CompTIA CertMaster CE Security+ Domain 2.0
Threats, Vulnerabilities, and Mitigations EXAM
LATEST UPDATE THIS YEAR (2026-2027) ALL 300
QUESTIONS AND CORRECT ANSWERS WITH
RATIONALES
CompTIA CertMaster CE Security+ Domain 2.0: Threats, Vulnerabilities, and Mitigations –
Complete 300-Question Assessment
SECTION A: THREAT ACTORS & MOTIVATIONS (Questions 1–40)
1. A recent cyberattack led to massive disruptions in a country's power grid, causing
widespread blackouts and significant economic damage. The cyber team traced the attack to a
hostile nation-state's cyber warfare division. What is the PRIMARY motivation of the
perpetrators?
A) Financial gain
B) Espionage
C) War
D) Hacktivism
1
, Page 2 of 184
Answer: C – Nation-state threat actors attacking critical infrastructure such as power grids are
typically motivated by geopolitical objectives, often categorized as warfare. This represents the
highest level of threat actor capability and intent.
2. A hacker group infiltrated a global financial institution's systems and stole the credit card
information of millions of customers. The stolen data was soon available on the dark web. What
is the MOST likely motivation of this group?
A) Espionage
B) Financial gain
C) Hacktivism
D) Revenge
Answer: B – Organized crime groups and financially motivated threat actors target financial
institutions specifically to steal payment card data and PII for resale on the dark web. Financial
gain is the primary driver for these attacks.
2
, Page 3 of 184
3. A company discovers that an employee has been selling sensitive proprietary data to
competitors for the past six months. What type of threat actor does this represent?
A) Nation-state
B) Organized crime
C) Hacktivist
D) Insider threat
Answer: D – Insider threats originate from individuals within the organization—employees,
contractors, or business partners—who misuse their authorized access to cause harm.
4. Which threat actor is MOST likely to use common hacking tools found on the internet to
attempt to remotely compromise an organization's web server without customizing the attack?
A) Organized crime
B) Insider threat
C) Unskilled attacker
D) Nation-state
3
, Page 4 of 184
Answer: C – Unskilled attackers (often called "script kiddies") use readily available hacking tools
and scripts from the internet. They lack sophisticated capabilities and rely on known
vulnerabilities without customization.
5. A company receives a ransom demand after attackers encrypted their critical database and
demanded payment in cryptocurrency. Which type of threat actor is MOST likely responsible?
A) Hacktivist
B) Nation-state
C) Organized crime
D) Insider
Answer: C – Ransomware attacks are primarily conducted by organized crime groups seeking
financial gain. These groups have developed sophisticated ransomware-as-a-service (RaaS)
operations.
6. An attack disrupts a major online retailer's services during peak holiday shopping season by
overwhelming servers with traffic. What attack strategy best aligns with this scenario?
4