All practice questions
2232 questions
A security analyst is reviewing the transport layer cryptographic configuration for a high-security financial microservice. The service requirements dictate that even if an adversary compromises the server's long-term private key in the future, previously intercepted session traffic must remain unencrypted and unreadable. Which cryptographic mechanism should be implemented to satisfy this requirement?
During a routine compliance audit, a security team discovers that network edge firewalls across several branch offices frequently deviate from approved hardening standards. Investigation reveals that local technicians frequently perform out-of-band emergency modifications to resolve service outages, which are never synchronized back to the central repository. Which of the following technical and procedural controls should the security team implement to resolve configuration drift and ensure ongoing baseline compliance? (Select TWO.)
Select all that apply
A Chief Information Security Officer (CISO) at a global logistics firm is updating the corporate cybersecurity governance framework to clarify the enforceability of various security documents. Which of the following governance document types establish MANDATORY compliance requirements that enterprise personnel must follow? (Select TWO)
Select all that apply
A security analyst at a financial institution is conducting a vendor risk assessment for a prospective software-as-a-service (SaaS) human resources platform. The vendor provides a SOC 1 Type II report to demonstrate financial reporting integrity. However, the analyst must verify the operational effectiveness of the vendor's data encryption, system availability, and confidentiality controls over the past 12 months. Which attestation deliverable should the analyst request from the vendor?
A biotechnology firm operates an automated gene-sequencing platform with an estimated Asset Value () of . Security analysts assess that a major malware incident would result in an Exposure Factor () of . Threat intelligence estimates the Annual Rate of Occurrence () for such an incident to be (once every 5 years). What is the expected Annual Loss Expectancy () associated with this risk?
An enterprise organization is updating its software supply chain oversight procedures. To prevent vulnerable open-source dependencies from entering its production environment, the security team requires third-party software providers to submit a formal, machine-readable inventory detailing all sub-components, libraries, and module versions included in their software releases. Which of the following artifacts should the security administrator mandate from vendors to satisfy this requirement?
A security engineer is updating the organization's cryptographic policy to cover emerging operational scenarios including IoT deployments, cloud analytics, secure password storage, and covert communication detection. Match each cryptographic concept on the left with its primary operational characteristic or security use case on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise facility installs biometric fingerprint readers on all access doors leading into its main server room to explicitly prevent unauthorized personnel from physically touching server hardware. How should the security team classify this access mechanism based on CompTIA Security+ control category and functional type definitions?
Following an infrastructure update, a security team conducts an external unauthenticated vulnerability scan against an enterprise web server. The report highlights several critical kernel vulnerabilities based on the software version header returned by the web service. However, host-based agent logs confirm the operating system was fully patched, and the service header was intentionally customized for version obfuscation. Which of the following best accounts for the high-severity findings in the external scan report?
An enterprise cloud service provider assesses a critical customer database system with an estimated Asset Value () of . Quantitative risk analysis indicates that an unmitigated database security breach has an Annual Rate of Occurrence () of and results in an Annual Loss Expectancy () of . What is the Exposure Factor (), expressed as a percentage, for this potential security incident?
An enterprise security risk manager for a municipal smart grid utility is finalizing Business Impact Analysis (BIA) parameters and recovery strategies for two key systems: the real-time SCADA control network and the customer metering telemetry database. Which of the following statements accurately characterize the operational metrics or recovery dependencies established during this assessment? (Select TWO.)
Select all that apply
A security analyst is investigating a multi-vector social engineering campaign targeting an organization's accounting department. The incident report highlights two distinct activities: first, an attacker placed a direct phone call to a payroll clerk, posing as an executive and demanding an immediate wire transfer; second, several accountants received SMS text messages on their corporate mobile devices containing links to a fraudulent login page designed to harvest credentials. Which of the following social engineering attack vectors were executed during this campaign? (Select TWO.)
Select all that apply
A network security monitoring sensor positioned at a cloud perimeter captures the following HTTP payload in a triggered NIDS alert log:
http
POST /api/v1/auth/login HTTP/1.1
Host: portal.example.com
Content-Type: application/x-www-form-urlencoded
Content-Length: 46
user=admin%27%20OR%20%271%27%3D%271&pass=secret
The NIDS rule signature incorrectly labeled the alert as a generic client-side scripting event. Which of the following correctly identifies the actual threat vector represented by this payload and its primary objective?
An enterprise security team is establishing formal documentation for employee mobile devices connecting to the corporate network. Management mandates a technical document that defines enforced minimum security parameters, including mandatory AES-256 storage encryption, minimum operating system patch levels, and a mandatory 12-character passcode length. Which type of security governance document should be published to enforce these mandatory minimum technical configurations?
An organization wants to reduce employee vulnerability to social engineering attacks where attackers impersonate internal IT support over the phone to collect passwords. Which of the following procedures should be emphasized during security awareness training to best mitigate this risk?
A security operations team is preparing to remediate a newly disclosed critical vulnerability affecting enterprise application servers. In what order should the team execute the patch management lifecycle steps from first to last?
Drag items to arrange them in the correct order
An organization is updating its credential storage architecture to protect user account passwords against offline precomputed table attacks. System analysis reveals that many users select identical plaintext passwords, which currently results in identical stored hash values within the credential database. Which of the following cryptographic techniques should the security administrator implement to ensure that identical passwords produce distinct stored hashes?
An enterprise security team is auditing organizational controls against the CompTIA Security+ framework. Match each implemented security control on the left to its corresponding dual-axis classification (Control Category / Functional Type) on the right.
Click a left item, then click its matching right item
Items
Matches
A municipal water authority operates a SCADA telemetry gateway with an Asset Value () of . A quantitative risk assessment identifies that an unmitigated malware attack carries an Exposure Factor () of with an estimated Annual Rate of Occurrence () of . The CISO is evaluating an industrial endpoint monitoring control that costs annually to deploy, which would reduce the Exposure Factor () to . What is the net annual financial benefit of implementing this security control?
An enterprise chief information security officer (CISO) is aligning the organization's global compliance baseline against sector-specific legal mandates and privacy extension standards. Match each compliance framework or regulation to its primary operational mandate.
Click a left item, then click its matching right item
Items
Matches