Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 81 pages
Exam (elaborations)

CompTIA CertMaster CE Security+ Domain 1.0 General Security Concepts Assessment | Latest Update 2026/2027 | 200 Questions and Verified Answers | Complete Q&A Guide | A+ Graded

Document preview thumbnail
Preview 4 out of 81 pages

This comprehensive CompTIA CertMaster CE Security+ Domain 1.0 General Security Concepts Assessment study guide provides 200 practice questions and verified answers with detailed rationales designed to support candidates preparing for the CompTIA Security+ SY0-701 certification exam. The material covers the full scope of Domain 1.0, which accounts for 12% of the exam weight, including security controls (technical, managerial, operational, physical), fundamental concepts (CIA triad, non-repudiation, AAA, zero trust, and deception/disruption technologies), cryptographic solutions, authentication models, allowlists and denylists, change management, and PKI implementation. Each question includes detailed rationales to strengthen conceptual understanding and improve exam readiness. Perfect for IT professionals and cybersecurity students seeking to build a strong foundation in general security concepts and achieve a top score on their CompTIA Security+ certification.

Content preview

CompTIA CertMaster CE Security+ Domain 1.0 General
Security Concepts Assessment | Latest Update 2026/2027 |
200 Questions and Verified Answers | Complete Q&A Guide |
A+ Graded

1. Which of the following is the BEST description of the CIA triad?

A) Control, Integrity, Access

B) Confidentiality, Integrity, Availability

C) Compliance, Integrity, Authorization

D) Confidentiality, Identification, Auditing



Answer: B

Rationale: The CIA triad stands for Confidentiality (protecting information from unauthorized access),
Integrity (ensuring data is accurate and unaltered), and Availability (ensuring systems and data are
accessible when needed). This is a core framework in security principles.




2. What type of security control is a firewall?

A) Physical

B) Managerial

C) Technical

D) Administrative



Answer: C

Rationale: A firewall is a technical control because it uses software and hardware to prevent or restrict
network traffic based on rules.

,3. Which term describes controls that identify and record unwanted activity?

A) Preventive

B) Detective

C) Compensating

D) Directive



Answer: B

Rationale: Detective controls are meant to detect and alert — for example, intrusion detection systems
(IDS), audit logs, and monitoring tools.




4. A security team installs locked filing cabinets to physically store sensitive documents, creates a
mandatory cleandesk policy with monthly audits, and reduces printed documents by moving to a
paperless workflow. How should these controls be classified?

A) Preventive, detective, and corrective

B) Preventive, preventive, and corrective

C) Detective, preventive, and corrective

D) Corrective, detective, and preventive



Answer: B

Rationale: The locked filing cabinets are preventive (stop the behavior). The cleandesk policy with audits
is also preventive because it enforces ongoing compliance. The paperless workflow is corrective because
it removes the root cause.




5. Which cryptographic concept converts plaintext into ciphertext?

A) Hashing

,B) Encryption

C) Tokenization

D) Auditing



Answer: B

Rationale: Encryption transforms readable data into an unreadable format (ciphertext) using keys so
that only authorized parties can decrypt it later.




6. What is the primary use of hashing in security?

A) Encrypting data for confidentiality

B) Ensuring data integrity

C) Providing access control

D) Auditing events



Answer: B

Rationale: Hashing produces a fixedlength output (hash) from input data; changes in the input produce
different hashes, so hashing helps verify that data hasn't been altered.




7. A security analyst wants to ensure that the privileges granted to an individual align with their role
within the organization. What is the primary concept the analyst should implement?

A) Mandatory Access Control (MAC)

B) RoleBased Access Control (RBAC)

C) Discretionary Access Control (DAC)

D) AttributeBased Access Control (ABAC)



Answer: B

, Rationale: RoleBased Access Control (RBAC) assigns permissions based on a user's role within the
organization, ensuring that privileges align with job responsibilities.




8. What is the main goal of Zero Trust architecture?

A) Trust all users inside the network by default

B) Enforce leastprivilege and continuously verify every access request

C) Eliminate the need for authentication

D) Allow all traffic from trusted IP addresses



Answer: B

Rationale: Zero Trust architecture enforces leastprivilege access and continuously verifies every access
request, never trusting any user or device by default.




9. Which of the following is an example of a physical security control?

A) Firewall

B) Encryption

C) Security guard

D) Access control list (ACL)



Answer: C

Rationale: A security guard is a physical control because it involves human presence to protect physical
assets. Firewalls and ACLs are technical controls, and encryption is a cryptographic control.




10. What does the "A" in the AAA framework stand for in cybersecurity?

Document information

Uploaded on
July 10, 2026
Number of pages
81
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$23.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
francisndungu1
5.0
(1)
Sold
7
Followers
0
Items
589
Last sold
2 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions