CompTIA Security+ CertMaster CE | Complete Practice
Questions, Correct Answers & Detailed Rationales (2026/2027)
Question 1
What concept defines the minimum necessary access rights granted to
a user or system process to perform its required functions?
• A. Principle of least privilege
• B. Separation of duties
• C. Discretionary access control
• D. Mandatory data labeling
Correct Answer: A. Principle of least privilege
Detailed Rationale: The principle of least privilege restricts user
permissions to only what is strictly necessary to perform authorized job
duties, reducing the potential blast radius of a compromised account.
Question 2
What cryptographic attack attempts to decrypt ciphertext by
systematically trying every possible key combination until the correct
key is found?
• A. Brute-force attack
• B. Birthday attack
• C. Rainbow table lookup
• D. Dictionary attack
,Correct Answer: A. Brute-force attack
Detailed Rationale: Brute-force attacks test every possible key or
password permutation exhaustively, making key length and complexity
critical defenses.
Question 3
What protocol provides secure, encrypted command-line shell remote
access over an unsecured network, replacing legacy Telnet?
• A. SSH (Secure Shell)
• B. FTP (File Transfer Protocol)
• C. SNMP (Simple Network Management Protocol)
• D. TFTP (Trivial File Transfer Protocol)
Correct Answer: A. SSH (Secure Shell)
Detailed Rationale: SSH encrypts all remote terminal traffic, preventing
packet sniffers from capturing administrative credentials in transit.
Question 4
What type of malware locks a user out of their device or encrypts files
and demands payment for restoration?
• A. Ransomware
• B. Adware
• C. Spyware
• D. Rootkit
Correct Answer: A. Ransomware
,Detailed Rationale: Ransomware holds enterprise files or device access
hostage using strong encryption until a ransom is paid in
cryptocurrency.
Question 5
What physical security control uses biometric verification combined
with interlocking doors to prevent piggybacking or tailgating?
• A. Mantrap
• B. Turnstile gate
• C. Security bollard
• D. Privacy filter
Correct Answer: A. Mantrap
Detailed Rationale: Mantraps force individuals to authenticate in an
isolated chamber before a secondary door unlocks, halting
unauthorized tailgaters.
Question 6
What framework is maintained by NIST to help organizations improve
their cybersecurity posture across five core functions: Identify, Protect,
Detect, Respond, and Recover?
• A. NIST Cybersecurity Framework (CSF)
• B. ISO/IEC 27001 standard
• C. MITRE ATT&CK framework
• D. OWASP Top Ten project
Correct Answer: A. NIST Cybersecurity Framework (CSF)
, Detailed Rationale: The NIST CSF provides a universal taxonomy and
guidance for managing and reducing cybersecurity risk across
enterprise environments.
Question 7
What type of backup saves all files that have been modified since the
last full backup, making restoration faster but backup times longer over
the week?
• A. Differential backup
• B. Incremental backup
• C. Snapshot clone
• D. Mirror copy
Correct Answer: A. Differential backup
Detailed Rationale: Differential backups accumulate all changes since
the last full backup, simplifying restoration to require only the full
backup and the latest differential set.
Question 8
What cloud service model provides fully managed infrastructure,
storage, and networking resources where customers manage operating
systems, middleware, and applications?
• A. IaaS (Infrastructure as a Service)
• B. PaaS (Platform as a Service)
• C. SaaS (Software as a Service)
• D. SECaaS (Security as a Service)
Questions, Correct Answers & Detailed Rationales (2026/2027)
Question 1
What concept defines the minimum necessary access rights granted to
a user or system process to perform its required functions?
• A. Principle of least privilege
• B. Separation of duties
• C. Discretionary access control
• D. Mandatory data labeling
Correct Answer: A. Principle of least privilege
Detailed Rationale: The principle of least privilege restricts user
permissions to only what is strictly necessary to perform authorized job
duties, reducing the potential blast radius of a compromised account.
Question 2
What cryptographic attack attempts to decrypt ciphertext by
systematically trying every possible key combination until the correct
key is found?
• A. Brute-force attack
• B. Birthday attack
• C. Rainbow table lookup
• D. Dictionary attack
,Correct Answer: A. Brute-force attack
Detailed Rationale: Brute-force attacks test every possible key or
password permutation exhaustively, making key length and complexity
critical defenses.
Question 3
What protocol provides secure, encrypted command-line shell remote
access over an unsecured network, replacing legacy Telnet?
• A. SSH (Secure Shell)
• B. FTP (File Transfer Protocol)
• C. SNMP (Simple Network Management Protocol)
• D. TFTP (Trivial File Transfer Protocol)
Correct Answer: A. SSH (Secure Shell)
Detailed Rationale: SSH encrypts all remote terminal traffic, preventing
packet sniffers from capturing administrative credentials in transit.
Question 4
What type of malware locks a user out of their device or encrypts files
and demands payment for restoration?
• A. Ransomware
• B. Adware
• C. Spyware
• D. Rootkit
Correct Answer: A. Ransomware
,Detailed Rationale: Ransomware holds enterprise files or device access
hostage using strong encryption until a ransom is paid in
cryptocurrency.
Question 5
What physical security control uses biometric verification combined
with interlocking doors to prevent piggybacking or tailgating?
• A. Mantrap
• B. Turnstile gate
• C. Security bollard
• D. Privacy filter
Correct Answer: A. Mantrap
Detailed Rationale: Mantraps force individuals to authenticate in an
isolated chamber before a secondary door unlocks, halting
unauthorized tailgaters.
Question 6
What framework is maintained by NIST to help organizations improve
their cybersecurity posture across five core functions: Identify, Protect,
Detect, Respond, and Recover?
• A. NIST Cybersecurity Framework (CSF)
• B. ISO/IEC 27001 standard
• C. MITRE ATT&CK framework
• D. OWASP Top Ten project
Correct Answer: A. NIST Cybersecurity Framework (CSF)
, Detailed Rationale: The NIST CSF provides a universal taxonomy and
guidance for managing and reducing cybersecurity risk across
enterprise environments.
Question 7
What type of backup saves all files that have been modified since the
last full backup, making restoration faster but backup times longer over
the week?
• A. Differential backup
• B. Incremental backup
• C. Snapshot clone
• D. Mirror copy
Correct Answer: A. Differential backup
Detailed Rationale: Differential backups accumulate all changes since
the last full backup, simplifying restoration to require only the full
backup and the latest differential set.
Question 8
What cloud service model provides fully managed infrastructure,
storage, and networking resources where customers manage operating
systems, middleware, and applications?
• A. IaaS (Infrastructure as a Service)
• B. PaaS (Platform as a Service)
• C. SaaS (Software as a Service)
• D. SECaaS (Security as a Service)