Skip to main content
CompTIA Security+
Free practice questions12

Free CompTIA Security+ practice questions

Real exam-format questions from the CertBase CompTIA Security+ bank — pick an answer and the answer key and explanation follow. No signup needed.

500 questions in the full bank · Bank updated July 2026

Question 01

A bank's governance framework requires that its information security policies be formally reviewed and reapproved at defined intervals and whenever a major business or regulatory change occurs, to ensure they remain current and relevant. Which stage of the policy lifecycle does this requirement address?

Question 02

An application security team debates two techniques: one inspects source code without executing it, flagging insecure patterns as developers write, and the other tests the running application by sending inputs and observing responses to find runtime-only flaws. Which statement correctly distinguishes static from dynamic analysis?

Question 03

A bank's security awareness team runs monthly simulated phishing and tracks the percentage of employees who click, watching the trend decline over time as evidence the program is effective. Which type of metric is the team using?

Question 04

A bank wants its SOC to detect insider data theft where an employee with legitimate access downloads unusually large volumes of customer records compared to their peers in the same role. Which analytic approach is BEST suited to catch this?

Question 05

A university's IDS flags active exploitation of a flaw in its PDF-rendering library; the vendor confirms it was previously unaware of the flaw and no patch or advisory exists. Which type of vulnerability is being exploited?

Question 06

A supply-chain consortium wants a shared, distributed ledger of shipment handoffs that no single member controls, where each block is cryptographically linked to its predecessor so any tampering with past records is evident to all participants. Which technology provides this?

Question 07

A bank's application generates session identifiers derived from a poorly seeded value, and an attacker who registers a single account finds that by generating a large number of accounts he can force two of them to be issued the same session token, exploiting the mathematical likelihood of a shared value across many samples far sooner than trying every possible token. Which attack principle is being leveraged?

Question 08

A bank's leadership formally states the organization will accept only minimal cybersecurity risk in pursuit of its strategic goals, setting the overall tone that guides all subordinate risk decisions. Which concept does this statement represent?

Question 09

An energy utility deploys convincing fake control-system HMI screens and decoy engineering workstations on an isolated segment, then feeds them fabricated but realistic traffic, purely to attract and study attackers who breach the perimeter. Analysts want to observe adversary techniques across multiple interconnected decoys at once. Which deception technology is this?

Question 10

A brokerage must automatically inspect outbound email for customer account-number patterns and block or quarantine such messages before they leave the organization. Which solution addresses this?

Question 11

A bank's board sets an overall philosophy stating it will accept only a low level of cybersecurity risk in pursuit of its objectives. Separately, for its transaction-monitoring system, management defines that no more than 2% of alerts may go unreviewed beyond 24 hours before corrective action is triggered. Which statement correctly distinguishes these two concepts?

Question 12

Customers of a commercial bank whose real domain is bankofmeridian.com report reaching a credential-harvesting site after mistyping the address as bankofmeridain.com, a domain an attacker registered to capture fat-finger traffic. Which attack does the attacker's domain registration represent?

Detailed explanations like these run throughout the full bank.

One-time payment

Want the other 488 questions?

The full CompTIA Security+ bank includes 500 questions with detailed explanations, progress tracking, and performance analytics. Pay once, keep it forever — no subscription.

Get the full bank — $19.99

30-day money-back guarantee · Secure payment via Paddle