wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Security+ Certification Questions

Total questions: 77

Worksheet time: 1hrs 17mins

Name
Class
Date
1.

What does a digital signature verify in an email?

a)

Encryption

b)

Authentication

c)

Confidentiality

d)

Integrity

2.

In asymmetric encryption, which key is used to encrypt the data?

a)

Public key

b)

Private key

c)

Symmetric key

d)

Hashing key

3.

What is the primary purpose of a Public Key Infrastructure (PKI)?

a)

Secure email communication

b)

Digital signatures and certificates management

c)

Secure network authentication

d)

Encrypting data at rest

4.

Which of the following encryption methods uses both asymmetric and symmetric encryption?

4 lines
5.

Which of the following is the purpose of hashing in digital signatures?

a)

Encrypt the message content

b)

Verify the integrity of the message

c)

Create a public/private key pair

d)

Authenticate the sender's identity

6.

Which of the following is a benefit of implementing a mandatory vacation policy?

a)

Prevents unauthorized data access

b)

Detects fraudulent activity or misconduct

c)

Reduces the need for encryption

d)

Ensures network uptime

7.

Which policy helps to ensure that employees understand the organization's rules for using resources?

a)

Acceptable Use Policy

b)

Data Retention Policy

c)

Incident Response Policy

d)

Change Management Policy

8.

Which of the following is an example of an asymmetric encryption algorithm?

a)

AES

b)

RSA

c)

DES

d)

Blowfish

9.

What type of certificate allows an organization to secure multiple subdomains under a single certificate?

a)

Wildcard certificate

b)

Extended Validation certificate

c)

Self-signed certificate

d)

Domain Validation certificate

10.

In a symmetric encryption system, what key is used for both encryption and decryption?

a)

Public key

b)

Private key

c)

Secret key

d)

Session key

11.

11. The function of a Certificate Authority (CA) in the context of email encryption is to issue and manage digital certificates that authenticate the identity of email users, ensuring secure communication.

a)

It issues and manages digital certificates for authenticating email identities.

b)

It filters out spam emails.

c)

It stores and archives emails securely.

d)

It converts emails into encrypted messages automatically.

12.

What is the primary purpose of a Certificate Authority (CA)?

a)

Encrypt email messages

b)

Issue and manage digital certificates

c)

Provide secure storage for private keys

d)

Store public keys of users

13.

Which cryptographic protocol is most commonly used for securing web traffic?

a)

FTP

b)

SSH

c)

HTTPS

d)

Telnet

14.

What is the main function of a Hash-based Message Authentication Code (HMAC)?

a)

Encrypt data during transmission

b)

Ensure data integrity and authenticity

c)

Encrypt the symmetric key

d)

Provide confidentiality in communication

15.

What does the process of "key stretching" help to improve?

a)

The efficiency of encryption algorithms

b)

The strength of stored passwords

c)

The speed of key exchange

d)

The security of symmetric key encryption

16.

Which port is used for secure HTTP (HTTPS)?

a)

A) 80

b)

B) 443

c)

C) 21

d)

D) 23

17.

Which cryptographic protocol provides confidentiality, integrity, and authentication for IP traffic?

a)

A) IPsec

b)

B) HTTPS

c)

C) SSL

d)

D) SSH

18.

Which of the following is NOT a typical use case for S/MIME?

a)

Signing email messages

b)

Encrypting email messages

c)

Verifying email sender’s identity

d)

Creating secure web sessions

19.

What is the main purpose of a Service Level Agreement (SLA)?

a)

Establishes expectations for service performance

b)

Defines the terms of a partnership

20.

What is the purpose of a Recovery Agent in the context of key escrow?

a)

To manage certificates

b)

To recover encrypted data when a private key is lost

c)

To perform system backups

d)

To generate encryption keys

21.

Which of the following is a characteristic of a Self-Signed Certificate?

a)

It is issued by a trusted third-party CA.

b)

It must be manually installed on each system.

c)

It provides extended validation for secure websites.

d)

It can be revoked by the issuing CA.

22.

What is the role of an Incident Response Team (IRT)?

a)

To prevent network breaches

b)

To monitor employee behavior

c)

To detect and respond to security incidents

d)

To perform system backups

23.

What type of attack does a "Man-in-the-Middle" (MITM) exploit?

4 lines
24.

Which of the following ensures that a user is who they claim to be?

a)

Data integrity

b)

Authentication

c)

Confidentiality

d)

Availability

25.

What is the purpose of a chain of custody in forensic procedures?

a)

To prevent the loss of digital evidence

b)

To prove the authenticity of the collected evidence

c)

To encrypt sensitive data during transmission

d)

To store the evidence in a secure location

26.

Which of the following is an example of out-of-band key exchange?

a)

Sending the key via email

b)

Sharing the key over a secure channel

c)

Exchanging the key over an insecure communication method

d)

Generating the key using a shared secret

27.

Which of the following policies is designed to prevent unauthorized access to sensitive information?

a)

Privacy Policy

b)

Data Retention Policy

c)

Acceptable Use Policy

d)

Account Management Policy

28.

What is the function of a port scanner in network security?

a)

To encrypt network traffic

b)

To detect open ports and vulnerabilities

c)

To monitor network performance

d)

To establish secure communication channels

29.

What is the primary goal of data classification?

a)

To determine the most appropriate encryption method

b)

To categorize data based on its level of sensitivity

c)

To enforce access controls based on roles

d)

To optimize system performance

30.

Which of the following ports is used by RDP (Remote Desktop Protocol)?

a)

21

b)

3389

c)

23

d)

443

31.

Which of the following is a reason for revoking a digital certificate?

a)

The certificate has expired

b)

The private key has been compromised

32.

What does "data wiping" refer to in security practices?

a)

Encrypting data before storage

b)

Deleting data without leaving a trace

c)

Backing up critical data

d)

Compressing data for efficient storage

33.

Which of the following is an example of a "clean desk" policy requirement?

a)

Employees should keep only a single document on their desk at all times.

b)

Sensitive information must be locked in filing cabinets when not in use.

c)

All files must be printed daily for security purposes.

d)

Employees are required to log out of all devices after every task.

34.

Which of the following is the purpose of a Business Partner Agreement (BPA)?

a)

It outlines obligations between business partners.

b)

It defines the relationship between users and administrators.

c)

It sets service levels for network uptime.

d)

It outlines acceptable use policies for email.

35.

Which port is used for Simple Mail Transfer Protocol (SMTP)?

a)

21

b)

25

c)

80

d)

110

36.

Which of the following best describes an Incident Response Plan (IRP)?

a)

A plan to monitor network activity

b)

A set of guidelines to handle security breaches

c)

A system to manage digital certificates

d)

A policy for password management

37.

What type of attack is most likely to occur when a hacker impersonates a legitimate user to gain access to a system?

a)

SQL Injection

b)

Phishing

c)

Spoofing

d)

Denial of Service

38.

What does "least privilege" mean in the context of access control?

a)

A) Users should have access only to the resources necessary for their job.

b)

B) Users should be granted the highest level of access at all times.

c)

C) Only administrators should have access to critical systems.

d)

D) All users should share the same access level for simplicity.

39.

Which of the following is an essential aspect of the Change Management Policy?

a)

Monitoring user behavior after changes

b)

Ensuring changes do not disrupt system functionality

c)

Allowing untracked changes in critical systems

d)

Limiting documentation and reviews of changes

40.

Which of the following security measures helps prevent a single individual from controlling an entire process or system?

a)

Separation of duties

b)

Mandatory vacations

c)

Job rotation

d)

Least privilege

41.

What does the term "Data Loss Prevention" (DLP) refer to?

a)

Techniques for preventing unauthorized data access

b)

A backup strategy for critical systems

c)

Software that prevents the physical loss of hardware

d)

Policies and tools designed to prevent data from leaving an organization

42.

What is the purpose of a "disaster recovery" plan in cybersecurity?

a)

To identify critical system vulnerabilities

b)

To ensure the restoration of systems after a breach or disaster

43.

What is an example of a physical security control?

a)

Antivirus software

b)

Password policies

c)

Biometrics

d)

Firewalls

44.

Which of the following is a best practice for handling Personally Identifiable Information (PII)?

a)

Store PII in plain text for easy access

b)

Ensure PII is encrypted and access is restricted

c)

Share PII freely among employees for convenience

d)

Regularly delete all PII from company systems

45.

Which of the following is an example of two-factor authentication (2FA)?

a)

Using only a username and password

b)

Using a password and a one-time code sent to your phone

c)

Using a single PIN code for login

d)

Using a fingerprint scan and a password

46.

What is a primary function of a Security Information and Event Management (SIEM) system?

a)

To filter network traffic

b)

To monitor and analyze security events in real time

c)

To manage digital certificates

d)

To enforce password policies

47.

What is the purpose of an Interconnection Security Agreement (ISA)?

a)

To establish service levels between two parties

b)

To set security requirements for connecting networks or systems

c)

To define incident response procedures

d)

To clarify user access policies between two systems

48.

Which of the following is an example of "social engineering"?

a)

Phishing email that asks for login credentials

b)

Installing a firewall to block unauthorized traffic

c)

Performing a vulnerability scan

d)

Updating software to fix security flaws

49.

Which type of attack aims to overload a system with excessive traffic to make it unavailable?

a)

DDoS (Distributed Denial of Service)

b)

Man-in-the-Middle

c)

SQL Injection

50.

What does a "business continuity plan" ensure during a disaster?

a)

The business can continue operations with minimal disruption

b)

The business can increase profits by cutting costs

c)

All employees are retrained to avoid security issues

d)

No external access to critical systems

51.

Which of the following is an example of a vulnerability scanner?

a)

A) Nessus

b)

B) McAfee Antivirus

c)

C) Palo Alto Firewall

d)

D) Cisco ASA

52.

What is the purpose of a Memorandum of Understanding (MOU) in a business context?

a)

To formalize an agreement between two parties

b)

To outline service level expectations

c)

To establish guidelines for network communication

d)

To implement encryption between business partners

53.

The goal of a data retention policy is to manage how long data is kept.

a)

To manage how long data is kept

b)

To store data forever

c)

To delete data immediately

d)

To archive all data

54.

What is the purpose of a data retention policy?

a)

To ensure data is stored permanently

b)

To limit the storage of unnecessary or sensitive data

c)

To guarantee data is backed up regularly

d)

To share data with authorized users

55.

What is the purpose of a patch management policy?

a)

To manage network devices

b)

To update software and systems regularly to fix vulnerabilities

c)

To ensure the confidentiality of user data

d)

To monitor system logs for security threats

56.

Which of the following is the most secure method of data disposal?

a)

Deleting files and emptying the trash

b)

Using a file shredder application

c)

Degaussing hard drives

d)

Storing data on encrypted external drives

57.

Which of the following is a best practice for preventing unauthorized access to a network?

a)

Use complex passwords and change them regularly

b)

Leave user accounts with minimal permissions open

c)

Share access credentials among employees

d)

Disable multi-factor authentication

58.

What is the purpose of a risk assessment in cybersecurity?

a)

To identify and evaluate risks to the organization’s assets

b)

To increase system availability

c)

To automate system updates

d)

To block all incoming network traffic

59.

Which of the following is an example of a technical security control?

a)

Employee background checks

b)

Password complexity requirements

c)

Security training programs

d)

Risk assessments

60.

Which protocol is commonly used to prevent unauthorized devices from connecting to a network?

a)

WEP

b)

WPA2

c)

802.1X

d)

SSL/TLS

61.

Which of the following ports is used for DNS (Domain Name System)?

(a)  

62.

What is the port number for DNS?

a)

21

b)

22

c)

53

d)

80

63.

Which of the following is the primary function of a firewall?

a)

To monitor network traffic for malware

b)

To filter traffic based on security policies

c)

To store encryption keys securely

d)

To prevent physical theft of devices

64.

Which type of backup is the most time-efficient but provides the least recovery options?

a)

Full backup

b)

Differential backup

c)

Incremental backup

d)

Mirror backup

65.

What is the primary function of a digital signature in email communication?

a)

To encrypt the email content

b)

To authenticate the sender's identity and ensure integrity

c)

To hide the email content

d)

To verify the recipient's identity

66.

What is the function of the Hash-based Message Authentication Code (HMAC)?

a)

To provide encryption for messages

b)

To ensure data integrity and authentication

c)

To convert plaintext into ciphertext

d)

To encrypt the symmetric key

67.

Which protocol is used for securing communication over the web on port 443?

a)

A) SSL

b)

B) IPsec

c)

C) TLS

d)

D) FTP

68.

What is the purpose of the Order of Volatility in forensic procedures?

a)

To determine the timeline of an incident

b)

To guide the order in which evidence is collected to avoid modification

c)

To track system performance during an attack

d)

To capture logs from all network devices

69.

What is the role of a Certificate Authority (CA) in Public Key Infrastructure (PKI)?

a)

To encrypt data using symmetric keys

b)

To issue and manage digital certificates

c)

To generate session keys for encryption

d)

To distribute encryption algorithms to users

70.

What is a "wildcard certificate" used for?

a)

Encrypting web traffic

b)

Securing multiple subdomains with one certificate

c)

Validating email signatures

d)

Verifying the identity of a server

71.

What does a Service Level Agreement (SLA) typically define?

a)

Technical guidelines for maintaining secure connections

b)

The financial penalties for failing to meet certain service requirements

c)

Guidelines for encrypting data in transit

d)

A company’s policies on encryption standards

72.

Which of the following is a feature of elliptic curve cryptography (ECC)?

a)

It requires significant computational power

b)

It is mainly used in high-performance environments with limited resources

c)

It is slower than RSA

d)

It is only used in symmetric encryption

73.

What is the main benefit of using a symmetric encryption algorithm?

a)

A) It is more secure than asymmetric encryption

b)

B) It requires more computational power than asymmetric encryption

74.

What is the purpose of the "least privilege" principle in security policies?

a)

To restrict access to sensitive data based on job requirements

b)

To ensure that all users have access to all data

c)

To allow users to access all information for audit purposes

d)

To ensure that only administrators can access the system

75.

In a Public Key Infrastructure (PKI), what does the Certificate Revocation List (CRL) contain?

a)

A) A list of all certificates issued by the CA

b)

B) A list of certificates that have been revoked or are no longer valid

c)

C) A list of all valid certificates in the system

d)

D) A list of users who need new certificates

76.

What is the primary function of a VPN (Virtual Private Network)?

a)

To encrypt web traffic

b)

To securely connect a device to a private network over the internet

c)

To create a secure communication channel within a local area network

d)

To prevent malware from entering the network

77.

Which of the following is an advantage of symmetric encryption?

a)

A) It requires a key exchange mechanism

b)

B) It is slower than asymmetric encryption

c)

C) It is faster than asymmetric encryption

d)

D) It does not require a key exchange mechanism