Verified Content
CompTIA-SecurityPlus Demo Questions
Get a glimpse of our premium question bank. Practice these highly-curated demo questions to boost your CompTIA-SecurityPlus preparation and identify your weak spots.
Sample Question Bank
In a on-premises data center involving the payment API and admin credentials, A private application checks user identity, device compliance, location, and risk score before each session. Which architecture principle best fits?
+1-0
MCQA
Trust internal network by defaultB
Authenticate once and allow all appsC
Disable segmentation after VPN loginD
Never trust, always verifyCompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.2-security-conceptszero-trustdifficulty-2
In a AWS account involving the SIEM rule set and audit logs, A firewall exception for the payment API requires testing, rollback steps, owner approval, and a maintenance window. Which process is this?
+1-0
MCQA
Change managementB
Threat huntingC
Evidence preservationD
Credential rotationCompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.3-change-managementchange-controldifficulty-2
In a Kubernetes cluster involving the identity provider and audit logs, A patch causes failed logins in production. Which change-management artifact allows the team to restore service quickly?
+1-0
MCQA
Data classification labelB
Password complexity ruleC
Certificate chainD
Rollback planCompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.3-change-managementrollbackdifficulty-2
In a AWS account involving the identity provider and source code, A design review focuses on preventing unauthorized disclosure of admin credentials. Which CIA objective is the review primarily addressing?
+1-0
MCQA
AvailabilityB
ConfidentialityC
IntegrityD
Non-repudiationCompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.2-security-conceptscia-confidentialitydifficulty-1
In a hybrid cloud involving the identity provider and medical records, A release manager requires signed commits so unauthorized changes to production code can be detected. Which objective is most directly supported?
+1-0
MCQA
Privacy by designB
AvailabilityC
IntegrityD
ConfidentialityCompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.2-security-conceptscia-integritydifficulty-2
In a manufacturing OT segment involving the patient-record system and customer PII, A private application checks user identity, device compliance, location, and risk score before each session. Which architecture principle best fits?
+1-0
MCQA
Disable segmentation after VPN loginB
Trust internal network by defaultC
Authenticate once and allow all appsD
Never trust, always verifyCompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.2-security-conceptszero-trustdifficulty-2
In a hybrid cloud involving the developer CI/CD pipeline and financial reports, A private application checks user identity, device compliance, location, and risk score before each session. Which architecture principle best fits?
+1-0
MCQA
Authenticate once and allow all appsB
Trust internal network by defaultC
Never trust, always verifyD
Disable segmentation after VPN loginCompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.2-security-conceptszero-trustdifficulty-2
In a retail branch network involving the identity provider and audit logs, A firewall exception for the SIEM rule set requires testing, rollback steps, owner approval, and a maintenance window. Which process is this?
+1-0
MCQA
Change managementB
Evidence preservationC
Threat huntingD
Credential rotationCompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.3-change-managementchange-controldifficulty-2
In a Kubernetes cluster involving the patient-record system and audit logs, A firewall exception for the public web application requires testing, rollback steps, owner approval, and a maintenance window. Which process is this?
+1-0
MCQA
Credential rotationB
Threat huntingC
Change managementD
Evidence preservationCompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.3-change-managementchange-controldifficulty-2
In a AWS account involving the container platform and admin credentials, A patch causes failed logins in production. Which change-management artifact allows the team to restore service quickly?
+1-0
MCQA
Rollback planB
Certificate chainC
Data classification labelD
Password complexity ruleCompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.3-change-managementrollbackdifficulty-2
In a on-premises data center involving the SIEM rule set and customer PII, A patch causes failed logins in production. Which change-management artifact allows the team to restore service quickly?
+1-0
MCQA
Rollback planB
Password complexity ruleC
Data classification labelD
Certificate chainCompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.3-change-managementrollbackdifficulty-2
In a Azure tenant involving the container platform and source code, A vendor publishes a SHA-256 digest for an installer. What should the customer use it for?
+1-0
MCQA
Authenticate to Wi-FiB
Verify file integrity after downloadC
Assign RBAC permissionsD
Decrypt the installerCompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.4-cryptographyhashingdifficulty-2
In a manufacturing OT segment involving the patient-record system and encryption keys, A server proves its identity using a certificate and private key during TLS negotiation. Which cryptographic approach is involved?
+1-0
MCQA
Asymmetric cryptographyB
Disk deduplicationC
Shared local password onlyD
Plaintext encodingCompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.4-cryptographyasymmetricdifficulty-2
In a retail branch network involving the HR portal and medical records, A team stores database encryption keys in a managed HSM instead of application code. What risk is reduced?
+1-0
MCQA
DNS cache poisoningB
Weak physical lightingC
DDoS bandwidth exhaustionD
Key exposure through source-code leakageCompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.4-cryptographykey-managementdifficulty-2
In a on-premises data center involving the branch-office firewall and customer PII, A vendor publishes a SHA-256 digest for an installer. What should the customer use it for?
+1-0
MCQA
Assign RBAC permissionsB
Verify file integrity after downloadC
Decrypt the installerD
Authenticate to Wi-FiCompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.4-cryptographyhashingdifficulty-2
In a remote workforce involving the patient-record system and audit logs, A vendor publishes a SHA-256 digest for an installer. What should the customer use it for?
+1-0
MCQA
Authenticate to Wi-FiB
Decrypt the installerC
Assign RBAC permissionsD
Verify file integrity after downloadCompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.4-cryptographyhashingdifficulty-2
In a Kubernetes cluster involving the identity provider and customer PII, A server proves its identity using a certificate and private key during TLS negotiation. Which cryptographic approach is involved?
+1-0
MCQA
Asymmetric cryptographyB
Plaintext encodingC
Shared local password onlyD
Disk deduplicationCompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.4-cryptographyasymmetricdifficulty-2
In a remote workforce involving the EDR console and cardholder data, A server proves its identity using a certificate and private key during TLS negotiation. Which cryptographic approach is involved?
+1-0
MCQA
Disk deduplicationB
Asymmetric cryptographyC
Shared local password onlyD
Plaintext encodingCompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.4-cryptographyasymmetricdifficulty-2
In a hybrid cloud involving the EDR console and customer PII, A team stores database encryption keys in a managed HSM instead of application code. What risk is reduced?
+1-0
MCQA
DDoS bandwidth exhaustionB
Key exposure through source-code leakageC
DNS cache poisoningD
Weak physical lightingCompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.4-cryptographykey-managementdifficulty-2
In a Kubernetes cluster involving the patient-record system and financial reports, A team stores database encryption keys in a managed HSM instead of application code. What risk is reduced?
+1-0
MCQA
DDoS bandwidth exhaustionB
Weak physical lightingC
Key exposure through source-code leakageD
DNS cache poisoningCompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.4-cryptographykey-managementdifficulty-2
In a retail branch network involving the container platform and medical records, A retail branch network team blocks inbound traffic with a stateful firewall before it reaches the identity provider. Which control type is being used?
+1-0
MCQA
Physical corrective controlB
Technical preventive controlC
Managerial compensating controlD
Administrative detective controlCompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.1-security-controlstechnical-preventivedifficulty-1
In a Kubernetes cluster involving the branch-office firewall and audit logs, Security installs lighting, fencing, and warning signs around a data-center loading dock. What is the main purpose of these controls?
+1-0
MCQA
Validate software inputB
Deter unauthorized physical accessC
Federate user identitiesD
Encrypt data in transitCompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.1-security-controlsphysical-deterrentdifficulty-1
In a Kubernetes cluster involving the remote-access VPN and medical records, A Kubernetes cluster team blocks inbound traffic with a stateful firewall before it reaches the container platform. Which control type is being used?
+1-0
MCQA
Managerial compensating controlB
Physical corrective controlC
Technical preventive controlD
Administrative detective controlCompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.1-security-controlstechnical-preventivedifficulty-1
In a retail branch network involving the public web application and medical records, A Kubernetes cluster team blocks inbound traffic with a stateful firewall before it reaches the public web application. Which control type is being used?
+1-0
MCQA
Managerial compensating controlB
Physical corrective controlC
Administrative detective controlD
Technical preventive controlCompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.1-security-controlstechnical-preventivedifficulty-1
In a retail branch network involving the SIEM rule set and financial reports, Security installs lighting, fencing, and warning signs around a data-center loading dock. What is the main purpose of these controls?
+1-0
MCQA
Validate software inputB
Deter unauthorized physical accessC
Federate user identitiesD
Encrypt data in transitCompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.1-security-controlsphysical-deterrentdifficulty-1
In a Azure tenant involving the public web application and source code, Security installs lighting, fencing, and warning signs around a data-center loading dock. What is the main purpose of these controls?
+1-0
MCQA
Federate user identitiesB
Validate software inputC
Deter unauthorized physical accessD
Encrypt data in transitCompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.1-security-controlsphysical-deterrentdifficulty-1
In a AWS account involving the SIEM rule set and encryption keys, A design review focuses on preventing unauthorized disclosure of customer PII. Which CIA objective is the review primarily addressing?
+1-0
MCQA
IntegrityB
AvailabilityC
ConfidentialityD
Non-repudiationCompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.2-security-conceptscia-confidentialitydifficulty-1
In a retail branch network involving the payment API and customer PII, A design review focuses on preventing unauthorized disclosure of source code. Which CIA objective is the review primarily addressing?
+1-0
MCQA
Non-repudiationB
AvailabilityC
IntegrityD
ConfidentialityCompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.2-security-conceptscia-confidentialitydifficulty-1
In a retail branch network involving the EDR console and medical records, A release manager requires signed commits so unauthorized changes to production code can be detected. Which objective is most directly supported?
+1-0
MCQA
ConfidentialityB
AvailabilityC
Privacy by designD
IntegrityCompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.2-security-conceptscia-integritydifficulty-2
In a Kubernetes cluster involving the cloud storage account and audit logs, A release manager requires signed commits so unauthorized changes to production code can be detected. Which objective is most directly supported?
+1-0
MCQA
Privacy by designB
ConfidentialityC
IntegrityD
AvailabilityCompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.2-security-conceptscia-integritydifficulty-2
In a Azure tenant involving the HR portal and financial reports, A user logs in, receives access based on group membership, and the action is written to an audit log. Which sequence is represented?
+1-0
MCQA
Authentication, authorization, and accountingB
Identification, compression, and steganographyC
Accounting, federation, and tokenizationD
Authorization, hashing, and encryptionCompTIA-SecurityPlusSY0-701practice-test-01domain-1-general-security-concepts1.2-security-conceptsaaadifficulty-2
In a on-premises data center involving the identity provider and admin credentials, A user logs in, receives access based on group membership, and the action is written to an audit log. Which sequence is represented?
+1-0
MCQA
Authorization, hashing, and encryptionB
Accounting, federation, and tokenizationC
Identification, compression, and steganographyD
Authentication, authorization, and accountingCompTIA-SecurityPlusSY0-701practice-test-02domain-1-general-security-concepts1.2-security-conceptsaaadifficulty-2
In a on-premises data center involving the HR portal and customer PII, A user logs in, receives access based on group membership, and the action is written to an audit log. Which sequence is represented?
+1-0
MCQA
Authorization, hashing, and encryptionB
Accounting, federation, and tokenizationC
Authentication, authorization, and accountingD
Identification, compression, and steganographyCompTIA-SecurityPlusSY0-701practice-test-03domain-1-general-security-concepts1.2-security-conceptsaaadifficulty-2
In a remote workforce involving the payment API and financial reports, A login field accepts input that changes a database query and bypasses authentication. Which flaw exists?
+1-0
MCQA
CSRF token reuse onlyB
SQL injectionC
ARP inspectionD
Key stretchingCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiessql-injectiondifficulty-2
In a remote workforce involving the SIEM rule set and audit logs, A stored product review executes JavaScript in other shoppers’ browsers. What vulnerability is present?
+1-0
MCQA
Pass-the-ticketB
VLAN hopping onlyC
Stored cross-site scriptingD
DNSSEC failureCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesxssdifficulty-2
In a remote workforce involving the SIEM rule set and medical records, A storage bucket containing encryption keys is readable without authentication. What is the root issue?
+1-0
MCQA
Cloud access misconfigurationB
Strong certificate validationC
Secure boot enforcementD
Offline backup retentionCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiescloud-public-bucketdifficulty-2
In a hybrid cloud involving the developer CI/CD pipeline and source code, A login field accepts input that changes a database query and bypasses authentication. Which flaw exists?
+1-0
MCQA
Key stretchingB
ARP inspectionC
CSRF token reuse onlyD
SQL injectionCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiessql-injectiondifficulty-2
In a AWS account involving the remote-access VPN and medical records, A login field accepts input that changes a database query and bypasses authentication. Which flaw exists?
+1-0
MCQA
Key stretchingB
SQL injectionC
CSRF token reuse onlyD
ARP inspectionCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiessql-injectiondifficulty-2
In a remote workforce involving the identity provider and source code, A stored product review executes JavaScript in other shoppers’ browsers. What vulnerability is present?
+1-0
MCQA
VLAN hopping onlyB
Pass-the-ticketC
Stored cross-site scriptingD
DNSSEC failureCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesxssdifficulty-2
In a hybrid cloud involving the cloud storage account and admin credentials, A stored product review executes JavaScript in other shoppers’ browsers. What vulnerability is present?
+1-0
MCQA
Stored cross-site scriptingB
DNSSEC failureC
VLAN hopping onlyD
Pass-the-ticketCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesxssdifficulty-2
In a AWS account involving the public web application and audit logs, A storage bucket containing customer PII is readable without authentication. What is the root issue?
+1-0
MCQA
Cloud access misconfigurationB
Secure boot enforcementC
Strong certificate validationD
Offline backup retentionCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiescloud-public-bucketdifficulty-2
In a AWS account involving the HR portal and source code, A storage bucket containing customer PII is readable without authentication. What is the root issue?
+1-0
MCQA
Cloud access misconfigurationB
Offline backup retentionC
Secure boot enforcementD
Strong certificate validationCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiescloud-public-bucketdifficulty-2
In a hybrid cloud involving the developer CI/CD pipeline and admin credentials, File servers begin renaming files with a new extension and leave payment instructions. Which activity is indicated?
+1-0
MCQA
Ransomware encryptionB
Normal deduplicationC
Certificate renewalD
Federated logoutCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activityransomwaredifficulty-2
In a remote workforce involving the payment API and financial reports, EDR alerts on a tool reading LSASS memory shortly after admin login. Which activity should be suspected?
+1-0
MCQA
Credential dumpingB
Clean desk auditC
Data classificationD
RAID rebuildCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitycredential-dumpingdifficulty-3
In a Azure tenant involving the developer CI/CD pipeline and financial reports, DNS logs show long random-looking subdomains leaving the network at high volume. What should analysts investigate?
+1-0
MCQA
Normal DHCP renewalB
DNS tunneling or exfiltrationC
Disk encryptionD
Certificate staplingCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitydns-tunnelingdifficulty-3
In a AWS account involving the identity provider and audit logs, File servers begin renaming files with a new extension and leave payment instructions. Which activity is indicated?
+1-0
MCQA
Normal deduplicationB
Federated logoutC
Ransomware encryptionD
Certificate renewalCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activityransomwaredifficulty-2
In a on-premises data center involving the remote-access VPN and cardholder data, File servers begin renaming files with a new extension and leave payment instructions. Which activity is indicated?
+1-0
MCQA
Certificate renewalB
Federated logoutC
Ransomware encryptionD
Normal deduplicationCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activityransomwaredifficulty-2
In a manufacturing OT segment involving the developer CI/CD pipeline and financial reports, EDR alerts on a tool reading LSASS memory shortly after admin login. Which activity should be suspected?
+1-0
MCQA
Data classificationB
RAID rebuildC
Credential dumpingD
Clean desk auditCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitycredential-dumpingdifficulty-3
In a retail branch network involving the HR portal and source code, EDR alerts on a tool reading LSASS memory shortly after admin login. Which activity should be suspected?
+1-0
MCQA
RAID rebuildB
Clean desk auditC
Credential dumpingD
Data classificationCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitycredential-dumpingdifficulty-3
In a AWS account involving the identity provider and source code, Changing an order ID in an API URL returns another customer’s order. Which vulnerability is most likely?
+1-0
MCQA
Secure cookie flagB
Certificate transparencyC
Broken object-level authorizationD
Port securityCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesinsecure-apidifficulty-3
In a on-premises data center involving the container platform and cardholder data, DNS logs show long random-looking subdomains leaving the network at high volume. What should analysts investigate?
+1-0
MCQA
Certificate staplingB
Normal DHCP renewalC
DNS tunneling or exfiltrationD
Disk encryptionCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitydns-tunnelingdifficulty-3
In a AWS account involving the branch-office firewall and source code, DNS logs show long random-looking subdomains leaving the network at high volume. What should analysts investigate?
+1-0
MCQA
DNS tunneling or exfiltrationB
Normal DHCP renewalC
Disk encryptionD
Certificate staplingCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitydns-tunnelingdifficulty-3
In a on-premises data center involving the patient-record system and admin credentials, One password is attempted once against hundreds of user accounts. Which attack pattern is this?
+1-0
MCQA
TailgatingB
Birthday attackC
Directory traversalD
Password sprayingCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitypassword-sprayingdifficulty-2
In a Azure tenant involving the public web application and admin credentials, One password is attempted once against hundreds of user accounts. Which attack pattern is this?
+1-0
MCQA
TailgatingB
Birthday attackC
Directory traversalD
Password sprayingCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitypassword-sprayingdifficulty-2
In a remote workforce involving the patient-record system and financial reports, One password is attempted once against hundreds of user accounts. Which attack pattern is this?
+1-0
MCQA
TailgatingB
Directory traversalC
Birthday attackD
Password sprayingCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitypassword-sprayingdifficulty-2
In a retail branch network involving the HR portal and medical records, A vulnerable legacy server cannot be patched immediately. Which mitigation best reduces lateral movement risk?
+1-0
MCQA
Share local administrator passwordsB
Network segmentation with restricted accessC
Disable endpoint loggingD
Expose RDP to the internetCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.5-mitigationsegmentationdifficulty-2
In a retail branch network involving the branch-office firewall and source code, A kiosk should run only one approved application. Which mitigation is strongest?
+1-0
MCQA
Open proxy serviceB
Application allow listingC
Guest administrator accountD
Unrestricted PowerShell executionCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.5-mitigationallow-listingdifficulty-2
In a remote workforce involving the SIEM rule set and customer PII, Developers need to reduce injection risk in database queries. What should they implement?
+1-0
MCQA
Parameterized queries and input validationB
Public write accessC
Disabled output encodingD
Plaintext credential storageCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.5-mitigationsecure-codingdifficulty-2
In a remote workforce involving the HR portal and customer PII, A vulnerable legacy server cannot be patched immediately. Which mitigation best reduces lateral movement risk?
+1-0
MCQA
Disable endpoint loggingB
Network segmentation with restricted accessC
Share local administrator passwordsD
Expose RDP to the internetCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationsegmentationdifficulty-2
In a Azure tenant involving the public web application and admin credentials, A vulnerable legacy server cannot be patched immediately. Which mitigation best reduces lateral movement risk?
+1-0
MCQA
Disable endpoint loggingB
Expose RDP to the internetC
Share local administrator passwordsD
Network segmentation with restricted accessCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationsegmentationdifficulty-2
In a on-premises data center involving the cloud storage account and cardholder data, A kiosk should run only one approved application. Which mitigation is strongest?
+1-0
MCQA
Unrestricted PowerShell executionB
Application allow listingC
Guest administrator accountD
Open proxy serviceCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationallow-listingdifficulty-2
In a Azure tenant involving the patient-record system and cardholder data, A kiosk should run only one approved application. Which mitigation is strongest?
+1-0
MCQA
Open proxy serviceB
Guest administrator accountC
Unrestricted PowerShell executionD
Application allow listingCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationallow-listingdifficulty-2
In a hybrid cloud involving the container platform and encryption keys, Developers need to reduce injection risk in database queries. What should they implement?
+1-0
MCQA
Disabled output encodingB
Parameterized queries and input validationC
Plaintext credential storageD
Public write accessCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationsecure-codingdifficulty-2
In a manufacturing OT segment involving the SIEM rule set and financial reports, Developers need to reduce injection risk in database queries. What should they implement?
+1-0
MCQA
Plaintext credential storageB
Parameterized queries and input validationC
Disabled output encodingD
Public write accessCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.5-mitigationsecure-codingdifficulty-2
In a Azure tenant involving the container platform and audit logs, A hacktivist group targets a public agency to disrupt services and publish political messages. Which motivation is most likely?
+1-0
MCQA
Disaster recovery validationB
Accidental misconfigurationC
Ideological or political motivationD
Routine patch testingCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.1-threat-actorsmotivationdifficulty-2
In a AWS account involving the remote-access VPN and source code, A organized crime group targets a public agency to disrupt services and publish political messages. Which motivation is most likely?
+1-0
MCQA
Ideological or political motivationB
Accidental misconfigurationC
Disaster recovery validationD
Routine patch testingCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.1-threat-actorsmotivationdifficulty-2
In a retail branch network involving the cloud storage account and audit logs, A nation-state team targets a public agency to disrupt services and publish political messages. Which motivation is most likely?
+1-0
MCQA
Routine patch testingB
Ideological or political motivationC
Accidental misconfigurationD
Disaster recovery validationCompTIA-SecurityPlusSY0-701practice-test-03domain-2-threats-vulnerabilities-mitigations2.1-threat-actorsmotivationdifficulty-2
In a Azure tenant involving the HR portal and admin credentials, Employees receive a benefits-update email linking to a lookalike login portal. Which vector is being used?
+1-0
MCQA
BGP route summarizationB
PhishingC
Secure boot bypassD
SQL injectionCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsphishingdifficulty-1
In a Kubernetes cluster involving the developer CI/CD pipeline and admin credentials, Attackers compromise a website frequently used by the company’s engineers and wait for them to visit. Which attack is this?
+1-0
MCQA
Disk wipingB
Passwordless authenticationC
Risk transferenceD
Watering-hole attackCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorswatering-holedifficulty-2
In a on-premises data center involving the identity provider and medical records, Several branded USB drives are left in the parking lot before malware appears on workstations. Which vector is most likely?
+1-0
MCQA
NTP amplification onlyB
Data maskingC
Malicious removable mediaD
Certificate pinningCompTIA-SecurityPlusSY0-701practice-test-01domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsusb-dropdifficulty-2
In a manufacturing OT segment involving the developer CI/CD pipeline and audit logs, Employees receive a benefits-update email linking to a lookalike login portal. Which vector is being used?
+1-0
MCQA
SQL injectionB
PhishingC
BGP route summarizationD
Secure boot bypassCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsphishingdifficulty-1
In a manufacturing OT segment involving the remote-access VPN and medical records, Employees receive a benefits-update email linking to a lookalike login portal. Which vector is being used?
+1-0
MCQA
SQL injectionB
Secure boot bypassC
PhishingD
BGP route summarizationCompTIA-SecurityPlusSY0-701practice-test-03domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsphishingdifficulty-1
In a hybrid cloud involving the developer CI/CD pipeline and source code, Attackers compromise a website frequently used by the company’s engineers and wait for them to visit. Which attack is this?
+1-0
MCQA
Passwordless authenticationB
Watering-hole attackC
Risk transferenceD
Disk wipingCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorswatering-holedifficulty-2
In a Azure tenant involving the remote-access VPN and audit logs, Attackers compromise a website frequently used by the company’s engineers and wait for them to visit. Which attack is this?
+1-0
MCQA
Risk transferenceB
Passwordless authenticationC
Watering-hole attackD
Disk wipingCompTIA-SecurityPlusSY0-701practice-test-03domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorswatering-holedifficulty-2
In a hybrid cloud involving the identity provider and customer PII, Several branded USB drives are left in the parking lot before malware appears on workstations. Which vector is most likely?
+1-0
MCQA
Certificate pinningB
Data maskingC
Malicious removable mediaD
NTP amplification onlyCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsusb-dropdifficulty-2
In a manufacturing OT segment involving the cloud storage account and customer PII, Several branded USB drives are left in the parking lot before malware appears on workstations. Which vector is most likely?
+1-0
MCQA
Certificate pinningB
Data maskingC
NTP amplification onlyD
Malicious removable mediaCompTIA-SecurityPlusSY0-701practice-test-03domain-2-threats-vulnerabilities-mitigations2.2-threat-vectorsusb-dropdifficulty-2
In a retail branch network involving the SIEM rule set and medical records, Changing an order ID in an API URL returns another customer’s order. Which vulnerability is most likely?
+1-0
MCQA
Broken object-level authorizationB
Certificate transparencyC
Secure cookie flagD
Port securityCompTIA-SecurityPlusSY0-701practice-test-02domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesinsecure-apidifficulty-3
In a retail branch network involving the HR portal and medical records, Changing an order ID in an API URL returns another customer’s order. Which vulnerability is most likely?
+1-0
MCQA
Secure cookie flagB
Certificate transparencyC
Broken object-level authorizationD
Port securityCompTIA-SecurityPlusSY0-701practice-test-03domain-2-threats-vulnerabilities-mitigations2.3-vulnerabilitiesinsecure-apidifficulty-3
In a retail branch network involving the remote-access VPN and encryption keys, A switch denies production access until endpoint posture is checked. Which control is used?
+1-0
MCQA
Network access controlB
Disk wipingC
Open relayD
Password sprayingCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.2-secure-infrastructurenacdifficulty-2
In a AWS account involving the payment API and encryption keys, Workloads in the same data center are allowed to communicate only on explicitly required ports. Which design is this?
+1-0
MCQA
Flat network trustB
Implicit any-any accessC
MicrosegmentationD
Broadcast expansionCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.2-secure-infrastructuremicrosegmentationdifficulty-2
In a manufacturing OT segment involving the HR portal and audit logs, Documents are labeled public, internal, confidential, or restricted before DLP policies apply. Which process is this?
+1-0
MCQA
Port mirroringB
Data classificationC
KerberoastingD
NAT overloadCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.3-data-protectionclassificationdifficulty-1
In a Kubernetes cluster involving the cloud storage account and medical records, Where should a public reverse proxy normally sit to limit exposure of internal application servers?
+1-0
MCQA
DMZ or perimeter networkB
Domain controller subnetC
Offline backup vaultD
Privileged admin workstationCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.2-secure-infrastructuredmzdifficulty-1
In a AWS account involving the payment API and medical records, A switch denies production access until endpoint posture is checked. Which control is used?
+1-0
MCQA
Network access controlB
Open relayC
Disk wipingD
Password sprayingCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.2-secure-infrastructurenacdifficulty-2
In a hybrid cloud involving the remote-access VPN and admin credentials, A switch denies production access until endpoint posture is checked. Which control is used?
+1-0
MCQA
Network access controlB
Open relayC
Password sprayingD
Disk wipingCompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.2-secure-infrastructurenacdifficulty-2
In a retail branch network involving the developer CI/CD pipeline and source code, Workloads in the same data center are allowed to communicate only on explicitly required ports. Which design is this?
+1-0
MCQA
Implicit any-any accessB
Flat network trustC
Broadcast expansionD
MicrosegmentationCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.2-secure-infrastructuremicrosegmentationdifficulty-2
In a retail branch network involving the payment API and source code, Workloads in the same data center are allowed to communicate only on explicitly required ports. Which design is this?
+1-0
MCQA
MicrosegmentationB
Flat network trustC
Broadcast expansionD
Implicit any-any accessCompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.2-secure-infrastructuremicrosegmentationdifficulty-2
In a remote workforce involving the branch-office firewall and customer PII, A payment platform replaces card numbers with surrogate values while storing the mapping in a protected vault. What technique is this?
+1-0
MCQA
SteganographyB
Credential stuffingC
TokenizationD
ARP poisoningCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.3-data-protectiontokenizationdifficulty-2
In a retail branch network involving the developer CI/CD pipeline and medical records, A lost laptop contains an encrypted SSD. Which data state is protected most directly?
+1-0
MCQA
Data at restB
Data in use onlyC
Data in transit onlyD
Data remanence after secure wipeCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.3-data-protectiondata-at-restdifficulty-1
In a retail branch network involving the HR portal and financial reports, Documents are labeled public, internal, confidential, or restricted before DLP policies apply. Which process is this?
+1-0
MCQA
Port mirroringB
KerberoastingC
NAT overloadD
Data classificationCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.3-data-protectionclassificationdifficulty-1
In a Azure tenant involving the EDR console and source code, Documents are labeled public, internal, confidential, or restricted before DLP policies apply. Which process is this?
+1-0
MCQA
Data classificationB
NAT overloadC
Port mirroringD
KerberoastingCompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.3-data-protectionclassificationdifficulty-1
In a Kubernetes cluster involving the developer CI/CD pipeline and admin credentials, A payment platform replaces card numbers with surrogate values while storing the mapping in a protected vault. What technique is this?
+1-0
MCQA
Credential stuffingB
TokenizationC
ARP poisoningD
SteganographyCompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.3-data-protectiontokenizationdifficulty-2
In a on-premises data center involving the developer CI/CD pipeline and customer PII, A lost laptop contains an encrypted SSD. Which data state is protected most directly?
+1-0
MCQA
Data at restB
Data in use onlyC
Data remanence after secure wipeD
Data in transit onlyCompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.3-data-protectiondata-at-restdifficulty-1
In a AWS account involving the cloud storage account and medical records, A design target says payroll must be restored within four hours after an outage. Which metric is this?
+1-0
MCQA
Annualized loss expectancyB
Recovery point objectiveC
Recovery time objectiveD
Exposure factorCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.4-resiliencertodifficulty-2
In a Kubernetes cluster involving the developer CI/CD pipeline and cardholder data, Which backup design best resists ransomware modifying backup copies?
+1-0
MCQA
Writable backups mounted to all serversB
Immutable or offline backups with restore testingC
One untested backup on the same hostD
Backups with shared admin passwordCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.4-resilienceimmutable-backupdifficulty-2
In a hybrid cloud involving the branch-office firewall and admin credentials, An application uses load balancing across two availability zones. Which goal is improved?
+1-0
MCQA
Data minimizationB
Password entropyC
High availabilityD
Non-repudiationCompTIA-SecurityPlusSY0-701practice-test-01domain-3-security-architecture3.4-resiliencehadifficulty-2
In a Kubernetes cluster involving the container platform and financial reports, A design target says payroll must be restored within four hours after an outage. Which metric is this?
+1-0
MCQA
Recovery point objectiveB
Annualized loss expectancyC
Recovery time objectiveD
Exposure factorCompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.4-resiliencertodifficulty-2
In a manufacturing OT segment involving the payment API and admin credentials, A design target says payroll must be restored within four hours after an outage. Which metric is this?
+1-0
MCQA
Exposure factorB
Recovery time objectiveC
Annualized loss expectancyD
Recovery point objectiveCompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.4-resiliencertodifficulty-2
In a remote workforce involving the container platform and admin credentials, Which backup design best resists ransomware modifying backup copies?
+1-0
MCQA
Backups with shared admin passwordB
One untested backup on the same hostC
Writable backups mounted to all serversD
Immutable or offline backups with restore testingCompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.4-resilienceimmutable-backupdifficulty-2
In a remote workforce involving the HR portal and audit logs, Which backup design best resists ransomware modifying backup copies?
+1-0
MCQA
Immutable or offline backups with restore testingB
Backups with shared admin passwordC
Writable backups mounted to all serversD
One untested backup on the same hostCompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.4-resilienceimmutable-backupdifficulty-2
In a hybrid cloud involving the SIEM rule set and financial reports, An application uses load balancing across two availability zones. Which goal is improved?
+1-0
MCQA
High availabilityB
Data minimizationC
Password entropyD
Non-repudiationCompTIA-SecurityPlusSY0-701practice-test-02domain-3-security-architecture3.4-resiliencehadifficulty-2
Ready for the full experience?
Unlock hundreds of verified questions, full-length mock tests, and deep performance analytics for CompTIA-SecurityPlus.
Start Full Test Series