Directory traversal
D
Password spraying
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitypassword-sprayingdifficulty-2

In a Azure tenant involving the public web application and admin credentials, One password is attempted once against hundreds of user accounts. Which attack pattern is this?

+1-0
MCQ
A
Tailgating
B
Birthday attack
C
Directory traversal
D
Password spraying
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitypassword-sprayingdifficulty-2

In a remote workforce involving the patient-record system and financial reports, One password is attempted once against hundreds of user accounts. Which attack pattern is this?

+1-0
MCQ
A
Tailgating
B
Directory traversal
C
Birthday attack
D
Password spraying
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitypassword-sprayingdifficulty-2

In a retail branch network involving the HR portal and medical records, A vulnerable legacy server cannot be patched immediately. Which mitigation best reduces lateral movement risk?

+1-0
MCQ
A
Share local administrator passwords
B
Network segmentation with restricted access
C
Disable endpoint logging
D
Expose RDP to the internet
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.5-mitigationsegmentationdifficulty-2

In a retail branch network involving the branch-office firewall and source code, A kiosk should run only one approved application. Which mitigation is strongest?

+1-0
MCQ
A
Open proxy service
B
Application allow listing
C
Guest administrator account
D
Unrestricted PowerShell execution
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.5-mitigationallow-listingdifficulty-2

In a remote workforce involving the SIEM rule set and customer PII, Developers need to reduce injection risk in database queries. What should they implement?

+1-0
MCQ
A
Parameterized queries and input validation
B
Public write access
C
Disabled output encoding
D
Plaintext credential storage
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.5-mitigationsecure-codingdifficulty-2

In a remote workforce involving the HR portal and customer PII, A vulnerable legacy server cannot be patched immediately. Which mitigation best reduces lateral movement risk?

+1-0
MCQ
A
Disable endpoint logging
B
Network segmentation with restricted access
C
Share local administrator passwords
D
Expose RDP to the internet
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationsegmentationdifficulty-2

In a Azure tenant involving the public web application and admin credentials, A vulnerable legacy server cannot be patched immediately. Which mitigation best reduces lateral movement risk?

+1-0
MCQ
A
Disable endpoint logging
B
Expose RDP to the internet
C
Share local administrator passwords
D
Network segmentation with restricted access
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationsegmentationdifficulty-2

In a on-premises data center involving the cloud storage account and cardholder data, A kiosk should run only one approved application. Which mitigation is strongest?

+1-0
MCQ
A
Unrestricted PowerShell execution
B
Application allow listing
C
Guest administrator account
D
Open proxy service
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationallow-listingdifficulty-2

In a Azure tenant involving the patient-record system and cardholder data, A kiosk should run only one approved application. Which mitigation is strongest?

+1-0
MCQ
A
Open proxy service
B
Guest administrator account
C
Unrestricted PowerShell execution
D
Application allow listing
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationallow-listingdifficulty-2

In a hybrid cloud involving the container platform and encryption keys, Developers need to reduce injection risk in database queries. What should they implement?

+1-0
MCQ
A
Disabled output encoding
B
Parameterized queries and input validation
C
Plaintext credential storage
D
Public write access
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationsecure-codingdifficulty-2

In a manufacturing OT segment involving the SIEM rule set and financial reports, Developers need to reduce injection risk in database queries. What should they implement?

+1-0
MCQ
A
Plaintext credential storage
B
Parameterized queries and input validation
C
Disabled output encoding
D
Public write access
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationsecure-codingdifficulty-2

In a Azure tenant involving the container platform and audit logs, A hacktivist group targets a public agency to disrupt services and publish political messages. Which motivation is most likely?

+1-0
MCQ
A
Disaster recovery validation
B
Accidental misconfiguration
C
Ideological or political motivation
D
Routine patch testing
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.1-threat-actorsmotivationdifficulty-2

In a AWS account involving the remote-access VPN and source code, A organized crime group targets a public agency to disrupt services and publish political messages. Which motivation is most likely?

+1-0
MCQ
A
Ideological or political motivation
B
Accidental misconfiguration
C
Disaster recovery validation
D
Routine patch testing
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.1-threat-actorsmotivationdifficulty-2

In a retail branch network involving the cloud storage account and audit logs, A nation-state team targets a public agency to disrupt services and publish political messages. Which motivation is most likely?

+1-0
MCQ
A
Routine patch testing
B
Ideological or political motivation
C
Accidental misconfiguration
D
Disaster recovery validation
CompTIA-SecurityPlusSY0-701practice-test-03domain-2-threats-vulnerabilities-mitigations2.1-threat-actorsmotivationdifficulty-2

In a Azure tenant involving the HR portal and admin credentials, Employees receive a benefits-update email linking to a lookalike login portal. Which vector is being used?

+1-0
MCQ
A
BGP route summarization
B
Phishing
C
Secure boot bypass
D
SQL injection
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsphishingdifficulty-1

In a Kubernetes cluster involving the developer CI/CD pipeline and admin credentials, Attackers compromise a website frequently used by the company’s engineers and wait for them to visit. Which attack is this?

+1-0
MCQ
A
Disk wiping
B
Passwordless authentication
C
Risk transference
D
Watering-hole attack
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorswatering-holedifficulty-2

In a on-premises data center involving the identity provider and medical records, Several branded USB drives are left in the parking lot before malware appears on workstations. Which vector is most likely?

+1-0
MCQ
A
NTP amplification only
B
Data masking
C
Malicious removable media
D
Certificate pinning
CompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsusb-dropdifficulty-2

In a manufacturing OT segment involving the developer CI/CD pipeline and audit logs, Employees receive a benefits-update email linking to a lookalike login portal. Which vector is being used?

+1-0
MCQ
A
SQL injection
B
Phishing
C
BGP route summarization
D
Secure boot bypass
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsphishingdifficulty-1

In a manufacturing OT segment involving the remote-access VPN and medical records, Employees receive a benefits-update email linking to a lookalike login portal. Which vector is being used?

+1-0
MCQ
A
SQL injection
B
Secure boot bypass
C
Phishing
D
BGP route summarization
CompTIA-SecurityPlusSY0-701practice-test-03domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsphishingdifficulty-1

In a hybrid cloud involving the developer CI/CD pipeline and source code, Attackers compromise a website frequently used by the company’s engineers and wait for them to visit. Which attack is this?

+1-0
MCQ
A
Passwordless authentication
B
Watering-hole attack
C
Risk transference
D
Disk wiping
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorswatering-holedifficulty-2

In a Azure tenant involving the remote-access VPN and audit logs, Attackers compromise a website frequently used by the company’s engineers and wait for them to visit. Which attack is this?

+1-0
MCQ
A
Risk transference
B
Passwordless authentication
C
Watering-hole attack
D
Disk wiping
CompTIA-SecurityPlusSY0-701practice-test-03domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorswatering-holedifficulty-2

In a hybrid cloud involving the identity provider and customer PII, Several branded USB drives are left in the parking lot before malware appears on workstations. Which vector is most likely?

+1-0
MCQ
A
Certificate pinning
B
Data masking
C
Malicious removable media
D
NTP amplification only
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsusb-dropdifficulty-2

In a manufacturing OT segment involving the cloud storage account and customer PII, Several branded USB drives are left in the parking lot before malware appears on workstations. Which vector is most likely?

+1-0
MCQ
A
Certificate pinning
B
Data masking
C
NTP amplification only
D
Malicious removable media
CompTIA-SecurityPlusSY0-701practice-test-03domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsusb-dropdifficulty-2

In a retail branch network involving the SIEM rule set and medical records, Changing an order ID in an API URL returns another customer’s order. Which vulnerability is most likely?

+1-0
MCQ
A
Broken object-level authorization
B
Certificate transparency
C
Secure cookie flag
D
Port security
CompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesinsecure-apidifficulty-3

In a retail branch network involving the HR portal and medical records, Changing an order ID in an API URL returns another customer’s order. Which vulnerability is most likely?

+1-0
MCQ
A
Secure cookie flag
B
Certificate transparency
C
Broken object-level authorization
D
Port security
CompTIA-SecurityPlusSY0-701practice-test-03domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesinsecure-apidifficulty-3

In a retail branch network involving the remote-access VPN and encryption keys, A switch denies production access until endpoint posture is checked. Which control is used?

+1-0
MCQ
A
Network access control
B
Disk wiping
C
Open relay
D
Password spraying
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.2-secure-infrastructurenacdifficulty-2

In a AWS account involving the payment API and encryption keys, Workloads in the same data center are allowed to communicate only on explicitly required ports. Which design is this?

+1-0
MCQ
A
Flat network trust
B
Implicit any-any access
C
Microsegmentation
D
Broadcast expansion
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.2-secure-infrastructuremicrosegmentationdifficulty-2

In a manufacturing OT segment involving the HR portal and audit logs, Documents are labeled public, internal, confidential, or restricted before DLP policies apply. Which process is this?

+1-0
MCQ
A
Port mirroring
B
Data classification
C
Kerberoasting
D
NAT overload
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.3-data-protectionclassificationdifficulty-1

In a Kubernetes cluster involving the cloud storage account and medical records, Where should a public reverse proxy normally sit to limit exposure of internal application servers?

+1-0
MCQ
A
DMZ or perimeter network
B
Domain controller subnet
C
Offline backup vault
D
Privileged admin workstation
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.2-secure-infrastructuredmzdifficulty-1

In a AWS account involving the payment API and medical records, A switch denies production access until endpoint posture is checked. Which control is used?

+1-0
MCQ
A
Network access control
B
Open relay
C
Disk wiping
D
Password spraying
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.2-secure-infrastructurenacdifficulty-2

In a hybrid cloud involving the remote-access VPN and admin credentials, A switch denies production access until endpoint posture is checked. Which control is used?

+1-0
MCQ
A
Network access control
B
Open relay
C
Password spraying
D
Disk wiping
CompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.2-secure-infrastructurenacdifficulty-2

In a retail branch network involving the developer CI/CD pipeline and source code, Workloads in the same data center are allowed to communicate only on explicitly required ports. Which design is this?

+1-0
MCQ
A
Implicit any-any access
B
Flat network trust
C
Broadcast expansion
D
Microsegmentation
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.2-secure-infrastructuremicrosegmentationdifficulty-2

In a retail branch network involving the payment API and source code, Workloads in the same data center are allowed to communicate only on explicitly required ports. Which design is this?

+1-0
MCQ
A
Microsegmentation
B
Flat network trust
C
Broadcast expansion
D
Implicit any-any access
CompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.2-secure-infrastructuremicrosegmentationdifficulty-2

In a remote workforce involving the branch-office firewall and customer PII, A payment platform replaces card numbers with surrogate values while storing the mapping in a protected vault. What technique is this?

+1-0
MCQ
A
Steganography
B
Credential stuffing
C
Tokenization
D
ARP poisoning
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.3-data-protectiontokenizationdifficulty-2

In a retail branch network involving the developer CI/CD pipeline and medical records, A lost laptop contains an encrypted SSD. Which data state is protected most directly?

+1-0
MCQ
A
Data at rest
B
Data in use only
C
Data in transit only
D
Data remanence after secure wipe
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.3-data-protectiondata-at-restdifficulty-1

In a retail branch network involving the HR portal and financial reports, Documents are labeled public, internal, confidential, or restricted before DLP policies apply. Which process is this?

+1-0
MCQ
A
Port mirroring
B
Kerberoasting
C
NAT overload
D
Data classification
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.3-data-protectionclassificationdifficulty-1

In a Azure tenant involving the EDR console and source code, Documents are labeled public, internal, confidential, or restricted before DLP policies apply. Which process is this?

+1-0
MCQ
A
Data classification
B
NAT overload
C
Port mirroring
D
Kerberoasting
CompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.3-data-protectionclassificationdifficulty-1

In a Kubernetes cluster involving the developer CI/CD pipeline and admin credentials, A payment platform replaces card numbers with surrogate values while storing the mapping in a protected vault. What technique is this?

+1-0
MCQ
A
Credential stuffing
B
Tokenization
C
ARP poisoning
D
Steganography
CompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.3-data-protectiontokenizationdifficulty-2

In a on-premises data center involving the developer CI/CD pipeline and customer PII, A lost laptop contains an encrypted SSD. Which data state is protected most directly?

+1-0
MCQ
A
Data at rest
B
Data in use only
C
Data remanence after secure wipe
D
Data in transit only
CompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.3-data-protectiondata-at-restdifficulty-1

In a AWS account involving the cloud storage account and medical records, A design target says payroll must be restored within four hours after an outage. Which metric is this?

+1-0
MCQ
A
Annualized loss expectancy
B
Recovery point objective
C
Recovery time objective
D
Exposure factor
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.4-resiliencertodifficulty-2

In a Kubernetes cluster involving the developer CI/CD pipeline and cardholder data, Which backup design best resists ransomware modifying backup copies?

+1-0
MCQ
A
Writable backups mounted to all servers
B
Immutable or offline backups with restore testing
C
One untested backup on the same host
D
Backups with shared admin password
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.4-resilienceimmutable-backupdifficulty-2

In a hybrid cloud involving the branch-office firewall and admin credentials, An application uses load balancing across two availability zones. Which goal is improved?

+1-0
MCQ
A
Data minimization
B
Password entropy
C
High availability
D
Non-repudiation
CompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.4-resiliencehadifficulty-2

In a Kubernetes cluster involving the container platform and financial reports, A design target says payroll must be restored within four hours after an outage. Which metric is this?

+1-0
MCQ
A
Recovery point objective
B
Annualized loss expectancy
C
Recovery time objective
D
Exposure factor
CompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.4-resiliencertodifficulty-2

In a manufacturing OT segment involving the payment API and admin credentials, A design target says payroll must be restored within four hours after an outage. Which metric is this?

+1-0
MCQ
A
Exposure factor
B
Recovery time objective
C
Annualized loss expectancy
D
Recovery point objective
CompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.4-resiliencertodifficulty-2

In a remote workforce involving the container platform and admin credentials, Which backup design best resists ransomware modifying backup copies?

+1-0
MCQ
A
Backups with shared admin password
B
One untested backup on the same host
C
Writable backups mounted to all servers
D
Immutable or offline backups with restore testing
CompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.4-resilienceimmutable-backupdifficulty-2

In a remote workforce involving the HR portal and audit logs, Which backup design best resists ransomware modifying backup copies?

+1-0
MCQ
A
Immutable or offline backups with restore testing
B
Backups with shared admin password
C
Writable backups mounted to all servers
D
One untested backup on the same host
CompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.4-resilienceimmutable-backupdifficulty-2

In a hybrid cloud involving the SIEM rule set and financial reports, An application uses load balancing across two availability zones. Which goal is improved?

+1-0
MCQ
A
High availability
B
Data minimization
C
Password entropy
D
Non-repudiation
CompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.4-resiliencehadifficulty-2

Ready for the full experience?

Unlock hundreds of verified questions, full-length mock tests, and deep performance analytics for CompTIA-SecurityPlus.

Start Full Test Series