100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

CompTIA CertMaster CE Security+ Section 2 Practice Questions – CompTIA Security+, 2026 | Verified Questions with Correct Answers

Rating
-
Sold
-
Pages
8
Grade
A+
Uploaded on
10-01-2026
Written in
2025/2026

This document contains CompTIA CertMaster CE Security+ Section 2 practice questions with fully correct and verified answers, aligned with the 2026 Security+ exam objectives. It focuses on reinforcing core Security+ concepts through exam-style questions designed for effective review and certification renewal. The material is suitable for self-study, targeted practice, and ensuring readiness for the latest Security+ CE requirements.

Show more Read less
Institution
COMPTIA CERTMASTER CE SECURITY+
Module
COMPTIA CERTMASTER CE SECURITY+









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
COMPTIA CERTMASTER CE SECURITY+
Module
COMPTIA CERTMASTER CE SECURITY+

Document information

Uploaded on
January 10, 2026
Number of pages
8
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

COMPTIA CERTMASTER CE SECURITY+ SECTION 2
QUESTIONS WITH CORRECT ANSWERS 2026
A firewall - CORRECT ANSWER -
any software or hardware device that protects a system or network by blocking unwanted network tra
ffic. Firewalls generally are configured to stop suspicious or unsolicited incoming traffic through a proc
ess called implicit deny.



A stateful firewall - CORRECT ANSWER -
A stateful firewall does track the active state of a connection and is able to make decisions based on t
he contents of a network packet as it relates to the state of the connection.



stateless firewall - CORRECT ANSWER -
does not track the active state of a connection as it reaches the firewall. It allows or blocks traffic bas
ed on some static value associated with that traffic.



An access control list (ACL) - CORRECT ANSWER -
a list of objects with permissions attached to those objects. The list specifies which entities (such as in
dividuals) have the rights to access specific resources and to what extent those resources may be mo
dified (if at all).



Implicit deny - CORRECT ANSWER -
The principle that establishes that everything that is not explicitly allowed is denied.



A VPN concentrator - CORRECT ANSWER -
A single device that incorporates advanced encryption and authentication methods in order to handle
a large number of VPN tunnels.



Remote access vs. site-to-site - CORRECT ANSWER -
A remote access VPN connects individual remote users to the private network, whereas a site-to-
site VPN connects two private networks together.



Internet Protocol Security (IPSec) - CORRECT ANSWER -an open-
source protocol framework for security development within the TCP/IP family of protocol standards. IP
Sec is not application dependent as it operates at the network layer (layer 3) of the OSI model.

, IPSec transport mode - CORRECT ANSWER -
IPSec encrypts just the IP payload, leaving the IP packet header unchanged so it can be easily routed t
hrough the internet



IPSec tunnel mode - CORRECT ANSWER -both the packet contents and header are encrypted.



IPSec, Authentication Header (AH) - CORRECT ANSWER -
One of the two protocols used in IPSec, Authentication Header (AH) provides authentication for the or
igin of transmitted data as well as integrity and protection against replay attacks.



IPSec, Encapsulation Security Payload (ESP) - CORRECT ANSWER -
One of the two protocols used in IPSec, provides the same functionality as Authentication Header (AH
), with the addition of encryption to support the confidentiality of transmitted data.



Split tunnel vs. full tunnel - CORRECT ANSWER -
When a device is connected to the VPN in full tunnel mode, all network traffic is sent through the tun
nel and encrypted. In split mode, only some of the traffic is sent through the tunnel and encrypted.



TLS/SSL (Transport Layer Security and Secure Sockets Layer) - CORRECT ANSWER -
Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are security protocols that combine digit
al certificates for authentication with public key data encryption.



Always-on VPN - CORRECT ANSWER -Some VPN concentrators support an always-
on capability so that the user's device will automatically connect to the VPN any time it has an Intern
et connection.



NIPS (network-based intrusion prevention system) - CORRECT ANSWER -
A network intrusion prevention system (NIPS) monitors suspicious traffic on the network and reacts in
real time to block it.



NIDS (network-based intrusion detection system) - CORRECT ANSWER -
A NIDS primarily uses passive hardware sensors to monitor traffic on a specific segment of the networ
k. It can sniff traffic and send alerts about anomalies or concerns.

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Puresilver4 stuvia
Follow You need to be logged in order to follow users or courses
Sold
67
Member since
1 year
Number of followers
0
Documents
1361
Last sold
20 hours ago
PASS SILVER

EXAMS practice with verified and correct answers pass grade A+ SILVER PASSI have Accounting, Finance, Statistics, Computer Science, Nursing, Chemistry, Biology And All Other Subjects A+ solutions A+ SOLUTIONS FOR FELLOW STUDENTS Nursing Being my main profession line, My mission is to be your LIGHT in the dark. If you're worried or having trouble in nursing school, I really want my notes to be your guide! I know they have helped countless others get through and that's all I want for YOU! I have essential Study guides that are Almost A+ graded, I am a very friendly person: Solutions SolutionsStuvia

Read more Read less
4.1

11 reviews

5
6
4
0
3
5
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these revision notes.

Didn't get what you expected? Choose another document

No problem! You can straightaway pick a different document that better suits what you're after.

Pay as you like, start learning straight away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and smashed it. It really can be that simple.”

Alisha Student

Frequently asked questions