Security+ Security Operations: 528 practice questions
12 of the 528 Security Operations questions in the Certsqill Security+ bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for Security+? Take the free 5-min readiness check →
1. Document tested secure settings for supported systems: Which control most directly establishes the required ba
- Enable multifactor authentication for administrators.Multifactor authentication protects privileged access, but it does not define the server's complete secure configuration baseline.
- Deploy a web application firewall before production release.A web application firewall protects web traffic, but it does not establish host configuration requirements.
- Run static analysis against custom applications.Static analysis examines application code, but it does not establish operating-system settings or service configurations.
- Document tested secure settings for supported systems. ✓A documented, tested set of secure settings directly establishes the approved baseline for supported systems.
A tested, documented set of secure settings establishes the configuration baseline that later deployments must follow.
2. Deploy the tested hardened image through change control: Which action best satisfies the deployment objective?
- Scan production servers for application vulnerabilities first.Vulnerability scanning provides evidence, but it does not deploy the already tested configuration.
- Require developers to review every operating-system setting.Developer review may add insight, but it is not a controlled mechanism for deploying an approved server baseline.
- Place a web application firewall in front of each server.A web application firewall filters application traffic, but it does not deploy host hardening settings.
- Deploy the tested hardened image through change control. ✓Deploying the validated image through approved change control moves the tested baseline into production safely.
The tested hardened image should be deployed using the approved change process.
3. Disable the unused service after confirming dependencies: What should the administrator do first?
- Perform static analysis of the office’s source code.Static analysis examines software code, but it does not address an enabled infrastructure service with no business purpose.
- Add multifactor authentication to every user account.Multifactor authentication improves identity assurance, but it does not remove exposure from an unnecessary listening service.
- Disable the unused service after confirming dependencies. ✓Disabling an unnecessary service reduces attack surface after confirming that no legitimate process depends on it.
- Place the server behind a web application firewall.A web application firewall may protect web traffic, but it does not directly disable an unrelated file-transfer service.
An unused service should be disabled after dependency confirmation because removal directly reduces the server’s attack surface.
4. Limit each workstation to administration and approved: Which control most directly hardens these privileged wo
- Use standard accounts for routine daily activity.Standard accounts reduce routine privilege, but they do not isolate privileged administration from browsing and email exposure.
- Limit each workstation to administration and approved management tools. ✓Restricting these systems to administrative functions removes unnecessary browsing and email exposure from privileged sessions.
- Place an additional firewall between workstations and directory servers.Network filtering can limit connections, but it does not stop users from browsing or reading email on privileged systems.
- Install endpoint detection and response software on each workstation.Endpoint detection improves visibility and response, but it does not prevent risky general-purpose activity on privileged systems.
Privileged workstations should be limited to administrative functions and approved tools.
5. Suppress public banners and verbose errors: Which control is most appropriate?
- Deploy a web application firewall for inbound requests.A web application firewall may filter attacks, but it does not reliably remove verbose banners and error details.
- Enable multifactor authentication for developers.Multifactor authentication protects accounts, but it does not change information disclosed by server responses.
- Suppress public banners and verbose errors; retain internal logs. ✓Changing exposed server settings directly reduces public information while preserving diagnostic evidence for authorized staff.
- Run dynamic analysis against the production application.Dynamic analysis can assess running behavior, but it is not the direct configuration change needed to suppress disclosures.
Suppress public banners and verbose errors while retaining internal diagnostic logging.
6. Apply vendor-tested settings during the approved: Which action should the security team take first?
- Expose the controller to the internet for remote monitoring.Internet exposure increases risk and is unrelated to safely applying an approved industrial configuration.
- Apply vendor-tested settings during the approved maintenance window. ✓Using vendor-tested settings during an approved window reduces security risk while respecting operational availability constraints.
- Replace the controller with a newer model before changing settings.Replacement may be costly and unnecessary when approved hardening settings can be applied within a planned window.
- Force an immediate reboot to install generic hardening settings.An immediate reboot may disrupt production and ignores the controller’s vendor-specific operational requirements.
Apply the vendor-tested baseline during the planned maintenance window to balance hardening and operational availability.
7. Deploy mobile device management with enforced policies: Which control best meets all three requirements?
- Require users to install endpoint detection software.Endpoint detection may monitor threats, but it does not centrally enforce mobile settings or provide complete device administration.
- Create a separate wireless network for student tablets.Network separation limits connectivity, but it does not manage applications, screen locks, or lost-device response.
- Encrypt only the district’s wireless traffic.Wireless encryption protects data in transit, but it does not enforce device settings or enable remote wipe.
- Deploy mobile device management with enforced policies. ✓MDM centrally enforces settings and applications while supporting administrative actions such as remote wiping.
MDM centrally enforces mobile settings and applications and supports remote-wipe administration.
8. Use a managed work container with selective wipe: Which control best fits this BYOD requirement?
- Use a managed work container with selective wipe. ✓A managed work container separates business data and permits selective wiping while preserving personal content.
- Provide a corporate-owned phone to every employee.Corporate ownership may simplify control, but it changes the stated ownership model instead of protecting existing personal devices.
- Require employees to use only the office wireless network.Restricting network location does not remove business data from a lost personal phone or protect it while offsite.
- Require a full-device wipe whenever a phone is lost.A full-device wipe removes personal content and ignores the privacy requirement associated with personal ownership.
A managed work container with selective wipe protects corporate data while respecting personal-device ownership.
9. COPE with full MDM enrollment: Which policy model and control combination is most appropriate?
- Personal-use-only devices with network segmentation.Restricting personal use conflicts with the stated allowance and network segmentation does not manage device settings or wiping.
- BYOD with optional antivirus installation.BYOD describes personal ownership and optional antivirus does not provide centralized administrative control.
- CYOD with employee-controlled security settings.CYOD offers approved device choices, but employee-controlled settings conflict with the organization’s ownership and management requirement.
- COPE with full MDM enrollment. ✓COPE describes corporate ownership with personal use, while MDM provides centralized policy and lost-device management.
Corporate ownership with permitted personal use is COPE, and MDM supplies centralized device management.
10. Selective work-data wipe: Which control should administrators use?
- Selective work-data wipe ✓A selective wipe removes managed organizational data while preserving personal content, matching the library’s privacy and separation requirement.
- Full-device remote wipeA full wipe removes organizational and personal content, exceeding the stated requirement and creating unnecessary privacy impact.
- Application allowlistingAllowlisting limits approved applications but does not remove existing organizational data from a departing user’s device.
- Factory reset after departureA factory reset erases the entire tablet and does not selectively preserve the staff member’s personal photos.
Selective wipe removes managed work data without erasing personal content, unlike a factory reset or full remote wipe.
11. Conduct a wireless site survey: Which activity should come first?
- Create a wireless heat map from collected measurementsA heat map visualizes measured signal conditions, but surveying collects the measurements initially.
- Configure centralized enterprise wireless authentication servicesEnterprise authentication identifies users through centralized services but does not measure radio coverage or interference patterns.
- Conduct a wireless site survey ✓A site survey measures signal strength, interference, and environmental conditions needed for informed access-point placement.
- Enable WPA3WPA3 strengthens wireless protection but does not reveal physical coverage gaps, interference, or access-point placement needs.
A wireless site survey gathers radio measurements before deployment; heat maps present those measurements afterward.
12. Wireless heat map: Which deliverable is most appropriate?
- WPA3 configurationWPA3 configuration improves wireless protection but does not visualize measured signal strength or coverage boundaries.
- Certificate validationCertificate validation helps prevent authentication-server impersonation but does not represent wireless signal measurements.
- Wireless heat map ✓A heat map converts survey measurements into a visual representation of signal strength, coverage, and overlap.
- AAA server policyAAA policy manages authentication and authorization but does not display physical wireless coverage or interference.
A wireless heat map visualizes collected survey data so engineers can evaluate coverage and access-point overlap.
516 more Security Operations questions
The remaining 516 questions in this domain are part of the full Security+ bank — 1918 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your Security+ readiness — freeOther Security+ domains
- Threats, Vulnerabilities, and Mitigations — 425 questions →
- Security Program Management and Oversight — 384 questions →
- Security Architecture — 349 questions →
- General Security Concepts — 232 questions →
- All 1918 Security+ questions →