General Security Concepts
268 questions
An organization is updating its enterprise risk management framework and classifying its existing defense mechanisms according to CompTIA Security+ control categories. The Chief Information Security Officer (CISO) requests an inventory of all Managerial (Administrative) controls currently implemented across the company. Which of the following defense mechanisms qualify as Managerial controls? (Select TWO.)
Select all that apply
Following an internal audit that identified unauthorized workstation software modifications, an enterprise security team deploys an automated configuration management tool. This software continuously monitors workstation configuration files against an established baseline and automatically restores any modified settings back to their approved baseline state. Which of the following best classifies this security control according to CompTIA Security+ category and functional type definitions?
Match each enterprise security implementation to its primary CompTIA Security+ classification by category and functional type.
Click a left item, then click its matching right item
Items
Matches
An enterprise security administrator is establishing a Public Key Infrastructure (PKI) key lifecycle policy for employee S/MIME email certificates. The policy specifies that private keys associated with email encryption certificates must be backed up to a key escrow agent, whereas private keys associated with digital signature certificates are strictly prohibited from key escrow. Which of the following best explains the security rationale for prohibiting key escrow on digital signature private keys?
A security architect is deploying TLS certificates for three newly established internal microservices hosted on distinct domain structures: identity.corp.local, billing.corp.internal, and api.corp.com. To simplify management, the architect intends to issue a single digital certificate that will be trusted and valid across all three different fully qualified domain names. Which of the following configuration options should the security architect specify during certificate generation to achieve this goal?
An enterprise organization is replacing its legacy perimeter-based defenses with a Zero Trust Architecture (ZTA) across its internal API microservices. Currently, services authenticate once at session initiation and receive unrestricted inter-service communication permissions across the internal subnet. Which design change must the security team implement to adhere to core Zero Trust principles?
An enterprise organization is modernizing its security framework by implementing Zero Trust Architecture (ZTA) principles across its hybrid multi-cloud infrastructure. To validate the deployment, the lead security architect must map foundational Zero Trust principles to their specific technical operational mechanisms. Match each Zero Trust Architecture principle on the left with its correct technical implementation mechanism on the right.
Click a left item, then click its matching right item
Items
Matches
A security architecture team is designing an active defense strategy to detect threat actors performing lateral movement within a cloud-hybrid network. The team specifically wants to plant decoy authentication credentials into workstation memory and local caches so that any credential dumping attempt immediately generates high-fidelity alerts without exposing production directory services. Which of the following deception technologies best fulfills this operational requirement?
A security engineer is updating the cryptographic configuration of an internal API gateway to enhance session transport security. The new security baseline requires providing Perfect Forward Secrecy (PFS) for key establishment and guaranteeing message authentication and integrity for incoming payload headers. Which TWO cryptographic mechanisms or algorithms should the security engineer implement to satisfy these requirements?
Select all that apply
An enterprise security architect is auditing a remote access workflow designed for external software developers. Under the proposed model, after a developer successfully completes multi-factor authentication (MFA) at the edge gateway, their endpoint is assigned an IP address on the internal development network segment. From that point forward, the session maintains open access to all internal repository servers and staging databases without requiring further authentication or posture checks until disconnect. Which of the following best evaluates this architecture against Zero Trust Architecture (ZTA) principles and identifies the necessary architectural remediation?
An organization implements digital signatures for all high-value financial transactions to ensure that executives cannot deny approving a transaction after it has been submitted. Which security goal is primarily being addressed by this implementation?
A healthcare organization requires that when physicians approve electronic prescription orders, the system must generate proof of origin so that a physician cannot later deny authorizing the order. To accomplish this, the system applies a digital signature using the physician's private key combined with a cryptographic hash of the order details. Which security concept is directly fulfilled by implementing digital signatures to prevent denial of origin?
An enterprise security team is transitioning network operations to align with Zero Trust Architecture (ZTA) principles. Which of the following statements accurately describes a fundamental principle of access control within Zero Trust?
Match each core security goal or concept on the left with its primary operational objective on the right.
Click a left item, then click its matching right item
Items
Matches
A financial software firm secures its system log repository by encrypting log files with AES-256 and generating an HMAC-SHA256 checksum for each entry using a shared secret key accessible by all system administrators. During an investigation into an unauthorized privilege escalation, a senior administrator is suspected of editing log lines to erase evidence. The administrator claims that another employee with administrative credentials must have altered the logs using the shared key. Which security property is currently lacking in the firm's audit system that prevents proving which specific administrator committed the modification?
An enterprise API gateway receives automated configuration updates from external vendors. To satisfy auditing requirements, security policies dictate that the system must establish indisputable proof of origin for every payload, ensuring vendors cannot deny sending a specific update. The system architects propose utilizing SHA-256 hashing paired with pre-shared symmetric keys (HMAC) between the gateway and each vendor. Which security goal remains unfulfilled by this proposed architecture, and why?
Match each enterprise security technical implementation to the specific security pillar or concept it primarily satisfies.
Click a left item, then click its matching right item
Items
Matches
An enterprise logistics company requires software engineers to digitally sign all infrastructure configuration files using their individual asymmetric private keys before pushing them to the automated build pipeline. If an unapproved configuration change causes a service outage, management must be able to indisputably prove which specific engineer authored and submitted the change. Which security principle is primarily fulfilled by this implementation?
A software distribution platform requires package maintainers to cryptographically sign all published updates. This ensures that a maintainer cannot later deny having created and released a specific update package. Which of the following security concepts is best demonstrated by this requirement?
An industrial smart grid operator manages several automated telemetry, control, and audit subsystems. Match each operational security scenario on the left with the primary CIA triad pillar or related security objective that is either violated or enforced on the right.
Click a left item, then click its matching right item
Items
Matches