CompTIA A+ Core 2 Practice Questions: Security

30 free, exam-style CompTIA A+ Core 2 (220-1202) practice questions covering Security. Each question shows the correct answer and a clear explanation. Ready for the real thing? Take the full timed quiz below.

πŸš€ Take the full CompTIA A+ Core 2 quiz πŸ“˜ CompTIA A+ Core 2 study guide

Q1. Which wireless encryption standard is the most secure?

Explanation: WPA3 is currently the most secure Wi-Fi encryption standard. (Relevant for 1101 networking - wireless security) Learn more.

Q2. Which full-disk encryption solution is native to macOS?

Explanation: FileVault 2 provides XTS-AES-128 full-disk encryption on Mac systems. Learn more.

Q3. You need to securely wipe all data from an old HDD before disposal. Which method meets DoD 5220.22-M standard?

Explanation: The DoD standard calls for multiple passes: overwrite with zeroes, then ones, then random data to prevent data recovery. Learn more.

Q4. Which wireless security protocol uses 128-bit keys and a pre-shared key, but is considered insecure due to short IV?

Explanation: WEP uses a 24-bit IV with RC4, making it easily cracked. WPA2-TKIP and WPA2-AES are stronger; WPA3 uses SAE. Learn more.

Q5. In a SOHO router, which feature lets you limit inbound connections to only specified private IPs and ports?

Explanation: An ACL can explicitly permit or deny inbound/outbound traffic by IP, port, or protocol. Learn more.

Q6. Which Windows feature blocks unsigned or malicious applications from running based on publisher rules?

Explanation: AppLocker defines policies to allow or deny applications by publisher, path, or hash. Learn more.

Q7. When installing a browser extension, which built-in browser feature can warn you about malicious or tracker-heavy add-ons?

Explanation: Modern browsers prompt you about an extension’s requested permissions (e.g. read all data), helping you detect potentially malicious add-ons. Learn more.

Q8. What is the primary purpose of a TPM (Trusted Platform Module) chip in modern PCs?

Explanation: TPM provides hardware‐based secure storage for encryption keys, credentials, and platform integrity measurements. Learn more.

Q9. In Windows Defender Firewall, which profile applies when a device is connected to a public Wi-Fi hotspot?

Explanation: The Public Profile is used for network connections in untrusted locations like coffee shops to impose stricter firewall rules. Learn more.

Q10. A user should only have the permissions needed for daily work. Which security principle is being applied?

Explanation: Least privilege limits accounts to the minimum permissions required to perform assigned tasks. Learn more.

Q11. Which Windows feature encrypts an entire volume to protect data if a laptop is lost?

Explanation: BitLocker provides full-volume encryption for Windows systems. Learn more.

Q12. Which sign is most associated with a phishing attempt?

Explanation: Phishing commonly uses urgency and credential-harvesting links to trick users into revealing sensitive information. Learn more.

Q13. After malware is found on a workstation, what should be done before reconnecting it to the network?

Explanation: The system should be cleaned, updated, and verified before returning it to the network to reduce reinfection risk. Learn more.

Q14. Which mobile security action should be taken before repurposing a company phone?

Explanation: A managed wipe or factory reset protects company and personal data before reassignment. Learn more.

Q15. A user receives browser pop-ups after installing a free toolbar. Which malware type is most likely?

Explanation: Adware commonly displays unwanted advertisements or browser pop-ups, often bundled with other software. Learn more.

Q16. Which mobile security feature requires a user PIN before the device can decrypt stored data?

Explanation: Mobile device encryption is commonly protected by the device passcode or biometric unlock process. Learn more.

Q17. Which action is part of proper malware remediation after removing malicious files?

Explanation: After removal, defenses should be updated and enabled to reduce the chance of reinfection. Learn more.

Q18. Which Windows feature stores saved passwords and certificates for users?

Explanation: Credential Manager stores saved credentials used by Windows and applications. Learn more.

Q19. Which attack uses a fraudulent phone call to obtain credentials?

Explanation: Vishing is voice phishing, where attackers use phone calls to trick users into disclosing sensitive information. Learn more.

Q20. Which type of social engineering attack involves an attacker following an authorized employee through a secure door without proper credentials?

Explanation: Tailgating occurs when an unauthorized person follows an authorized person through a secured entrance, bypassing physical access controls like badge readers. Learn more.

Q21. What is the primary purpose of BitLocker in Windows?

Explanation: BitLocker provides full-disk encryption, protecting data if a device is lost or stolen by making the drive contents unreadable without the proper credentials or recovery key. Learn more.

Q22. Which security concept ensures users are only given the minimum access rights needed to perform their job functions?

Explanation: The principle of least privilege limits user and process access rights to only what is strictly necessary, reducing the potential damage from compromised accounts or insider threats. Learn more.

Q23. What is the purpose of a Data Loss Prevention (DLP) policy in an organization?

Explanation: DLP solutions monitor and control data transfers to prevent sensitive information, such as PII or financial data, from leaving the organization through email, USB drives, or cloud uploads without authorization. Learn more.

Q24. Which password policy setting limits repeated sign-in guessing by temporarily disabling an account after a defined number of failures?

Explanation: The account lockout threshold defines how many failed sign-in attempts are allowed before the account is locked, slowing online password-guessing attacks. Learn more.

Q25. A user receives a fraudulent text message containing a link to verify a bank account. Which attack is this?

Explanation: Smishing is phishing delivered through SMS or another text-messaging service. Learn more.

Q26. A technician confirms that a workstation is actively communicating with a command-and-control server. What should be done first?

Explanation: Isolating the infected host limits further data loss, lateral movement, and communication with the attacker while preserving the system for remediation. Learn more.

Q27. Which macOS privacy permission allows an approved application to access data across protected user folders?

Explanation: Full Disk Access is a macOS privacy control that grants selected applications access to protected files and user data locations. Learn more.

Q28. Where should a technician look for a history of failed sign-in attempts on a standalone Windows PC?

Explanation: When auditing is enabled, Windows records successful and failed account logon events in the Security log in Event Viewer. Learn more.

Q29. A document contains customer Social Security numbers. Which data classification is most appropriate?

Explanation: Personally identifiable information such as Social Security numbers requires a restricted classification and controls appropriate to sensitive regulated data. Learn more.

Q30. A user receives access through both an NTFS group permission and a more restrictive NTFS user permission. Which permission determines access?

Explanation: Effective NTFS access combines applicable permissions, but an explicit deny overrides otherwise allowed access for the same right. Learn more.

More CompTIA A+ Core 2 practice topics