COMPTIA SECURITY+ EXAM QUESTIONS AND CORRECT ANSWERS (VERIFIED ANSWERS)
PLUS RATIONALES 2026 Q&A | INSTANT DOWNLOAD PDF
Core Domains
- General Security Concepts
- Threats, Vulnerabilities, and Mitigations
- Security Architecture
- Security Operations
- Security Program Management and Oversight
- Cryptography and PKI
- Identity and Access Management
- Network Security
This assessment evaluates comprehensive knowledge required for the CompTIA
Security+ certification, validating foundational cybersecurity skills essential for entry-level security
professionals. The exam tests understanding of security concepts, threat detection, vulnerability
management, secure network architecture, incident response, and compliance frameworks. Questions include
multiple-choice and scenario-based formats that emphasize real-world application, critical thinking, and
decision-making in practical security situations. Candidates must demonstrate ability to analyze security
incidents, implement appropriate controls, and make informed security decisions across diverse
organizational contexts.
SECTION ONE: QUESTIONS 1–100
,Question 1
Which security principle ensures that no single individual has complete control over a critical system?
A. Defense in depth
B. Separation of duties
C. Least privilege
D. Job rotation
🟢 B. Separation of duties
🔴 RATIONALE: Separation of duties divides critical tasks among multiple individuals to prevent fraud and
errors, ensuring no single person has complete control over a system or process.
Question 2
A company wants to implement a security control that prevents unauthorized access even if credentials are
compromised. Which control provides the best protection?
A. Multi-factor authentication
B. Password complexity requirements
C. Account lockout policy
D. Single sign-on
🟢 A. Multi-factor authentication
,🔴 RATIONALE: Multi-factor authentication requires multiple verification methods (something you know,
have, or are), providing protection even if passwords are compromised since attackers need additional factors.
Question 3
Which attack involves overwhelming a system with traffic to make it unavailable to legitimate users?
A. Man-in-the-middle
B. SQL injection
C. Denial of service
D. Cross-site scripting
🟢 C. Denial of service
🔴 RATIONALE: Denial of service (DoS) attacks flood systems with excessive traffic or requests, exhausting
resources and preventing legitimate users from accessing services.
Question 4
What is the primary purpose of a hash function in cryptography?
A. Encryption of sensitive data
B. Data integrity verification
C. Key exchange
D. Digital signature creation
, 🟢 B. Data integrity verification
🔴 RATIONALE: Hash functions create fixed-size unique digests of data that change if the data is modified,
making them ideal for verifying data integrity rather than encryption.
Question 5
Which compliance framework specifically applies to healthcare organizations handling patient information in
the United States?
A. PCI DSS
B. HIPAA
C. SOX
D. GDPR
🟢 B. HIPAA
🔴 RATIONALE: HIPAA (Health Insurance Portability and Accountability Act) is the US federal regulation
protecting healthcare information and applying specifically to healthcare organizations and their business
associates.
Question 6
An attacker intercepts communication between two parties and impersonates each party to the other. What type
of attack is this?
PLUS RATIONALES 2026 Q&A | INSTANT DOWNLOAD PDF
Core Domains
- General Security Concepts
- Threats, Vulnerabilities, and Mitigations
- Security Architecture
- Security Operations
- Security Program Management and Oversight
- Cryptography and PKI
- Identity and Access Management
- Network Security
This assessment evaluates comprehensive knowledge required for the CompTIA
Security+ certification, validating foundational cybersecurity skills essential for entry-level security
professionals. The exam tests understanding of security concepts, threat detection, vulnerability
management, secure network architecture, incident response, and compliance frameworks. Questions include
multiple-choice and scenario-based formats that emphasize real-world application, critical thinking, and
decision-making in practical security situations. Candidates must demonstrate ability to analyze security
incidents, implement appropriate controls, and make informed security decisions across diverse
organizational contexts.
SECTION ONE: QUESTIONS 1–100
,Question 1
Which security principle ensures that no single individual has complete control over a critical system?
A. Defense in depth
B. Separation of duties
C. Least privilege
D. Job rotation
🟢 B. Separation of duties
🔴 RATIONALE: Separation of duties divides critical tasks among multiple individuals to prevent fraud and
errors, ensuring no single person has complete control over a system or process.
Question 2
A company wants to implement a security control that prevents unauthorized access even if credentials are
compromised. Which control provides the best protection?
A. Multi-factor authentication
B. Password complexity requirements
C. Account lockout policy
D. Single sign-on
🟢 A. Multi-factor authentication
,🔴 RATIONALE: Multi-factor authentication requires multiple verification methods (something you know,
have, or are), providing protection even if passwords are compromised since attackers need additional factors.
Question 3
Which attack involves overwhelming a system with traffic to make it unavailable to legitimate users?
A. Man-in-the-middle
B. SQL injection
C. Denial of service
D. Cross-site scripting
🟢 C. Denial of service
🔴 RATIONALE: Denial of service (DoS) attacks flood systems with excessive traffic or requests, exhausting
resources and preventing legitimate users from accessing services.
Question 4
What is the primary purpose of a hash function in cryptography?
A. Encryption of sensitive data
B. Data integrity verification
C. Key exchange
D. Digital signature creation
, 🟢 B. Data integrity verification
🔴 RATIONALE: Hash functions create fixed-size unique digests of data that change if the data is modified,
making them ideal for verifying data integrity rather than encryption.
Question 5
Which compliance framework specifically applies to healthcare organizations handling patient information in
the United States?
A. PCI DSS
B. HIPAA
C. SOX
D. GDPR
🟢 B. HIPAA
🔴 RATIONALE: HIPAA (Health Insurance Portability and Accountability Act) is the US federal regulation
protecting healthcare information and applying specifically to healthcare organizations and their business
associates.
Question 6
An attacker intercepts communication between two parties and impersonates each party to the other. What type
of attack is this?