Security+ General Security Concepts: 232 practice questions
12 of the 232 General Security Concepts questions in the Certsqill Security+ bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for Security+? Take the free 5-min readiness check →
1. Issue a charter assigning risk acceptance authority: Which control is managerial?
- Use a daily checklist for site supervisorsA supervisor checklist is an operational control because personnel use it to perform recurring work consistently.
- Install locks on temporary equipment cabinetsCabinet locks are physical controls because they restrict direct access to equipment through a facility mechanism.
- Issue a charter assigning risk acceptance authority ✓A leadership-approved charter is managerial because it establishes governance, accountability, and authority for risk decisions.
- Deploy multifactor authentication for project portalsMultifactor authentication is a technical control that verifies users through technology before granting portal access.
Managerial controls establish governance, accountability, and risk direction; they do not directly enforce access or perform routine work.
2. Install a badge-controlled door with a secured frame: Which control is physical?
- Install a badge-controlled door with a secured frame ✓A badge-controlled door and secured frame physically restrict entry to the protected room.
- Apply network access rules to instrument serversNetwork access rules are technical controls that restrict digital communications, not physical entry into the instrument room.
- Require annual security awareness trainingSecurity awareness training is an operational control that changes personnel behavior through instruction.
- Review camera footage for suspicious activityReviewing footage is primarily a detective activity because personnel examine evidence after or during events.
Physical controls protect facilities or equipment directly through barriers, locks, entry systems, and other tangible mechanisms.
3. Block unauthorized USB storage devices: Which control most directly provides a preventive purpose before copyi
- Block unauthorized USB storage devices ✓Device blocking prevents the risky action before data can be copied to unauthorized removable media.
- Display a warning about removable-media monitoringA warning may deter users by influencing behavior, but it does not directly block the copying action.
- Restore files from a clean backupRestoring files is corrective because it recovers from damage or loss after an adverse event.
- Alert analysts after large transfers occurPost-transfer alerts detect suspicious activity after it occurs rather than preventing the transfer beforehand.
Preventive controls stop or restrict an unwanted event before it occurs, making device blocking the direct response to unauthorized copying.
4. Deploy a tuned SIEM correlation rule: Which control fits?
- Deploy a tuned SIEM correlation rule ✓A SIEM correlation rule analyzes events and alerts analysts about patterns requiring investigation, making it detective.
- Enforce multifactor authentication for agentsMultifactor authentication prevents many unauthorized logins by requiring additional verification before access is granted.
- Post a notice stating that accounts are monitoredA monitoring notice primarily deters misuse by influencing behavior, although it may support transparency.
- Restore affected workstations from trusted imagesRestoring workstations is corrective because it returns systems to a usable state after compromise or damage.
Detective controls identify events or conditions and notify responsible personnel, enabling investigation rather than directly preventing or repairing them.
5. Display prominent signs announcing monitored premises: Which control is best?
- Require a locked reception entranceA locked entrance restricts access, so its primary purpose is prevention rather than discouragement.
- Review access logs each morningReviewing logs detects prior entry activity rather than discouraging an attempt before it occurs.
- Display prominent signs announcing monitored premises ✓Visible warning signs communicate observation and possible consequences, primarily discouraging unauthorized attempts.
- Install cameras monitored continuously by security staffContinuous camera review primarily detects and documents activity, although visible cameras may also deter.
Deterrent controls discourage unwanted behavior by signaling observation, consequences, or resistance before an event occurs.
6. Rebuild systems from the verified backup: Which control most directly restores affected services?
- Add redundancy to the storage clusterStorage redundancy primarily prevents or reduces future outages rather than restoring the already affected service.
- Rebuild systems from the verified backup ✓Rebuilding from a verified backup restores systems after disruption, making this a corrective control.
- Publish a policy requiring backup reviewsA backup review policy is directive and managerial; it establishes expectations rather than performing restoration.
- Alert administrators when storage errors appearStorage alerts are detective controls that identify errors but do not restore affected services.
Corrective controls repair, restore, or otherwise return systems to operation after an incident or failure has occurred.
7. Require access through a monitored privileged gateway: Which control is compensating?
- Create another backup of circulation recordsAdditional backups support availability and recovery but do not compensate for missing authentication protection.
- Replace the legacy application immediatelyReplacing the application implements the preferred capability rather than compensating for an unavoidable control limitation.
- Publish a policy requiring stronger passwordsA password policy directs behavior but does not provide comparable layered access protection by itself.
- Require access through a monitored privileged gateway ✓A monitored gateway substitutes controlled, observable access for unavailable application MFA, satisfying the need through another mechanism.
A compensating control provides an alternative way to meet the security objective when the preferred control cannot be implemented.
8. Review recorded camera footage after reported unauthorized: Which control use most directly meets that objecti
- Review recorded camera footage after reported unauthorized entry. ✓Reviewing recorded footage directly supports identifying unauthorized entry after the event, making the camera detective in purpose.
- Post camera-warning signs at each entrance.Signs may discourage entry, but they do not provide evidence identifying who entered after an incident.
- Require researchers to display identification badges.Badges support authorization decisions, but they do not independently record or identify an unauthorized physical entry.
- Assign guards to watch entrance activity periodically.Periodic observation may detect activity, but inconsistent coverage can miss unauthorized entry between patrols.
Recorded footage reviewed after an event directly supports detection and investigation, whereas signs and badges address different security needs.
9. Technical: Which category should be recorded?
- ManagerialManagerial controls govern security through leadership decisions, risk direction, and oversight rather than automated processing.
- PhysicalPhysical controls protect facilities or tangible assets, while ticket routing operates through software and system logic.
- OperationalOperational controls rely on people and procedures, while this rule executes automatically within an information system.
- Technical ✓An automated software rule is implemented through technology, so its category is technical even when supporting operations.
Because software automatically performs the routing decision, the control is technical regardless of the department using it.
10. Technical: Which implementation category best describes this control?
- OperationalOperational controls depend primarily on personnel or procedures, not an automated endpoint enforcement mechanism.
- Technical ✓Endpoint software automatically enforces the allowlist, making this a technical control despite its logging capability.
- PhysicalPhysical controls use tangible barriers or environmental safeguards, neither of which performs this software-based decision.
- ManagerialManagerial controls establish direction and oversight, but the observed blocking is performed automatically by endpoint software.
Automated endpoint enforcement is technical; the related logging does not change how the primary control is implemented.
11. Managerial: Which implementation category best describes this control?
- OperationalOperational controls are performed through routine procedures, while this board-level governance establishes direction and oversight.
- PhysicalPhysical controls protect tangible spaces or equipment, not organizational authority, responsibilities, and risk acceptance.
- TechnicalTechnical controls enforce requirements through systems, whereas this control establishes organizational direction and accountability.
- Managerial ✓Leadership-approved policies, assigned authority, and risk decisions are governance activities, making this a managerial control.
Board-approved policy and risk authority are managerial controls because they direct governance and accountability.
12. Operational: Which implementation category best describes the procedure?
- TechnicalTechnical controls execute through technology, while this requirement depends on staff following documented review steps.
- Operational ✓A documented process carried out by personnel is an operational control, even when it supports technical access decisions.
- ManagerialManagement may approve the procedure, but personnel performing its defined steps make the control operational.
- PhysicalPhysical controls use tangible protection, whereas this control specifies human review and escalation activities.
Because staff perform the documented review and escalation steps, the control is operational.
220 more General Security Concepts questions
The remaining 220 questions in this domain are part of the full Security+ bank — 1918 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your Security+ readiness — freeOther Security+ domains
- Security Operations — 528 questions →
- Threats, Vulnerabilities, and Mitigations — 425 questions →
- Security Program Management and Oversight — 384 questions →
- Security Architecture — 349 questions →
- All 1918 Security+ questions →