Study. uk . com
  1. Home
  2. All questions
  3. Operational security

CompTIA Security+ study material: Operational security

74 questions of the 611 in the CompTIA Security+ quiz. Each opens with its answer, the reasoning and where that is written down.

Challenge yourself on this topic → Study as cards

The questions

  1. 53. A user who clicked a phishing link waits two days before telling anyone, fearing discipline. Which change most directly reduces this delay?
  2. 71. Which parties should an incident response plan identify before an incident occurs?
  3. 101. Why is asset management treated as a security control rather than an IT housekeeping task?
  4. 115. An organisation treats every patch cycle as an emergency and never plans capacity for it. Which framing does NIST recommend instead?
  5. 118. A flaw is being exploited in the wild and no patch exists yet. According to NIST's patch planning guidance, how should the organisation treat this?
  6. 172. Systems are built to a hardened baseline but drift out of compliance within weeks. Which control addresses this?
  7. 175. A patching programme reports the number of patches installed each month. Why is this a weak enterprise-level metric?
  8. 177. Why are logging and monitoring failures serious even though they rarely cause the breach?
  9. 195. A data loss prevention deployment generates constant false positives and misses real exfiltration. What most likely needs fixing first?
  10. 204. Why does an alert from a honeypot carry unusually high confidence?
  11. 215. An organisation's hardening standard was written for an operating system version no longer deployed. What has happened to it?
  12. 222. An email gateway opens attachments in an isolated environment before delivery. Which control is this?
  13. 233. A monitoring team asks for an alert on repeated failed logins in an internal application, but the application emits no such event. What does this illustrate?
  14. 234. Which two attributes should an application security log entry carry to support correlation? Choose two.
  15. 246. What does configuration management provide that makes unauthorised change detectable?
  16. 353. A laptop fails a posture check because its endpoint agent is disabled. What should network access control do?
  17. 364. Which capability does a secrets platform give that a shared static password cannot?
  18. 387. What risk does an intrusion prevention system carry that an intrusion detection system does not?
  19. 388. A team wants detection that can catch previously unseen attack behaviour and accepts more investigation effort. Which approach fits?
  20. 411. A failover to an untested standby fails. Which two causes are most typical? Choose two.
  21. 415. A team wants visibility into traffic without any chance of disrupting it. Which deployment fits?
  22. 423. Why does analysing outbound traffic often reveal an intrusion the perimeter missed?
  23. 426. What do ATT&CK data sources tell a detection team?
  24. 442. On discovering ransomware, an administrator wants to wipe and rebuild the affected servers immediately. What should happen first?
  25. 445. How does an indicator of attack differ from an indicator of compromise?
  26. 448. What distinguishes threat hunting from alert triage?
  27. 455. Why does attachment sandboxing sit alongside link filtering rather than replacing it?
  28. 472. Why does process injection frustrate detection tools that judge activity by process name?
  29. 475. Why should a suspected rootkit infection not be investigated using tools running on the affected host?
  30. 478. Why does fileless malware evade a product that scans files on disk?
  31. 492. During an incident, defenders find their own administrative accounts have been disabled. Which ATT&CK tactic does this serve?
  32. 494. Which sequence lists the four phases of the NIST incident response lifecycle?
  33. 495. Which incident response phase most determines how well the other three go?
  34. 496. An engineer wants to reimage an infected server immediately to remove the malware. Why does NIST place containment before eradication?
  35. 497. Which two considerations does a containment strategy have to trade off? Choose two.
  36. 498. After eradication and recovery, what does NIST expect the team to do?
  37. 499. An organisation handles a major incident well but never holds a review afterwards. What has it lost?
  38. 500. Which dependency is most likely to delay an incident response if it was not settled in advance?
  39. 501. A responder spends hours attributing the attacking IP address during an active intrusion. What is NIST's guidance on this?
  40. 502. Three incidents are open at once. How should they be prioritised?
  41. 503. Which sequence describes the forensic process?
  42. 504. A responder is about to power down a compromised server for imaging. What should be captured first?
  43. 505. Why does the forensic process separate examination from analysis?
  44. 506. Why is forensic examination performed on a copy rather than the original media?
  45. 507. What does recomputing a hash of an evidence image months after acquisition demonstrate?
  46. 508. What does chain of custody add that a verified hash does not?
  47. 509. Litigation is anticipated and the retention schedule is about to delete relevant mailboxes. What must be issued?
  48. 510. An attacker wiped the endpoint's logs before leaving. Which evidence source may still show what was taken?
  49. 511. NIST expects log management duties to be assigned at two levels. Which two?
  50. 512. What is the principal security weakness of base syslog for centralised logging?
  51. 513. Why is log normalisation necessary before correlation?
  52. 514. An investigation cannot establish the order of events across three systems. Which prerequisite was most likely missing?
  53. 515. Why should logs be forwarded off the host promptly?
  54. 516. Why should log retention be planned against investigation needs rather than storage cost alone?
  55. 517. What does a security information and event management system add beyond centralised log storage?
  56. 518. A monitoring team is drowning in alerts nobody can act on. What is the underlying failure?
  57. 519. Which two capabilities does endpoint detection and response give an incident responder? Choose two.
  58. 520. What does extended detection and response add over endpoint detection and response?
  59. 521. What is the primary security benefit of orchestrating a response action rather than performing it manually?
  60. 522. A team scripts a repetitive hardening task. What new risk does this introduce?
  61. 523. Why do the credentials held by an automation platform deserve particular protection?
  62. 524. Which capability lets an organisation retain control of data on a device it does not own?
  63. 525. Under a bring-your-own-device policy, which approach separates corporate data from the owner's personal data?
  64. 526. Which monitoring approach continues to work when the network path to a host is down?
  65. 527. Which control alerts when a file that should never change is modified?
  66. 528. Which sequence describes the vulnerability management cycle the exam expects?
  67. 529. What question does root cause analysis ask that an incident timeline does not?
  68. 530. How do the questions asked by an incident responder and a forensic examiner differ?
  69. 596. Why does NIST advise building detection and analysis capability across the organisation rather than only in the security team?
  70. 597. Why does the forensic collection stage begin with identifying possible data sources?
  71. 598. Which two events should an application always log? Choose two.
  72. 599. Why do logs need their own access control and integrity protection?
  73. 600. What does the reporting step of the vulnerability management cycle achieve?
  74. 601. Which step of the secure baseline process do most programmes skip, and what is the result?