Professional Certification Test Bank | 300+
Verified Questions & Answers | Latest Study
Guide
SFPC EXAM 2026 PREP
Security Fundamentals Professional Certification
Test Bank | 300 Verified Questions & Answers
1. What is the primary goal of information security?
A. To prevent all cyberattacks
B. To ensure hardware availability
C. To protect the confidentiality, integrity, and availability of information
D. To monitor network traffic at all times
E. To eliminate all software vulnerabilities
✔ CORRECT ANSWER: C RATIONALE: The CIA Triad — Confidentiality, Integrity,
and Availability — forms the foundational goal of information security. All security
controls and policies are designed to uphold these three principles.
2. Which of the following BEST describes the concept of "least privilege"?
A. Users should have access to all systems by default
B. Administrators should share passwords with trusted staff
C. Systems should be patched frequently
D. Access logs should be reviewed monthly
E. Users should be granted only the minimum access necessary to perform
their job functions
✔ CORRECT ANSWER: E RATIONALE: Least privilege limits access rights to only
what is necessary, reducing the attack surface and minimizing the potential damage
from accidents or breaches.
,3. What does the term "non-repudiation" mean in security?
A. The ability to encrypt data at rest
B. The process of verifying user credentials
C. Preventing unauthorized access to systems
D. Ensuring that a party cannot deny having performed an action
E. The ability to restore data after a disaster
✔ CORRECT ANSWER: D RATIONALE: Non-repudiation ensures accountability by
providing proof of origin or delivery, so a sender cannot deny sending a message or
performing an action.
4. Which of the following is an example of a physical security control?
A. Firewall rules
B. Encryption algorithms
C. Antivirus software
D. Security badge access to a data center
E. Intrusion detection systems
✔ CORRECT ANSWER: D RATIONALE: Physical security controls include tangible
measures such as locks, badge readers, cameras, and guards that protect physical
assets and facilities.
5. What is a "zero-day vulnerability"?
A. A vulnerability that has been patched within 24 hours
B. A flaw in physical security systems
C. A misconfiguration in a firewall
D. A vulnerability exploited only by insiders
E. A software vulnerability that is unknown to the vendor and has no available
patch
,✔ CORRECT ANSWER: E RATIONALE: Zero-day vulnerabilities are particularly
dangerous because the vendor is unaware of them and no patch exists, leaving
systems exposed until a fix is developed.
6. Which security principle ensures that data is accurate and has not been
tampered with?
A. Availability
B. Confidentiality
C. Authentication
D. Integrity
E. Authorization
✔ CORRECT ANSWER: D RATIONALE: Integrity ensures that data remains
accurate, consistent, and unaltered during storage or transmission. Techniques like
hashing and checksums are used to verify integrity.
7. What is the purpose of a Security Policy?
A. To install antivirus software
B. To monitor employee emails
C. To replace firewall configurations
D. To train all staff on phishing
E. To establish rules and procedures that govern how an organization protects
its information assets
✔ CORRECT ANSWER: E RATIONALE: A security policy provides the high-level
framework and directives that guide an organization's security decisions, behavior, and
practices.
8. Which of the following BEST describes "defense in depth"?
A. Using the strongest possible firewall
B. Encrypting all stored data
, C. Patching systems weekly
D. Implementing multiple layers of security controls to protect assets
E. Relying solely on perimeter security
✔ CORRECT ANSWER: D RATIONALE: Defense in depth uses overlapping layers of
security so that if one control fails, others remain in place to protect the asset, reducing
single points of failure.
9. What is the role of a Security Operations Center (SOC)?
A. To develop software applications
B. To manage user accounts and passwords
C. To enforce physical access policies
D. To conduct annual penetration tests
E. To monitor, detect, analyze, and respond to cybersecurity incidents
✔ CORRECT ANSWER: E RATIONALE: A SOC is a centralized unit that continuously
monitors an organization's security posture, detects threats, and coordinates incident
response activities.
10. Which of the following is a characteristic of a strong password?
A. Contains only lowercase letters
B. Uses the user's date of birth
C. Is fewer than 8 characters
D. Is the same as the username
E. Combines uppercase, lowercase, numbers, and special characters
✔ CORRECT ANSWER: E RATIONALE: Strong passwords use a mix of character
types and sufficient length to resist brute-force and dictionary attacks, making them
harder to guess or crack.
11. What does "risk" refer to in information security?