WorksheetsCompTIA Security+ Certification Questions
Total questions: 77
Worksheet time: 1hrs 17mins
What does a digital signature verify in an email?
Encryption
Authentication
Confidentiality
Integrity
In asymmetric encryption, which key is used to encrypt the data?
Public key
Private key
Symmetric key
Hashing key
What is the primary purpose of a Public Key Infrastructure (PKI)?
Secure email communication
Digital signatures and certificates management
Secure network authentication
Encrypting data at rest
Which of the following encryption methods uses both asymmetric and symmetric encryption?
Which of the following is the purpose of hashing in digital signatures?
Encrypt the message content
Verify the integrity of the message
Create a public/private key pair
Authenticate the sender's identity
Which of the following is a benefit of implementing a mandatory vacation policy?
Prevents unauthorized data access
Detects fraudulent activity or misconduct
Reduces the need for encryption
Ensures network uptime
Which policy helps to ensure that employees understand the organization's rules for using resources?
Acceptable Use Policy
Data Retention Policy
Incident Response Policy
Change Management Policy
Which of the following is an example of an asymmetric encryption algorithm?
AES
RSA
DES
Blowfish
What type of certificate allows an organization to secure multiple subdomains under a single certificate?
Wildcard certificate
Extended Validation certificate
Self-signed certificate
Domain Validation certificate
In a symmetric encryption system, what key is used for both encryption and decryption?
Public key
Private key
Secret key
Session key
11. The function of a Certificate Authority (CA) in the context of email encryption is to issue and manage digital certificates that authenticate the identity of email users, ensuring secure communication.
It issues and manages digital certificates for authenticating email identities.
It filters out spam emails.
It stores and archives emails securely.
It converts emails into encrypted messages automatically.
What is the primary purpose of a Certificate Authority (CA)?
Encrypt email messages
Issue and manage digital certificates
Provide secure storage for private keys
Store public keys of users
Which cryptographic protocol is most commonly used for securing web traffic?
FTP
SSH
HTTPS
Telnet
What is the main function of a Hash-based Message Authentication Code (HMAC)?
Encrypt data during transmission
Ensure data integrity and authenticity
Encrypt the symmetric key
Provide confidentiality in communication
What does the process of "key stretching" help to improve?
The efficiency of encryption algorithms
The strength of stored passwords
The speed of key exchange
The security of symmetric key encryption
Which port is used for secure HTTP (HTTPS)?
A) 80
B) 443
C) 21
D) 23
Which cryptographic protocol provides confidentiality, integrity, and authentication for IP traffic?
A) IPsec
B) HTTPS
C) SSL
D) SSH
Which of the following is NOT a typical use case for S/MIME?
Signing email messages
Encrypting email messages
Verifying email sender’s identity
Creating secure web sessions
What is the main purpose of a Service Level Agreement (SLA)?
Establishes expectations for service performance
Defines the terms of a partnership
What is the purpose of a Recovery Agent in the context of key escrow?
To manage certificates
To recover encrypted data when a private key is lost
To perform system backups
To generate encryption keys
Which of the following is a characteristic of a Self-Signed Certificate?
It is issued by a trusted third-party CA.
It must be manually installed on each system.
It provides extended validation for secure websites.
It can be revoked by the issuing CA.
What is the role of an Incident Response Team (IRT)?
To prevent network breaches
To monitor employee behavior
To detect and respond to security incidents
To perform system backups
What type of attack does a "Man-in-the-Middle" (MITM) exploit?
Which of the following ensures that a user is who they claim to be?
Data integrity
Authentication
Confidentiality
Availability
What is the purpose of a chain of custody in forensic procedures?
To prevent the loss of digital evidence
To prove the authenticity of the collected evidence
To encrypt sensitive data during transmission
To store the evidence in a secure location
Which of the following is an example of out-of-band key exchange?
Sending the key via email
Sharing the key over a secure channel
Exchanging the key over an insecure communication method
Generating the key using a shared secret
Which of the following policies is designed to prevent unauthorized access to sensitive information?
Privacy Policy
Data Retention Policy
Acceptable Use Policy
Account Management Policy
What is the function of a port scanner in network security?
To encrypt network traffic
To detect open ports and vulnerabilities
To monitor network performance
To establish secure communication channels
What is the primary goal of data classification?
To determine the most appropriate encryption method
To categorize data based on its level of sensitivity
To enforce access controls based on roles
To optimize system performance
Which of the following ports is used by RDP (Remote Desktop Protocol)?
21
3389
23
443
Which of the following is a reason for revoking a digital certificate?
The certificate has expired
The private key has been compromised
What does "data wiping" refer to in security practices?
Encrypting data before storage
Deleting data without leaving a trace
Backing up critical data
Compressing data for efficient storage
Which of the following is an example of a "clean desk" policy requirement?
Employees should keep only a single document on their desk at all times.
Sensitive information must be locked in filing cabinets when not in use.
All files must be printed daily for security purposes.
Employees are required to log out of all devices after every task.
Which of the following is the purpose of a Business Partner Agreement (BPA)?
It outlines obligations between business partners.
It defines the relationship between users and administrators.
It sets service levels for network uptime.
It outlines acceptable use policies for email.
Which port is used for Simple Mail Transfer Protocol (SMTP)?
21
25
80
110
Which of the following best describes an Incident Response Plan (IRP)?
A plan to monitor network activity
A set of guidelines to handle security breaches
A system to manage digital certificates
A policy for password management
What type of attack is most likely to occur when a hacker impersonates a legitimate user to gain access to a system?
SQL Injection
Phishing
Spoofing
Denial of Service
What does "least privilege" mean in the context of access control?
A) Users should have access only to the resources necessary for their job.
B) Users should be granted the highest level of access at all times.
C) Only administrators should have access to critical systems.
D) All users should share the same access level for simplicity.
Which of the following is an essential aspect of the Change Management Policy?
Monitoring user behavior after changes
Ensuring changes do not disrupt system functionality
Allowing untracked changes in critical systems
Limiting documentation and reviews of changes
Which of the following security measures helps prevent a single individual from controlling an entire process or system?
Separation of duties
Mandatory vacations
Job rotation
Least privilege
What does the term "Data Loss Prevention" (DLP) refer to?
Techniques for preventing unauthorized data access
A backup strategy for critical systems
Software that prevents the physical loss of hardware
Policies and tools designed to prevent data from leaving an organization
What is the purpose of a "disaster recovery" plan in cybersecurity?
To identify critical system vulnerabilities
To ensure the restoration of systems after a breach or disaster
What is an example of a physical security control?
Antivirus software
Password policies
Biometrics
Firewalls
Which of the following is a best practice for handling Personally Identifiable Information (PII)?
Store PII in plain text for easy access
Ensure PII is encrypted and access is restricted
Share PII freely among employees for convenience
Regularly delete all PII from company systems
Which of the following is an example of two-factor authentication (2FA)?
Using only a username and password
Using a password and a one-time code sent to your phone
Using a single PIN code for login
Using a fingerprint scan and a password
What is a primary function of a Security Information and Event Management (SIEM) system?
To filter network traffic
To monitor and analyze security events in real time
To manage digital certificates
To enforce password policies
What is the purpose of an Interconnection Security Agreement (ISA)?
To establish service levels between two parties
To set security requirements for connecting networks or systems
To define incident response procedures
To clarify user access policies between two systems
Which of the following is an example of "social engineering"?
Phishing email that asks for login credentials
Installing a firewall to block unauthorized traffic
Performing a vulnerability scan
Updating software to fix security flaws
Which type of attack aims to overload a system with excessive traffic to make it unavailable?
DDoS (Distributed Denial of Service)
Man-in-the-Middle
SQL Injection
What does a "business continuity plan" ensure during a disaster?
The business can continue operations with minimal disruption
The business can increase profits by cutting costs
All employees are retrained to avoid security issues
No external access to critical systems
Which of the following is an example of a vulnerability scanner?
A) Nessus
B) McAfee Antivirus
C) Palo Alto Firewall
D) Cisco ASA
What is the purpose of a Memorandum of Understanding (MOU) in a business context?
To formalize an agreement between two parties
To outline service level expectations
To establish guidelines for network communication
To implement encryption between business partners
The goal of a data retention policy is to manage how long data is kept.
To manage how long data is kept
To store data forever
To delete data immediately
To archive all data
What is the purpose of a data retention policy?
To ensure data is stored permanently
To limit the storage of unnecessary or sensitive data
To guarantee data is backed up regularly
To share data with authorized users
What is the purpose of a patch management policy?
To manage network devices
To update software and systems regularly to fix vulnerabilities
To ensure the confidentiality of user data
To monitor system logs for security threats
Which of the following is the most secure method of data disposal?
Deleting files and emptying the trash
Using a file shredder application
Degaussing hard drives
Storing data on encrypted external drives
Which of the following is a best practice for preventing unauthorized access to a network?
Use complex passwords and change them regularly
Leave user accounts with minimal permissions open
Share access credentials among employees
Disable multi-factor authentication
What is the purpose of a risk assessment in cybersecurity?
To identify and evaluate risks to the organization’s assets
To increase system availability
To automate system updates
To block all incoming network traffic
Which of the following is an example of a technical security control?
Employee background checks
Password complexity requirements
Security training programs
Risk assessments
Which protocol is commonly used to prevent unauthorized devices from connecting to a network?
WEP
WPA2
802.1X
SSL/TLS
Which of the following ports is used for DNS (Domain Name System)?
(a)
What is the port number for DNS?
21
22
53
80
Which of the following is the primary function of a firewall?
To monitor network traffic for malware
To filter traffic based on security policies
To store encryption keys securely
To prevent physical theft of devices
Which type of backup is the most time-efficient but provides the least recovery options?
Full backup
Differential backup
Incremental backup
Mirror backup
What is the primary function of a digital signature in email communication?
To encrypt the email content
To authenticate the sender's identity and ensure integrity
To hide the email content
To verify the recipient's identity
What is the function of the Hash-based Message Authentication Code (HMAC)?
To provide encryption for messages
To ensure data integrity and authentication
To convert plaintext into ciphertext
To encrypt the symmetric key
Which protocol is used for securing communication over the web on port 443?
A) SSL
B) IPsec
C) TLS
D) FTP
What is the purpose of the Order of Volatility in forensic procedures?
To determine the timeline of an incident
To guide the order in which evidence is collected to avoid modification
To track system performance during an attack
To capture logs from all network devices
What is the role of a Certificate Authority (CA) in Public Key Infrastructure (PKI)?
To encrypt data using symmetric keys
To issue and manage digital certificates
To generate session keys for encryption
To distribute encryption algorithms to users
What is a "wildcard certificate" used for?
Encrypting web traffic
Securing multiple subdomains with one certificate
Validating email signatures
Verifying the identity of a server
What does a Service Level Agreement (SLA) typically define?
Technical guidelines for maintaining secure connections
The financial penalties for failing to meet certain service requirements
Guidelines for encrypting data in transit
A company’s policies on encryption standards
Which of the following is a feature of elliptic curve cryptography (ECC)?
It requires significant computational power
It is mainly used in high-performance environments with limited resources
It is slower than RSA
It is only used in symmetric encryption
What is the main benefit of using a symmetric encryption algorithm?
A) It is more secure than asymmetric encryption
B) It requires more computational power than asymmetric encryption
What is the purpose of the "least privilege" principle in security policies?
To restrict access to sensitive data based on job requirements
To ensure that all users have access to all data
To allow users to access all information for audit purposes
To ensure that only administrators can access the system
In a Public Key Infrastructure (PKI), what does the Certificate Revocation List (CRL) contain?
A) A list of all certificates issued by the CA
B) A list of certificates that have been revoked or are no longer valid
C) A list of all valid certificates in the system
D) A list of users who need new certificates
What is the primary function of a VPN (Virtual Private Network)?
To encrypt web traffic
To securely connect a device to a private network over the internet
To create a secure communication channel within a local area network
To prevent malware from entering the network
Which of the following is an advantage of symmetric encryption?
A) It requires a key exchange mechanism
B) It is slower than asymmetric encryption
C) It is faster than asymmetric encryption
D) It does not require a key exchange mechanism
