COMPTIA SECURE INFRASTRUCTURE
SPECIALIST CERTIFICATION EXAM WITH
QUESTIONS AND VERIFIED ANSWERS,
PLUS DETAILED RATIONALES/EXPERT
VERIFIED FOR GUARANTEED PASS
2026/LATEST UPDATE/INSTANT
DOWNLOAD PDF
1. A security administrator is designing a secure enterprise
infrastructure for an organization that has both on-premises servers
and workloads hosted in a public cloud. The organization wants to
reduce the likelihood that a compromised workstation can access
sensitive server resources. Which security architecture BEST
addresses this requirement?
A. Flat network architecture with a perimeter firewall
B. Zero Trust architecture with microsegmentation
C. Hub-and-spoke architecture without access controls
D. Workgroup-based architecture with shared credentials
Answer: B. Zero Trust architecture with microsegmentation
Rationale: Zero Trust assumes that no user, device, or network
location should automatically be trusted. Microsegmentation further
limits lateral movement by isolating workloads and restricting
communication between network segments. A traditional perimeter
firewall alone does not adequately protect against threats originating
inside the network.
1
, 2. A company wants administrators to access production servers
without exposing management interfaces directly to the internet.
Which solution provides the MOST secure approach?
A. Enable SSH on all servers using public IP addresses
B. Place management interfaces behind a dedicated bastion host
C. Disable all authentication requirements
D. Allow administrators to connect directly using FTP
Answer: B. Place management interfaces behind a dedicated bastion
host
Rationale: A bastion host provides a controlled entry point into a
protected administrative environment. Access can be restricted
through MFA, IP allowlisting, logging, and additional security
controls. Exposing SSH or other management services directly to the
internet increases the attack surface.
3. An organization is implementing network access control. A laptop
attempting to connect to the corporate network must be checked
for operating-system patches, antivirus status, and security
configuration before receiving network access. Which technology
BEST supports this requirement?
A. NAT
B. NAC
C. DNSSEC
D. VLAN trunking
Answer: B. NAC
Rationale: Network Access Control (NAC) evaluates endpoints before
or during network access and can enforce security policies based on
device identity and posture. NAT translates addresses, DNSSEC
2
,protects DNS integrity, and VLAN trunking carries multiple VLANs
over a network link.
4. A security engineer wants to separate finance, human resources,
development, and guest devices into different logical broadcast
domains while using the same physical switching infrastructure.
Which technology should be implemented?
A. VLANs
B. RAID
C. VPN
D. SAN zoning only
Answer: A. VLANs
Rationale: VLANs logically separate devices into distinct Layer 2
broadcast domains. This improves segmentation and can be combined
with routing and firewall policies to control communication between
departments. RAID provides storage redundancy, while VPNs provide
encrypted tunnels.
5. A company uses VLANs extensively but discovers that
compromised systems can still communicate with systems in other
VLANs. Which security control should be implemented to regulate
inter-VLAN traffic?
A. Layer 3 firewall or ACL rules
B. DHCP relay only
C. Port mirroring
D. RAID 10
Answer: A. Layer 3 firewall or ACL rules
3
, Rationale: VLANs provide segmentation but do not inherently enforce
detailed security policies between routed networks. Layer 3 ACLs or
firewalls can explicitly allow or deny communication between VLANs
based on addresses, ports, protocols, applications, or other criteria.
6. A company wants employees working remotely to access internal
applications through an encrypted connection over the public
internet. Which technology is MOST appropriate?
A. VPN
B. Telnet
C. HTTP
D. SNMPv1
Answer: A. VPN
Rationale: A Virtual Private Network creates an encrypted tunnel over
an untrusted network such as the internet. Modern VPN technologies
can provide confidentiality, integrity, authentication, and secure
remote access. Telnet and HTTP do not provide adequate encryption,
while SNMP is primarily a network-management protocol.
7. A network administrator wants to replace an insecure remote-
management protocol that transmits credentials in plaintext. Which
protocol should be used instead?
A. Telnet
B. FTP
C. SSH
D. TFTP
Answer: C. SSH
4
SPECIALIST CERTIFICATION EXAM WITH
QUESTIONS AND VERIFIED ANSWERS,
PLUS DETAILED RATIONALES/EXPERT
VERIFIED FOR GUARANTEED PASS
2026/LATEST UPDATE/INSTANT
DOWNLOAD PDF
1. A security administrator is designing a secure enterprise
infrastructure for an organization that has both on-premises servers
and workloads hosted in a public cloud. The organization wants to
reduce the likelihood that a compromised workstation can access
sensitive server resources. Which security architecture BEST
addresses this requirement?
A. Flat network architecture with a perimeter firewall
B. Zero Trust architecture with microsegmentation
C. Hub-and-spoke architecture without access controls
D. Workgroup-based architecture with shared credentials
Answer: B. Zero Trust architecture with microsegmentation
Rationale: Zero Trust assumes that no user, device, or network
location should automatically be trusted. Microsegmentation further
limits lateral movement by isolating workloads and restricting
communication between network segments. A traditional perimeter
firewall alone does not adequately protect against threats originating
inside the network.
1
, 2. A company wants administrators to access production servers
without exposing management interfaces directly to the internet.
Which solution provides the MOST secure approach?
A. Enable SSH on all servers using public IP addresses
B. Place management interfaces behind a dedicated bastion host
C. Disable all authentication requirements
D. Allow administrators to connect directly using FTP
Answer: B. Place management interfaces behind a dedicated bastion
host
Rationale: A bastion host provides a controlled entry point into a
protected administrative environment. Access can be restricted
through MFA, IP allowlisting, logging, and additional security
controls. Exposing SSH or other management services directly to the
internet increases the attack surface.
3. An organization is implementing network access control. A laptop
attempting to connect to the corporate network must be checked
for operating-system patches, antivirus status, and security
configuration before receiving network access. Which technology
BEST supports this requirement?
A. NAT
B. NAC
C. DNSSEC
D. VLAN trunking
Answer: B. NAC
Rationale: Network Access Control (NAC) evaluates endpoints before
or during network access and can enforce security policies based on
device identity and posture. NAT translates addresses, DNSSEC
2
,protects DNS integrity, and VLAN trunking carries multiple VLANs
over a network link.
4. A security engineer wants to separate finance, human resources,
development, and guest devices into different logical broadcast
domains while using the same physical switching infrastructure.
Which technology should be implemented?
A. VLANs
B. RAID
C. VPN
D. SAN zoning only
Answer: A. VLANs
Rationale: VLANs logically separate devices into distinct Layer 2
broadcast domains. This improves segmentation and can be combined
with routing and firewall policies to control communication between
departments. RAID provides storage redundancy, while VPNs provide
encrypted tunnels.
5. A company uses VLANs extensively but discovers that
compromised systems can still communicate with systems in other
VLANs. Which security control should be implemented to regulate
inter-VLAN traffic?
A. Layer 3 firewall or ACL rules
B. DHCP relay only
C. Port mirroring
D. RAID 10
Answer: A. Layer 3 firewall or ACL rules
3
, Rationale: VLANs provide segmentation but do not inherently enforce
detailed security policies between routed networks. Layer 3 ACLs or
firewalls can explicitly allow or deny communication between VLANs
based on addresses, ports, protocols, applications, or other criteria.
6. A company wants employees working remotely to access internal
applications through an encrypted connection over the public
internet. Which technology is MOST appropriate?
A. VPN
B. Telnet
C. HTTP
D. SNMPv1
Answer: A. VPN
Rationale: A Virtual Private Network creates an encrypted tunnel over
an untrusted network such as the internet. Modern VPN technologies
can provide confidentiality, integrity, authentication, and secure
remote access. Telnet and HTTP do not provide adequate encryption,
while SNMP is primarily a network-management protocol.
7. A network administrator wants to replace an insecure remote-
management protocol that transmits credentials in plaintext. Which
protocol should be used instead?
A. Telnet
B. FTP
C. SSH
D. TFTP
Answer: C. SSH
4