Security+ practice questions: 1918 with full explanations
1918 practice questions for CompTIA Security+, grouped by exam domain. Every question below shows all four options, which one is correct, and why each of the other three is not — the wrong answers are where most candidates lose marks.
Not sure where you stand? Take the free 5-min Security+ readiness check →
Security+ exam format → · Security+ passing score → · Security+ exam cost →
Questions by domain
- Security Operations — 528 questions →
- Threats, Vulnerabilities, and Mitigations — 425 questions →
- Security Program Management and Oversight — 384 questions →
- Security Architecture — 349 questions →
- General Security Concepts — 232 questions →
Sample questions
Document tested secure settings for supported systems: Which control most directly establishes the required ba
A library is establishing a secure baseline for newly issued servers. The security lead has approved the baseline scope, but implementation has not begun. Which control most directly establishes the required baseline?
- Enable multifactor authentication for administrators.Multifactor authentication protects privileged access, but it does not define the server's complete secure configuration baseline.
- Deploy a web application firewall before production release.A web application firewall protects web traffic, but it does not establish host configuration requirements.
- Run static analysis against custom applications.Static analysis examines application code, but it does not establish operating-system settings or service configurations.
- Document tested secure settings for supported systems. ✓A documented, tested set of secure settings directly establishes the approved baseline for supported systems.
The trap
Confuses one access control with establishing a system-wide baseline. Applies an application-development assessment to infrastructure hardening. Selects a perimeter application control instead of defining the baseline.All 528 Security Operations questions →
Apply least privilege and department-based role: Which control directly meets this objective?
A municipal office is reviewing whether clerks can access resident records beyond their assigned departments. There is no confirmed compromise, and the security manager wants to reduce harm from authorized insider misuse. Which control directly meets this objective?
- Require multifactor authentication for every clerk account.Multifactor authentication reduces account takeover but does not limit actions performed by a legitimately authenticated insider.
- Segment public-facing systems from internal resident-record networks.Segmentation can limit lateral movement but does not directly restrict excessive permissions within resident-record applications.
- Apply least privilege and department-based role permissions. ✓Least privilege and department-based roles restrict each clerk to records and functions required for assigned duties, directly reducing insider misuse.
- Create immutable backups so altered resident records can be restored after an incident.Immutable backups support recovery after alteration or deletion but do not prevent an authorized clerk from viewing records.
The trap
Confuses proving identity with restricting an authenticated user’s permissions. Applies a network-boundary control to an authorization problem. Addresses recovery rather than inappropriate access.All 425 Threats, Vulnerabilities, and Mitigations questions →
Publish a security policy stating management’s required: Which control best meets this objective?
A telecommunications provider wants management to declare its organization-wide direction for protecting customer network data. Which control best meets this objective?
- Create a firewall rule restricting administrative traffic.A firewall rule enforces a specific technical restriction, but it does not communicate management direction across the organization.
- Deploy endpoint software that blocks unauthorized configuration changes.Endpoint enforcement can support security objectives, but it does not establish management’s formal direction or accountability.
- Write a procedure describing how administrators review access logs.A procedure provides step-by-step execution details, rather than setting organization-wide management direction or intent.
- Publish a security policy stating management’s required protection objectives. ✓A policy expresses management direction and establishes broad organizational expectations for protecting customer network data.
The trap
Confuses a technical enforcement mechanism with governance direction. Confuses operational instructions with policy. Treats implementation technology as the governance control.All 384 Security Program Management and Oversight questions →
Would you pass Security+ today?
Five minutes, and you get a score per domain — not one number, but which section to open tonight.
Test your Security+ readiness — free
Certsqill Security+ question bank · 1918 questions across 5 domains ·
Every answer, right and wrong, comes with its own explanation.