Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 63 pages
Exam (elaborations)

CompTIA Security+ CertMaster CE | Complete Practice Questions, Correct Answers & Detailed Rationales (2026/2027)

Document preview thumbnail
Preview 4 out of 63 pages

CompTIA Security+ CertMaster CE | Complete Practice Questions, Correct Answers & Detailed Rationales (2026/2027)

Content preview

CompTIA Security+ CertMaster CE | Complete Practice
Questions, Correct Answers & Detailed Rationales (2026/2027)


Question 1
What concept defines the minimum necessary access rights granted to
a user or system process to perform its required functions?
• A. Principle of least privilege
• B. Separation of duties
• C. Discretionary access control
• D. Mandatory data labeling
Correct Answer: A. Principle of least privilege
Detailed Rationale: The principle of least privilege restricts user
permissions to only what is strictly necessary to perform authorized job
duties, reducing the potential blast radius of a compromised account.
Question 2
What cryptographic attack attempts to decrypt ciphertext by
systematically trying every possible key combination until the correct
key is found?
• A. Brute-force attack
• B. Birthday attack
• C. Rainbow table lookup
• D. Dictionary attack

,Correct Answer: A. Brute-force attack
Detailed Rationale: Brute-force attacks test every possible key or
password permutation exhaustively, making key length and complexity
critical defenses.
Question 3
What protocol provides secure, encrypted command-line shell remote
access over an unsecured network, replacing legacy Telnet?
• A. SSH (Secure Shell)
• B. FTP (File Transfer Protocol)
• C. SNMP (Simple Network Management Protocol)
• D. TFTP (Trivial File Transfer Protocol)
Correct Answer: A. SSH (Secure Shell)
Detailed Rationale: SSH encrypts all remote terminal traffic, preventing
packet sniffers from capturing administrative credentials in transit.
Question 4
What type of malware locks a user out of their device or encrypts files
and demands payment for restoration?
• A. Ransomware
• B. Adware
• C. Spyware
• D. Rootkit
Correct Answer: A. Ransomware

,Detailed Rationale: Ransomware holds enterprise files or device access
hostage using strong encryption until a ransom is paid in
cryptocurrency.
Question 5
What physical security control uses biometric verification combined
with interlocking doors to prevent piggybacking or tailgating?
• A. Mantrap
• B. Turnstile gate
• C. Security bollard
• D. Privacy filter
Correct Answer: A. Mantrap
Detailed Rationale: Mantraps force individuals to authenticate in an
isolated chamber before a secondary door unlocks, halting
unauthorized tailgaters.
Question 6
What framework is maintained by NIST to help organizations improve
their cybersecurity posture across five core functions: Identify, Protect,
Detect, Respond, and Recover?
• A. NIST Cybersecurity Framework (CSF)
• B. ISO/IEC 27001 standard
• C. MITRE ATT&CK framework
• D. OWASP Top Ten project
Correct Answer: A. NIST Cybersecurity Framework (CSF)

, Detailed Rationale: The NIST CSF provides a universal taxonomy and
guidance for managing and reducing cybersecurity risk across
enterprise environments.
Question 7
What type of backup saves all files that have been modified since the
last full backup, making restoration faster but backup times longer over
the week?
• A. Differential backup
• B. Incremental backup
• C. Snapshot clone
• D. Mirror copy
Correct Answer: A. Differential backup
Detailed Rationale: Differential backups accumulate all changes since
the last full backup, simplifying restoration to require only the full
backup and the latest differential set.
Question 8
What cloud service model provides fully managed infrastructure,
storage, and networking resources where customers manage operating
systems, middleware, and applications?
• A. IaaS (Infrastructure as a Service)
• B. PaaS (Platform as a Service)
• C. SaaS (Software as a Service)
• D. SECaaS (Security as a Service)

Document information

Uploaded on
August 17, 2026
Number of pages
63
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CreativeWrites
3.6
(21)
Sold
93
Followers
3
Items
8251
Last sold
2 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions