Security+: 1918 practice questions with explanations
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

Security+ practice questions: 1918 with full explanations

5 domains 1918 questions 90 min exam

1918 practice questions for CompTIA Security+, grouped by exam domain. Every question below shows all four options, which one is correct, and why each of the other three is not — the wrong answers are where most candidates lose marks.

Not sure where you stand? Take the free 5-min Security+ readiness check →

Security+ exam format →  ·  Security+ passing score →  · Security+ exam cost →

Questions by domain

Sample questions

Document tested secure settings for supported systems: Which control most directly establishes the required ba

Security Operations Medium
A library is establishing a secure baseline for newly issued servers. The security lead has approved the baseline scope, but implementation has not begun. Which control most directly establishes the required baseline?
  1. Enable multifactor authentication for administrators.
    Multifactor authentication protects privileged access, but it does not define the server's complete secure configuration baseline.
  2. Deploy a web application firewall before production release.
    A web application firewall protects web traffic, but it does not establish host configuration requirements.
  3. Run static analysis against custom applications.
    Static analysis examines application code, but it does not establish operating-system settings or service configurations.
  4. Document tested secure settings for supported systems.
    A documented, tested set of secure settings directly establishes the approved baseline for supported systems.
The trap
Confuses one access control with establishing a system-wide baseline. Applies an application-development assessment to infrastructure hardening. Selects a perimeter application control instead of defining the baseline.

All 528 Security Operations questions →

Apply least privilege and department-based role: Which control directly meets this objective?

Threats, Vulnerabilities, and Mitigations Easy
A municipal office is reviewing whether clerks can access resident records beyond their assigned departments. There is no confirmed compromise, and the security manager wants to reduce harm from authorized insider misuse. Which control directly meets this objective?
  1. Require multifactor authentication for every clerk account.
    Multifactor authentication reduces account takeover but does not limit actions performed by a legitimately authenticated insider.
  2. Segment public-facing systems from internal resident-record networks.
    Segmentation can limit lateral movement but does not directly restrict excessive permissions within resident-record applications.
  3. Apply least privilege and department-based role permissions.
    Least privilege and department-based roles restrict each clerk to records and functions required for assigned duties, directly reducing insider misuse.
  4. Create immutable backups so altered resident records can be restored after an incident.
    Immutable backups support recovery after alteration or deletion but do not prevent an authorized clerk from viewing records.
The trap
Confuses proving identity with restricting an authenticated user’s permissions. Applies a network-boundary control to an authorization problem. Addresses recovery rather than inappropriate access.

All 425 Threats, Vulnerabilities, and Mitigations questions →

Publish a security policy stating management’s required: Which control best meets this objective?

Security Program Management and Oversight Easy
A telecommunications provider wants management to declare its organization-wide direction for protecting customer network data. Which control best meets this objective?
  1. Create a firewall rule restricting administrative traffic.
    A firewall rule enforces a specific technical restriction, but it does not communicate management direction across the organization.
  2. Deploy endpoint software that blocks unauthorized configuration changes.
    Endpoint enforcement can support security objectives, but it does not establish management’s formal direction or accountability.
  3. Write a procedure describing how administrators review access logs.
    A procedure provides step-by-step execution details, rather than setting organization-wide management direction or intent.
  4. Publish a security policy stating management’s required protection objectives.
    A policy expresses management direction and establishes broad organizational expectations for protecting customer network data.
The trap
Confuses a technical enforcement mechanism with governance direction. Confuses operational instructions with policy. Treats implementation technology as the governance control.

All 384 Security Program Management and Oversight questions →

Would you pass Security+ today?

Five minutes, and you get a score per domain — not one number, but which section to open tonight.

Test your Security+ readiness — free
Certsqill Security+ question bank · 1918 questions across 5 domains · Every answer, right and wrong, comes with its own explanation.