wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Security+

Total questions: 98

Worksheet time: 1hrs 2mins

Name
Class
Date
1.

The most important aspect of maintaining the chain of custody is:

a)

Documentation

b)

Security

c)

Access control

d)

Labeling

2.

How can technical debt affect long-term security issues?

a)

By increasing the risk of vulnerabilities

b)

By reducing the need for security updates

c)

By eliminating security concerns

d)

By ensuring complete security

3.

UTM (Unified Threat Management) consolidates multiple security functions into a single appliance. Which of the following is NOT typically included?

a)

Firewall

b)

Antivirus

c)

Data Backup

d)

Intrusion Detection

4.

Who is responsible for setting data access policies and security requirements?

a)

Data Analyst

b)

System Administrator

c)

Data Owner

d)

Network Engineer

5.

The role of a data owner is to:

a)

manage and protect data assets

b)

write code for data processing

c)

design user interfaces

d)

conduct market research

6.

What is the responsibility of a data controller?

a)

To manage and process personal data on behalf of the data subject

b)

To determine the purposes and means of processing personal data

c)

To ensure the security of the data processing environment

d)

To provide data subjects with access to their personal data

7.

Who collects employee information in the context of data processing?

a)

Human Resources Department

b)

IT Department

c)

Finance Department

d)

Marketing Department

8.

The role of a data processor is to:

a)

store data

b)

process data

c)

delete data

d)

create data

9.

The responsibility of a data custodian is to:

a)

Manage data access and security

b)

Create data models

c)

Analyze data trends

d)

Develop software applications

10.

Probability in the context of risk events is defined as:

a)

The likelihood of an event occurring

b)

The impact of an event

c)

The cost associated with an event

d)

The time taken for an event to occur

11.

Likelihood in risk assessment measures:

a)

the probability of an event occurring

b)

the impact of an event

c)

the cost of an event

d)

the duration of an event

12.

The exposure factor (EF) in a security incident is:

a)

a measure of the potential loss from a threat

b)

a method to prevent security breaches

c)

a type of encryption algorithm

d)

a security protocol for data transmission

13.

What does severity ranking determine in risk management?

a)

The likelihood of a risk occurring

b)

The impact of a risk on project objectives

c)

The priority of addressing a risk

d)

The cost associated with a risk

14.

Data espionage is:

a)

a form of cybercrime involving the theft of confidential information

b)

a type of data analysis technique

c)

a method of data storage

d)

a way to protect data from unauthorized access

15.

The purpose of due diligence in vendor appraisal is to:

a)

Evaluate the vendor's financial stability and reputation

b)

Negotiate better pricing terms

c)

Establish a long-term partnership

d)

Improve product quality

16.

How does ticket creation aid in automation and orchestration?

a)

By providing a manual process for tracking issues

b)

By enabling automated workflows and task management

c)

By requiring human intervention for every step

d)

By complicating the orchestration process

17.

A responsibility matrix is:

a)

a tool used to assign tasks and responsibilities to team members

b)

a chart that shows the hierarchy of an organization

c)

a document that outlines the project timeline

d)

a list of project stakeholders

18.

Risk tolerance in an organization refers to:

a)

The level of risk an organization is willing to accept.

b)

The amount of risk an organization can eliminate.

c)

The strategies used to avoid risk.

d)

The process of identifying risks.

19.

Fill in the blank: Risk appetite represents the organization's overall attitude towards (a)   .

20.

What is 'Risk threshold' in the context of organizational risk management?

a)

A specific point at which risk becomes unacceptable

b)

A measure of the likelihood of a risk occurring

c)

A strategy to mitigate risks

d)

A tool for assessing risk impact

21.

In a Reflected DDoS attack, the victim's IP is used for:

a)

initiating the attack

b)

receiving the attack

c)

spoofing the source

d)

amplifying the traffic

22.

An Amplified DDoS attack exploits a server by:

a)

overloading it with a high volume of traffic using amplification techniques.

b)

hacking into the server and stealing data.

c)

installing malware on the server.

d)

redirecting traffic to a different server.

23.

The purpose of 'Key escrow' in cryptographic systems is to:

a)

allow recovery of encrypted data by authorized parties

b)

enhance encryption strength

c)

provide faster encryption

d)

reduce the cost of encryption

24.

PKI stands for Public Key Infrastructure. What is its purpose?

a)

To encrypt data

b)

To manage digital certificates and public-key encryption

c)

To provide internet access

d)

To store passwords

25.

Fill in the blank: Federation allows different organizations to share digital identities, enabling single (a)   across them.

26.

The role of 'Continuous integration' in security teams is to:

a)

automate code testing and deployment

b)

manage team communications

c)

handle customer support

d)

design user interfaces

27.

EAP stands for ______ and its function is to provide support to employees.

a)

Employee Assistance Program

b)

Enterprise Application Platform

c)

Emergency Action Plan

d)

Electronic Authentication Protocol

28.

Fill in the blank: LDAP is mainly used for user directory querying and (a)   .

29.

The purpose of the SPF (Sender Policy Framework) in email security is to:

a)

Authenticate the sender's IP address to prevent email spoofing.

b)

Encrypt the email content for privacy.

c)

Filter spam emails based on content.

d)

Provide a backup for email data.

30.

What does SPF check in an email?

a)

Content of the email

b)

Sending server IP

c)

Header From address

31.

How does DKIM ensure the integrity of an email?

a)

By encrypting the email content

b)

By adding a digital signature to the email header

c)

By requiring a password to open the email

d)

By scanning the email for viruses

32.

The role of DMARC in email security is to:

a)

Authenticate email senders and prevent email spoofing

b)

Encrypt email content for privacy

c)

Filter spam emails

d)

Provide end-to-end email encryption

33.

Which protocol uses asymmetric encryption to verify the sender's identity?

a)

SPF

b)

DKIM

c)

DMARC

34.

What happens if an email fails the DMARC check?

a)

The email is delivered to the inbox.

b)

The email is marked as spam.

c)

The email is rejected or quarantined.

d)

The email is forwarded to the recipient.

35.

What is the purpose of the SPF protocol?

(a)  

36.

Which protocol ensures email integrity?

(a)  

37.

What does DMARC enhance?

(a)  

38.

What is the key function of S/MIME?

(a)  

39.

What does RTO stand for?

(a)  

40.

What is the definition of MTBF?

(a)  

41.

Which protocol is used for sending emails?

(a)  

42.

What is the communication flow for IMAP?

(a)  

43.

What is the purpose of POP3 in email communication?

a)

Sending emails

b)

Retrieving emails

c)

Encrypting emails

44.

Fill in the blank: POP3 is used when you want to store emails locally and access from a (a)   .

45.

What is the example use of a Public Key?

a)

Decrypt message

b)

Encrypt a message

c)

Create a digital signature

46.

Fill in the blank: Logical segmentation segments a larger network into distinct units, improving traffic management and (a)   .

47.

What does Software-defined networking (SDN) focus on?

a)

Segmenting networks

b)

Centralizing network control

c)

Encrypting data

48.

Fill in the blank: Containerization encapsulates applications and their environments but does not pertain to network (a)   .

49.

What is the purpose of log aggregation?

a)

Encrypting data

b)

Collecting and normalizing log data

c)

Segmenting networks

50.

Fill in the blank: E-discovery focuses on the systematic search of electronic data to identify pieces of evidence that can be produced in a (a)   context.

51.

What is the function of Telnet?

a)

Allows user to remotely access and control another computer through a text-based interface

b)

Allows send and receive emails

c)

Translate IPs to human-readable names.

52.

Which protocol uses port number 25?

a)

A) Telnet

b)

B) Simple Mail Transfer Protocol (SMTP)

c)

C) Domain Name System (DNS)

53.

Fill in the blank: Domain Name System (DNS) translates IPs to (a)   .

54.

What is the function of Trivial File Transfer Protocol (TFTP)?

a)

Securely move files between devices on local network

b)

Allow access and view webpages

c)

Verifies user identities without sending passwords over the internet.

55.

Which protocol uses port number 80?

a)

Kerberos

b)

Hypertext Transfer Protocol (HTTP)

c)

Post Office Protocol (POP3)

56.

Fill in the blank: Kerberos verifies user identities without sending (a)   over the internet.

57.

What is the function of Post Office Protocol (POP3)?

a)

Downloads emails from a server to a local device

b)

Distribute, retrieve, inquire about, and post news articles on the internet

c)

Allows program to request a service from another program on a different device.

58.

Which protocol uses port number 119?

a)

Remote Procedure Call (RPC)

b)

Network News Transfer Protocol (NNTP)

c)

NetBIOS

59.

Fill in the blank: Remote Procedure Call (RPC) allows program to request a service from another program on a different (a)   .

60.

What is the function of NetBIOS?

a)

A) Allows applications on different devices to communicate over

b)

B) Translate IPs to human-readable names

c)

C) Securely move files between devices on local network.

61.

What is the function of the Internet Message Access Protocol (IMAP)?

a)

Allows users to access their email from any device

b)

Monitor and manage network devices

c)

Encrypts data transmitted between a user’s web browser and a website

d)

Share files, printers, and other resources across a network

62.

Which protocol uses port number 161 and is used to monitor and manage network devices by collecting status, health, and performance data?

(a)  

63.

What is the purpose of SNMPTrap?

a)

Allows applications to access and manage user information

b)

Messages sent by network devices to an SNMP management system to indicate a specific event or error

c)

Method for securing the SMTP using transport layer security (TLS)

d)

Encrypts the transmission of data related to network accounts

64.

Which protocol allows applications to access and manage user information within a network directory and uses port number 389?

(a)  

65.

What is the function of HTTPS?

a)

Allows users to access their email from any device

b)

Monitor and manage network devices

c)

Encrypts data transmitted between a user’s web browser and a website

d)

Share files, printers, and other resources across a network

66.

Which protocol uses port number 445 and is used to share files, printers, and other resources across a network?

(a)  

67.

What is the purpose of SMTPS?

a)

Allows applications to access and manage user information

b)

Method for securing the SMTP using transport layer security (TLS)

c)

Encrypts the transmission of data related to network accounts

d)

Share files, printers, and other resources across a network

68.

Which protocol allows a system administrator to monitor and manage logs from different parts of the system and uses port number 514?

(a)  

69.

What is the function of LDAPS?

a)

Allows users to access their email from any device

b)

Encrypts the transmission of data related to network accounts

c)

Monitor and manage network devices

d)

Share files, printers, and other resources across a network

70.

Which protocol uses port number 636 and is used to secure authentication?

(a)  

71.

What is the purpose of IMAPS?

a)

Secure IMAP

b)

Secure POP3

c)

Secure Syslog

72.

Which protocol uses port 995?

a)

IMAPS

b)

POP3S

c)

RADIUS UDP

73.

What is the function of Microsoft SQL?

a)

Secure Syslog

b)

Storing and processing information in a relational database

c)

Makes connections between computers

74.

Fill in the blank: Remote Authenticate (RADIUS) makes connections between computers and provides authentication, authorization, and (a)   .

75.

Which protocol is NOT secure RADIUS?

a)

RADIUS UDP

b)

Remote Desktop Protocol

c)

Syslog TLS

76.

What is the purpose of Remote Desktop Protocol (RDP)?

a)

Secure IMAP

b)

Allows users to connect to a remote device over a network

c)

Storing and processing information in a relational database.

77.

What is the purpose of Syslog TLS?

a)

Secure Syslog

b)

Secure POP3

c)

Secure IMAP

78.

GDPR mandates that personal data must be:

a)

Collected with consent and used transparently

b)

Shared freely without restrictions

c)

Stored indefinitely without purpose

d)

Accessible to everyone without control

79.

The purpose of a risk register is to:

a)

Identify potential risks and their impact

b)

Track project timelines

c)

Manage team performance

d)

Allocate project resources

80.

Ephemeral credentials are designed for:

a)

Long-term access to resources

b)

Temporary access to resources

c)

Permanent user authentication

d)

Data encryption

81.

What is the process that involves real-time tracking of system events?

(a)  

82.

What is the process of securing and preserving evidence related to a security incident for potential use in legal proceedings?

(a)  

83.

What allows for the visualization of flow patterns?

(a)  

84.

Which agreement defines service performance levels?

(a)  

85.

Which agreement formalizes business partnership terms?

(a)  

86.

Which agreement outlines mutual understandings?

(a)  

87.

Which agreement sets terms for ongoing services?

(a)  

88.

What is the primary use case for a Jump Server?

(a)  

89.

What is the primary use case for a Proxy?

(a)  

90.

The role of a security analyst in interpreting NetFlow data is to:

a)

Monitor network traffic for anomalies and threats.

b)

Develop software applications for data analysis.

c)

Manage hardware installations for network infrastructure.

d)

Provide customer support for network issues.

91.

What type of security offers more stringent monitoring and access control for administrators?

4 lines
92.

Fill in the blank: Traffic goes through a central, secure server, then to other (a)   systems.

93.

Which of the following is a common use in remote access?

4 lines
94.

An admin connects to a jump server to access databases or servers inside a private network by using:

a)

SSH (Secure Shell)

b)

FTP (File Transfer Protocol)

c)

HTTP (Hypertext Transfer Protocol)

d)

SMTP (Simple Mail Transfer Protocol)

95.

What is the key size for AES encryption?

4 lines
96.

Fill in the blank: RSA is an (a)   (public-key) algorithm with a key size of 1024 - 4096 bits.

97.

Which encryption algorithm is considered weak and obsolete?

4 lines
98.

What is the block size for TDES encryption?

4 lines