Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 88 páginas
Examen

CompTIA CertMaster CE Security+ (2026/2027) Complete Practice Questions and Answers with Explanations

Document preview thumbnail
Vista previa 4 fuera de 88 páginas

This document provides a comprehensive set of assessment questions and answers aligned with the CompTIA CertMaster CE Security+ 2026/2027 curriculum, specifically targeting Domain 1.0 (General Security Concepts). Each question includes 100% verified correct answers, covering key topics such as zero trust, policy-driven access, secure enclaves, compensating controls, and deception technologies like honeypots and honeyfiles. Ideal for candidates aiming to recertify or prepare for Security+ CE through CertMaster.

Vista previa del contenido

CompTIA CertMaster CE Security+ (2026/2027)
Complete Practice Questions and Answers with
Explanations

1. Which of the following is the primary purpose of the CIA triad in
information security?
A) To ensure data is encrypted at rest
B) To define the core security objectives: Confidentiality, Integrity, and Availability
C) To establish authentication protocols
D) To manage access control lists
Answer B: To define the core security objectives: Confidentiality, Integrity,
and Availability
Rationale: The CIA triad is the foundation of information security, balancing three
goals: keeping data secret, ensuring it is trustworthy, and keeping it accessible.




2. An attacker sends a phishing email to employees, posing as the IT
department and requesting password verification. This is an example of:
A) Social engineering
B) Malware infection
C) Denial of service
D) Spoofing
Answer A: Social engineering

,Rationale: Social engineering manipulates people into revealing confidential
information or performing actions. Phishing is a classic social engineering attack.




3. A company implements a policy requiring employees to use both a smart
card and a PIN to access workstations. This is an example of:
A) Single-factor authentication
B) Multi-factor authentication (MFA)
C) Biometric authentication
D) Role-based access control
Answer B: Multi-factor authentication (MFA)
Rationale: MFA uses two or more authentication factors. A smart card (something
you have) and a PIN (something you know) are distinct factors, providing stronger
security.




4. An organization wants to ensure that a security patch is tested before
deployment. Which change management step should be performed first?
A) Approve the change
B) Initiate a change request in a lab environment
C) Deploy to production
D) Document the rollback procedure
Answer B: Initiate a change request in a lab environment
Rationale: Change management includes testing changes in a non-production
environment before approval and deployment to production.

,5. Which of the following is a detective security control?
A) Firewall rule blocking inbound traffic
B) Intrusion Detection System (IDS) alerting on suspicious traffic
C) Encryption of data at rest
D) Mandatory access control policy
Answer B: Intrusion Detection System (IDS) alerting on suspicious traffic
Rationale: Detective controls identify and alert on security events after they occur.
Firewalls and encryption are preventive; policies are administrative.




6. A security analyst reviews logs and notices multiple failed login attempts
from a single IP address followed by a successful login. This activity is most
indicative of:
A) Normal user behavior
B) A brute-force attack followed by successful compromise
C) A denial-of-service attack
D) System maintenance activity
Answer B: A brute-force attack followed by successful compromise
Rationale: A series of failed logins followed by a successful one suggests an
attacker was attempting to guess credentials and succeeded.




7. What is the primary purpose of a hardware security module (HSM)?

, A) To store and manage digital certificates for web servers
B) To securely generate, store, and manage cryptographic keys
C) To provide endpoint detection and response
D) To scan for vulnerabilities in the network
Answer B: To securely generate, store, and manage cryptographic keys
Rationale: HSMs are physical devices designed to protect cryptographic keys
from theft or misuse.




8. Which of the following is a valid recovery time objective (RTO)?
A) The maximum acceptable data loss measured in time
B) The target time to restore systems after a disruption
C) The minimum system uptime required
D) The time between security patches
Answer B: The target time to restore systems after a disruption
Rationale: RTO is the time from disaster declaration to system restoration.
Recovery Point Objective (RPO) measures data loss.




9. A network administrator configures a firewall rule to allow only traffic on
port 443 to a web server. This is an example of:
A) Least privilege
B) Defense in depth
C) Zero trust
D) Separation of duties

Información del documento

Subido en
19 de agosto de 2026
Número de páginas
88
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$19.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
AcademicACHIEVER
3.3
(85)
Vendido
479
Seguidores
20
Artículos
12413
Última venta
8 horas hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes