All practice questions
2232 questions
A financial institution is restructuring its cybersecurity governance framework to resolve ambiguities between executive mandates, operational requirements, and administrative duties. The Chief Information Security Officer (CISO) must clearly delineate the legal enforceability of document types and role responsibilities across the organization. Which of the following statements accurately characterize governance structures and policy hierarchy principles within an enterprise security framework? (Select TWO.)
Select all that apply
A logistics firm plans to contract a third-party software vendor to manage its real-time route optimization platform. Prior to completing vendor onboarding, the security manager requires verifiable proof that the vendor's security controls have operated effectively throughout a sustained six-month evaluation period. Which of the following third-party documentation types best fulfills this requirement?
A security architect is establishing cryptographic standards for an enterprise API service. The service requirements specify that past session communications must remain secure even if the server's long-term private key is compromised in the future. Additionally, incoming API requests must provide proof of origin and data integrity that cannot be denied by the sender. Which of the following cryptographic mechanisms should the architect implement to satisfy these security requirements? (Select TWO).
Select all that apply
A cloud services enterprise performs a Business Impact Analysis (BIA) for its core payment settlement microservice. The assessment establishes that data loss exceeding 15 minutes will cause catastrophic financial reconciliation errors, and overall system outage cannot exceed 4 hours before regulatory non-compliance fines occur. The engineering team deploys asynchronous database replication operating on a 5-minute sync interval and an automated failover system capable of restoring full application functionality within 30 minutes. Which statement correctly evaluates this technical recovery architecture against the established BIA metrics?
A security operations team is responding to a newly disclosed critical remote code execution vulnerability impacting enterprise database servers. To ensure operational stability while mitigating risk, what is the correct chronological sequence of steps the team should perform during this emergency patch deployment workflow?
Drag items to arrange them in the correct order
A healthcare technology company hosts its multi-tenant application on a cloud service provider's infrastructure. To satisfy client enterprise compliance requirements, the company must provide an independent auditor's report verifying that its security controls protecting customer data were appropriately designed and operated effectively throughout the preceding 12-month period. Which of the following compliance deliverables best satisfies this requirement?
A security analyst receives a high-severity report from an unauthenticated network-based vulnerability scan indicating that several internal Linux servers are susceptible to a critical remote code execution vulnerability in OpenSSL. However, local patch management logs confirm that all vendor-issued security updates were applied earlier that week. Which of the following is the most appropriate action for the analyst to take to verify whether the servers are genuinely vulnerable?
Match each enterprise security incident scenario on the left with the corresponding social engineering attack vector or technique on the right.
Click a left item, then click its matching right item
Items
Matches
A security administrator discovers that members of the financial operations team are being targeted by fraudulent wire transfer requests disguised as emails from executive leadership. Which of the following represents the most effective human risk management control to mitigate this threat?
An organization updates its enterprise defense baseline to satisfy compliance requirements. As part of this initiative, the security team deploys an inline Network Intrusion Prevention System (NIPS) to automatically drop unauthorized network traffic, and publishes an updated Acceptable Use Policy (AUP) mandating clean desk and screen lock procedures for all staff members.
Which of the following statements correctly classify these security controls according to CompTIA Security+ categories and functional types? (Select TWO.)
Select all that apply
Match each regulatory framework or standard to its primary compliance mandate.
Click a left item, then click its matching right item
Items
Matches
Match each Business Impact Analysis (BIA) metric or continuity planning parameter with its corresponding operational description.
Click a left item, then click its matching right item
Items
Matches
Match each security audit, assessment, or attestation deliverable with its primary operational scope and objective.
Click a left item, then click its matching right item
Items
Matches
Following an application security review, a Chief Information Security Officer (CISO) discovers that engineering teams are utilizing inconsistent cryptographic configurations across microservices. To resolve this, the CISO needs to issue a mandatory document that establishes explicit, uniform technical requirements—such as requiring AES-256 for data at rest and TLS 1.3 for data in transit—without specifying step-by-step execution workflows or platform-specific OS images. Which governance document type should the CISO publish to meet these requirements?
An enterprise security team discovers that several Linux application servers frequently deviate from established security baselines following system maintenance. Local administrators have been making manual configuration edits directly on production instances to resolve immediate service issues, bypassing the organization's deployment pipeline. Which of the following strategies best addresses this configuration drift while ensuring all future changes adhere to baseline security standards?
During a security monitoring shift, an analyst reviews the following alert log snippet generated by a perimeter Network Intrusion Detection System (NIDS) inspecting traffic directed at an internal web application server:
[ALERT] 2026-07-27 14:12:08 UTC - NIDS-Rule-90421
Src: 198.51.100.44:48210 -> Dst: 172.16.10.15:443
Payload snippet: POST /catalog/search HTTP/1.1
Body: item=widget' UNION SELECT username, password_hash FROM user_credentials--
Based on this alert payload and monitoring data, which of the following correctly identifies the attack type and the appropriate analyst action?
During a disaster recovery simulation for a financial institution's core transaction system, a database storage array failure occurred. Technical teams completed failover operations and declared the transaction service operational hours after the initial outage. Transaction records were restored from log backups up to minutes prior to the failure. The organization's Business Impact Analysis (BIA) established a Recovery Time Objective (RTO) of hours, a Recovery Point Objective (RPO) of minutes, and a Maximum Tolerable Downtime (MTD) of hours. Based on these operational recovery metrics, which assessment accurately describes the outcome of this exercise?
A company is enhancing its human risk management efforts to better prepare employees against social engineering threats. Which of the following initiatives directly support an effective security awareness program? (Select TWO.)
Select all that apply
A medical imaging clinic based in the United States plans to migrate its patient diagnostic archives to a third-party cloud storage and analytics platform. The archives contain sensitive Protected Health Information (PHI). Before transmitting any data to the cloud service provider, which mandatory legal agreement or compliance instrument must the chief information security officer (CISO) execute to satisfy Health Insurance Portability and Accountability Act (HIPAA) regulatory requirements?
An organization is evaluating its third-party risk management governance framework to ensure proper compliance, software oversight, and vendor auditability. Match each third-party documentation artifact or agreement to its primary security function.
Click a left item, then click its matching right item
Items
Matches