COMPTIA SECURITY+ COMPLETE 2026-2027 EXAM PAPER- REVISION
QUESTIONS & SOLUTIONS
What is the default PPTP port?
TCP port 1723
Which port number does SNMP use?
UDP port 161
Which type of access control associates roles with each user?
role-based access control (RBAC)
Is the Data Encryption Standard (DES) algorithm asymmetric or symmetric?
symmetric
Which authentication protocol encrypts the entire packet (not just the password): TACACS+ or
RADIUS?
TACACS+
Which Linux file contains encrypted user passwords that only the root user can read?
/etc/shadow
How is a digital signature created from a message digest?
It is encrypted using the sender's private key.
Which type of fire suppression system is the safest for both computer equipment and
personnel: FM-200 or Carbon Dioxide?
FM-200
Which backup method serves as the baseline for a backup set?
the full backup
According to CompTIA, why should you disable the SSID broadcast of your wireless router?
to improve your network's security
What is whaling?
a special type of phishing that targets a single power user, such as a Chief Executive Officer
(CEO)
,Which type of connectivity provides a remote user the ability to safely connect to his or her
corporate network while maintaining data confidentiality and integrity?
a virtual private network (VPN)
Which Application-layer protocol supports public-key encryption and key distribution centers
(KDCs)?
Internet Key Management Protocol (IKMP)
Which authentication protocol uses tickets to authenticate users?
Kerberos
Which type of controls includes access control mechanisms, password management,
identification methods, authentication methods, and security devices?
technical or logical controls
Which port number does LDAP use for communications encrypted using SSL/TLS?
port 636
What are the four types of personally identifiable information (PII)?
Personal characteristics - such as full name, date of birth, height, ethnicity, place of birth,
mother's maiden name, and biometric characteristics
•A unique set of numbers assigned to an individual - such as government ID number, telephone
number, driver's license number, and PIN
•Descriptions of events or points in time - such as arrest records, employment records, and
medical records
•Descriptions of locations or places - such as GPS tracking information
According to CompTIA's Security+ examination blueprint, what are the three listed controls to
provide availability?
redundancy, fault tolerance, and patching
According to CompTIA's Security+ examination blueprint, what are the four listed controls to
provide integrity?
hashing, digital signatures, certificates, and non-repudiation
Which type of access control is the multi-level security mechanism used by the Department of
Defense (DoD)?
mandatory access control (MAC)
,What are the steps in the business continuity planning process?
1. Develop the business continuity planning policy statement.
2. Conduct the business impact analysis (BIA).
3. Identify preventative controls.
4. Develop the recovery strategies.
5. Develop the contingency plans.
6. Test the plan, and train the users.
7. Maintain the plan.
What must you do for an effective security auditing policy, besides creating security logs?
analyze the logs
Which term refers to the loss potential of an asset for a single year?
annualized loss expectancy (ALE)
What is the purpose of hot and cold aisles?
to control airflow in the data center
Which audit category tracks access to all objects outside Active Directory?
the Audit Object Access audit category
What is the proper life cycle of evidence steps?
collection, analysis, storage, court presentation, and return to owner
What is the primary security advantage of using NAT?
Network Address Translation (NAT) hides internal IP addresses from the public network
What is the purpose of filters on a Web server?
They limit the traffic that is allowed through.
Why should a first responder be familiar with the incident response plan?
to ensure that the appropriate procedures are followed
What is the purpose of fuzz testing?
to identify bugs and security flaws within an application
What is the primary concern of RAID?
Redundant Array of Inexpensive Disks (RAID) is concerned with availability
, Which term is used for an agreement that is signed by two partnering companies?
a business partners agreement (BPA)
What is the term for the method of determining which kinds of controls are needed to classify
and protect a company's information assets?
risk assessment
Which type of attack sequentially generates every possible password and checks them all
against a password file?
brute force attack
What is the purpose of screen locks on mobile devices?
to prevent users from accessing the mobile device until a password or other factor is entered
What is the best protection against cross-site scripting (XSS)?
Disable the running of scripts.
Which type of controls include developing policies and procedures, screening personnel,
conducting security awareness training, and implementing change control?
administrative controls
On which standard are certificates based?
X.509
Which key is used to decrypt a digital signature: public or private?
public
What is the default L2TP port?
UDP port 1701
What is Fibre Channel?
a high-speed network technology (commonly running at 2-, 4-, 8- and 16-gigabit per second
rates) that connects computer data storage
Which address is faked with IP spoofing attacks?
the source IP address
What is bluesnarfing?
QUESTIONS & SOLUTIONS
What is the default PPTP port?
TCP port 1723
Which port number does SNMP use?
UDP port 161
Which type of access control associates roles with each user?
role-based access control (RBAC)
Is the Data Encryption Standard (DES) algorithm asymmetric or symmetric?
symmetric
Which authentication protocol encrypts the entire packet (not just the password): TACACS+ or
RADIUS?
TACACS+
Which Linux file contains encrypted user passwords that only the root user can read?
/etc/shadow
How is a digital signature created from a message digest?
It is encrypted using the sender's private key.
Which type of fire suppression system is the safest for both computer equipment and
personnel: FM-200 or Carbon Dioxide?
FM-200
Which backup method serves as the baseline for a backup set?
the full backup
According to CompTIA, why should you disable the SSID broadcast of your wireless router?
to improve your network's security
What is whaling?
a special type of phishing that targets a single power user, such as a Chief Executive Officer
(CEO)
,Which type of connectivity provides a remote user the ability to safely connect to his or her
corporate network while maintaining data confidentiality and integrity?
a virtual private network (VPN)
Which Application-layer protocol supports public-key encryption and key distribution centers
(KDCs)?
Internet Key Management Protocol (IKMP)
Which authentication protocol uses tickets to authenticate users?
Kerberos
Which type of controls includes access control mechanisms, password management,
identification methods, authentication methods, and security devices?
technical or logical controls
Which port number does LDAP use for communications encrypted using SSL/TLS?
port 636
What are the four types of personally identifiable information (PII)?
Personal characteristics - such as full name, date of birth, height, ethnicity, place of birth,
mother's maiden name, and biometric characteristics
•A unique set of numbers assigned to an individual - such as government ID number, telephone
number, driver's license number, and PIN
•Descriptions of events or points in time - such as arrest records, employment records, and
medical records
•Descriptions of locations or places - such as GPS tracking information
According to CompTIA's Security+ examination blueprint, what are the three listed controls to
provide availability?
redundancy, fault tolerance, and patching
According to CompTIA's Security+ examination blueprint, what are the four listed controls to
provide integrity?
hashing, digital signatures, certificates, and non-repudiation
Which type of access control is the multi-level security mechanism used by the Department of
Defense (DoD)?
mandatory access control (MAC)
,What are the steps in the business continuity planning process?
1. Develop the business continuity planning policy statement.
2. Conduct the business impact analysis (BIA).
3. Identify preventative controls.
4. Develop the recovery strategies.
5. Develop the contingency plans.
6. Test the plan, and train the users.
7. Maintain the plan.
What must you do for an effective security auditing policy, besides creating security logs?
analyze the logs
Which term refers to the loss potential of an asset for a single year?
annualized loss expectancy (ALE)
What is the purpose of hot and cold aisles?
to control airflow in the data center
Which audit category tracks access to all objects outside Active Directory?
the Audit Object Access audit category
What is the proper life cycle of evidence steps?
collection, analysis, storage, court presentation, and return to owner
What is the primary security advantage of using NAT?
Network Address Translation (NAT) hides internal IP addresses from the public network
What is the purpose of filters on a Web server?
They limit the traffic that is allowed through.
Why should a first responder be familiar with the incident response plan?
to ensure that the appropriate procedures are followed
What is the purpose of fuzz testing?
to identify bugs and security flaws within an application
What is the primary concern of RAID?
Redundant Array of Inexpensive Disks (RAID) is concerned with availability
, Which term is used for an agreement that is signed by two partnering companies?
a business partners agreement (BPA)
What is the term for the method of determining which kinds of controls are needed to classify
and protect a company's information assets?
risk assessment
Which type of attack sequentially generates every possible password and checks them all
against a password file?
brute force attack
What is the purpose of screen locks on mobile devices?
to prevent users from accessing the mobile device until a password or other factor is entered
What is the best protection against cross-site scripting (XSS)?
Disable the running of scripts.
Which type of controls include developing policies and procedures, screening personnel,
conducting security awareness training, and implementing change control?
administrative controls
On which standard are certificates based?
X.509
Which key is used to decrypt a digital signature: public or private?
public
What is the default L2TP port?
UDP port 1701
What is Fibre Channel?
a high-speed network technology (commonly running at 2-, 4-, 8- and 16-gigabit per second
rates) that connects computer data storage
Which address is faked with IP spoofing attacks?
the source IP address
What is bluesnarfing?