CompTIA Security+ Practice Exam Questions
and Correct Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant Download Pdf
1. Which security principle ensures that information is accessible
only to authorized individuals?
A. Availability
B. Integrity
C. Confidentiality
D. Nonrepudiation
Rationale: Confidentiality is one of the three pillars of the CIA triad. It
ensures that sensitive information is only accessible by authorized
users through controls such as encryption, authentication, and access
permissions. Availability ensures systems remain operational, integrity
protects data from unauthorized modification, and nonrepudiation
prevents users from denying their actions.
2. Which component of the CIA triad ensures that information has
not been altered without authorization?
,A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Rationale: Integrity guarantees that data remains accurate, complete,
and trustworthy throughout its lifecycle. Hashing, digital signatures,
and checksums are common mechanisms used to verify integrity.
3. Which authentication factor does a fingerprint scanner represent?
A. Something you know
B. Somewhere you are
C. Something you are
D. Something you have
Rationale: Biometrics such as fingerprints, iris scans, and facial
recognition are examples of "something you are." This category relies
on unique biological characteristics to verify identity.
4. What type of malware disguises itself as legitimate software?
A. Worm
B. Trojan horse
,C. Rootkit
D. Logic bomb
Rationale: A Trojan horse appears to be legitimate software but
secretly performs malicious actions once installed. Unlike worms,
Trojans do not self-replicate.
5. Which attack attempts to overwhelm a server with excessive
traffic from multiple systems?
A. Spoofing
B. Phishing
C. Smishing
D. Distributed Denial-of-Service (DDoS)
Rationale: A DDoS attack uses many compromised devices to flood a
target with traffic, exhausting resources and preventing legitimate
users from accessing services.
6. Which encryption algorithm is considered symmetric?
A. RSA
B. ECC
, C. AES
D. Diffie-Hellman
Rationale: AES is a symmetric encryption algorithm that uses the same
key for encryption and decryption. RSA and ECC are asymmetric
algorithms.
7. Which protocol securely encrypts web traffic?
A. FTP
B. HTTP
C. HTTPS
D. Telnet
Rationale: HTTPS combines HTTP with TLS encryption to protect data
transmitted between clients and web servers against interception and
tampering.
8. What is the primary purpose of hashing?
A. Encrypt data
B. Verify data integrity
C. Compress files
D. Authenticate users
and Correct Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant Download Pdf
1. Which security principle ensures that information is accessible
only to authorized individuals?
A. Availability
B. Integrity
C. Confidentiality
D. Nonrepudiation
Rationale: Confidentiality is one of the three pillars of the CIA triad. It
ensures that sensitive information is only accessible by authorized
users through controls such as encryption, authentication, and access
permissions. Availability ensures systems remain operational, integrity
protects data from unauthorized modification, and nonrepudiation
prevents users from denying their actions.
2. Which component of the CIA triad ensures that information has
not been altered without authorization?
,A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Rationale: Integrity guarantees that data remains accurate, complete,
and trustworthy throughout its lifecycle. Hashing, digital signatures,
and checksums are common mechanisms used to verify integrity.
3. Which authentication factor does a fingerprint scanner represent?
A. Something you know
B. Somewhere you are
C. Something you are
D. Something you have
Rationale: Biometrics such as fingerprints, iris scans, and facial
recognition are examples of "something you are." This category relies
on unique biological characteristics to verify identity.
4. What type of malware disguises itself as legitimate software?
A. Worm
B. Trojan horse
,C. Rootkit
D. Logic bomb
Rationale: A Trojan horse appears to be legitimate software but
secretly performs malicious actions once installed. Unlike worms,
Trojans do not self-replicate.
5. Which attack attempts to overwhelm a server with excessive
traffic from multiple systems?
A. Spoofing
B. Phishing
C. Smishing
D. Distributed Denial-of-Service (DDoS)
Rationale: A DDoS attack uses many compromised devices to flood a
target with traffic, exhausting resources and preventing legitimate
users from accessing services.
6. Which encryption algorithm is considered symmetric?
A. RSA
B. ECC
, C. AES
D. Diffie-Hellman
Rationale: AES is a symmetric encryption algorithm that uses the same
key for encryption and decryption. RSA and ECC are asymmetric
algorithms.
7. Which protocol securely encrypts web traffic?
A. FTP
B. HTTP
C. HTTPS
D. Telnet
Rationale: HTTPS combines HTTP with TLS encryption to protect data
transmitted between clients and web servers against interception and
tampering.
8. What is the primary purpose of hashing?
A. Encrypt data
B. Verify data integrity
C. Compress files
D. Authenticate users