Security+ Threats, Vulnerabilities practice questions
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

Security+ Threats, Vulnerabilities, and Mitigations: 425 practice questions

Security+ 425 questions 12 shown free

12 of the 425 Threats, Vulnerabilities, and Mitigations questions in the Certsqill Security+ bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for Security+? Take the free 5-min readiness check →

1. Apply least privilege and department-based role: Which control directly meets this objective?

Easy
A municipal office is reviewing whether clerks can access resident records beyond their assigned departments. There is no confirmed compromise, and the security manager wants to reduce harm from authorized insider misuse. Which control directly meets this objective?
  1. Require multifactor authentication for every clerk account.
    Multifactor authentication reduces account takeover but does not limit actions performed by a legitimately authenticated insider.
  2. Segment public-facing systems from internal resident-record networks.
    Segmentation can limit lateral movement but does not directly restrict excessive permissions within resident-record applications.
  3. Apply least privilege and department-based role permissions.
    Least privilege and department-based roles restrict each clerk to records and functions required for assigned duties, directly reducing insider misuse.
  4. Create immutable backups so altered resident records can be restored after an incident.
    Immutable backups support recovery after alteration or deletion but do not prevent an authorized clerk from viewing records.
The trap
Confuses proving identity with restricting an authenticated user’s permissions. Applies a network-boundary control to an authorization problem. Addresses recovery rather than inappropriate access.

Least privilege and role permissions limit what authorized insiders can access.

2. Use threat intelligence to prioritize targeted defensive: Which control most directly supports that objective?

Medium
A telecommunications provider handles sensitive infrastructure plans and has observed carefully timed reconnaissance from several external addresses. The security team has not proven the actor's identity, but leadership wants to reduce exposure to a well-resourced espionage campaign. Which control most directly supports that objective?
  1. Replace all employee passwords every thirty days.
    Frequent password changes do not specifically detect espionage and may create weak reuse or predictable password behaviors.
  2. Use threat intelligence to prioritize targeted defensive monitoring.
    Threat intelligence helps identify relevant nation-state patterns and focus monitoring on likely espionage techniques and targets.
  3. Require annual security awareness training for all employees.
    Awareness training can reduce user-driven attacks, but it is less direct against persistent, resourceful external espionage.
  4. Install additional badge readers at telecommunications facilities.
    Badge readers strengthen physical access control, but the described exposure involves external reconnaissance of sensitive information.
The trap
It treats a sophisticated campaign primarily as a routine user-awareness problem. It assumes routine password rotation is the primary defense against every advanced actor. It selects a physical control without evidence that facility entry is the attack path.

Threat intelligence focuses defensive monitoring on capable actors and espionage-relevant behavior.

3. Maintain tested: Which control most directly supports recovery from this financially motivated attack?

Medium
A warehouse's shipping systems were encrypted after an intrusion, and the attacker demanded payment. The organization has isolated affected servers and confirmed that recent recovery copies are available. Which control most directly supports recovery from this financially motivated attack?
  1. Add security awareness posters near warehouse workstations.
    Posters may improve awareness, but they provide limited recovery value after systems have already been encrypted.
  2. Maintain tested, offline, immutable backups of shipping data.
    Offline immutable backups provide recoverable copies that ransomware cannot easily alter or encrypt with production systems.
  3. Require stronger badge authentication at loading docks.
    Physical authentication can restrict dock access, but it does not restore data or address ransomware encryption directly.
  4. Deploy endpoint detection and response agents.
    Endpoint detection may identify malicious activity, but it does not by itself restore encrypted warehouse systems.
The trap
It confuses detection of ransomware with recovery after successful encryption. It treats a completed destructive event as primarily an awareness deficiency. It selects a physical access control for an information recovery requirement.

Tested offline and immutable backups directly enable recovery from financially motivated ransomware.

4. Use DDoS protection and traffic scrubbing for public: Which control most directly addresses the likely hacktiv

Medium
A software company expects an online protest campaign after releasing a controversial product feature. Security staff have received public warnings of service disruption, but no data theft has been confirmed. Which control most directly addresses the likely hacktivist objective?
  1. Use DDoS protection and traffic scrubbing for public services.
    DDoS protection and scrubbing preserve service availability against disruption, matching the likely hacktivist objective.
  2. Encrypt confidential source code stored in development systems.
    Encryption protects confidentiality of source code, but does not directly maintain availability of public services during flooding.
  3. Increase retention of employee security-training records.
    Training records support governance and awareness measurement, but they do not mitigate deliberate public-service disruption.
  4. Require privileged developers to use hardware security keys.
    Hardware keys strengthen privileged authentication, but do not absorb or filter distributed availability attacks.
The trap
It addresses possible data exposure rather than the stated disruption objective. It applies an account-protection control to a service-availability threat. It confuses administrative evidence with an active availability defense.

DDoS protection directly targets hacktivist disruption of public-facing services.

5. Use cloud access security controls to discover and govern: Which control most directly reduces this shadow IT

Medium
A support center discovers employees creating accounts on unapproved cloud file-sharing services to exchange customer documents. No malicious intent is established, but the services are unmanaged and lack approved retention settings. Which control most directly reduces this shadow IT exposure?
  1. Install additional cameras near support-center workstations.
    Cameras may deter physical misuse but do not provide visibility into cloud accounts or sharing policies.
  2. Require annual privacy training for support representatives.
    Training may influence behavior but does not discover or govern unmanaged services handling customer documents.
  3. Create local backup copies of every customer document.
    Local copies may aid availability but increase duplication without controlling where employees upload sensitive documents.
  4. Use cloud access security controls to discover and govern unsanctioned services.
    Cloud access security controls provide visibility and policy enforcement for unapproved services and sensitive-data use.
The trap
Assumes education alone provides visibility and enforcement. Treats shadow IT as a physical-surveillance issue. Confuses data redundancy with governance of unmanaged services.

Cloud access security controls discover and govern unapproved services and their data use.

6. Independently verify unusual payment changes through: Which control is most direct?

Medium
A telecommunications provider receives an email requesting an urgent change to a major customer's payment account. The request uses familiar branding, but the sender's address is slightly unusual. The security manager's immediate objective is to reduce financially motivated payment fraud. Which control is most direct?
  1. Require employees to complete quarterly phishing awareness modules.
    Training helps users recognize suspicious messages, but does not provide reliable transaction verification for urgent account changes.
  2. Independently verify unusual payment changes through a trusted channel.
    Independent verification prevents fraudulent account changes even when an attacker convincingly impersonates a customer or executive.
  3. Block all external email attachments at the gateway.
    Attachment blocking may reduce malware delivery, but does not independently validate payment-account change requests.
  4. Encrypt all payment-request messages before delivery.
    Encryption protects message confidentiality, but cannot prove that the requester or destination account is legitimate.
The trap
It focuses on files when the immediate risk is impersonated payment instructions. It treats education as a substitute for an independent business process. It confuses private communication with authenticating a transaction request.

Independent verification through a trusted channel directly counters payment impersonation and business email compromise.

7. Preserve evidence: Which action is best?

Easy
A municipal office sees one alert showing a tool commonly associated with an advanced threat group on a public workstation. No matching logins, persistence, or data transfer are confirmed. The incident manager wants to avoid unsupported attribution while improving defensive decisions. Which action is best?
  1. Publicly name the suspected group because the tool matches its activity.
    A tool association alone cannot establish actor identity and could create inaccurate public claims.
  2. Replace the workstation immediately and discard it without collecting additional evidence.
    Replacement may destroy useful forensic evidence and does not establish whether the alert represents compromise.
  3. Temporarily isolate the workstation pending validation.
    Temporary containment may be appropriate, but isolation alone does not address the need to preserve evidence and assess attribution.
  4. Preserve evidence, correlate independent indicators, and defer attribution.
    Evidence preservation and corroboration support proportionate defensive decisions without treating one alert as conclusive actor attribution.
The trap
Treats containment as a substitute for investigation. Assumes a shared tool proves attribution. Prioritizes disposal over preservation and validation.

Preserve evidence and corroborate indicators before attributing activity.

8. Provide targeted data-handling training: Which control most directly reduces recurrence of this negligent insi

Medium
A research laboratory employee accidentally uploads experimental data to a personal storage account after following an outdated procedure. The employee reports the mistake immediately, and no malicious intent is indicated. Which control most directly reduces recurrence of this negligent insider event?
  1. Deploy a second internet firewall at the laboratory perimeter.
    Additional perimeter filtering may block some traffic, but does not correct employee understanding or distinguish approved storage reliably.
  2. Provide targeted data-handling training.
    Targeted training corrects the outdated procedure and helps employees recognize approved handling requirements before repeating the mistake.
  3. Create an isolated backup copy of the experimental dataset.
    Backups support recovery from loss, but do not stop employees from uploading data to unauthorized personal storage.
  4. Require biometric access to every research room.
    Biometrics strengthen physical entry controls, but do not prevent an authorized employee from mishandling data online.
The trap
It applies a broad network control to a documented procedural error. It confuses facility access with safe information-handling behavior. It addresses availability rather than recurrence of negligent disclosure.

Targeted training directly corrects the procedural mistake behind the negligent upload.

9. Investigate, preserve evidence, and communicate: Which action is best?

Easy
A library's monitoring platform flags traffic resembling a known criminal group's technique, but the same tool is publicly available and no account, host, or data-transfer evidence links it to that group. The security lead wants a defensible response. Which action is best?
  1. Block every public tool associated with criminal activity across library systems.
    Broad blocking may disrupt legitimate operations and cannot reliably distinguish benign use from malicious activity.
  2. Assume the named group caused the event and notify the media.
    A public accusation based on a shared technique is unsupported and could misdirect response or damage credibility.
  3. Ignore the alert until attribution is confirmed.
    Uncertain attribution does not eliminate potential risk; the library should investigate and apply proportionate defensive measures.
  4. Investigate, preserve evidence, and communicate attribution uncertainty.
    Investigation and evidence preservation support a useful response while acknowledging that a shared technique cannot establish actor identity.
The trap
Treats lack of actor certainty as proof that the event is harmless. Converts an indicator into conclusive attribution. Assumes tool identity alone determines intent and requires an impractical universal response.

Investigate and preserve evidence while communicating attribution uncertainty.

10. Malicious insider: What threat category best describes the observed context?

Easy
A university employee with authorized access copies restricted research files to a personal drive shortly before resignation. No malware or external compromise is confirmed. What threat category best describes the observed context?
  1. Accidental insider
    An accidental insider mishandles information unintentionally, whereas copying restricted files before resignation suggests purposeful behavior.
  2. Compromised account
    A compromised account remains possible, but the evidence does not establish unauthorized takeover or malware involvement.
  3. External attacker
    An external attacker lacks the employee’s authorized access and does not best explain the observed internal handling.
  4. Malicious insider
    An authorized user deliberately copying restricted files represents a malicious-insider context, although investigators should still verify intent and facts.
The trap
Confuses suspicious activity by an authorized user with activity originating outside the organization. Treats all insider activity as accidental without considering apparent intent. Assumes account compromise from suspicious behavior alone.

Authorized access and apparently deliberate copying indicate a malicious-insider context.

11. Strategic espionage: Which actor motive is most likely?

Medium
A software company finds carefully timed access to unpublished product designs, custom tooling, and attempts to remain persistent for months. The activity targets strategic research rather than immediate payment. Which actor motive is most likely?
  1. Accidental disclosure
    Accidental disclosure does not explain persistence, custom tooling, or deliberate targeting of strategic designs.
  2. Strategic espionage
    Long-term collection of strategic research aligns with nation-state espionage objectives rather than immediate financial gain.
  3. Ideological publicity
    Ideological actors generally seek attention or disruption, not quiet sustained acquisition of proprietary research.
  4. Ransom demand
    Ransom activity primarily seeks payment by restricting or threatening access, which is not described here.
The trap
Focuses on a common cybercrime outcome despite evidence emphasizing intelligence collection. Confuses covert intelligence collection with hacktivist publicity. Treats coordinated collection indicators as an unintentional business error.

Patient collection of strategic intellectual property and persistence most strongly indicate nation-state espionage motivation.

12. Organized financial crime: Which actor motivation best fits this pattern?

Medium
An engineering firm receives repeated messages offering stolen credentials for cryptocurrency. Several accounts are then used to access billing data, followed by demands for payment. Which actor motivation best fits this pattern?
  1. Unskilled experimentation
    Unskilled actors may use available tools, but this pattern provides stronger evidence of organized financial motivation.
  2. Organized financial crime
    Credential sales, billing-data access, and payment demands collectively indicate coordinated financially motivated criminal activity.
  3. Ideological protest
    Ideological protest normally seeks a political message or disruption, not repeated credential monetization and payment demands.
  4. Strategic intelligence collection
    Intelligence collection seeks information or advantage, whereas this activity directly monetizes stolen access.
The trap
Mistakes visible disruption or messaging for financially motivated account abuse. Overweights unauthorized access without considering the clear financial objective. Uses apparent simplicity to dismiss the demonstrated monetization pattern.

Credential monetization and payment demands are characteristic of organized financial crime rather than espionage or ideology.

413 more Threats, Vulnerabilities, and Mitigations questions

The remaining 413 questions in this domain are part of the full Security+ bank — 1918 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your Security+ readiness — free

Other Security+ domains

Part of the Certsqill Security+ question bank · Threats, Vulnerabilities, and Mitigations · Every answer, right and wrong, comes with its own explanation.