CompTIA Security+ Practice Exam Questions
And Correct Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant Download Pdf
1. Which of the following is the PRIMARY purpose of a firewall?
A. Encrypt network traffic
B. Filter network traffic
C. Perform backups
D. Monitor CPU usage
Firewalls are designed to control network traffic by allowing or
blocking data packets based on security rules. They do not
inherently encrypt traffic or perform backups.
2. What does the principle of least privilege ensure?
A. Users have unrestricted access
B. Users have only the access necessary to perform their job
C. Users can install any software
D. Users can bypass security controls
Least privilege reduces risk by limiting user access to only what is
needed, minimizing potential misuse or damage.
,3. Which type of malware can spread itself without user interaction?
A. Trojan
B. Spyware
C. Worm
D. Rootkit
Worms propagate independently across networks, unlike Trojans
which require user action.
4. What is the main difference between symmetric and asymmetric
encryption?
A. Symmetric uses longer keys
B. Symmetric uses the same key for encryption and decryption;
asymmetric uses a public and private key
C. Asymmetric is faster than symmetric
D. Symmetric uses hash functions
Symmetric encryption is faster but requires secure key sharing;
asymmetric uses a key pair allowing public distribution of one
key.
5. Which of the following is an example of multi-factor
authentication?
A. Password only
B. Security question only
, C. Password and fingerprint scan
D. Username only
Multi-factor authentication combines two or more types of
factors: something you know, something you have, or something
you are.
6. A company wants to prevent unauthorized users from connecting
to its wireless network. Which security measure is MOST
effective?
A. WEP encryption
B. SSID broadcasting
C. WPA3 encryption with strong passwords
D. MAC address filtering only
WPA3 is currently the most secure Wi-Fi standard, providing
robust encryption and authentication. WEP is obsolete.
7. What is the primary purpose of a VPN?
A. Block malware
B. Filter spam
C. Secure remote communications over the Internet
D. Scan for vulnerabilities
VPNs encrypt network traffic between endpoints to protect data
in transit, especially over untrusted networks.
, 8. Which attack involves intercepting and modifying communications
between two parties?
A. Phishing
B. Man-in-the-middle
C. SQL injection
D. Brute force
Man-in-the-middle attacks exploit communication channels by
intercepting and potentially altering messages.
9. What is the function of a demilitarized zone (DMZ) in network
security?
A. Encrypt all internal data
B. Provide a buffer zone between internal networks and the
Internet
C. Block viruses automatically
D. Manage internal authentication
A DMZ hosts public-facing services while isolating them from the
internal network, reducing risk if they are compromised.
10. Which of the following BEST describes social engineering
attacks?
A. Exploiting software vulnerabilities
B. Manipulating people to gain confidential information
And Correct Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant Download Pdf
1. Which of the following is the PRIMARY purpose of a firewall?
A. Encrypt network traffic
B. Filter network traffic
C. Perform backups
D. Monitor CPU usage
Firewalls are designed to control network traffic by allowing or
blocking data packets based on security rules. They do not
inherently encrypt traffic or perform backups.
2. What does the principle of least privilege ensure?
A. Users have unrestricted access
B. Users have only the access necessary to perform their job
C. Users can install any software
D. Users can bypass security controls
Least privilege reduces risk by limiting user access to only what is
needed, minimizing potential misuse or damage.
,3. Which type of malware can spread itself without user interaction?
A. Trojan
B. Spyware
C. Worm
D. Rootkit
Worms propagate independently across networks, unlike Trojans
which require user action.
4. What is the main difference between symmetric and asymmetric
encryption?
A. Symmetric uses longer keys
B. Symmetric uses the same key for encryption and decryption;
asymmetric uses a public and private key
C. Asymmetric is faster than symmetric
D. Symmetric uses hash functions
Symmetric encryption is faster but requires secure key sharing;
asymmetric uses a key pair allowing public distribution of one
key.
5. Which of the following is an example of multi-factor
authentication?
A. Password only
B. Security question only
, C. Password and fingerprint scan
D. Username only
Multi-factor authentication combines two or more types of
factors: something you know, something you have, or something
you are.
6. A company wants to prevent unauthorized users from connecting
to its wireless network. Which security measure is MOST
effective?
A. WEP encryption
B. SSID broadcasting
C. WPA3 encryption with strong passwords
D. MAC address filtering only
WPA3 is currently the most secure Wi-Fi standard, providing
robust encryption and authentication. WEP is obsolete.
7. What is the primary purpose of a VPN?
A. Block malware
B. Filter spam
C. Secure remote communications over the Internet
D. Scan for vulnerabilities
VPNs encrypt network traffic between endpoints to protect data
in transit, especially over untrusted networks.
, 8. Which attack involves intercepting and modifying communications
between two parties?
A. Phishing
B. Man-in-the-middle
C. SQL injection
D. Brute force
Man-in-the-middle attacks exploit communication channels by
intercepting and potentially altering messages.
9. What is the function of a demilitarized zone (DMZ) in network
security?
A. Encrypt all internal data
B. Provide a buffer zone between internal networks and the
Internet
C. Block viruses automatically
D. Manage internal authentication
A DMZ hosts public-facing services while isolating them from the
internal network, reducing risk if they are compromised.
10. Which of the following BEST describes social engineering
attacks?
A. Exploiting software vulnerabilities
B. Manipulating people to gain confidential information