CompTIA Sec+ Practice Assessment questions and
answers (verified answers graded a+) latest update
2025/2026
An organization recently hired a new employee who passed all the necessary
background checks and completed the recruitment process successfully. The
organization wants to ensure that the new employee's integration into the
company is as smooth and secure as possible. Which of the following procedures
would be MOST appropriate to apply in this situation? -
...(ANSWERS)....Onboarding
The company's system has recently detected suspicious network activity, signaling
a possible cybersecurity incident. The incident response team has assembled, and
after going through the detection and analysis phases, the containment phase of
the incident response process has started. In this phase, what is the primary
objective? - ...(ANSWERS)....Limiting the scope and magnitude of the incident
An organization has decommissioned several laptops used for handling sensitive
data. Which of the following should be the primary step to ensure data security
and compliance with regulations before repurposing or disposing of these
devices? - ...(ANSWERS)....Initiating a secure data destruction process
A newly established organization has decided to implement Virtual LANs (VLANs)
for segmenting workstation computer hosts from Voice over Internet Protocol
(VoIP) handsets. The organization is using two VLANs that map to two subnets:
10.1.32.0/24 for workstation computers and 10.1.40.0/24 for VoIP handsets. In
this setup, what could be a potential security advantage? -
...(ANSWERS)....Enhanced control over communication between VLANs.
,A software engineer discovers a flaw in one of its products that could allow
nefarious attackers to gain unauthorized access to the system on which it is
running. What vulnerability signifies that developers must immediately fix the
problem or widespread damage could ensue before a patch is available. -
...(ANSWERS)....Zero-day
A technology company experiences several security vulnerabilities with its online
application, leading to customer complaints and legal threats. In response, the
board of directors decides to outsource the maintenance and associated liabilities
of the application to a third party. Which risk management strategy is the
company primarily implementing? - ...(ANSWERS)....Risk transference
A multinational firm headquartered in San Francisco, California, serves customers
from various countries, including European Union countries. The company
collects, processes, and stores substantial amounts of personal data. With which
of the following legal regulations must the company's governance committee
ensure compliance? - ...(ANSWERS)....Both General Data Protection Regulation
(GDPR) and California Consumer Privacy Act (CCPA)
An organization considers a new third-party vendor to provide critical technology
solutions. It is nearing the final stages of the vendor selection process and wants
to ensure a robust assessment of the vendor's security practices and risk
management capabilities. Provided approval is granted, which method would be
MOST suitable for the organization to gain an in-depth understanding of the
vendor's security controls, identify potential vulnerabilities in its systems, and
validate the effectiveness of its security measures? - ...(ANSWERS)....Conduct a
penetration test
, After an extensive security audit, a medium-sized corporation discovers several of
its company laptops contain malware. The malware is most likely the result of the
use of unauthorized USB storage devices. The chief information security officer
(CISO) wants to prevent similar incidents in the future. Which of the following
options would best mitigate this risk? - ...(ANSWERS)....Deploy port control
software and restrict the use of USB storage devices
Under the General Data Protection Regulation (GDPR), how soon must an
organization report a breach of personal data? - ...(ANSWERS)....Within 72 hours
of becoming aware of the breach
A company is considering moving its applications and data to the cloud. The
company handles sensitive data and wants to maintain control over the security
of its applications and data. It is considering using an infrastructure-as-a-service
(IaaS) model. Which of the following is a key responsibility the company will need
to manage in an IaaS model? - ...(ANSWERS)....Protection of operating systems
when deployed
Which of the following is a correct interpretation of data sovereignty? -
...(ANSWERS)....A jurisdiction can restrict or prevent processing and storage of
data on systems that do not physically reside within that jurisdiction.
An employee at a company is having difficulty remembering a complex password
and is looking for a more secure and memorable alternative. What type of
credential would be the BEST recommendation? - ...(ANSWERS)....A device-
specific PIN with any characters and length
answers (verified answers graded a+) latest update
2025/2026
An organization recently hired a new employee who passed all the necessary
background checks and completed the recruitment process successfully. The
organization wants to ensure that the new employee's integration into the
company is as smooth and secure as possible. Which of the following procedures
would be MOST appropriate to apply in this situation? -
...(ANSWERS)....Onboarding
The company's system has recently detected suspicious network activity, signaling
a possible cybersecurity incident. The incident response team has assembled, and
after going through the detection and analysis phases, the containment phase of
the incident response process has started. In this phase, what is the primary
objective? - ...(ANSWERS)....Limiting the scope and magnitude of the incident
An organization has decommissioned several laptops used for handling sensitive
data. Which of the following should be the primary step to ensure data security
and compliance with regulations before repurposing or disposing of these
devices? - ...(ANSWERS)....Initiating a secure data destruction process
A newly established organization has decided to implement Virtual LANs (VLANs)
for segmenting workstation computer hosts from Voice over Internet Protocol
(VoIP) handsets. The organization is using two VLANs that map to two subnets:
10.1.32.0/24 for workstation computers and 10.1.40.0/24 for VoIP handsets. In
this setup, what could be a potential security advantage? -
...(ANSWERS)....Enhanced control over communication between VLANs.
,A software engineer discovers a flaw in one of its products that could allow
nefarious attackers to gain unauthorized access to the system on which it is
running. What vulnerability signifies that developers must immediately fix the
problem or widespread damage could ensue before a patch is available. -
...(ANSWERS)....Zero-day
A technology company experiences several security vulnerabilities with its online
application, leading to customer complaints and legal threats. In response, the
board of directors decides to outsource the maintenance and associated liabilities
of the application to a third party. Which risk management strategy is the
company primarily implementing? - ...(ANSWERS)....Risk transference
A multinational firm headquartered in San Francisco, California, serves customers
from various countries, including European Union countries. The company
collects, processes, and stores substantial amounts of personal data. With which
of the following legal regulations must the company's governance committee
ensure compliance? - ...(ANSWERS)....Both General Data Protection Regulation
(GDPR) and California Consumer Privacy Act (CCPA)
An organization considers a new third-party vendor to provide critical technology
solutions. It is nearing the final stages of the vendor selection process and wants
to ensure a robust assessment of the vendor's security practices and risk
management capabilities. Provided approval is granted, which method would be
MOST suitable for the organization to gain an in-depth understanding of the
vendor's security controls, identify potential vulnerabilities in its systems, and
validate the effectiveness of its security measures? - ...(ANSWERS)....Conduct a
penetration test
, After an extensive security audit, a medium-sized corporation discovers several of
its company laptops contain malware. The malware is most likely the result of the
use of unauthorized USB storage devices. The chief information security officer
(CISO) wants to prevent similar incidents in the future. Which of the following
options would best mitigate this risk? - ...(ANSWERS)....Deploy port control
software and restrict the use of USB storage devices
Under the General Data Protection Regulation (GDPR), how soon must an
organization report a breach of personal data? - ...(ANSWERS)....Within 72 hours
of becoming aware of the breach
A company is considering moving its applications and data to the cloud. The
company handles sensitive data and wants to maintain control over the security
of its applications and data. It is considering using an infrastructure-as-a-service
(IaaS) model. Which of the following is a key responsibility the company will need
to manage in an IaaS model? - ...(ANSWERS)....Protection of operating systems
when deployed
Which of the following is a correct interpretation of data sovereignty? -
...(ANSWERS)....A jurisdiction can restrict or prevent processing and storage of
data on systems that do not physically reside within that jurisdiction.
An employee at a company is having difficulty remembering a complex password
and is looking for a more secure and memorable alternative. What type of
credential would be the BEST recommendation? - ...(ANSWERS)....A device-
specific PIN with any characters and length