HomeCompTIA Security+ Exam PrepsQuestions 21–30
CompTIA Security+ Exam PrepsPart 3 of 3

CompTIA Security+ Exam Preps Exam Questions & Answers 2026 (21–30)

CompTIA Security+ Exam Preps practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.

Practise CompTIA Security+ Exam Preps questions free, download the PDF, or unlock timed mock exams when you are ready.
Multiple choice — pick the best answer, then reveal it
  1. Q21An organization is implementing a technology to authenticate users locally without involving remote servers. This technology verifies a user's credentials locally on their device. Which of the following is an example of such a localized authentication method suitable for this situation?

    • AKerberos
    • BRADIUS
    • COAuth
    • DSAML
    Show answer

    ✓ Correct answer: A. Kerberos

    Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet. Unlike RADIUS, OAuth, and SAML which are used for remote or internet-based authentication, Kerberos can be utilized for local authentication.

  2. Q22A security administrator at XYZ Corp. is assessing the organization's security controls and identifying any gaps. They have reviewed access controls, logging mechanisms, network segmentation, and encryption protocols, and have conducted a vulnerability assessment. Which of the following control categories is the administrator auditing?

    • ATechnical
    • BAdministrative
    • CPhysical
    • DDetective
    Show answer

    ✓ Correct answer: A. Technical

    Technical controls involve the use of technology to protect systems and data. These controls are installed and configured by administrators and work autonomously to maintain security.

  3. Q23A compliance officer at Tech Solutions Inc. is evaluating different measures to ensure the security of the company's data. They have completed assessments of encrypting sensitive data, implementing security policies, and using biometric access controls. Which of the following control types is being evaluated?

    • ACorrective
    • BCompensating
    • CPreventive
    • DDetective
    Show answer

    ✓ Correct answer: C. Preventive

    Answer: Preventive Preventive controls are security measures that aim to prevent security incidents and breaches. Encrypting sensitive data makes it unreadable to unauthorized users, implementing security policies ensures that employees follow best practices to avoid incidents, and biometric access controls ensure that only authorized individuals can access secure areas or information.

  4. Q24Encryption is an example of which of the following types of security controls?

    • ADeterrent
    • BPreventative
    • CCorrective
    • DCompensating
    Show answer

    ✓ Correct answer: B. Preventative

    Correct answer: Preventative Security controls can be classified into one of six different types, including: Preventative: Preventative controls stop a security incident from occurring. Encryption is an example of preventative control because it protects data before unauthorized access occurs. Corrective: Corrective controls mitigate a security incident after it has occurred. For example, backups are corrective because they can restore data after an incident. Detective: Detective controls identify if a security incident has occurred. Intrusion detection systems (IDS) and monitoring tools are examples of detective controls. Deterrent: Deterrent controls disincentivize an attacker from performing a malicious action. Physical deterrents include things like barbed wire fences or visible CCTV cameras. Compensating: Compensating controls are alternatives to primary controls, often used when ideal controls are infeasible. For instance, hiring a security guard in lieu of a damaged fence. Physical: Physical controls manage or prevent physical access to resources. Examples include locks and fences.

  5. Q25Organizations often rely on threat intelligence platforms to predict and respond to potential cyber threats proactively. These platforms play a key role in safeguarding digital assets by providing real-time information on emerging threats. What is one commonly used threat intelligence platform by security professionals?

    • ACyberduck
    • BMISP
    • CSketchUp
    • DWireshark
    Show answer

    ✓ Correct answer: B. MISP

    Answer: MISP MISP (Malware Information Sharing Platform) is a widely used threat intelligence platform that helps security professionals collect, correlate, and share information about various cyber threats. By leveraging MISP, organizations can enhance their security posture and improve incident response capabilities.

  6. Q26TechSec Inc. experienced a data breach, and the company is currently under investigation by cybersecurity authorities. TechSec Inc. has been ordered to preserve all electronic communications from the past two years pertinent to the investigation. What action has been implemented in this scenario?

    • AAn assertion of the chain of custody
    • BA data encryption mandate
    • CA requirement to perform a vulnerability scan
    • DAn application of a legal hold
    Show answer

    ✓ Correct answer: D. An application of a legal hold

    Answer: An application of a legal hold When an organization is required by legal authorities to retain evidence, it is referred to as a legal hold. This ensures that all relevant data is preserved in its current state until the investigation or litigation is concluded.

  7. Q27A cybersecurity analyst needs to verify that the configuration of two network devices is identical to ensure network integrity. Which of the following actions should they take?

    • ACompare checksums of configuration files
    • BManually review configuration settings
    • CRun a virus scan on the devices
    • DReset to factory settings and reconfigure
    Show answer

    ✓ Correct answer: A. Compare checksums of configuration files

    Answer: Compare checksums of configuration files Comparing the checksums of the configuration files ensures that the configurations are identical without the risk of human error. Checksums provide a reliable method to verify data integrity.

  8. Q28Triage of different security events to determine the most serious threat relies on what type of evidence?

    • AAdmissible
    • BCompetent
    • CCritical
    • DRelevant
    Show answer

    ✓ Correct answer: C. Critical

    Correct answer: Critical During triage in incident response, critical evidence is instrumental in identifying the most serious threats requiring immediate attention. Relevant evidence relates to the matter at hand but may not indicate severity. Admissible evidence is suitable for legal proceedings. Competent evidence is lawfully obtained and credible. To prioritize effectively, it's crucial to distinguish the most critical evidence.

  9. Q29Which of the following tools provides comprehensive cybersecurity threat intelligence reports?

    • ASnort
    • Btcpdump
    • CFireEye
    • DWireshark
    Show answer

    ✓ Correct answer: C. FireEye

    Answer: FireEye FireEye is a leading provider of cybersecurity solutions that offer comprehensive threat intelligence reports, helping organizations to understand and mitigate cybersecurity threats. Wireshark, Snort, and tcpdump are primarily network analysis and packet sniffing tools, used for inspecting network traffic but do not provide comprehensive threat intelligence reports.

  10. Q30Which of the following network devices is the MOST volatile? Device Volatility Router High Firewall Medium Switch Low Backup Server Very Low

    • AFirewall
    • BSwitch
    • CRouter
    • DBackup Server
    Show answer

    ✓ Correct answer: C. Router

    Answer: Router The volatility of network devices refers to how quickly data on the device can be lost or altered. Routers are highly volatile because they store ephemeral data such as routing tables and device configurations that are frequently modified. In contrast, backup servers have very low volatility because they store long-term, persistent data. Device Volatility Router High Firewall Medium Switch Low Backup Server Very Low

Free practice here. Timed mocks when you are ready.

Use the free CompTIA Security+ Exam Preps sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.