Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CompTIA Security+ Certification Exam Practice Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Rating
-
Sold
-
Pages
23
Grade
A+
Uploaded on
30-06-2026
Written in
2025/2026

CompTIA Security+ Certification Exam Practice Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Institution
CompTIA Security+ Certification
Course
CompTIA Security+ Certification

Content preview

CompTIA Security+ Certification Exam
Practice Questions And Correct Answers
(Verified Answers) Plus Rationales 2026
Q&A | Instant Download Pdf
1. Which of the following cryptographic algorithms is best suited for securely
transmitting a symmetric encryption key over an insecure network? A) RSA
B) AES C) SHA-256 D) HMAC Rationale: RSA is an asymmetric algorithm
commonly used for secure key exchange, allowing two parties to securely
establish a symmetric key (like AES) over an insecure channel. AES is
symmetric, SHA is hashing, and HMAC provides integrity and authenticity,
not key exchange.
2. A security analyst notices multiple failed login attempts from a single IP
address followed by a successful login. What type of attack has most likely
occurred? A) Cross-site scripting B) Brute force C) SQL injection D) Pass the
hash Rationale: A brute force attack involves systematically submitting
many passwords or passphrases with the hope of eventually guessing
correctly. The pattern of multiple failed attempts followed by a success is a
classic indicator of this attack type.
3. Which of the following access control models uses labels and security
clearances to grant access to objects? A) Discretionary Access Control (DAC)
B) Role-Based Access Control (RBAC) C) Mandatory Access Control (MAC)
D) Attribute-Based Access Control (ABAC) Rationale: Mandatory Access
Control (MAC) relies on security clearances for subjects and classification
labels for objects. Access is determined by comparing these attributes, a
model heavily used in military and government environments.
4. Which network device is primarily designed to actively filter and block
malicious traffic based on a set of defined rules and signatures before it

, reaches the internal network? A) Switch B) Load Balancer C) Passive IDS D)
Intrusion Prevention System (IPS) Rationale: An Intrusion Prevention
System (IPS) sits inline with network traffic and actively blocks or prevents
malicious activity based on signatures or anomalies. A passive IDS only
detects and alerts, while switches and load balancers serve routing and
availability functions.
5. In the context of incident response, which phase involves isolating an
infected workstation to prevent the spread of malware? A) Containment B)
Identification C) Eradication D) Recovery Rationale: The Containment phase
focuses on limiting the scope and impact of an incident. Isolating an
infected system from the network prevents malware from spreading
laterally to other systems.
6. An organization wants to ensure that data stored on stolen corporate
laptops cannot be accessed. Which of the following is the most effective
solution? A) BIOS passwords B) Full Disk Encryption (FDE) C) Complex OS
passwords D) Cable locks Rationale: Full Disk Encryption (FDE) encrypts the
entire hard drive, ensuring that even if the physical drive is removed and
placed in another system, the data remains unreadable without the
correct decryption key. Passwords can be bypassed if the drive is removed.
7. Which of the following is a primary characteristic of a watering hole attack?
A) Directly attacking the target organization's firewall B) Sending massive
amounts of spam to employee emails C) Compromising a specific website
that the target group frequently visits D) Intercepting communications over
a public Wi-Fi network Rationale: A watering hole attack targets a specific
group of users by infecting a website they are known to trust and visit
frequently. The attacker waits for the targets to visit the compromised site
to deliver malware.
8. What is the primary purpose of implementing a demilitarized zone (DMZ) in
a network architecture? A) To completely isolate the internal network from
all external access B) To encrypt all outgoing traffic from the internal
network C) To provide a secure space for internal databases D) To provide a

, subnetwork for external-facing services while protecting the internal
network Rationale: A DMZ is designed to host public-facing servers (like
web or email servers) in an isolated subnet. This setup adds a layer of
security, meaning an external attacker must breach the DMZ and a
secondary firewall to reach the sensitive internal network.
9. Which protocol is considered insecure and should be replaced by SSH for
remote command-line administration? A) Telnet B) RDP C) HTTPS D) SFTP
Rationale: Telnet transmits data, including usernames and passwords, in
cleartext, making it highly vulnerable to packet sniffing. SSH (Secure Shell)
provides a secure, encrypted alternative for remote command-line
administration.
10.A user receives an SMS message claiming to be from their bank, asking
them to click a link to verify their account details. What type of attack is
this? A) Vishing B) Smishing C) Pharming D) Whaling Rationale: Smishing
(SMS phishing) is a form of social engineering that uses text messages to
trick victims into providing sensitive information or clicking malicious
links. Vishing uses voice, and whaling targets high-profile executives.
11.Which risk management strategy involves purchasing cybersecurity
insurance to handle potential financial losses from a data breach? A)
Mitigation B) Acceptance C) Transference D) Avoidance Rationale: Risk
transference (or sharing) involves shifting the financial burden of a risk to
a third party, such as an insurance company. This does not eliminate the
risk but offsets the financial impact.
12.Which of the following best describes the principle of least privilege? A)
Giving administrators full access to all systems B) Ensuring all users have the
same level of access C) Providing temporary elevated access only when
requested D) Granting users only the minimum access rights necessary to
perform their job functions Rationale: The principle of least privilege
dictates that users, systems, and processes should only have the exact
permissions required to complete their authorized tasks, minimizing the
potential impact of a compromised account.

Written for

Institution
CompTIA Security+ Certification
Course
CompTIA Security+ Certification

Document information

Uploaded on
June 30, 2026
Number of pages
23
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$23.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller
Seller avatar
elitelearninghub

Get to know the seller

Seller avatar
elitelearninghub Cambridge university
View profile
Follow You need to be logged in order to follow users or courses
Sold
-
Member since
3 weeks
Number of followers
0
Documents
28
Last sold
-
elitelearninghub

Welcome to elitelearninghub Welcome to elitelearninghub – your trusted source for high-quality academic and professional study materials. Our mission is to help students, job seekers, and professionals succeed by providing accurate, well-organized, and easy-to-understand study resources. Whether you\'re preparing for university exams, professional certification tests, licensing exams, or career advancement, our materials are designed to make your learning more effective and your preparation more confident. At elitelearninghub, you\'ll find: Comprehensive exam questions and answers Detailed explanations and rationales Study guides and revision notes Practice tests and mock exams Career certification preparation materials Academic resources for a wide range of subjects Every document is carefully formatted to save you time, improve your understanding, and help you perform at your best. Our goal is to provide reliable learning resources that support your academic and professional journey. Thank you for choosing elitelearninghub. We are committed to helping you study smarter, build confidence, and achieve success in your exams and career. Study Smart. Prepare Better. Succeed with Confidence.

Read more Read less
0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions