SECURITY Plus Exam Prep Free practice test →

Free SECURITY Plus Practice Questions

10 free, exam-style CompTIA Security+ (SECURITY Plus) practice questions with answers and explanations. No signup required. Work through them below, then take the full free SECURITY Plus practice test to study every exam domain.

Question 1

An organization is implementing Zero Trust architecture. A user requests access to a sensitive database. Which Zero Trust component is responsible for making the actual decision to allow or deny that access?

  1. The Policy Engine
  2. The Policy Enforcement Point
  3. The Policy Administrator
  4. The Implicit Trust Zone
Show answer & explanation

Correct answer: A - The Policy Engine

Question 2

A SIEM analyst notices that a finance employee successfully authenticated to the corporate VPN from New York at 9:00 AM, then authenticated again from Tokyo at 9:15 AM. No travel is recorded in the HR system. Which indicator of compromise does this BEST represent?

  1. Concurrent session usage
  2. An account lockout pattern
  3. Out-of-cycle logging activity
  4. Impossible travel detection
Show answer & explanation

Correct answer: D - Impossible travel detection

Question 3

A startup is choosing between AWS EC2 (IaaS), Azure App Service (PaaS), and Microsoft 365 (SaaS) for different workloads. Which model places the GREATEST share of security responsibility on the customer?

  1. IaaS, because the customer manages the OS upward
  2. PaaS, because the customer manages app and data
  3. SaaS, because the customer accesses the application
  4. All three share security responsibility equally
Show answer & explanation

Correct answer: A - IaaS, because the customer manages the OS upward

Question 4

A network engineer is configuring an IPsec VPN tunnel between two offices. The traffic must be both encrypted in transit and authenticated for integrity. Which IPsec component provides confidentiality, which AH cannot provide on its own?

  1. The Internet Key Exchange (IKE)
  2. The Encapsulating Security Payload (ESP)
  3. The Authentication Header (AH)
  4. A Security Association (SA)
Show answer & explanation

Correct answer: B - The Encapsulating Security Payload (ESP)

Question 5

A user authenticates to the corporate portal by entering their password and then approving a push notification on their authenticator app. Which combination of authentication factors is being used?

  1. Something you know plus something you are
  2. Something you have plus something you are
  3. Something you know plus something you have
  4. Two separate instances of something you know
Show answer & explanation

Correct answer: C - Something you know plus something you have

Question 6

A developer is integrating a third-party application that needs to access a user's calendar data on their behalf, without ever seeing the user's password. Which protocol BEST fits this use case, and how does it differ from OpenID Connect (OIDC)?

  1. OAuth 2.0 - handles authorization (delegated access); OIDC builds on OAuth and adds authentication
  2. OAuth 2.0 - handles authentication; OIDC handles authorization on top of it
  3. SAML - handles delegated access via XML; OIDC uses JSON for the same task
  4. OAuth and OIDC perform identical functions and can be used interchangeably
Show answer & explanation

Correct answer: A - OAuth 2.0 - handles authorization (delegated access); OIDC builds on OAuth and adds authentication

Question 7

An organization configures DMARC with a policy of 'p=reject'. For DMARC to actually reject a forged email, the message must fail authentication checks performed by which two underlying technologies that DMARC builds on?

  1. MX records and PTR records for mail routing
  2. SPF and DKIM for sender authentication
  3. TLS and STARTTLS for transport encryption
  4. DNSSEC and DANE for DNS-layer protection
Show answer & explanation

Correct answer: B - SPF and DKIM for sender authentication

Question 8

A SOC analyst detects active ransomware encrypting files on three workstations. Following CompTIA's incident response process, the team's IMMEDIATE next action is to disconnect the affected hosts from the network. Which IR phase does this action represent?

  1. The Eradication phase
  2. The Recovery phase
  3. The Containment phase
  4. The Lessons Learned phase
Show answer & explanation

Correct answer: C - The Containment phase

Question 9

A risk analyst is calculating the Annualized Loss Expectancy for a server. The server is valued at $200,000. A flood would destroy 25% of its value. Floods occur in this region approximately once every two years. What is the ALE?

  1. $25,000 per year
  2. $50,000 per year
  3. $100,000 per year
  4. $10,000 per year
Show answer & explanation

Correct answer: A - $25,000 per year

Question 10

A company is establishing a long-term relationship with a managed service provider. They expect to issue multiple specific projects to this vendor over several years. They want a single contract that sets the overall terms - pricing, liability, confidentiality, dispute resolution - so each individual project can be authorized quickly without renegotiating those terms. Which document is MOST appropriate?

  1. A Service Level Agreement (SLA)
  2. A Memorandum of Understanding (MOU)
  3. A Statement of Work (SOW)
  4. A Master Service Agreement (MSA)
Show answer & explanation

Correct answer: D - A Master Service Agreement (MSA)

Ready for the real thing?

Practice hundreds more SECURITY Plus questions with instant scoring, weak-area drills, and full exam simulations.

Start the free practice test See pricing