S+ Practice Set
S+ Practice Set
1. Which security principle ensures users have only the permissions needed to perform
their job duties?
A. Separation of duties
B. Least privilege
C. Job rotation
D. Mandatory vacation
Explanation: Least privilege grants users only the minimum permissions required to perform
their tasks. This limits the damage that can occur if an account is compromised.
2. Which type of malware encrypts files and demands payment for their release?
A. Trojan
B. Worm
C. Spyware
D. Ransomware
Answer: D. Ransomware
Explanation: Ransomware encrypts victim data and demands a ransom payment, usually in
cryptocurrency, for the decryption key.
Explanation: Biometrics such as fingerprints, facial recognition, and iris scans fall under
“something you are.”
A. HTTP
B. FTP
C. HTTPS
D. Telnet
Answer: C. HTTPS
Explanation: HTTPS uses TLS to encrypt communications between clients and web servers.
A. Administrative
B. Detective
C. Physical
D. Technical
Answer: C. Physical
Explanation: Physical controls protect facilities and equipment from unauthorized physical
access.
6. Which attack uses fraudulent emails to trick users into revealing sensitive
information?
A. Smishing
B. Vishing
C. Phishing
D. Tailgating
Answer: C. Phishing
Explanation: Symmetric encryption uses the same key for encryption and decryption,
making it faster than asymmetric encryption.
8. Which component of the CIA Triad ensures data remains accurate and unaltered?
A. Confidentiality
B. Integrity
C. Availability
D. Accountability
Answer: B. Integrity
A. Encrypt files
B. Filter network traffic
C. Detect malware signatures
D. Create backups
A. Telnet
B. FTP
C. SSH
D. SNMP
Answer: C. SSH
A. Dictionary attack
B. Password spraying
C. Brute force attack
D. Replay attack
Explanation: Brute force attacks systematically try all possible combinations until the
correct password is found.
A. Nessus
B. Nmap
C. Wireshark
D. Metasploit
Answer: C. Wireshark
Explanation: Wireshark is widely used for network troubleshooting and packet analysis.
A. Availability
B. Integrity
C. Confidentiality
D. Authentication
Answer: C. Confidentiality
A. Integrity
B. Confidentiality
C. Availability
D. Authentication
Answer: A. Integrity
A. Preventive
B. Detective
C. Deterrent
D. Corrective
Answer: C. Deterrent
Explanation: Incremental backups are efficient but restoration can take longer.
Explanation: Differential backups grow larger over time but simplify restoration.
A. Vishing
B. Smishing
C. Whaling
D. Pharming
Answer: B. Smishing
A. Smishing
B. Pharming
C. Vishing
D. Whaling
Answer: C. Vishing
A. Spear phishing
B. Whaling
C. Smishing
D. Baiting
Answer: B. Whaling
A. Cross-Site Scripting
B. SQL Injection
C. Buffer Overflow
D. Replay Attacks
A. SQL Injection
B. Cross-Site Request Forgery
C. Cross-Site Scripting (XSS)
D. DNS Poisoning
A. Malware infections
B. Fraud and abuse
C. Network outages
D. Data encryption failures
A. Zero Trust
B. Defense in Depth
C. Segmentation
D. Need to Know
A. User discretion
B. Job roles
C. Security labels
D. Time restrictions
Explanation: Access decisions are based on classifications like Secret or Top Secret.
A. User preference
B. Security labels
C. Job responsibilities
D. Geographic location
A. Secure email
B. Centralized authentication
C. Web encryption
D. VPN tunneling
A. Directory services
B. Email delivery
C. DNS resolution
D. Packet analysis
A. 80
B. 21
C. 443
D. 25
Answer: C. 443
A. 21
B. 22
C. 23
D. 443
Answer: B. 22
A. 25
B. 53
C. 80
D. 110
Answer: B. 53
Explanation: DNS uses port 53 for both UDP and TCP communications.
A. 25
B. 53
C. 80
D. 110
Answer: A. 25
A. 443
B. 22
C. 3389
D. 8080
Answer: C. 3389
A. NAT
B. VLAN
C. VPN
D. DHCP
Answer: C. VPN
A. SNMP
B. IPsec
C. FTP
D. Telnet
Answer: B. IPsec
A. Steal credentials
B. Prevent system availability
C. Modify databases
D. Encrypt files
41. A Distributed Denial-of-Service (DDoS) attack differs from a DoS attack because it:
Explanation: DDoS attacks leverage many infected devices (botnets) to overwhelm a target,
making them harder to mitigate than single-source DoS attacks.
42. Which wireless attack involves setting up a rogue access point that mimics a
legitimate network?
A. Bluesnarfing
B. Evil Twin
C. Bluejacking
D. Wardriving
Explanation: An Evil Twin attack tricks users into connecting to a malicious wireless access
point, allowing attackers to intercept traffic.
43. Which wireless security protocol is currently considered the most secure?
A. WEP
B. WPA
C. WPA2
D. WPA3
Answer: D. WPA3
Explanation: WPA3 provides stronger encryption and improved protection against brute-
force attacks compared to earlier protocols.
A. WPA3
B. WPA2-AES
C. WPA
D. WEP
Answer: D. WEP
Explanation: WEP uses weak encryption algorithms that can be cracked relatively easily.
45. Which tool is commonly used to identify open ports and services?
A. Wireshark
B. Nessus
C. Nmap
D. John the Ripper
Answer: C. Nmap
Explanation: Nmap is a network scanning tool used to discover hosts, services, and open
ports.
A. MD5
B. SHA-1
C. SHA-256
D. CRC32
Answer: C. SHA-256
Explanation: SHA-256 is part of the SHA-2 family and is widely used because of its
resistance to collision attacks.
48. Which cryptographic system uses a public and private key pair?
A. Symmetric encryption
B. Asymmetric encryption
C. Hashing
D. Tokenization
Explanation: Asymmetric encryption uses a public key for encryption and a private key for
decryption.
49. Which certificate format is Base64 encoded and commonly used with web servers?
A. DER
B. PEM
C. CER
D. PKCS#12
Answer: B. PEM
Explanation: PEM certificates are ASCII encoded and are commonly used in Apache and
Nginx environments.
50. Which attack captures valid authentication data and reuses it later?
A. SQL Injection
B. Replay Attack
C. Buffer Overflow
D. Rootkit
Explanation: Replay attacks occur when attackers capture valid transmissions and resend
them to gain unauthorized access.
51. Which vulnerability occurs when a program writes data beyond allocated memory
boundaries?
A. SQL Injection
B. Buffer Overflow
C. Cross-Site Scripting
D. CSRF
Explanation: Buffer overflows can allow attackers to execute arbitrary code or crash
applications.
A. Worm
B. Trojan
C. Spyware
D. Ransomware
Answer: B. Trojan
Explanation: Trojans trick users into installing malicious software by appearing legitimate.
A. Virus
B. Trojan
C. Worm
D. Rootkit
Answer: C. Worm
54. Which malware type is designed to hide its existence while maintaining privileged
access?
A. Adware
B. Spyware
C. Rootkit
D. Worm
Answer: C. Rootkit
Explanation: Rootkits provide stealthy privileged access and are difficult to detect.
A. Spyware
B. Worm
C. Trojan
D. Logic Bomb
Answer: A. Spyware
Explanation: Zero-day vulnerabilities are unknown or unpatched flaws that attackers can
exploit before fixes are available.
57. Which penetration testing approach provides no prior knowledge of the target
environment?
A. White Box
B. Gray Box
C. Black Box
D. Transparent Box
58. Which penetration testing approach provides full knowledge of the target
environment?
A. Black Box
B. White Box
C. Gray Box
D. External Box
Explanation: White-box testing provides testers with complete access to system information.
A. White Box
B. Black Box
C. Gray Box
D. Open Box
A. Nmap
B. Wireshark
C. Nessus
D. tcpdump
Answer: C. Nessus
A. Encrypt data
B. Aggregate and analyze security logs
C. Replace firewalls
D. Create backups
Explanation: EDR tools monitor endpoints for suspicious activities and assist with incident
response.
64. Which control type restores systems after a security incident?
A. Preventive
B. Detective
C. Corrective
D. Deterrent
Answer: C. Corrective
Explanation: Corrective controls minimize the impact of incidents and restore normal
operations.
A. Detective
B. Preventive
C. Corrective
D. Compensating
Answer: A. Detective
Explanation: Detective controls include IDS, monitoring systems, and security audits.
67. Which attack exploits human psychology rather than technical vulnerabilities?
A. Social Engineering
B. SQL Injection
C. DDoS
D. Buffer Overflow
68. Which attack involves following an authorized individual into a restricted area?
A. Shoulder Surfing
B. Tailgating
C. Vishing
D. Baiting
Answer: B. Tailgating
A. Shoulder Surfing
B. Smishing
C. Whaling
D. Pharming
70. Which social engineering tactic involves creating a fabricated scenario to gain trust?
A. Baiting
B. Pretexting
C. Smishing
D. Impersonation
Answer: B. Pretexting
A. Tailgating
B. Vishing
C. Baiting
D. Smishing
Answer: C. Baiting
A. SLA
B. MOU
C. NDA
D. AUP
Answer: C. NDA
75. Which process ensures critical business operations continue during disruptions?
A. Disaster Recovery
B. Incident Response
C. Business Continuity
D. Threat Hunting
Explanation: Disaster recovery plans address the restoration of systems and data.
77. Which incident response phase involves identifying and analyzing threats?
A. Preparation
B. Recovery
C. Detection and Analysis
D. Lessons Learned
Explanation: This phase confirms incidents and determines their scope and severity.
78. During which incident response phase are systems restored to normal operation?
A. Containment
B. Recovery
C. Preparation
D. Detection
Answer: B. Recovery
79. Which incident response phase removes the root cause of an incident?
A. Eradication
B. Preparation
C. Recovery
D. Detection
Answer: A. Eradication
80. What is typically the final phase of the incident response lifecycle?
A. Recovery
B. Containment
C. Lessons Learned
D. Detection
82. Which data classification label is generally considered the highest sensitivity level?
A. Public
B. Internal Use Only
C. Confidential
D. Top Secret
84. Which technique replaces sensitive data with non-sensitive substitute values?
A. Hashing
B. Encryption
C. Tokenization
D. Salting
Answer: C. Tokenization
Explanation: Tokenization substitutes sensitive data with tokens while maintaining the
ability to reference the original data securely.
85. Which technique hides portions of sensitive information, such as displaying only the
last four digits of a credit card number?
A. Tokenization
B. Data Masking
C. Hashing
D. Obfuscation
Explanation: Data masking obscures sensitive information while allowing users to work
with realistic-looking data.
Explanation: Network segmentation divides networks into smaller sections, reducing the
impact of breaches and limiting lateral movement.
87. Which security model assumes no user or device should be trusted automatically?
A. Defense in Depth
B. Least Privilege
C. Zero Trust
D. Separation of Duties
Explanation: Zero Trust follows the principle of “never trust, always verify,” requiring
continuous validation of access requests.
88. Which cloud deployment model provides services to the general public over the
internet?
A. Private Cloud
B. Hybrid Cloud
C. Public Cloud
D. Community Cloud
Explanation: Public cloud services are offered by third-party providers and shared among
multiple customers.
89. Which cloud deployment model combines private and public cloud environments?
A. Public Cloud
B. Hybrid Cloud
C. Community Cloud
D. Dedicated Cloud
90. Which cloud service model delivers fully functional applications to end users?
A. IaaS
B. PaaS
C. SaaS
D. FaaS
Answer: C. SaaS
A. SaaS
B. PaaS
C. IaaS
D. XaaS
Answer: C. IaaS
92. Which cloud service model provides a platform for application development and
deployment?
A. IaaS
B. PaaS
C. SaaS
D. SECaaS
Answer: B. PaaS
Explanation: CASBs provide visibility and enforcement of security policies across cloud
services.
94. Which protocol is commonly used for Single Sign-On (SSO) in enterprise
environments?
A. LDAP
B. SAML
C. SSH
D. SNMP
Answer: B. SAML
A. Kerberos
B. OAuth
C. RADIUS
D. TACACS+
Answer: B. OAuth
96. Which authentication protocol builds on OAuth 2.0 to provide identity information?
A. Kerberos
B. LDAP
C. OpenID Connect
D. TACACS+
A. SAML
B. Kerberos
C. RADIUS
D. LDAP
Answer: B. Kerberos
A. LDAP
B. SSH
C. TACACS+
D. FTP
Answer: C. TACACS+
Explanation: Risk mitigation implements controls that decrease the probability of an event
occurring or minimize its impact.
Answer: D. Transfer
Explanation: Risk transfer shifts the financial impact of a risk to another party, such as
through insurance policies or outsourcing agreements.
Security+ (SY0-701) Practice Questions – Set 2
(Questions 101–120)
101. Which type of encryption uses two mathematically related keys?
A. Symmetric encryption
B. Stream encryption
C. Asymmetric encryption
D. Block encryption
Explanation: Asymmetric encryption uses a public key and a private key. The public key
encrypts data, while the private key decrypts it. RSA and ECC are common examples.
A. Session key
B. Private key
C. Shared key
D. Public key
Explanation: The public key is designed to be shared openly. The private key must remain
confidential.
103. Which key must remain secret in a public key infrastructure (PKI)?
A. Public key
B. Session key
C. Private key
D. Recovery key
A. Encrypt files
B. Verify authenticity and integrity
C. Compress data
D. Increase availability
Answer: B. Verify authenticity and integrity
Explanation: Digital signatures confirm that data has not been altered and verify the identity
of the sender.
Explanation: The CA validates identities and issues digital certificates that bind identities to
public keys.
Explanation: CRLs allow systems to verify whether a certificate should no longer be trusted
before its expiration date.
A. LDAP
B. OCSP
C. SNMP
D. SFTP
Answer: B. OCSP
108. Which hashing algorithm is currently considered secure and widely used?
A. MD5
B. SHA-1
C. SHA-256
D. CRC32
Answer: C. SHA-256
Explanation: SHA-256 belongs to the SHA-2 family and is resistant to known collision
attacks.
A. AES
B. RSA
C. DES
D. ECC
Answer: C. DES
Explanation: AES is the current standard for symmetric encryption and replaced DES.
A. 56-bit
B. 128-bit
C. 192-bit
D. 256-bit
Answer: D. 256-bit
Explanation: Larger key sizes provide greater resistance against brute-force attacks.
A. RSA
B. ECC
C. AES
D. DSA
Answer: C. AES
Explanation: AES uses the same key for encryption and decryption.
A. AES
B. Blowfish
C. Twofish
D. RSA
Answer: D. RSA
114. Which algorithm provides strong security with smaller key sizes?
A. DES
B. ECC
C. RC4
D. 3DES
Answer: B. ECC
Explanation: Elliptic Curve Cryptography offers equivalent security to RSA using much
smaller keys.
Explanation: Salting makes identical passwords produce different hash values, defeating
precomputed attacks.
116. What is the purpose of a nonce in cryptographic operations?
A. Generate certificates
B. Prevent replay attacks
C. Store keys
D. Hash passwords
Explanation: A nonce is a unique value used only once, preventing attackers from reusing
captured communications.
118. Which attack manipulates DNS records to redirect users to malicious websites?
A. ARP spoofing
B. SQL injection
C. DNS poisoning
D. Cross-site scripting
Explanation: DNS poisoning corrupts DNS caches to redirect users to fraudulent websites.
A. DNSSEC
B. IPsec
C. SSH
D. TLS
Answer: A. DNSSEC
A. ARP spoofing
B. Smishing
C. SQL injection
D. Pharming
Explanation: ARP spoofing associates an attacker’s MAC address with another device’s IP
address to intercept communications.
121. Which vulnerability occurs when the timing of events can be manipulated by an
attacker?
A. SQL Injection
B. Cross-Site Scripting
C. Race Condition
D. Buffer Overflow
Explanation: Race conditions occur when multiple processes access shared resources
simultaneously, allowing attackers to exploit timing differences to gain unauthorized access
or alter data.
A. Weak encryption
B. Improper Input Handling
C. Poor logging practices
D. Network segmentation failure
Explanation: Failing to validate input can lead to vulnerabilities such as SQL injection,
command injection, and cross-site scripting attacks.
A. Regression Testing
B. Unit Testing
C. Fuzz Testing
D. Penetration Testing
Explanation: Code reviews help developers identify vulnerabilities before applications are
deployed.
126. Which development approach integrates security throughout the software development
lifecycle?
A. Agile
B. Waterfall
C. DevSecOps
D. ITIL
Answer: C. DevSecOps
A. Testing
B. Deployment
C. Requirements Gathering
D. Maintenance
Explanation: Identifying security requirements early reduces costly fixes later in the
development process.
A. Production
B. Staging
C. Development
D. Disaster Recovery
Answer: C. Development
Explanation: Development environments are used for coding and initial testing before
moving applications to later stages.
129. Which environment most closely resembles production and is used for final testing?
A. Sandbox
B. Development
C. Staging
D. Backup
Answer: C. Staging
130. Which security technique isolates applications to prevent them from affecting the host
system?
A. Tokenization
B. Sandboxing
C. Segmentation
D. Obfuscation
Answer: B. Sandboxing
Explanation: Sandboxing limits application access to system resources, reducing the impact
of malicious code.
A. Encrypt data
B. Run multiple virtual systems on a single physical host
C. Improve DNS resolution
D. Eliminate malware
132. Which technology packages applications with their dependencies into isolated units?
A. RAID
B. PKI
C. Containerization
D. Segmentation
Answer: C. Containerization
A. Docker
B. Kubernetes
C. Nessus
D. Wireshark
Answer: B. Kubernetes
A. Store backups
B. Isolate public-facing services from internal networks
C. Replace firewalls
D. Encrypt network traffic
Answer: B. Isolate public-facing services from internal networks
A. Router
B. Firewall
C. IDS
D. Load Balancer
A. Hub
B. Switch
C. Router
D. Bridge
Answer: C. Router
Explanation: Routers operate at Layer 3 and direct packets between networks using IP
addresses.
137. Which device forwards frames within a LAN based on MAC addresses?
A. Router
B. Switch
C. Firewall
D. Modem
Answer: B. Switch
Explanation: Switches operate at Layer 2 and improve efficiency by forwarding traffic only
where needed.
Explanation: IDS solutions monitor network or host activity and generate alerts when
suspicious behavior is detected.
Explanation: IPS solutions actively detect and block malicious traffic automatically.
Answer: B. IDS monitors and alerts; IPS can block malicious activity
Explanation: IDS provides visibility into threats, while IPS adds active prevention
capabilities by stopping malicious traffic.
141. Which type of firewall tracks the state of active network connections?
A. Packet-filtering firewall
B. Stateless firewall
C. Stateful firewall
D. Proxy firewall
Explanation: Stateful firewalls monitor the state of active connections and make filtering
decisions based on the context of the traffic, providing better security than simple packet
filtering.
142. Which firewall type acts as an intermediary between clients and servers?
A. Stateful firewall
B. Packet-filtering firewall
C. Proxy firewall
D. Circuit-level firewall
Explanation: Proxy firewalls terminate incoming connections and establish new ones on
behalf of clients, hiding internal systems from external networks.
Explanation: NAC solutions enforce security policies before allowing devices to connect to
the network.
Explanation: NAC ensures only compliant and authorized devices can access organizational
resources.
A. Manage backups
B. Define rules that permit or deny traffic
C. Encrypt data transmissions
D. Generate authentication tokens
146. Which wireless frequency band generally provides the greatest range?
A. 5 GHz
B. 6 GHz
C. 2.4 GHz
D. 60 GHz
Explanation: The 2.4 GHz band travels farther and penetrates walls more effectively than
higher frequencies, though it is more susceptible to interference.
147. Which wireless frequency band typically offers higher speeds and less interference?
A. 900 MHz
B. 2.4 GHz
C. 5 GHz
D. 433 MHz
Answer: C. 5 GHz
Explanation: The 5 GHz band provides higher throughput and experiences less congestion
than the 2.4 GHz band.
148. Which Bluetooth attack involves sending unsolicited messages to nearby devices?
A. Bluesnarfing
B. Bluejacking
C. Evil Twin
D. Bluespoofing
Answer: B. Bluejacking
A. Bluejacking
B. Bluesnarfing
C. Evil Twin
D. Smishing
Answer: B. Bluesnarfing
Explanation: Bluesnarfing allows attackers to steal contacts, messages, and other sensitive
information from vulnerable Bluetooth devices.
Explanation: Security awareness training educates employees about threats such as phishing
and social engineering to reduce successful attacks.
Answer: C. Preparation
152. During which incident response phase are affected systems isolated to limit damage?
A. Recovery
B. Preparation
C. Containment
D. Lessons Learned
Answer: C. Containment
153. Which forensic concept ensures evidence remains unaltered and properly documented?
A. Chain of Custody
B. Data Masking
C. Tokenization
D. Data Classification
Explanation: Chain of custody documents who handled evidence and when, preserving its
integrity for legal proceedings.
Explanation: Proper chain of custody ensures evidence is admissible and has not been
tampered with.
Explanation: Investigators should preserve the original evidence and conduct analysis on a
copy to maintain integrity.
157. Which type of evidence is lost when a system loses power?
A. Archived logs
B. Backup files
C. Volatile memory (RAM)
D. Printed reports
Explanation: Volatile memory contains temporary information that disappears when power
is removed.
158. Which tool is commonly used for memory analysis in digital forensics?
A. Nmap
B. Wireshark
C. Volatility
D. Nessus
Answer: C. Volatility
160. Which type of logs commonly records authentication successes and failures?
A. Application logs
B. System logs
C. Security logs
D. Network logs
161. Which type of log primarily records firewall activity and network traffic events?
A. Application logs
B. Security logs
C. Network logs
D. System logs
Explanation: Network logs capture information about traffic flow, firewall decisions, and
communication events between systems, making them essential for identifying suspicious
activity.
Explanation: Audit logs record who performed specific actions and when they occurred,
supporting compliance and forensic investigations.
Explanation: RTO defines the maximum acceptable amount of downtime after a disruption
before operations must be restored.
Explanation: RPO defines the maximum acceptable amount of data loss measured in time.
A. MTTD
B. MTTR
C. RPO
D. RTO
Answer: D. RTO
Explanation: RTO focuses on how quickly systems must be restored after an outage.
166. Which metric determines the maximum acceptable amount of data loss?
A. RPO
B. RTO
C. MTTR
D. ALE
Answer: A. RPO
Explanation: RPO helps organizations determine how frequently backups should occur.
167. Which disaster recovery site provides the fastest restoration capability?
A. Cold Site
B. Warm Site
C. Hot Site
D. Alternate Site
Explanation: Hot sites contain fully operational systems and up-to-date data, allowing for
rapid recovery.
168. Which recovery site contains hardware but requires data restoration before becoming
operational?
A. Cold Site
B. Warm Site
C. Hot Site
D. Mobile Site
Explanation: Warm sites offer a balance between cost and recovery speed.
A. Hot Site
B. Warm Site
C. Cold Site
D. Mirrored Site
Explanation: Cold sites are inexpensive but require significant time to become operational.
Explanation: A BIA identifies critical functions and helps establish recovery priorities.
171. Which process identifies critical business functions and their dependencies?
A. Vulnerability Assessment
B. Penetration Testing
C. Business Impact Analysis
D. Threat Hunting
Explanation: BIAs help organizations understand operational risks and prioritize recovery
efforts.
172. Which risk assessment approach uses numerical values and financial estimates?
Explanation: Quantitative analysis uses measurable data, such as monetary values, to assess
risk.
173. Which risk assessment approach categorizes risks as High, Medium, or Low?
A. Quantitative Analysis
B. Qualitative Analysis
C. Cost-Benefit Analysis
D. Trend Analysis
Explanation: Qualitative analysis uses subjective measures to prioritize risks when exact
financial values are unavailable.
A. ALE = AV × EF
B. ALE = SLE × ARO
C. ALE = RTO × RPO
D. ALE = ARO ÷ SLE
Explanation: ALE estimates expected annual financial loss by multiplying Single Loss
Expectancy (SLE) by Annual Rate of Occurrence (ARO).
Explanation: ARO estimates how often a specific threat is expected to occur annually.
177. Which risk response strategy involves accepting the risk without implementing
additional controls?
A. Mitigation
B. Transfer
C. Avoidance
D. Acceptance
Answer: D. Acceptance
Explanation: Organizations may accept risks when the cost of mitigation exceeds the
potential impact.
178. Which risk response strategy eliminates activities that create the risk?
A. Mitigation
B. Avoidance
C. Transfer
D. Acceptance
Answer: B. Avoidance
Explanation: Avoidance removes the source of risk entirely, such as discontinuing a risky
business process.
179. Which administrative control requires employees to take time away from their duties to
uncover fraud?
A. Job Rotation
B. Separation of Duties
C. Mandatory Vacations
D. Least Privilege
Explanation: Mandatory vacations can reveal fraudulent activities that require continuous
involvement by a malicious employee.
180. Which type of control includes policies, procedures, and security awareness training?
A. Physical Controls
B. Technical Controls
C. Administrative Controls
D. Detective Controls
181. Which cybersecurity framework is widely used for managing and improving
organizational security programs?
A. PCI DSS
B. NIST Cybersecurity Framework (CSF)
C. HIPAA
D. GDPR
Explanation: The NIST CSF provides a flexible approach to managing cybersecurity risks
through five core functions: Identify, Protect, Detect, Respond, and Recover.
182. Which regulation is designed to protect healthcare information in the United States?
A. PCI DSS
B. SOX
C. HIPAA
D. GDPR
Answer: C. HIPAA
Explanation: The Health Insurance Portability and Accountability Act (HIPAA) establishes
standards for protecting patient health information (PHI).
183. Which standard applies to organizations that process, store, or transmit payment card
information?
A. HIPAA
B. GDPR
C. PCI DSS
D. SOX
Explanation: The Payment Card Industry Data Security Standard (PCI DSS) defines security
requirements for handling payment card data.
184. Which regulation focuses on protecting the personal data and privacy of individuals in
the European Union?
A. HIPAA
B. SOX
C. GDPR
D. FERPA
Answer: C. GDPR
Explanation: The General Data Protection Regulation (GDPR) establishes strict rules
regarding the collection, processing, and protection of EU citizens’ personal data.
185. Which regulation primarily addresses financial reporting and internal controls for
publicly traded companies?
A. HIPAA
B. GDPR
C. PCI DSS
D. SOX
Answer: D. SOX
Explanation: Data retention policies ensure that information is kept only as long as
necessary to satisfy business, legal, and regulatory requirements.
188. Which method physically destroys storage media to prevent data recovery?
A. Data wiping
B. Degaussing
C. Shredding
D. Encryption
Answer: C. Shredding
189. Which data sanitization method uses strong magnetic fields to erase information from
magnetic media?
A. Data wiping
B. Tokenization
C. Degaussing
D. Masking
Answer: C. Degaussing
Explanation: Degaussing disrupts the magnetic fields used to store data, rendering the media
unusable.
190. Which data sanitization method overwrites existing information with new data patterns?
A. Data wiping
B. Degaussing
C. Shredding
D. Encryption
Explanation: Data wiping securely overwrites stored information to prevent recovery while
allowing media reuse.
192. Which process ensures that proposed system changes are evaluated before
implementation?
A. Vulnerability Management
B. Change Management
C. Threat Hunting
D. Incident Response
Explanation: Change management provides a structured process for assessing the impact
and risk of changes.
194. Which process verifies that systems comply with organizational policies and regulatory
requirements?
A. Penetration Testing
B. Compliance Auditing
C. Fuzz Testing
D. Threat Hunting
Explanation: Threat hunting involves actively investigating networks and systems to identify
adversaries that have evaded traditional detection methods.
197. Which team is primarily responsible for defending systems and responding to incidents?
A. Red Team
B. Blue Team
C. Purple Team
D. White Team
Explanation: Blue teams focus on defensive security operations, monitoring, and incident
response.
A. Blue Team
B. Purple Team
C. Red Team
D. Green Team
Explanation: Red teams emulate real-world adversaries to test security controls and identify
weaknesses.
199. Which team facilitates collaboration between offensive and defensive security
personnel?
A. Red Team
B. Blue Team
C. Purple Team
D. White Team
Explanation: Purple teams combine insights from red and blue teams to improve overall
security effectiveness.
200. An administrator discovers that employees have excessive access permissions beyond
their job requirements. Which security principle should be implemented to address this issue?
A. Mandatory Vacations
B. Job Rotation
C. Least Privilege
D. Data Masking
Explanation: The principle of least privilege ensures users receive only the permissions
necessary to perform their job duties, reducing the risk
Security+ (SY0-701) Practice Questions – Set 3
(Questions 201–220)
201. An employee reports that all files on their workstation have become inaccessible and a
note demands cryptocurrency payment. What type of malware is MOST likely responsible?
A. Worm
B. Spyware
C. Trojan
D. Ransomware
Answer: D. Ransomware
Explanation: Ransomware encrypts a victim’s files and demands payment for the decryption
key. Organizations should isolate affected systems immediately and restore data from
backups when possible.
202. Which security control BEST prevents users from installing unauthorized applications?
A. Antivirus software
B. Application allow listing
C. DLP solution
D. Network segmentation
Explanation: Application allow listing permits only approved applications to run, preventing
unauthorized or malicious software execution.
203. Which authentication method generates a unique code that changes periodically?
A. Password history
B. TOTP
C. Kerberos
D. LDAP
Answer: B. TOTP
Explanation: Password history prevents users from reusing recently used passwords,
encouraging stronger password practices.
205. Which attack uses a small number of commonly used passwords against many accounts?
A. Dictionary attack
B. Brute-force attack
C. Password spraying
D. Credential stuffing
206. Which attack uses stolen username and password combinations from previous breaches?
A. Password spraying
B. Credential stuffing
C. Brute force
D. Replay attack
207. Which control limits the number of consecutive failed login attempts?
A. Password history
B. Password complexity
C. Account lockout
D. Single Sign-On
208. Which security principle grants access only when it is necessary for job responsibilities?
A. Need to Know
B. Separation of Duties
C. Due Care
D. Job Rotation
Explanation: Due diligence involves assessing risks and gathering information to make
informed decisions.
211. Which security practice BEST limits lateral movement of attackers in IoT
environments?
Explanation: Segmentation isolates IoT devices from critical systems, limiting attacker
movement after compromise.
Explanation: Many IoT devices ship with default passwords and lack robust security
controls.
A. TPM
B. Secure Boot
C. RAID
D. DLP
Explanation: Secure Boot ensures that only trusted software is loaded during startup.
A. DLP
B. Full Disk Encryption (FDE)
C. Tokenization
D. RAID
Explanation: FDE protects data stored on a device, especially if the device is lost or stolen.
A. Antivirus software
B. Full Disk Encryption
C. Patch management
D. Network segmentation
Explanation: FDE ensures that data remains inaccessible without proper authentication.
218. Which process ensures systems receive updates that address security vulnerabilities?
A. Vulnerability scanning
B. Patch management
C. Threat hunting
D. Data classification
220. Which concept describes the ability of systems to continue operating despite attacks or
failures?
A. Availability
B. Integrity
C. Resilience
D. Confidentiality
Answer: C. Resilience
221. Which assessment type verifies that systems comply with internal policies and external
regulations?
A. Penetration testing
B. Vulnerability scanning
C. Compliance assessment
D. Threat hunting
Answer: B. A temporary control that provides equivalent protection when the preferred
control cannot be implemented
223. Which security principle denies all access unless explicitly permitted?
A. Need to Know
B. Separation of Duties
C. Implicit Deny
D. Due Care
Explanation: Implicit deny ensures that access is blocked by default and only granted
through specific authorization.
Explanation: Geofencing uses location-based rules to allow or deny access from specific
regions.
225. Which authentication factor category does GPS location belong to?
A. Fingerprint recognition
B. Facial recognition
C. Keystroke dynamics
D. Retina scanning
A. Fingerprint scanning
B. Vein recognition
C. Voice recognition
D. Iris recognition
Explanation: Vein recognition uses infrared light to identify unique vein patterns beneath the
skin.
229. Which attack attempts to exhaust system resources by flooding a service with traffic?
A. SQL Injection
B. DDoS attack
C. Smishing
D. Tailgating
230. Which backup type copies all selected data every time it runs?
A. Incremental backup
B. Differential backup
C. Full backup
D. Snapshot backup
Explanation: Full backups provide complete copies of data but require the most storage and
time.
A. RAID 0
B. RAID 1
C. RAID 5
D. RAID 10
Answer: A. RAID 0
A. RAID 0
B. RAID 1
C. RAID 5
D. RAID 6
Answer: B. RAID 1
Explanation: RAID 1 duplicates data across disks, providing redundancy in case of drive
failure.
233. Which RAID level uses distributed parity and requires a minimum of three disks?
A. RAID 0
B. RAID 1
C. RAID 5
D. RAID 10
Answer: C. RAID 5
Explanation: RAID 5 offers a balance between performance, storage efficiency, and fault
tolerance.
A. RAID 0
B. RAID 1
C. RAID 5
D. RAID 10
Answer: D. RAID 10
A. AAAA
B. MX
C. PTR
D. A
Answer: D. A
A. A
B. MX
C. AAAA
D. PTR
Answer: C. AAAA
Explanation: AAAA records perform the same function as A records but for IPv6 addresses.
237. Which DNS record specifies mail servers responsible for receiving email?
A. TXT
B. PTR
C. MX
D. CNAME
Answer: C. MX
Explanation: Mail Exchange (MX) records identify the mail servers responsible for handling
email for a domain.
238. Which DNS record is commonly used for reverse DNS lookups?
A. A
B. MX
C. PTR
D. TXT
Answer: C. PTR
Explanation: PTR records map IP addresses back to hostnames, often used in email
validation.
239. Which email security technology uses cryptographic signatures to validate message
authenticity?
A. SPF
B. DKIM
C. DMARC
D. TLS
Answer: B. DKIM
240. Which email security technology specifies which mail servers are authorized to send
email on behalf of a domain?
A. SPF
B. DKIM
C. DMARC
D. S/MIME
Answer: A. SPF
Explanation: Sender Policy Framework (SPF) helps prevent email spoofing by identifying
authorized sending servers.
241. Which email security standard uses SPF and DKIM results to determine how to handle
suspicious messages?
A. SMTP
B. DMARC
C. S/MIME
D. DNSSEC
Answer: B. DMARC
Explanation: IOCs are artifacts such as malicious IP addresses, file hashes, or domain names
that indicate potential security incidents.
245. Which framework is commonly used to map adversary behaviors and attack techniques?
A. COBIT
B. PCI DSS
C. MITRE ATT&CK
D. ITIL
A. Behavioral indicator
B. Atomic indicator
C. Computed indicator
D. Sequential indicator
Explanation: Atomic indicators include individual artifacts such as IP addresses, file hashes,
or domain names that can be directly observed.
Explanation: Threat hunting actively searches for indicators of malicious activity that may
have evaded automated detection tools.
248. Which type of malware remains dormant until a specific condition triggers it?
A. Worm
B. Rootkit
C. Logic Bomb
D. Spyware
Explanation: Logic bombs activate when predefined conditions are met, such as a specific
date or user action.
249. Which attack redirects users to malicious websites even when they enter the correct
URL?
A. Smishing
B. Vishing
C. Pharming
D. Tailgating
Answer: C. Pharming
A. Tokenization
B. Segmentation
C. Obfuscation
D. Hashing
Answer: B. Segmentation
Explanation: Segmentation limits the spread of attacks and improves access control.
253. Which security model assumes that no entity should be trusted by default?
A. Defense in Depth
B. Zero Trust
C. Least Privilege
D. Separation of Duties
Explanation: Zero Trust continuously verifies users and devices before granting access.
A. Public Cloud
B. Hybrid Cloud
C. Community Cloud
D. Private Cloud
Explanation: Private clouds provide greater control and customization but often require
higher costs.
255. What is the primary purpose of a CASB (Cloud Access Security Broker)?
A. Replace firewalls
B. Enforce security policies across cloud environments
C. Provide VPN connectivity
D. Manage certificates
Explanation: CASBs provide visibility, compliance enforcement, and data protection for
cloud services.
256. Which testing approach verifies that updates do not introduce unintended issues?
A. Fuzz Testing
B. Penetration Testing
C. Regression Testing
D. Stress Testing
257. Which phase of change management evaluates the risks and impact of proposed
modifications?
A. Approval
B. Assessment
C. Implementation
D. Documentation
Answer: B. Assessment
259. Which forensic principle helps ensure digital evidence is admissible in legal
proceedings?
A. Encryption
B. Chain of Custody
C. Segmentation
D. Tokenization
Answer: B. Chain of Custody
Explanation: Chain of custody documents how evidence was collected, handled, and
transferred to maintain integrity.
260. Malware has been detected on a critical server. What should be done FIRST?
Explanation: Isolation limits the spread of malware and preserves evidence for investigation
and remediation.
261. Which security principle ensures that no single individual has complete control over a
critical process?
A. Least Privilege
B. Job Rotation
C. Separation of Duties
D. Mandatory Vacations
Explanation: Separation of Duties (SoD) divides critical tasks among multiple individuals to
reduce the risk of fraud, errors, and abuse of privileges.
A. Smishing
B. Buffer Overflow
C. Malformed Packet Attack
D. Credential Stuffing
Explanation: Attackers may send specially crafted packets designed to crash services or
exploit weaknesses in packet processing logic.
263. Which technology allows users to authenticate once and access multiple applications?
A. LDAP
B. SSO
C. MFA
D. RADIUS
Answer: B. SSO
A. Tailgating
B. Baiting
C. Impersonation
D. Shoulder Surfing
Answer: C. Impersonation
Explanation: Attackers use impersonation to gain trust and convince victims to reveal
sensitive information.
266. Which physical security control uses electronic credentials to restrict access?
A. Bollards
B. Access Badges
C. Security Guards
D. Motion Sensors
267. Which physical control is designed to stop vehicles from entering restricted areas?
A. CCTV Cameras
B. Access Badges
C. Bollards
D. Turnstiles
Answer: C. Bollards
Explanation: Bollards are physical barriers used to prevent unauthorized vehicle access.
268. Which physical security control detects movement within a secured area?
A. Motion Sensors
B. Locks
C. Security Signage
D. Fencing
Explanation: Motion sensors help identify unauthorized movement and can trigger alarms or
surveillance systems.
269. Which fire suppression system is most appropriate for protecting data centers without
damaging equipment?
Explanation: Clean agent systems suppress fires without leaving residue or damaging
electronic equipment.
270. Which environmental control helps detect excessive heat in server rooms?
A. Humidity Sensors
B. Motion Sensors
C. Temperature Sensors
D. Smoke Detectors
Answer: C. Temperature Sensors
Explanation: Temperature monitoring helps prevent overheating that could damage systems
or cause outages.
271. Which cloud characteristic allows resources to scale automatically based on demand?
A. Segmentation
B. Elasticity
C. Redundancy
D. Obfuscation
Answer: B. Elasticity
272. Which component of the CIA Triad ensures systems and data remain accessible when
needed?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Answer: C. Availability
273. Which component of the CIA Triad protects against unauthorized disclosure of
information?
A. Integrity
B. Confidentiality
C. Availability
D. Accountability
Answer: B. Confidentiality
Explanation: Confidentiality ensures that only authorized individuals can access sensitive
information.
274. What is the purpose of an incident response playbook?
Explanation: Playbooks improve consistency and speed during incident response activities.
A. Discovery
B. Prioritization
C. Reporting
D. Verification
Answer: B. Prioritization
Explanation: Prioritization considers factors such as severity, exploitability, and business
impact.
278. Which assessment method identifies known weaknesses without actively exploiting
them?
A. Penetration Testing
B. Red Team Exercise
C. Vulnerability Scanning
D. Social Engineering Assessment
279. Which security exercise simulates realistic adversary behavior against an organization?
A. Vulnerability Assessment
B. Red Team Exercise
C. Compliance Audit
D. Fuzz Testing
Explanation: Red teams emulate attackers to evaluate detection and response capabilities.
Explanation: Purple Teams facilitate knowledge sharing between Red Teams and Blue
Teams to strengthen defenses.
281. Which document provides evidence that security controls are operating as intended
during audits?
A. Security Metrics
B. Documentation and Audit Records
C. Threat Intelligence Reports
D. Incident Playbooks
Explanation: Documentation such as policies, procedures, access logs, and change records
demonstrates compliance and effective security practices during assessments.
Explanation: MTTD measures the average amount of time required to identify a security
incident after it occurs.
Explanation: MTTR measures how quickly an organization can respond to and recover from
security incidents.
285. What is a major advantage of automation in security operations?
Explanation: Automation reduces response times and minimizes errors in repetitive security
tasks.
Explanation: SOAR platforms integrate tools and automate workflows to improve incident
response efficiency.
Explanation: Baselining helps identify unusual behavior that may indicate security incidents.
Explanation: UEBA analyzes behavior patterns to identify anomalies that may indicate
insider threats or compromised accounts.
289. Which principle ensures that sensitive information is only accessible to authorized
individuals?
A. Availability
B. Confidentiality
C. Integrity
D. Accountability
Answer: B. Confidentiality
290. Which policy defines how employees should properly handle organizational data?
294. Which document often defines security expectations between organizations and
vendors?
296. Which cybersecurity principle assumes that breaches are inevitable and organizations
should prepare accordingly?
A. Defense in Depth
B. Assume Breach
C. Least Privilege
D. Need to Know
A. Authorization
B. Authentication
C. Accounting
D. Federation
Answer: B. Authentication
Explanation: Authentication confirms that users are who they claim to be through
credentials or other factors.
298. Which process determines what actions an authenticated user is permitted to perform?
A. Authentication
B. Accounting
C. Authorization
D. Federation
Answer: C. Authorization
Explanation: Authorization defines permissions and access rights after identity verification.
299. Which process records and tracks user activities within a system?
A. Authentication
B. Authorization
C. Accounting
D. Federation
Answer: C. Accounting
Explanation: Accounting provides audit trails and supports monitoring by recording user
actions and resource usage.
300. Which study approach is MOST effective for preparing for the Security+ exam?