Security+ Threats, Vulnerabilities, and Mitigations: 425 practice questions
12 of the 425 Threats, Vulnerabilities, and Mitigations questions in the Certsqill Security+ bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for Security+? Take the free 5-min readiness check →
1. Apply least privilege and department-based role: Which control directly meets this objective?
- Require multifactor authentication for every clerk account.Multifactor authentication reduces account takeover but does not limit actions performed by a legitimately authenticated insider.
- Segment public-facing systems from internal resident-record networks.Segmentation can limit lateral movement but does not directly restrict excessive permissions within resident-record applications.
- Apply least privilege and department-based role permissions. ✓Least privilege and department-based roles restrict each clerk to records and functions required for assigned duties, directly reducing insider misuse.
- Create immutable backups so altered resident records can be restored after an incident.Immutable backups support recovery after alteration or deletion but do not prevent an authorized clerk from viewing records.
Least privilege and role permissions limit what authorized insiders can access.
2. Use threat intelligence to prioritize targeted defensive: Which control most directly supports that objective?
- Replace all employee passwords every thirty days.Frequent password changes do not specifically detect espionage and may create weak reuse or predictable password behaviors.
- Use threat intelligence to prioritize targeted defensive monitoring. ✓Threat intelligence helps identify relevant nation-state patterns and focus monitoring on likely espionage techniques and targets.
- Require annual security awareness training for all employees.Awareness training can reduce user-driven attacks, but it is less direct against persistent, resourceful external espionage.
- Install additional badge readers at telecommunications facilities.Badge readers strengthen physical access control, but the described exposure involves external reconnaissance of sensitive information.
Threat intelligence focuses defensive monitoring on capable actors and espionage-relevant behavior.
3. Maintain tested: Which control most directly supports recovery from this financially motivated attack?
- Add security awareness posters near warehouse workstations.Posters may improve awareness, but they provide limited recovery value after systems have already been encrypted.
- Maintain tested, offline, immutable backups of shipping data. ✓Offline immutable backups provide recoverable copies that ransomware cannot easily alter or encrypt with production systems.
- Require stronger badge authentication at loading docks.Physical authentication can restrict dock access, but it does not restore data or address ransomware encryption directly.
- Deploy endpoint detection and response agents.Endpoint detection may identify malicious activity, but it does not by itself restore encrypted warehouse systems.
Tested offline and immutable backups directly enable recovery from financially motivated ransomware.
4. Use DDoS protection and traffic scrubbing for public: Which control most directly addresses the likely hacktiv
- Use DDoS protection and traffic scrubbing for public services. ✓DDoS protection and scrubbing preserve service availability against disruption, matching the likely hacktivist objective.
- Encrypt confidential source code stored in development systems.Encryption protects confidentiality of source code, but does not directly maintain availability of public services during flooding.
- Increase retention of employee security-training records.Training records support governance and awareness measurement, but they do not mitigate deliberate public-service disruption.
- Require privileged developers to use hardware security keys.Hardware keys strengthen privileged authentication, but do not absorb or filter distributed availability attacks.
DDoS protection directly targets hacktivist disruption of public-facing services.
5. Use cloud access security controls to discover and govern: Which control most directly reduces this shadow IT
- Install additional cameras near support-center workstations.Cameras may deter physical misuse but do not provide visibility into cloud accounts or sharing policies.
- Require annual privacy training for support representatives.Training may influence behavior but does not discover or govern unmanaged services handling customer documents.
- Create local backup copies of every customer document.Local copies may aid availability but increase duplication without controlling where employees upload sensitive documents.
- Use cloud access security controls to discover and govern unsanctioned services. ✓Cloud access security controls provide visibility and policy enforcement for unapproved services and sensitive-data use.
Cloud access security controls discover and govern unapproved services and their data use.
6. Independently verify unusual payment changes through: Which control is most direct?
- Require employees to complete quarterly phishing awareness modules.Training helps users recognize suspicious messages, but does not provide reliable transaction verification for urgent account changes.
- Independently verify unusual payment changes through a trusted channel. ✓Independent verification prevents fraudulent account changes even when an attacker convincingly impersonates a customer or executive.
- Block all external email attachments at the gateway.Attachment blocking may reduce malware delivery, but does not independently validate payment-account change requests.
- Encrypt all payment-request messages before delivery.Encryption protects message confidentiality, but cannot prove that the requester or destination account is legitimate.
Independent verification through a trusted channel directly counters payment impersonation and business email compromise.
7. Preserve evidence: Which action is best?
- Publicly name the suspected group because the tool matches its activity.A tool association alone cannot establish actor identity and could create inaccurate public claims.
- Replace the workstation immediately and discard it without collecting additional evidence.Replacement may destroy useful forensic evidence and does not establish whether the alert represents compromise.
- Temporarily isolate the workstation pending validation.Temporary containment may be appropriate, but isolation alone does not address the need to preserve evidence and assess attribution.
- Preserve evidence, correlate independent indicators, and defer attribution. ✓Evidence preservation and corroboration support proportionate defensive decisions without treating one alert as conclusive actor attribution.
Preserve evidence and corroborate indicators before attributing activity.
8. Provide targeted data-handling training: Which control most directly reduces recurrence of this negligent insi
- Deploy a second internet firewall at the laboratory perimeter.Additional perimeter filtering may block some traffic, but does not correct employee understanding or distinguish approved storage reliably.
- Provide targeted data-handling training. ✓Targeted training corrects the outdated procedure and helps employees recognize approved handling requirements before repeating the mistake.
- Create an isolated backup copy of the experimental dataset.Backups support recovery from loss, but do not stop employees from uploading data to unauthorized personal storage.
- Require biometric access to every research room.Biometrics strengthen physical entry controls, but do not prevent an authorized employee from mishandling data online.
Targeted training directly corrects the procedural mistake behind the negligent upload.
9. Investigate, preserve evidence, and communicate: Which action is best?
- Block every public tool associated with criminal activity across library systems.Broad blocking may disrupt legitimate operations and cannot reliably distinguish benign use from malicious activity.
- Assume the named group caused the event and notify the media.A public accusation based on a shared technique is unsupported and could misdirect response or damage credibility.
- Ignore the alert until attribution is confirmed.Uncertain attribution does not eliminate potential risk; the library should investigate and apply proportionate defensive measures.
- Investigate, preserve evidence, and communicate attribution uncertainty. ✓Investigation and evidence preservation support a useful response while acknowledging that a shared technique cannot establish actor identity.
Investigate and preserve evidence while communicating attribution uncertainty.
10. Malicious insider: What threat category best describes the observed context?
- Accidental insiderAn accidental insider mishandles information unintentionally, whereas copying restricted files before resignation suggests purposeful behavior.
- Compromised accountA compromised account remains possible, but the evidence does not establish unauthorized takeover or malware involvement.
- External attackerAn external attacker lacks the employee’s authorized access and does not best explain the observed internal handling.
- Malicious insider ✓An authorized user deliberately copying restricted files represents a malicious-insider context, although investigators should still verify intent and facts.
Authorized access and apparently deliberate copying indicate a malicious-insider context.
11. Strategic espionage: Which actor motive is most likely?
- Accidental disclosureAccidental disclosure does not explain persistence, custom tooling, or deliberate targeting of strategic designs.
- Strategic espionage ✓Long-term collection of strategic research aligns with nation-state espionage objectives rather than immediate financial gain.
- Ideological publicityIdeological actors generally seek attention or disruption, not quiet sustained acquisition of proprietary research.
- Ransom demandRansom activity primarily seeks payment by restricting or threatening access, which is not described here.
Patient collection of strategic intellectual property and persistence most strongly indicate nation-state espionage motivation.
12. Organized financial crime: Which actor motivation best fits this pattern?
- Unskilled experimentationUnskilled actors may use available tools, but this pattern provides stronger evidence of organized financial motivation.
- Organized financial crime ✓Credential sales, billing-data access, and payment demands collectively indicate coordinated financially motivated criminal activity.
- Ideological protestIdeological protest normally seeks a political message or disruption, not repeated credential monetization and payment demands.
- Strategic intelligence collectionIntelligence collection seeks information or advantage, whereas this activity directly monetizes stolen access.
Credential monetization and payment demands are characteristic of organized financial crime rather than espionage or ideology.
413 more Threats, Vulnerabilities, and Mitigations questions
The remaining 413 questions in this domain are part of the full Security+ bank — 1918 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your Security+ readiness — freeOther Security+ domains
- Security Operations — 528 questions →
- Security Program Management and Oversight — 384 questions →
- Security Architecture — 349 questions →
- General Security Concepts — 232 questions →
- All 1918 Security+ questions →