CompTIA Security+ · every answer carries the reasoning, and why each
other option fails.
2,147 questions
9 chapters of notes
EN + ZH languages
Tap an option to see the answer, the reasoning, and why the other three fail.
Question 1 of 10
Which of the following threat actors is the most likely to be hired by a foreign government to attack critical systems located in other countries?
AHacktivistA hacktivist is driven by political or ideological causes and picks their own targets to deface sites or leak data for publicity — they wouldn't act on behalf of a foreign government for pay.
BWhistleblowerA whistleblower is an insider who discloses an organization's internal wrongdoing to regulators or the media; their stance is exposure, not attack, and they lack the technical and organizational capacity to breach another nation's critical systems.
COrganized crime
DUnskilled attackerAn unskilled attacker (formerly called a script kiddie) only uses off-the-shelf tools, has no funding or organization, and lacks persistence — critical infrastructure is far beyond their capability.
Why C is correct
The determining fact is "hired by a foreign government": being paid, organized, and attacking another nation's critical systems on order is the classic pattern of organized crime being used as a state proxy — the government pays for capability while retaining plausible deniability. The exam objectives distinguish threat actors along three lines: resources/funding, technical sophistication, and motivation. Organized crime is well-funded, technically mature, and driven purely by profit, so the target can be anyone as long as the price is right. The trap is reflexively jumping to "nation-state" the moment "foreign government" appears — but that option isn't even on the list here, and the word "hired" itself rules out the government's own military cyber units, since your own staff isn't something you hire.
Question 2 of 10
Which of the following should a security administrator adhere to when setting up a new set of firewall rules?
ADisaster recovery planA disaster recovery plan specifies how to rebuild systems and data at an alternate site after a major disaster — it governs post-incident recovery, not the approval process for routine rule configuration.
BIncident response procedureAn incident response procedure specifies how to contain, eradicate, and recover from a security incident once it is detected; although the firewall might be temporarily modified during handling, this is not the routine basis for adding new rules.
CBusiness continuity planA business continuity plan focuses on how critical business functions keep operating during a disruption, oriented toward processes and staffing, and does not address the approval of specific network policy changes.
DChange management procedure
Why D is correct
Firewall rules directly determine what traffic can pass in and out of the network — getting even one rule wrong can disrupt business or open an unintended pathway — so this is a textbook controlled change: it must go through a change request, impact analysis, a defined implementation and rollback window, approval, and then execution, with the rule documentation and network diagrams updated afterward. The change management procedure is exactly what governs this whole set of actions, delivering an approval trail, the ability to roll back, and after-the-fact auditability. The determining factor is that the prompt asks what should be followed "when setting up new rules," which lands on the routine authorization process for operations. The trap is being drawn to the names of the three emergency-related plans, but disaster recovery, business continuity, and incident response are all plans triggered after something has already gone wrong — they are not on the same timeline as day-to-day configuration changes.
Question 3 of 10
An organization is building a new backup data center with cost-benefit as the primary requirement and RTO and RPO values around two days. Which of the following types of sites is the best for this scenario?
AReal-time recoveryReal-time recovery means data is continuously synchronized and service is barely interrupted, corresponding to a recovery target close to zero; it carries the highest cost, far exceeding this question's requirement of around two days.
BHotA hot site keeps equipment and data in a constant state of readiness, allowing failover within minutes to hours — a capability far beyond what is needed here — and cost is exactly the constraint the question cares about most.
CColdA cold site provides only the site, power, and network access; equipment and data must be procured and restored afterward, which usually takes several weeks, and cannot meet a two-day recovery target.
DWarm
Why D is correct
Choosing a site type is essentially a balance between cost and recovery speed: a hot site has full hardware with real-time data synchronization and can switch over in minutes, but is the most expensive; a cold site has only the site and power, taking weeks to recover but being the cheapest; a warm site sits between the two — it has hardware and networking, with data synchronized periodically, and can typically be brought into service in one to a few days. The RTO and RPO given in the question are both around two days, and cost-benefit is stated as the top priority, which lands squarely in the capability range of a warm site. The point being tested is matching each of the three site types to its recovery time and cost. The trap is letting the phrase "cost-benefit as the primary requirement" push you toward the cold site: a cold site is indeed the cheapest, but recovery is measured in weeks and cannot meet a two-day target.
Question 4 of 10
What type of gap analysis involves evaluating an organization's current technical infrastructure and identifying areas where it falls short of required technical capabilities?
ATechnical gap analysis
BBusiness gap analysis
CPerformance gap analysis
DFinancial gap analysis
Why A is correct
Correct Answer: A) Technical gap analysis
Question 5 of 10
What is the purpose of a Certificate Signing Request (CSR)?
AAuthenticating web servers
BGenerating public keys
CCreating digital certificates
DRequesting digital certificates from a CA
Why D is correct
Correct Answer: D
A CSR is used to request a digital certificate from a Certificate Authority (CA) by providing necessary information about the entity requesting the certificate, including its public key.
Question 6 of 10
What is a potential consequence of non-compliance with regulatory considerations?
AIncreased market share
BEnhanced reputation
CSevere penalties and reputational damage
DStreamlined operations
Why C is correct
Answer: C. Non-compliance with regulatory considerations can lead to severe penalties and reputational damage for organizations, affecting their financial stability, credibility, and trustworthiness in the market.
Question 7 of 10
What role does encryption play in data backups?
AReducing storage requirements
BAccelerating the backup process
CProtecting data from unauthorized access
DEnsuring data consistency
Why C is correct
Answer: C) Protecting data from unauthorized access
Encryption in data backups helps protect data from unauthorized access and potential breaches. It ensures data confidentiality and integrity, safeguarding sensitive information from prying eyes.
Question 8 of 10
In which scenario would DTLS be a preferred security protocol?
ASecuring web-based email communication
BSecuring real-time video streaming
CSecuring file transfers over FTP
DSecuring DNS (Domain Name System) queries
Why B is correct
Answer: B) Securing real-time video streaming
DTLS is particularly useful for securing real-time applications such as video streaming, VoIP, online gaming, and other UDP-based communications. Its ability to provide encryption and integrity for UDP traffic makes it suitable for scenarios where low-latency and efficient data transmission are critical, such as in real-time media streaming.
Question 9 of 10
How does missing logs contribute to indicators of compromise?
ARoutine log rotation practices
BAnomalies in system log files suggesting tampering or deletion by attackers
CTemporary system outages
DUser errors causing data loss
Why B is correct
Answer: B. Missing logs indicate anomalies in system log files, potentially suggesting tampering or deletion by attackers to cover their tracks and evade detection.
Question 10 of 10
Why is internal reporting considered the first line of defense in vulnerability management?
AIt involves reporting vulnerabilities to external stakeholders
BIt focuses on installing security patches
CIt identifies, documents, and communicates vulnerabilities within the organization
DIt involves responsible disclosure of vulnerabilities
Why C is correct
C) It identifies, documents, and communicates vulnerabilities within the organization
Internal reporting is considered the first line of defense in vulnerability management because it involves identifying, documenting, and communicating vulnerabilities within the organization's structure. This allows for timely remediation and improved security posture.
These 10 are a sample
✓2,147 questions, each with the full reasoning
✓Every wrong option explained, not just the right one
✓9 chapters of syllabus notes, written from a cold start
✓Full-length mock exam with per-domain scoring
✓Printable PDF included — one purchase, no renewal