HomeCompTIA Security+ Exam PrepsQuestions 11–20
CompTIA Security+ Exam PrepsPart 2 of 3

CompTIA Security+ Exam Preps Exam Questions & Answers 2026 (11–20)

CompTIA Security+ Exam Preps practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.

Practise CompTIA Security+ Exam Preps questions free, download the PDF, or unlock timed mock exams when you are ready.
Multiple choice — pick the best answer, then reveal it
  1. Q11A network administrator is looking to implement secure file transfer across the organization's internal network. The network already has a PKI set up for internal use, and the administrator wants to leverage this existing infrastructure. Which of the following protocols should they implement?

    • AHTTP
    • BFTPS
    • CFTP
    • DSCP
    Show answer

    ✓ Correct answer: B. FTPS

    Answer: FTPS FTPS (File Transfer Protocol Secure) allows for secure file transfer and utilizes SSL/TLS for encryption. It can leverage a Public Key Infrastructure (PKI) to manage certificates, ensuring secure and authenticated transfers across the network.

  2. Q12Which software development methodology was introduced by Kent Beck and emphasizes customer satisfaction, speed, and flexibility?

    • AScrum
    • BLean
    • CExtreme Programming (XP)
    • DWaterfall
    Show answer

    ✓ Correct answer: C. Extreme Programming (XP)

    Answer: Extreme Programming (XP) Extreme Programming (XP) is a software development methodology that emphasizes customer satisfaction, speed, and flexibility. Developed by Kent Beck, XP encourages frequent releases in short development cycles, which improves productivity and introduces checkpoints at which new customer requirements can be adopted. Waterfall, Scrum, and Lean are also software development methodologies but have different principles and practices focused on other aspects of software development.

  3. Q13An IT administrator needs to configure firewall rules and wants to specify which types of network traffic are permissible. What part of the firewall rules specifies the traffic that should be allowed?

    • ADeny rule
    • BLog rule
    • CMonitor rule
    • DAllow rule
    Show answer

    ✓ Correct answer: D. Allow rule

    Answer: Allow rule Firewall rules consist of different directives for various types of network traffic. An allow rule specifies the traffic that is explicitly permitted to pass through the firewall. Conversely, a deny rule blocks specified traffic. Log rules may record details about traffic without necessarily allowing or denying it, and monitor rules could be used to observe traffic patterns.

  4. Q14Which of the following methods is designed to discover encryption keys by trying common phrases and words?

    • APassword spraying attack
    • BDictionary attack
    • CBrute force attack
    • DRainbow table attack
    Show answer

    ✓ Correct answer: B. Dictionary attack

    Answer: Dictionary attack A dictionary attack targets encryption keys by trying variants of common phrases and words, similar to how it targets passwords. A brute force attack attempts every possible key, which guarantees eventual success but can be time-consuming. A rainbow table attack involves precomputing a lookup table for keys and their hashes, effective against unsalted encryption. Password spraying attacks use a single weak key on many different encrypted files or accounts.

  5. Q15An attacker has intercepted an encrypted communications channel and managed to obtain encrypted messages. They then utilize a precomputed set of hash values to recover the original messages. Which type of attack employs precomputed hash values to decrypt previously intercepted encrypted data?

    • ARainbow table attack
    • BBrute force attack
    • CMan-in-the-middle attack
    • DPhishing attack
    Show answer

    ✓ Correct answer: A. Rainbow table attack

    Rainbow table attacks utilize precomputed hash tables to quickly convert encrypted hash values back to their original plaintext form without brute-force computation.

  6. Q16A financial analyst within a company receives a personalized email that requests an Excel file containing the latest quarterly earnings report. The email appears to be from a senior executive and includes specific details about recent company meetings. What type of targeted phishing attack is this?

    • AWhaling
    • BPharming
    • CTailgating
    • DSpear phishing
    Show answer

    ✓ Correct answer: D. Spear phishing

    Spear phishing attacks are highly targeted attacks where attackers use specific information about the victim or their organization to make the attack seem more credible. In this case, the attacker uses details about recent meetings to make the financial analyst believe the email is legitimate.

  7. Q17A university decided to force students to use their campus network and not personal cellular data. They used a device to interrupt students' cellular signals, making it difficult for them to access the network via their mobile data. Which of the following devices did they MOST LIKELY use?

    • ALoad balancers
    • BProxy servers
    • CCellular jammers
    • DFirewalls
    Show answer

    ✓ Correct answer: C. Cellular jammers

    Answer: Cellular jammers Cellular jammers can be used to interrupt cellular signals. They can be employed to disrupt mobile data connections by creating interference that blocks mobile communication.

  8. Q18During a wireless authentication process, a user unknowingly connects to a rogue access point masquerading as a legitimate one. This allows an attacker to intercept and eavesdrop on all communications between the user and the actual network. Which type of attack permits an attacker to intercept and monitor communications by deceiving the user into connecting to a rogue network?

    • ADNS Poisoning
    • BTrojan Horse
    • CEvil Twin
    • DPhishing
    Show answer

    ✓ Correct answer: C. Evil Twin

    Answer: Evil Twin. An evil twin attack involves setting up a rogue access point that appears to be legitimate, tricking users into connecting to it. Once the connection is established, the attacker can intercept and eavesdrop on the communications between the user and the actual network. This type of attack exploits the wireless authentication process.

  9. Q19An IT manager receives an urgent email from someone claiming to be the CEO requesting immediate access to confidential files. What term describes the tactic used by the attacker in this social engineering scenario?

    • APretexting
    • BPhishing
    • CSpear phishing
    • DWatering hole attack
    Show answer

    ✓ Correct answer: A. Pretexting

    Answer: Pretexting Pretexting is part of social engineering. The attacker creates a convincing scenario or pretext to deceive the victim into revealing sensitive information, often impersonating someone in a position of authority or trust.

  10. Q20An employee at Johnson Corp. notices that their computer is running slower than usual and sees multiple pop-up messages claiming that the system is heavily corrupted. The messages suggest downloading an urgent security update to fix the problem. After installing the suggested update, the employee finds more warnings about system infections and a further decline in computer performance. What is the MOST LIKELY cause of the issue?

    • ATrojan
    • BRansomware
    • CAdware
    • DPhishing
    Show answer

    ✓ Correct answer: A. Trojan

    Answer: Trojan Trojans often mimic legitimate software, attempting to trick users into installing them. In many cases, these are disguised as security updates or antivirus software. Once installed, they can cause significant damage, including additional malware installations and system slowdowns, often leading to the system becoming unusable.

Free practice here. Timed mocks when you are ready.

Use the free CompTIA Security+ Exam Preps sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.