Quiz Bank — Security Exam Questions with
Correct Answers (Verifiedanswers) Plus
Rationales 2026 Q&A Instant Download PDF
Question 1
Which principle requires that users be granted only the
permissions necessary to perform their assigned duties?
A. Separation of duties
B. Least privilege
C. Mandatory vacation
D. Job rotation
Rationale: The principle of least privilege limits a user's access
rights to only those resources and actions required for
legitimate job responsibilities. This reduces the potential
damage caused by accidental misuse, compromised credentials,
or malicious activity. Separation of duties is related but focuses
on dividing critical responsibilities among multiple individuals so
that one person cannot complete an entire sensitive process
alone.
Question 2
,What is the primary purpose of multi-factor authentication
(MFA)?
A. To eliminate the need for passwords
B. To encrypt all network traffic
C. To require multiple independent authentication factors
D. To prevent all malware infections
Rationale: MFA strengthens authentication by requiring two or
more independent factors, such as something the user knows,
something the user has, or something the user is. If an attacker
obtains a password, the additional factor can still prevent
unauthorized access. MFA does not itself encrypt network traffic
or provide complete protection against malware.
Question 3
Which security property ensures that information cannot be
altered without authorization?
A. Availability
B. Confidentiality
C. Authentication
D. Integrity
Rationale: Integrity protects information from unauthorized
modification, destruction, or manipulation. Confidentiality
prevents unauthorized disclosure, while availability ensures
,authorized users can access systems and information when
needed. Together, confidentiality, integrity, and availability form
the classic CIA triad of information security.
Question 4
An organization wants to ensure that critical business systems
remain accessible after a major outage. Which security
objective is most relevant?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Rationale: Availability concerns ensuring that systems,
applications, and data remain accessible to authorized users
when required. Business continuity, redundancy, backups,
disaster recovery, and resilient infrastructure all contribute to
availability. Confidentiality instead addresses unauthorized
disclosure, while integrity addresses unauthorized modification.
Question 5
Which type of malware can replicate itself across networks
without requiring a user to execute an infected file?
, A. Trojan
B. Worm
C. Spyware
D. Rootkit
Rationale: A worm is self-replicating malware that can spread
automatically, often by exploiting vulnerabilities in networked
systems or services. A Trojan generally disguises itself as
legitimate software and relies on execution by a user or another
process. Spyware focuses on monitoring or collecting
information, while rootkits are designed primarily to conceal
malicious activity.
Question 6
What is phishing primarily designed to accomplish?
A. Physically damage network equipment
B. Improve password complexity
C. Trick users into revealing sensitive information or
performing an unsafe action
D. Automatically patch vulnerable systems
Rationale: Phishing is a social-engineering technique in which
attackers impersonate trustworthy individuals or organizations
to manipulate victims. Attackers may attempt to obtain
credentials, financial information, authentication codes, or
Correct Answers (Verifiedanswers) Plus
Rationales 2026 Q&A Instant Download PDF
Question 1
Which principle requires that users be granted only the
permissions necessary to perform their assigned duties?
A. Separation of duties
B. Least privilege
C. Mandatory vacation
D. Job rotation
Rationale: The principle of least privilege limits a user's access
rights to only those resources and actions required for
legitimate job responsibilities. This reduces the potential
damage caused by accidental misuse, compromised credentials,
or malicious activity. Separation of duties is related but focuses
on dividing critical responsibilities among multiple individuals so
that one person cannot complete an entire sensitive process
alone.
Question 2
,What is the primary purpose of multi-factor authentication
(MFA)?
A. To eliminate the need for passwords
B. To encrypt all network traffic
C. To require multiple independent authentication factors
D. To prevent all malware infections
Rationale: MFA strengthens authentication by requiring two or
more independent factors, such as something the user knows,
something the user has, or something the user is. If an attacker
obtains a password, the additional factor can still prevent
unauthorized access. MFA does not itself encrypt network traffic
or provide complete protection against malware.
Question 3
Which security property ensures that information cannot be
altered without authorization?
A. Availability
B. Confidentiality
C. Authentication
D. Integrity
Rationale: Integrity protects information from unauthorized
modification, destruction, or manipulation. Confidentiality
prevents unauthorized disclosure, while availability ensures
,authorized users can access systems and information when
needed. Together, confidentiality, integrity, and availability form
the classic CIA triad of information security.
Question 4
An organization wants to ensure that critical business systems
remain accessible after a major outage. Which security
objective is most relevant?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Rationale: Availability concerns ensuring that systems,
applications, and data remain accessible to authorized users
when required. Business continuity, redundancy, backups,
disaster recovery, and resilient infrastructure all contribute to
availability. Confidentiality instead addresses unauthorized
disclosure, while integrity addresses unauthorized modification.
Question 5
Which type of malware can replicate itself across networks
without requiring a user to execute an infected file?
, A. Trojan
B. Worm
C. Spyware
D. Rootkit
Rationale: A worm is self-replicating malware that can spread
automatically, often by exploiting vulnerabilities in networked
systems or services. A Trojan generally disguises itself as
legitimate software and relies on execution by a user or another
process. Spyware focuses on monitoring or collecting
information, while rootkits are designed primarily to conceal
malicious activity.
Question 6
What is phishing primarily designed to accomplish?
A. Physically damage network equipment
B. Improve password complexity
C. Trick users into revealing sensitive information or
performing an unsafe action
D. Automatically patch vulnerable systems
Rationale: Phishing is a social-engineering technique in which
attackers impersonate trustworthy individuals or organizations
to manipulate victims. Attackers may attempt to obtain
credentials, financial information, authentication codes, or