Security+ General Security Concepts: 232 practice questions
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

Security+ General Security Concepts: 232 practice questions

Security+ 232 questions 12 shown free

12 of the 232 General Security Concepts questions in the Certsqill Security+ bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for Security+? Take the free 5-min readiness check →

1. Issue a charter assigning risk acceptance authority: Which control is managerial?

Medium
A construction business has completed a preliminary risk inventory. Senior leadership now needs a control that establishes who may accept risks and approve treatment decisions. Which control is managerial?
  1. Use a daily checklist for site supervisors
    A supervisor checklist is an operational control because personnel use it to perform recurring work consistently.
  2. Install locks on temporary equipment cabinets
    Cabinet locks are physical controls because they restrict direct access to equipment through a facility mechanism.
  3. Issue a charter assigning risk acceptance authority
    A leadership-approved charter is managerial because it establishes governance, accountability, and authority for risk decisions.
  4. Deploy multifactor authentication for project portals
    Multifactor authentication is a technical control that verifies users through technology before granting portal access.
The trap
Confuses an access-enforcement mechanism with organizational governance. Confuses procedural execution with management oversight. Confuses physical protection with managerial direction.

Managerial controls establish governance, accountability, and risk direction; they do not directly enforce access or perform routine work.

2. Install a badge-controlled door with a secured frame: Which control is physical?

Easy
A research laboratory has completed a facility risk assessment and must prevent unauthorized visitors from entering a restricted instrument room. Which control is physical?
  1. Install a badge-controlled door with a secured frame
    A badge-controlled door and secured frame physically restrict entry to the protected room.
  2. Apply network access rules to instrument servers
    Network access rules are technical controls that restrict digital communications, not physical entry into the instrument room.
  3. Require annual security awareness training
    Security awareness training is an operational control that changes personnel behavior through instruction.
  4. Review camera footage for suspicious activity
    Reviewing footage is primarily a detective activity because personnel examine evidence after or during events.
The trap
Confuses logical access with facility access. Confuses personnel education with a physical barrier. Confuses surveillance detection with direct entry prevention.

Physical controls protect facilities or equipment directly through barriers, locks, entry systems, and other tangible mechanisms.

3. Block unauthorized USB storage devices: Which control most directly provides a preventive purpose before copyi

Medium
A manufacturing company has identified unauthorized removable-media copying as a current risk. Which control most directly provides a preventive purpose before copying occurs?
  1. Block unauthorized USB storage devices
    Device blocking prevents the risky action before data can be copied to unauthorized removable media.
  2. Display a warning about removable-media monitoring
    A warning may deter users by influencing behavior, but it does not directly block the copying action.
  3. Restore files from a clean backup
    Restoring files is corrective because it recovers from damage or loss after an adverse event.
  4. Alert analysts after large transfers occur
    Post-transfer alerts detect suspicious activity after it occurs rather than preventing the transfer beforehand.
The trap
Confuses detective alerting with preventive enforcement. Confuses recovery after harm with prevention before harm. Confuses deterrence with technical prevention.

Preventive controls stop or restrict an unwanted event before it occurs, making device blocking the direct response to unauthorized copying.

4. Deploy a tuned SIEM correlation rule: Which control fits?

Medium
A support center has completed log collection and baseline tuning. Analysts now need a control that identifies suspicious authentication patterns and produces alerts for investigation. Which control fits?
  1. Deploy a tuned SIEM correlation rule
    A SIEM correlation rule analyzes events and alerts analysts about patterns requiring investigation, making it detective.
  2. Enforce multifactor authentication for agents
    Multifactor authentication prevents many unauthorized logins by requiring additional verification before access is granted.
  3. Post a notice stating that accounts are monitored
    A monitoring notice primarily deters misuse by influencing behavior, although it may support transparency.
  4. Restore affected workstations from trusted images
    Restoring workstations is corrective because it returns systems to a usable state after compromise or damage.
The trap
Confuses preventive access enforcement with detection. Confuses remediation with detection. Confuses deterrence with alert generation.

Detective controls identify events or conditions and notify responsible personnel, enabling investigation rather than directly preventing or repairing them.

5. Display prominent signs announcing monitored premises: Which control is best?

Hard
A small accounting firm has completed a physical security review. The owner wants a visible control whose primary purpose is discouraging unauthorized people from attempting entry. Which control is best?
  1. Require a locked reception entrance
    A locked entrance restricts access, so its primary purpose is prevention rather than discouragement.
  2. Review access logs each morning
    Reviewing logs detects prior entry activity rather than discouraging an attempt before it occurs.
  3. Display prominent signs announcing monitored premises
    Visible warning signs communicate observation and possible consequences, primarily discouraging unauthorized attempts.
  4. Install cameras monitored continuously by security staff
    Continuous camera review primarily detects and documents activity, although visible cameras may also deter.
The trap
Confuses retrospective detection with deterrence. Confuses a physical barrier with a warning. Confuses the primary detective function with a secondary deterrent effect.

Deterrent controls discourage unwanted behavior by signaling observation, consequences, or resistance before an event occurs.

6. Rebuild systems from the verified backup: Which control most directly restores affected services?

Medium
A university has completed containment after a storage failure and confirmed that a recent backup is clean. Which control most directly restores affected services?
  1. Add redundancy to the storage cluster
    Storage redundancy primarily prevents or reduces future outages rather than restoring the already affected service.
  2. Rebuild systems from the verified backup
    Rebuilding from a verified backup restores systems after disruption, making this a corrective control.
  3. Publish a policy requiring backup reviews
    A backup review policy is directive and managerial; it establishes expectations rather than performing restoration.
  4. Alert administrators when storage errors appear
    Storage alerts are detective controls that identify errors but do not restore affected services.
The trap
Confuses future prevention with present correction. Confuses detection with restoration. Confuses governance with corrective recovery.

Corrective controls repair, restore, or otherwise return systems to operation after an incident or failure has occurred.

7. Require access through a monitored privileged gateway: Which control is compensating?

Easy
A library's legacy circulation application cannot support multifactor authentication. The security manager must provide comparable protection without replacing the application this year. Which control is compensating?
  1. Create another backup of circulation records
    Additional backups support availability and recovery but do not compensate for missing authentication protection.
  2. Replace the legacy application immediately
    Replacing the application implements the preferred capability rather than compensating for an unavoidable control limitation.
  3. Publish a policy requiring stronger passwords
    A password policy directs behavior but does not provide comparable layered access protection by itself.
  4. Require access through a monitored privileged gateway
    A monitored gateway substitutes controlled, observable access for unavailable application MFA, satisfying the need through another mechanism.
The trap
Confuses the primary control with a substitute control. Confuses directive guidance with compensating enforcement. Confuses resilience for authentication control substitution.

A compensating control provides an alternative way to meet the security objective when the preferred control cannot be implemented.

8. Review recorded camera footage after reported unauthorized: Which control use most directly meets that objecti

Hard
A research laboratory has installed cameras at restricted specimen-room entrances. The security manager’s explicit objective is to identify unauthorized entry after an incident, not merely discourage visitors. Which control use most directly meets that objective?
  1. Review recorded camera footage after reported unauthorized entry.
    Reviewing recorded footage directly supports identifying unauthorized entry after the event, making the camera detective in purpose.
  2. Post camera-warning signs at each entrance.
    Signs may discourage entry, but they do not provide evidence identifying who entered after an incident.
  3. Require researchers to display identification badges.
    Badges support authorization decisions, but they do not independently record or identify an unauthorized physical entry.
  4. Assign guards to watch entrance activity periodically.
    Periodic observation may detect activity, but inconsistent coverage can miss unauthorized entry between patrols.
The trap
Confuses a deterrent purpose with the stated detective objective. Treats an access-control measure as equivalent to post-event detection. Assumes intermittent operational observation provides continuous evidence.

Recorded footage reviewed after an event directly supports detection and investigation, whereas signs and badges address different security needs.

9. Technical: Which category should be recorded?

Easy
A support center wants to classify its new automated ticket-routing rule by implementation category for its control inventory. The rule evaluates ticket metadata and automatically assigns requests to queues. Which category should be recorded?
  1. Managerial
    Managerial controls govern security through leadership decisions, risk direction, and oversight rather than automated processing.
  2. Physical
    Physical controls protect facilities or tangible assets, while ticket routing operates through software and system logic.
  3. Operational
    Operational controls rely on people and procedures, while this rule executes automatically within an information system.
  4. Technical
    An automated software rule is implemented through technology, so its category is technical even when supporting operations.
The trap
Confuses the business process supported by the rule with its implementation category. Mistakes organizational ownership for the control’s actual implementation. Applies a facility-oriented category to an electronic process.

Because software automatically performs the routing decision, the control is technical regardless of the department using it.

10. Technical: Which implementation category best describes this control?

Medium
A school district’s security review finds that endpoint software automatically blocks execution of applications absent from an approved allowlist. The system records blocked attempts for later review. Which implementation category best describes this control?
  1. Operational
    Operational controls depend primarily on personnel or procedures, not an automated endpoint enforcement mechanism.
  2. Technical
    Endpoint software automatically enforces the allowlist, making this a technical control despite its logging capability.
  3. Physical
    Physical controls use tangible barriers or environmental safeguards, neither of which performs this software-based decision.
  4. Managerial
    Managerial controls establish direction and oversight, but the observed blocking is performed automatically by endpoint software.
The trap
Uses policy ownership instead of the mechanism performing the action. Confuses routine administration with the control’s implementation category. Treats the protected laptops as the control rather than the enforcing mechanism.

Automated endpoint enforcement is technical; the related logging does not change how the primary control is implemented.

11. Managerial: Which implementation category best describes this control?

Medium
A library’s board approves a formal risk-management policy that assigns security responsibilities, establishes review authority, and requires annual risk acceptance decisions. Which implementation category best describes this control?
  1. Operational
    Operational controls are performed through routine procedures, while this board-level governance establishes direction and oversight.
  2. Physical
    Physical controls protect tangible spaces or equipment, not organizational authority, responsibilities, and risk acceptance.
  3. Technical
    Technical controls enforce requirements through systems, whereas this control establishes organizational direction and accountability.
  4. Managerial
    Leadership-approved policies, assigned authority, and risk decisions are governance activities, making this a managerial control.
The trap
Confuses a policy’s security subject with technology that might later enforce it. Mistakes recurring review activity for the governing control itself. Associates library facilities with a control that is actually governance-based.

Board-approved policy and risk authority are managerial controls because they direct governance and accountability.

12. Operational: Which implementation category best describes the procedure?

Easy
A university security office requires staff to follow a documented procedure for manually reviewing privileged-access requests before fulfillment. The procedure specifies reviewers, escalation steps, and recordkeeping. Which implementation category best describes the procedure?
  1. Technical
    Technical controls execute through technology, while this requirement depends on staff following documented review steps.
  2. Operational
    A documented process carried out by personnel is an operational control, even when it supports technical access decisions.
  3. Managerial
    Management may approve the procedure, but personnel performing its defined steps make the control operational.
  4. Physical
    Physical controls use tangible protection, whereas this control specifies human review and escalation activities.
The trap
Confuses approval or oversight with the control’s day-to-day implementation. Treats the request system as the control instead of the manual process. Applies a facility category to a personnel-driven approval process.

Because staff perform the documented review and escalation steps, the control is operational.

220 more General Security Concepts questions

The remaining 220 questions in this domain are part of the full Security+ bank — 1918 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your Security+ readiness — free

Other Security+ domains

Part of the Certsqill Security+ question bank · General Security Concepts · Every answer, right and wrong, comes with its own explanation.