Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 164 pages
Exam (elaborations)

COMPTIA SECURITY+ CERTMASTER CE EXAM BANK | 300 QUESTIONS - COMPLETE PRACTICE EXAM ALL DOMAINS COVERED - EXPERT VERIFIED FOR GUARANTEED PASS

Document preview thumbnail
Preview 4 out of 164 pages

Pass the CompTIA Security+ SY0-701 exam on your first attempt with this comprehensive 300-question practice test PDF. Covering all five domains—General Security Concepts, Threats & Vulnerabilities, Security Architecture, Security Operations, and Governance—this guide features expert-verified questions with detailed rationales. Master critical topics like zero-trust architecture, incident response, cryptography, network security, and compliance. Perfect for IT professionals seeking certification, this updated practice exam simulates the real test, identifies weak areas, and builds confidence. Download now and get guaranteed exam readiness with the most current CompTIA Security+ study material available.

Content preview

TABLE OF CONTENTS

SECTION 1: CompTIA Security+ Certmaster - Domain 1.0 ....................... Q1-Q8
SECTION 2: CompTIA Certmaster CE Security+ Domain 1.0
General Security Concepts Assessment ............................. Q9-Q14
SECTION 3: Certmaster CE Security+ Domain 1.0
General Security Concepts ....................................... Q15-Q18
SECTION 4: CompTIA Certmaster CE Security+ Domain 1.0
General Security Concepts Assessment ............................ Q19-Q25
SECTION 5: Security+ Certmaster CE 701 Renewal - Domain 1.0 ............... Q26-Q30
SECTION 6: Security+ SY0-701 Certmaster CE Domain 1.0 ..................... Q31-Q33
SECTION 7: CompTIA Certmaster CE Security+ Domain 2.0
Threats, Vulnerabilities, And Mitigations Assessment ............ Q34-Q44
SECTION 8: CompTIA Certmaster CE Security+ Section 2 ...................... Q45-Q54
SECTION 9: CompTIA Security+ Certmaster - Domain 3.0 Assessment ........... Q55-Q65
SECTION 10: Sec+ Certmaster SY0-701 Domain 3 Assessment ................... Q66-Q77
SECTION 11: CompTIA Certmaster Security+ SY0-701 Domain 3.0
Security Architecture Assessment ............................... Q78-Q88
SECTION 12: CompTIA Certmaster CE For Security+ - Domain 4.0
Security Operations Assessment ................................ Q89-Q131
SECTION 13: CompTIA Certmaster CE Security+ Domain 4.0
Security Operations Assessment ............................... Q132-Q138
SECTION 14: CompTIA Certmaster Security+ SY0-701 Domain 4.0
Security Operations Assessment ............................... Q139-Q153
SECTION 15: CompTIA Certmaster CE Security+ Domain 5.0 ................... Q154-Q158
SECTION 16: CERTMASTER CE SECURITY+ DOMAIN 5.0 .......................... Q159-Q168
SECTION 17: Certmaster CompTIA Network+ Final Assessment ................. Q169-Q300




SCHOLARSOURCE 1

,SECTION 1: COMPTIA SECURITY+ CERTMASTER - DOMAIN 1.0
Questions 1-8

QUESTION 1
A security analyst is implementing a control that requires users to provide two different
types of authentication factors. Which of the following BEST describes this security
control?

A) Single sign-on
B) Multifactor authentication
C) Biometric verification
D) Password complexity

Correct Answer: B

Rationale: Multifactor authentication (MFA) requires users to provide two or more
verification factors from different categories: something you know (password),
something you have (smart card), or something you are (biometric). This significantly
enhances security compared to single-factor authentication. The key is that the factors
must be from different categories, not just multiple instances of the same type. MFA is a
fundamental security control recommended by security frameworks including NIST and
is mandatory for many compliance requirements such as PCI-DSS and HIPAA.
Implementing MFA reduces the risk of account compromise by over 99% according to
industry studies.



QUESTION 2
Which of the following attack types involves redirecting users from a legitimate website
to a malicious one without their knowledge?

A) Phishing
B) Pharming

SCHOLARSOURCE 2

,C) Spoofing
D) Vishing

Correct Answer: B

Rationale: Pharming is a cyberattack that redirects website traffic from a legitimate site
to a fraudulent one without the user's knowledge. This is typically achieved by exploiting
DNS vulnerabilities or modifying host files. Unlike phishing, which relies on deceptive
emails, pharming works at the DNS level and can affect multiple users simultaneously.
Organizations can mitigate pharming by implementing DNSSEC, ensuring DNS servers
are properly secured against poisoning attacks, and using HTTPS with proper certificate
validation. Users can protect themselves by verifying website URLs and being cautious
of unexpected redirects.



QUESTION 3
An organization wants to implement a security control that prevents unauthorized
access to sensitive data by ensuring that users only have access to the information
necessary for their job functions. Which principle is being applied?

A) Separation of duties
B) Least privilege
C) Defense in depth
D) Zero trust

Correct Answer: B

Rationale: The principle of least privilege ensures that users, systems, and processes are
granted only the minimum permissions necessary to perform their specific job
functions. This limits potential damage from accidental errors, malicious insiders, or
compromised accounts. Separation of duties divides critical functions among multiple
individuals to prevent fraud. The principle of least privilege is a cornerstone of zero trust
architectures and should be applied consistently across all systems and applications.
Regular access reviews and automated privilege management tools help maintain least
privilege over time.

SCHOLARSOURCE 3

, QUESTION 4
Which type of cryptographic algorithm uses the same key for both encryption and
decryption?

A) Asymmetric encryption
B) Symmetric encryption
C) Hashing
D) Elliptic curve cryptography

Correct Answer: B

Rationale: Symmetric encryption uses a single shared secret key for both encryption and
decryption processes. Examples include AES, DES, and 3DES. While it is significantly
faster than asymmetric encryption, the main challenge is secure key distribution.
Asymmetric encryption uses a public-private key pair, solving the key distribution
problem. Hashing is a one-way function used for integrity verification, not
confidentiality. AES-256 is currently considered the gold standard for symmetric
encryption and is widely used for encrypting data at rest and in transit. Key
management is critical when using symmetric encryption.



QUESTION 5
A security administrator is configuring a firewall to allow only specific types of traffic
into the network. Which security control is being implemented?

A) Deterrent control
B) Detective control
C) Preventive control
D) Compensating control

Correct Answer: C



SCHOLARSOURCE 4

Document information

Uploaded on
July 31, 2026
Number of pages
164
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$23.98

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
ScholarSource
4.8
(199)
Sold
281
Followers
3
Items
672
Last sold
1 day ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions