HomeCompTIA Network+ 2026 PrepQuestions 11–20
CompTIA Network+ 2026 PrepPart 2 of 3

CompTIA Network+ 2026 Prep Exam Questions & Answers (11–20)

CompTIA Network+ 2026 Prep practice questions and answers. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.

Practise CompTIA Network+ 2026 Prep questions free, download the PDF, or unlock timed mock exams when you are ready.
Multiple choice — pick the best answer, then reveal it
  1. Q11Which of the following is NOT primarily an attack on confidentiality?

    • ADDoS attack
    • BOn-path attack
    • CPhishing
    • DMan-in-the-middle attack
    Show answer

    ✓ Correct answer: A. DDoS attack

    Answer: DDoS attack A DDoS attack targets availability by attempting to overwhelm a network or service, rendering it unavailable to legitimate users. On-path attacks, phishing, and man-in-the-middle attacks are all aimed at compromising confidentiality.

  2. Q12Which of the following is NOT a commonly implemented firewall security best practice?

    • AEnabling logging and alerting
    • BImplementing access control lists (ACLs)
    • CConducting regular vulnerability assessments
    • DDisabling stateful inspection
    Show answer

    ✓ Correct answer: D. Disabling stateful inspection

    Answer: Disabling stateful inspection Stateful inspection is a core feature of many firewalls that tracks the state of active connections and helps distinguish between legitimate and illegitimate traffic. Other best practices include enabling logging and alerting, implementing ACLs, and conducting regular vulnerability assessments.

  3. Q13What type of attack involves overwhelming a network with excessive traffic causing legitimate users to experience delays or denied access?

    • ASQL injection
    • BDistributed denial of service
    • CMan-in-the-middle
    • DPhishing
    Show answer

    ✓ Correct answer: B. Distributed denial of service

    Answer: Distributed denial of service A distributed denial of service (DDoS) attack aims to disrupt normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic. Such attacks often use multiple compromised computer systems as sources of attack traffic.

  4. Q14Which of the following security practices helps in preventing an insider threat by ensuring critical tasks are distributed among multiple people?

    • ALeast privilege
    • BZero trust
    • CRole-based access controls
    • DSeparation of duties
    Show answer

    ✓ Correct answer: D. Separation of duties

    Answer: Separation of duties Separation of duties ensures that critical tasks, especially those prone to fraud or misuse, are divided among multiple individuals. This makes it harder for any single user to abuse their access. Least privilege grants users only the permissions necessary for their job functions, thereby minimizing the potential damage from compromised accounts. Zero trust is a security model that requires strict identity verification and assumes that threats could be both inside and outside the network. Role-based access controls assign permissions based on user roles, streamlining access management within an organization.

  5. Q15Which of the following concepts are associated with ensuring the authenticity and integrity of emails using cryptographic techniques?

    • APGP
    • BFTP
    • CIPsec
    • DSMTP
    Show answer

    ✓ Correct answer: A. PGP

    Answer: PGP Pretty Good Privacy (PGP) uses cryptographic techniques to provide security services such as email authentication and integrity verification. FTP is a protocol for transferring files, IPsec is used for securing internet communication, and SMTP is used for sending email, all of which do not directly provide email authentication or integrity.

  6. Q16Which of the following tools can be used for creating and managing cryptographic keys for network security?

    • AOpenSSL
    • BWireshark
    • CSplunk
    • DHoneypot
    Show answer

    ✓ Correct answer: A. OpenSSL

    Answer: OpenSSL OpenSSL is an open-source toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols. It provides various cryptographic functions including the management of cryptographic keys, certificate generation, and encryption. Wireshark is a network protocol analyzer, not a cryptographic toolkit. Splunk is a security information and event management (SIEM) system. A honeypot is a decoy system designed to detect and distract attackers.

  7. Q17Which of the following protocols is utilized to securely exchange keys over an insecure network?

    • ARSA (Rivest-Shamir-Adleman)
    • BInternet Key Exchange (IKE)
    • CTransport Layer Security (TLS)
    • DSecure/Multipurpose Internet Mail Extensions (S/MIME)
    Show answer

    ✓ Correct answer: B. Internet Key Exchange (IKE)

    Answer: Internet Key Exchange (IKE) Internet Key Exchange (IKE) is a protocol used to set up a secure and authenticated communication channel over an insecure network by securely exchanging encryption keys. Transport Layer Security (TLS) ensures data privacy between client and server communication. Secure/Multipurpose Internet Mail Extensions (S/MIME) provides a way to send encrypted email messages. RSA (Rivest-Shamir-Adleman) is a public-key cryptosystem used for secure data transmission.

  8. Q18Which of the following is NOT a valid ping command?

    • Aping -t
    • Bping unknown
    • Cping 127.0.0.1
    • Dping google.com
    Show answer

    ✓ Correct answer: B. ping unknown

    Answer: ping unknown ping 127.0.0.1, ping google.com, and ping -t are all valid commands. ping unknown is not a valid command.

  9. Q19When fiber optic cables have their glass core fractured, resulting in loss of signal transmission, this is referred to as which of the following?

    • AAttenuation
    • BReflection
    • CDispersion
    • DBreak
    Show answer

    ✓ Correct answer: D. Break

    Answer: Break When the glass core of a fiber optic cable is fractured, it results in a 'break', disrupting the signal transmission. An attenuation occurs when the signal strength decreases over distance. A reflection happens when light bounces back towards the source, causing loss of signal clarity. A dispersion is when light pulses spread out over time within the fiber, affecting the signal quality.

  10. Q20Which command should you use with the ifconfig utility to bring down a network interface in a Linux system?

    • Adown
    • Bdisable
    • Cstop
    • Ddeactivate
    Show answer

    ✓ Correct answer: A. down

    Answer: down The down command deactivates a network interface on a Linux system using ifconfig. The commands disable, stop, and deactivate are not valid for the ifconfig utility.

Free practice here. Timed mocks when you are ready.

Use the free CompTIA Network+ 2026 Prep sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.