22 Security Practice Questions & Answers
Every Security practice question from the CompTIA A+ Practice Test, with the correct answer and a short explanation.
Start practice test →1. Over a weekend, one infected laptop is left connected to the office network. By Monday, dozens of computers that nobody signed in to are infected as well. Which malware type best accounts for that spread?
- A.A Trojan, which arrives disguised as a useful tool that the person at each machine must download and run
- B.A boot sector virus, which infects a machine only when it restarts with the infected removable media left in it
- C.A worm, which copies itself to other hosts by abusing a network service, with no action taken by any user✓ Answer
- D.Ransomware, which spreads because every victim forwards the attacker's payment notice by email to coworkers
A worm is defined by self-propagation: it carries its own delivery mechanism and copies itself from host to host through a vulnerable network service, which is why machines nobody touched became infected. The Trojan option is tempting because a Trojan is also an executable that lands on a machine, but a Trojan has no self-replication at all — a person must be persuaded to run it on each computer, and that cannot happen on unattended systems over a weekend.
Source: CompTIA A+ Core 2 exam objectives, malware types (worm, Trojan, virus)Report a problem with this question
2. A user cannot open any of her documents. Every file now ends in an unfamiliar extension, and each folder holds a text file demanding cryptocurrency payment for a decryption key. Which malware type is this?
- A.Ransomware, which encrypts the user's data and sells access back through the payment note left in every folder✓ Answer
- B.A rootkit, which conceals its own files and processes from the tools an administrator would normally use to find it
- C.A cryptominer, which spends processor time on the attacker's behalf and leaves the stored data entirely untouched
- D.Spyware, which quietly gathers keystrokes and documents and ships them out while the user's own files still open
Ransomware is identified by its business model showing on screen: the data is encrypted in place, the extensions change, and a ransom note is dropped where the victim cannot miss it. Spyware is the distractor people reach for because both steal value from the user, but spyware depends on staying invisible and leaves files openable — the moment the victim is told what happened, the attack is ransomware, not surveillance.
Source: CompTIA A+ Core 2 exam objectives, malware types (ransomware, spyware, rootkit, cryptominer)Report a problem with this question
3. A laptop's fans run at full speed even when the user is away. Task Manager shows an unfamiliar process holding the processor near 100 percent, yet no files are missing, no ransom note appears, and the browser behaves normally. Which malware type fits?
- A.Ransomware in its staging phase, which loads the processor heavily while it enumerates the files it will encrypt
- B.A cryptominer, which quietly runs mining work for the attacker and shows itself as sustained processor load, heat and fan noise✓ Answer
- C.A worm mid-scan, which pegs the processor as it sprays connection attempts across the subnet looking for new hosts
- D.A keylogger, whose capture of every keystroke keeps the processor busy and warms the machine even while it sits idle
A cryptominer monetizes stolen compute, so its whole symptom picture is resource consumption: a persistent unknown process at high processor or graphics load, heat, fan noise and shortened battery life, with the user's data untouched. The keylogger option is the tempting one because spyware is also hidden and persistent, but capturing keystrokes costs almost no processor time, so a keylogger does not produce sustained full load on an idle machine.
Source: CompTIA A+ Core 2 exam objectives, malware types (cryptominer, keylogger, worm)Report a problem with this question
4. An accountant's banking password has been changed by someone else twice this month. Her documents open normally and the machine feels no slower, but an unknown program starts at every logon and uploads a small file each night. Which malware type fits best?
- A.Spyware such as a keylogger, which records credentials as they are typed and sends the collection out on a schedule✓ Answer
- B.A cryptominer, which would account for the nightly network traffic as it submits completed work to a mining pool
- C.Ransomware that has not triggered yet, which would explain the nightly upload of the encryption key to the attacker's server
- D.A rootkit, whose purpose is to keep an intruder's other tools hidden rather than to capture what the user types in
The symptom picture here is theft of credentials with no damage and no performance cost, which is exactly what spyware is built for: capture what the user types, store it, and exfiltrate it quietly on a schedule. The rootkit option tempts because both hide, but a rootkit's job is concealment of other components — it explains how something stays hidden, not how the banking password kept reaching an outsider.
Source: CompTIA A+ Core 2 exam objectives, malware types (spyware and keyloggers versus rootkits)Report a problem with this question
5. A desktop keeps opening outbound connections to an unknown address, and its antivirus service is disabled again after every restart. A full scan run from inside the running system reports that the machine is clean. What is the most appropriate next step?
- A.Start the computer from external anti-malware rescue media and scan the drive offline, before the suspect code can load✓ Answer
- B.Use System Restore to roll the computer back to a restore point made before the symptoms were first reported
- C.Update the definitions and schedule the same in-system scan to run nightly, since the first pass clearly used stale signatures
- D.Reset the browser, remove any unrecognized extensions and confirm that no proxy server is set for the user's profile
These symptoms point to a rootkit: code that loads with or beneath the operating system and hooks the very calls a scanner uses to enumerate files, processes and services, so a scanner running inside that operating system is asking a compromised referee for the score. Booting from external rescue or preinstallation media means the suspect code never runs, so the drive can be read as plain data; simply updating definitions and rescanning in place is the tempting answer, but it repeats the same flawed measurement no matter how current the signatures are.
Source: CompTIA A+ Core 2 exam objectives, rootkits and scanning from a recovery or preinstallation environmentReport a problem with this question
6. A technician has verified the symptoms on an infected Windows computer and has already disconnected it from the network. Which sequence of remaining steps follows the standard malware removal procedure?
- A.Disable System Restore, remediate with updated tools, then re-enable System Restore and create a fresh restore point✓ Answer
- B.Reimage the drive immediately, then update the anti-malware, scan the rebuilt system and disable System Restore
- C.Educate the user first, then scan and remove the infection, disabling System Restore only if the symptoms return later
- D.Create a restore point now for safety, scan and remove the infection, then leave System Restore running as it was
The order exists for a mechanical reason: restore points can hold a copy of the infection, so System Restore is switched off before remediation to keep the malware from being reinstated by a rollback, and it is switched back on afterwards with a clean point created so the user has a usable recovery baseline. Creating a restore point before cleaning is the plausible-sounding trap, because it preserves the very state the technician is trying to eliminate and gives the infection a way back.
Source: CompTIA A+ Core 2 exam objectives, best practice procedure for malware removalReport a problem with this question
7. An employee badges through the lobby door. A person carrying two coffee cups catches the door behind her and walks in without presenting a badge. Which technique describes what just happened?
- A.Shoulder surfing, which is watching a nearby person enter a code or read a screen in order to reuse what was seen
- B.Tailgating, which is entering a controlled area by following an authorized person through the door they opened✓ Answer
- C.Impersonation, which is claiming a role such as auditor or repair technician so that staff grant the access willingly
- D.Dumpster diving, which is recovering discarded printouts and old media from the trash to obtain usable information
Tailgating is defined by the physical mechanism: an unauthorized person crosses a controlled boundary on someone else's successful authentication, which is why full hands and a friendly door-hold are the classic setup. Impersonation is the near miss, and the difference is worth learning — impersonation works by talking staff into granting access on the strength of a claimed role, while tailgating never asks for permission at all.
Source: CompTIA A+ Core 2 exam objectives, social engineering attacks (tailgating, impersonation, shoulder surfing, dumpster diving)Report a problem with this question
8. A traveling employee types her VPN passcode on a laptop in a crowded airport lounge and later realizes a stranger behind her had a clear view of the screen and the keyboard. Which control most directly addresses this exposure?
- A.A shorter screen lock timeout, which returns the machine to the sign-in prompt whenever it is left unattended
- B.A privacy filter on the display, together with seating that keeps the screen out of the walkway's line of sight✓ Answer
- C.Full disk encryption, which keeps the laptop's contents unreadable to anyone who does not hold the volume key
- D.A longer and more complex passphrase, which raises the effort an attacker needs to guess this account's credentials
Shoulder surfing is an attack on line of sight, so the control has to break the line of sight: a privacy filter narrows the viewing angle and positioning removes the over-the-shoulder vantage point entirely. Full disk encryption is the tempting security-sounding answer, but it protects data at rest on a lost or stolen drive and does nothing about a credential being read off a screen that is unlocked and in use.
Source: CompTIA A+ Core 2 exam objectives, shoulder surfing and workstation physical safeguardsReport a problem with this question
9. A user takes a phone call from someone who says he works for the company's software vendor, cites a genuine open ticket number, and asks her to read back the six-digit code that has just arrived on her phone. Which technique is being used?
- A.Spear phishing, because the approach names a genuine ticket the attacker researched before making any contact
- B.Whaling, because the pretext borrows the authority of a vendor relationship that only an executive would hold
- C.Vishing, because the pretext is delivered by voice on a live call, and that live pressure is what makes her read the code back✓ Answer
- D.Smishing, because the attack turns on a text message being delivered to the target's phone during the exchange
The technique is named after the channel that carries the persuasion, and here the persuasion is a live human voice on a telephone call, which is what vishing means. Smishing is the trap because a text message really is part of the story, but that message is the legitimate one-time code sent by the service itself — the attacker never sent an SMS, he called and talked the user into surrendering it.
Source: CompTIA A+ Core 2 exam objectives, phishing variants (vishing, smishing, spear phishing, whaling)Report a problem with this question
10. An accounts payable clerk receives an email that addresses her by name, refers to a genuine supplier and a real invoice number, and asks her to update that supplier's bank account details before the next payment run. Which technique is this?
- A.Shoulder surfing, in which the invoice details were read directly from the clerk's screen by someone standing behind her
- B.Spear phishing, in which one researched recipient receives a message built from details that are true of her actual work✓ Answer
- C.Whaling, in which the message is aimed at a senior executive such as the chief financial officer of the organization
- D.A watering hole attack, in which a website the whole target group visits routinely is compromised so that it infects visitors
Spear phishing is distinguished by research: the message is aimed at one named person and carries details only someone who studied that person's role would know, which is why it survives the scepticism that stops bulk phishing. Whaling is the common mix-up, but whaling is spear phishing pointed at a senior executive, and an accounts payable clerk is targeted here for her access to the payment system rather than for her rank.
Source: CompTIA A+ Core 2 exam objectives, social engineering (spear phishing, whaling, watering hole attacks)Report a problem with this question
11. A help desk proposes that users sign in with a password and then answer a security question such as a childhood street name. Why does this fail to meet the definition of multifactor authentication?
- A.Multifactor calls for three separate categories, so even a password paired with a hardware token would fall short
- B.Both items are things the user knows, and a second category, something you have or something you are, is required✓ Answer
- C.The answers sit in the same database as the passwords, and one database can only ever supply a single valid factor
- D.A security question counts as an inherence factor, so the pair is missing the possession factor that any scheme needs
Factors are grouped into categories — knowledge (something you know), possession (something you have) and inherence (something you are) — and multifactor means drawing from at least two different categories, because an attacker who learns one secret usually learns them all. Calling a security question an inherence factor is the classic misreading: the answer is memorized information, so it lives in the same knowledge category as the password and adds a second step without adding a second factor.
Source: NIST Special Publication 800-63B, Digital Identity Guidelines: authenticator factor categoriesReport a problem with this question
12. After an incident, a manager asks which files a specific user account opened and at what times. Which part of authentication, authorization and accounting supplies that answer?
- A.Authentication, which tests that claim by checking the credential presented against the value stored for it
- B.Authorization, which decides which resources the verified identity is allowed to open once its session starts
- C.Identification, which is the claim of identity a user makes by typing a user name at the sign-in prompt
- D.Accounting, which records what the identity actually did, with timestamps, in logs kept for later review✓ Answer
Accounting is the record-keeping leg of the model: once an identity is verified and permitted, accounting logs the actions it took and when, which is the only one of the three that can answer a question about past behaviour. Authorization is the tempting pick because it also concerns files and access, but it only describes what the account was permitted to do, never what it actually did.
Source: CompTIA A+ Core 2 exam objectives, logical security concepts (authentication, authorization, accounting)Report a problem with this question
13. A user's account at a shopping website appeared in a public breach dump. A week later an attacker signs in to her work webmail on the first attempt, with no failed logons recorded before the successful one. What best explains this?
- A.An on-path attack, in which the attacker sits between the user and the mail server and reads the session traffic
- B.A brute-force attack, in which software works through great numbers of guesses until one of them finally succeeds
- C.A dictionary attack, in which likely words and their common variations are tried in turn against the mailbox
- D.Credential stuffing, in which the leaked pair is replayed against other services, and password reuse made it valid at work too✓ Answer
Credential stuffing does not guess anything: it takes a user name and password already known to be valid somewhere and replays that exact pair against other services, so a reused password produces a first-attempt success and leaves no trail of failures. Brute force is the intuitive answer, but it is a guessing attack that generates a burst of failed logons and normally trips account lockout long before it succeeds — the absence of failures is precisely what rules it out.
Source: NIST Special Publication 800-63B, Digital Identity Guidelines: breached credential screening and password reuseReport a problem with this question
14. Which statement correctly describes how symmetric and asymmetric encryption are normally used together on a client machine?
- A.Symmetric encryption is what stores account passwords, while asymmetric encryption protects each file written to disk
- B.Symmetric encryption protects bulk data with one shared key, while asymmetric exchanges that key and signs data✓ Answer
- C.Both schemes use one key, but asymmetric splits it into halves that must be rejoined before any data can be read
- D.Asymmetric encryption carries the bulk data because a key pair is faster, while symmetric work is limited to signatures
Symmetric algorithms use one key for both directions and are fast, so they do the heavy lifting on volumes, files and session traffic, while asymmetric key pairs are slow but solve the problem symmetric cryptography cannot — getting that shared key to the other side safely, and proving who sent something. Reversing the two roles is the common error: a key pair is orders of magnitude slower per byte, which is why nobody encrypts a whole disk or a whole session with it.
Source: NIST Special Publication 800-175B, Guideline for Using Cryptographic Standards: symmetric and asymmetric key useReport a problem with this question
15. Why does a well-designed system store a hash of each user's password instead of storing the password encrypted?
- A.Hashing runs one way, so a stolen store yields no key that could turn the values back into usable passwords✓ Answer
- B.A hash occupies far less space than ciphertext does, so the account database can be searched faster at each sign-in
- C.Encryption can be reversed only with the user's own key, which would leave an administrator unable to reset a password
- D.A hash is recomputed differently at every logon, so a value copied out of the database cannot be replayed later
Encryption is designed to be reversed, so an encrypted password store is only as safe as the key protecting it, and a breach that takes the database usually takes the key with it. Hashing is a one-way transformation: the system stores a fingerprint, verifies a login by hashing what was typed and comparing fingerprints, and no key exists anywhere that turns the stored value back into the password. The size-and-speed answer is tempting because it sounds practical, but storage efficiency has nothing to do with why the choice is made.
Source: OWASP Password Storage Cheat Sheet, one-way hashing of stored authentication secretsReport a problem with this question
16. A vendor publishes a hash value beside a driver download. After downloading, a technician computes the hash of the saved file and it matches the published one. What has that comparison established?
- A.That the vendor signed the file with its private key, so the identity of the publisher has been confirmed as well
- B.That the download travelled over an encrypted channel, since a hash cannot be computed across a plain connection
- C.That the file received is bit for bit the file the published value describes, so nothing was altered or truncated on the way✓ Answer
- D.That the file carries no malware, because a matching value is produced only by files the vendor has already scanned
A hash comparison is an integrity check and nothing more: any change to the bytes, whether corruption or tampering, produces a completely different value, so a match says the copy on disk is identical to the file the publisher measured. The signature answer is the seductive one, because integrity and authenticity feel like the same idea — but a plain hash proves nothing about who published it, since an attacker who controls the page can post his own file alongside his own hash.
Source: CompTIA A+ Core 2 exam objectives, browser security: verifying downloads against a published hashReport a problem with this question
17. A user asks whether the padlock icon and a valid certificate mean an unfamiliar online store is trustworthy to buy from. What does that certificate actually assert?
- A.That any personal details typed into the site will be stored encrypted on the merchant's servers after arrival
- B.That the operator's pages are scanned for malware every day by the authority that issued the certificate to it
- C.That traffic to the site is encrypted and the name in the address bar matches the name the issuer validated✓ Answer
- D.That the issuer examined the company's business practices and found the merchant financially sound and honest
A publicly trusted certificate is issued after the applicant proves control of the domain name, so what it attests to is name-to-key binding plus an encrypted channel to that name. Assuming it vouches for the merchant's honesty is the everyday mistake, and it is why fraudulent shops obtain certificates routinely: the padlock says nobody is reading the connection, not that the shop will ship the goods.
Source: CA/Browser Forum Baseline Requirements, domain validation and the meaning of a TLS server certificateReport a problem with this question
18. A user asks whether it is safe to read the news on a cafe's open wireless network as long as he does not sign in to anything. What is the best answer?
- A.The only real cost is speed, since an open network divides its bandwidth among all the customers connected to it
- B.A padlock in the browser removes the risk, because encrypted pages also conceal which sites are being requested
- C.Any traffic can be captured or altered by someone within range, because frames on an open network cross the air unencrypted✓ Answer
- D.Browsing there is safe, because the access point isolates clients so nearby devices cannot see one another's traffic
An open network provides no link-layer encryption, so every frame is readable by any radio in range and an attacker can also inject content or stand up an evil twin with the same network name. The padlock answer is the seductive one because transport encryption genuinely protects page contents, but the domain being visited still leaks, unencrypted pages and background app traffic remain exposed, and a user trained to trust the padlock will click through the certificate warning an interception attack produces.
Source: CompTIA A+ Core 2 exam objectives, wireless security and the risks of unprotected networksReport a problem with this question
19. A small office still runs an access point configured for WEP. Why must that be replaced, and what did the later schemes change?
- A.WEP reuses short initialization vectors, so captured traffic reveals the key; WPA2 brought in AES-CCMP and WPA3 added SAE✓ Answer
- B.WEP demands a certificate for every client, and the later schemes dropped certificates for a passphrase shared by everyone
- C.WEP protects only the association password, and the later schemes extended that very same cipher across the whole payload
- D.WEP has one weakness, a short key, so raising the key to 128 bits makes it the equal of the schemes that replaced it
WEP's flaw is structural, not a matter of key size: its initialization vectors are too short, so they repeat within ordinary traffic, and an eavesdropper who collects enough frames recovers the shared key regardless of how long that key is. The successors changed the cipher and the handshake — WPA2 requires AES-CCMP, and WPA3 replaces the pre-shared key exchange with SAE so that captured frames cannot be attacked offline. Believing a longer key fixes WEP is the classic misconception and the reason some sites left it running for years.
Source: IEEE 802.11 deprecation of WEP and Wi-Fi Alliance WPA2 and WPA3 security requirementsReport a problem with this question
20. A standard user asks the help desk for the local administrator password so that she can install an approved design application on her workstation herself. What is the correct response?
- A.Have her run the vendor's installer under the built-in guest account, which completes setup without an elevation prompt
- B.Read the administrator password out to her once, and ask her to use it only for this approved application's installer
- C.Put her account into the local Administrators group for the day and take it back out once the installation is finished
- D.Log the request, and have a technician install the application with elevated rights once the approval is confirmed✓ Answer
Least privilege means the standard account keeps the rights its job needs and no more, so the installation is performed by someone whose role carries administrative rights, under a logged request that leaves an audit trail. Temporarily adding the user to the local Administrators group sounds like a reasonable compromise, but for the whole of that day every program she opens, including anything malicious she encounters, runs with full administrative rights, and the change is easy to forget to reverse.
Source: CompTIA A+ Core 2 exam objectives, principle of least privilege and administrative account handlingReport a problem with this question
21. A solid-state drive is being cleared so the same laptop can be reissued to another employee inside the company. Why is a multi-pass overwrite unreliable here, and what should be used instead?
- A.Overwriting does work on flash, but it has to be run seven times, because a single pass leaves a recoverable remnant
- B.Degaussing clears flash cells just as it clears platters, so pass the drive through a magnetic field before reissuing it
- C.A quick format is sufficient on flash media, because clearing the file table leaves no data block that can still be addressed
- D.Wear leveling leaves spare blocks that an overwrite never addresses, so issue the drive's secure erase or cryptographic erase command✓ Answer
A solid-state drive's controller remaps writes across spare and over-provisioned blocks to spread wear, so a host-level overwrite reaches the logical addresses but not every physical cell that once held data. The right method for a drive staying inside the organization is the drive's own sanitize command — secure erase, or cryptographic erase that discards the internal encryption key — after which the drive can be redeployed. The seven-pass answer is a leftover rule of thumb from magnetic platters and, on flash, simply repeats an incomplete operation while consuming write endurance.
Source: NIST Special Publication 800-88, Guidelines for Media Sanitization: clear, purge and destroy for flash mediaReport a problem with this question
22. Drives pulled from decommissioned computers are collected by a third-party firm that shreds them off site. What purpose does the certificate of destruction serve?
- A.It records that the drives were wiped and are still fit to resell, so the same paperwork covers internal redeployment
- B.It transfers regulatory ownership of the data to the vendor, which ends the organization's own retention duties
- C.It guarantees that the firm will reimburse the organization if data is later recovered from the shredded media
- D.It is the vendor's documented evidence that the listed media were destroyed, which the organization keeps for its audits✓ Answer
When media leaves the building, the organization can no longer witness what happened to it, so the certificate of destruction is the evidence that closes the chain: it identifies the specific media by serial number, states the method and date, and is retained as proof for auditors and regulators. The redeployment answer confuses two different goals — media that will be reused inside the company is sanitized so the device survives, while media leaving for disposal is destroyed so the device does not, and a destruction certificate can only ever describe the second case.
Source: NIST Special Publication 800-88, Guidelines for Media Sanitization: documentation and certificate of destructionReport a problem with this question
Practice questions written to the published CompTIA A+ Core 1 and Core 2 exam objectives and to standard IT support practice. CompTIA and A+ are marks of CompTIA; this site is not affiliated with or endorsed by CompTIA. The exam objectives are revised periodically — confirm the current objectives and exam requirements with CompTIA before testing. About the CompTIA A+ certification →