CompTIA Security+ Final Assessment
EXAM SCRIPT VERIFIED QUESTIONS WITH
ACCURATE ANSWERS
Analyze the following scenarios and determine which attacker
used piggy backing. - Correct Answers ✅On the way to a
meeting in a restricted area of a government facility, a
contractor holds open a gate for a person in a military
uniform, who approaches the entry point at a jog, flashing a
badge just outside of the readable range.
Analyze and select the statements that accurately describe
both worms and Trojans. (Select all that apply.) - Correct
Answers ✅*Both worms and Trojans can provide a backdoor
*A worm is self-contained while a Trojan is concealed within
an application package.
A dissatisfied employee has discreetly begun exfiltrating
company secrets to sell to a competitor. The employee sets
up a malware script that will run in the event of the
employee's firing and account deletion. Analyze the attack
and determine what type of attack the employee has
emplaced. - Correct Answers ✅Logic bomb
A hacker gains access to a database of usernames for a
target company and then begins combining common, weak
passwords with each username to attempt authentication.
The hacker conducts what type of attack? - Correct
Answers ✅Password spraying
,CompTIA Security+ Final Assessment
EXAM SCRIPT VERIFIED QUESTIONS WITH
ACCURATE ANSWERS
When monitoring API usage on a system, an engineer notices
a very high error rate. The application's latency and
thresholds appear to be high. What does the engineer
determine to be the cause? (Select all that apply.) - Correct
Answers ✅*Overloaded system
*Security issues
An attacker compromises a confidential database at a
retailer. Investigators discover that unauthorized ad hoc
changes to the system were to blame. How do the
investigators describe the attack vector in a follow-up report?
(Select all that apply.) - Correct Answers ✅*Configuration
drift
*Shadow IT
An employee that carries a company credit card learns that
the card has become compromised. The employee only
remembers fueling a company vehicle. Consider the following
viable methods and determine which method compromised
the card. - Correct Answers ✅Card skimming
Identify the type of attack where malware forces a legitimate
process to load a malicious link library. - Correct Answers
✅DLL injection
, CompTIA Security+ Final Assessment
EXAM SCRIPT VERIFIED QUESTIONS WITH
ACCURATE ANSWERS
What type of attack replays a cookie? - Correct Answers
✅Session hijacking
A security engineer implements a secure wireless network. In
doing so, the engineer decides to use EAP with Flexible
Authentication via Secure Tunneling (EAP-FAST). Which
authentication approach does the engineer implement? -
Correct Answers ✅Protected Access Credential (PAC)
instead of a certificate
An engineer pieces together the clues from an attack that
temporarily disabled a critical web server. The engineer
determines that a SYN flood attack was the cause. Which
pieces of evidence led the engineer to this conclusion?
(Select all that apply.) - Correct Answers ✅*ACK packets
from the client were missing
*SYN/ACK packets from the server were misdirected
The IT staff at a large company review numerous security
logs and discover that the SAM database on Windows
workstations is being accessed by a malicious process. What
does the staff determine the issue to be? - Correct Answers
✅Credential dumping
An organization receives notification from an actor that
vulnerabilities have been found in an onsite firewall. While
the actor does not exploit the vulnerability, a bounty is
EXAM SCRIPT VERIFIED QUESTIONS WITH
ACCURATE ANSWERS
Analyze the following scenarios and determine which attacker
used piggy backing. - Correct Answers ✅On the way to a
meeting in a restricted area of a government facility, a
contractor holds open a gate for a person in a military
uniform, who approaches the entry point at a jog, flashing a
badge just outside of the readable range.
Analyze and select the statements that accurately describe
both worms and Trojans. (Select all that apply.) - Correct
Answers ✅*Both worms and Trojans can provide a backdoor
*A worm is self-contained while a Trojan is concealed within
an application package.
A dissatisfied employee has discreetly begun exfiltrating
company secrets to sell to a competitor. The employee sets
up a malware script that will run in the event of the
employee's firing and account deletion. Analyze the attack
and determine what type of attack the employee has
emplaced. - Correct Answers ✅Logic bomb
A hacker gains access to a database of usernames for a
target company and then begins combining common, weak
passwords with each username to attempt authentication.
The hacker conducts what type of attack? - Correct
Answers ✅Password spraying
,CompTIA Security+ Final Assessment
EXAM SCRIPT VERIFIED QUESTIONS WITH
ACCURATE ANSWERS
When monitoring API usage on a system, an engineer notices
a very high error rate. The application's latency and
thresholds appear to be high. What does the engineer
determine to be the cause? (Select all that apply.) - Correct
Answers ✅*Overloaded system
*Security issues
An attacker compromises a confidential database at a
retailer. Investigators discover that unauthorized ad hoc
changes to the system were to blame. How do the
investigators describe the attack vector in a follow-up report?
(Select all that apply.) - Correct Answers ✅*Configuration
drift
*Shadow IT
An employee that carries a company credit card learns that
the card has become compromised. The employee only
remembers fueling a company vehicle. Consider the following
viable methods and determine which method compromised
the card. - Correct Answers ✅Card skimming
Identify the type of attack where malware forces a legitimate
process to load a malicious link library. - Correct Answers
✅DLL injection
, CompTIA Security+ Final Assessment
EXAM SCRIPT VERIFIED QUESTIONS WITH
ACCURATE ANSWERS
What type of attack replays a cookie? - Correct Answers
✅Session hijacking
A security engineer implements a secure wireless network. In
doing so, the engineer decides to use EAP with Flexible
Authentication via Secure Tunneling (EAP-FAST). Which
authentication approach does the engineer implement? -
Correct Answers ✅Protected Access Credential (PAC)
instead of a certificate
An engineer pieces together the clues from an attack that
temporarily disabled a critical web server. The engineer
determines that a SYN flood attack was the cause. Which
pieces of evidence led the engineer to this conclusion?
(Select all that apply.) - Correct Answers ✅*ACK packets
from the client were missing
*SYN/ACK packets from the server were misdirected
The IT staff at a large company review numerous security
logs and discover that the SAM database on Windows
workstations is being accessed by a malicious process. What
does the staff determine the issue to be? - Correct Answers
✅Credential dumping
An organization receives notification from an actor that
vulnerabilities have been found in an onsite firewall. While
the actor does not exploit the vulnerability, a bounty is