CompTIA Security+ Certification Exam
Practice Examination 2026–2027 |
Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. What is the primary objective of information security?
A. Increase system performance
B. Protect confidentiality, integrity, and availability of information
C. Reduce storage costs
D. Improve network speed
Correct Answer: B
Rationale: Information security focuses on protecting data through the CIA Triad:
confidentiality, integrity, and availability.
2. Which component of the CIA Triad ensures information is accessible when needed?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Correct Answer: C
Rationale: Availability ensures authorized users can access systems and data when
required.
,3. Which component of the CIA Triad protects data from unauthorized disclosure?
A. Availability
B. Confidentiality
C. Integrity
D. Nonrepudiation
Correct Answer: B
Rationale: Confidentiality prevents unauthorized access to sensitive information.
4. Which component of the CIA Triad ensures data remains accurate and unaltered?
A. Integrity
B. Availability
C. Confidentiality
D. Authorization
Correct Answer: A
Rationale: Integrity ensures information is complete, accurate, and trustworthy.
5. What is malware?
A. Authorized software
B. Software designed to harm systems or data
C. Backup software
D. Monitoring software only
Correct Answer: B
Rationale: Malware includes viruses, worms, Trojans, ransomware, spyware, and other
malicious programs.
6. Which type of malware encrypts data and demands payment for its release?
A. Worm
B. Adware
C. Spyware
D. Ransomware
Correct Answer: D
Rationale: Ransomware locks or encrypts files and demands payment to restore access.
, 7. What is phishing?
A. Network optimization process
B. Fraudulent attempt to obtain sensitive information
C. Software installation method
D. Encryption algorithm
Correct Answer: B
Rationale: Phishing attacks trick users into revealing passwords, financial information, or
other sensitive data.
8. Which attack specifically targets executives and senior leaders?
A. Smishing
B. Spear Phishing
C. Whaling
D. Vishing
Correct Answer: C
Rationale: Whaling attacks are highly targeted phishing attempts aimed at executives.
9. What is social engineering?
A. Hardware installation
B. Manipulating individuals into revealing information
C. Network monitoring
D. Data encryption
Correct Answer: B
Rationale: Social engineering exploits human behavior rather than technical
vulnerabilities.
10. Which security control prevents unauthorized physical access to facilities?
A. Firewall
B. Biometric Scanner
C. Antivirus Software
D. IDS
Practice Examination 2026–2027 |
Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. What is the primary objective of information security?
A. Increase system performance
B. Protect confidentiality, integrity, and availability of information
C. Reduce storage costs
D. Improve network speed
Correct Answer: B
Rationale: Information security focuses on protecting data through the CIA Triad:
confidentiality, integrity, and availability.
2. Which component of the CIA Triad ensures information is accessible when needed?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Correct Answer: C
Rationale: Availability ensures authorized users can access systems and data when
required.
,3. Which component of the CIA Triad protects data from unauthorized disclosure?
A. Availability
B. Confidentiality
C. Integrity
D. Nonrepudiation
Correct Answer: B
Rationale: Confidentiality prevents unauthorized access to sensitive information.
4. Which component of the CIA Triad ensures data remains accurate and unaltered?
A. Integrity
B. Availability
C. Confidentiality
D. Authorization
Correct Answer: A
Rationale: Integrity ensures information is complete, accurate, and trustworthy.
5. What is malware?
A. Authorized software
B. Software designed to harm systems or data
C. Backup software
D. Monitoring software only
Correct Answer: B
Rationale: Malware includes viruses, worms, Trojans, ransomware, spyware, and other
malicious programs.
6. Which type of malware encrypts data and demands payment for its release?
A. Worm
B. Adware
C. Spyware
D. Ransomware
Correct Answer: D
Rationale: Ransomware locks or encrypts files and demands payment to restore access.
, 7. What is phishing?
A. Network optimization process
B. Fraudulent attempt to obtain sensitive information
C. Software installation method
D. Encryption algorithm
Correct Answer: B
Rationale: Phishing attacks trick users into revealing passwords, financial information, or
other sensitive data.
8. Which attack specifically targets executives and senior leaders?
A. Smishing
B. Spear Phishing
C. Whaling
D. Vishing
Correct Answer: C
Rationale: Whaling attacks are highly targeted phishing attempts aimed at executives.
9. What is social engineering?
A. Hardware installation
B. Manipulating individuals into revealing information
C. Network monitoring
D. Data encryption
Correct Answer: B
Rationale: Social engineering exploits human behavior rather than technical
vulnerabilities.
10. Which security control prevents unauthorized physical access to facilities?
A. Firewall
B. Biometric Scanner
C. Antivirus Software
D. IDS