- Home
- All questions
- Operational security
CompTIA Security+ study material: Operational security
74 questions of the 611 in the CompTIA Security+ quiz. Each opens with its answer, the reasoning and where that is written down.
Challenge yourself on this topic → Study as cards
The questions
- 53. A user who clicked a phishing link waits two days before telling anyone, fearing discipline. Which change most directly reduces this delay?
- 71. Which parties should an incident response plan identify before an incident occurs?
- 101. Why is asset management treated as a security control rather than an IT housekeeping task?
- 115. An organisation treats every patch cycle as an emergency and never plans capacity for it. Which framing does NIST recommend instead?
- 118. A flaw is being exploited in the wild and no patch exists yet. According to NIST's patch planning guidance, how should the organisation treat this?
- 172. Systems are built to a hardened baseline but drift out of compliance within weeks. Which control addresses this?
- 175. A patching programme reports the number of patches installed each month. Why is this a weak enterprise-level metric?
- 177. Why are logging and monitoring failures serious even though they rarely cause the breach?
- 195. A data loss prevention deployment generates constant false positives and misses real exfiltration. What most likely needs fixing first?
- 204. Why does an alert from a honeypot carry unusually high confidence?
- 215. An organisation's hardening standard was written for an operating system version no longer deployed. What has happened to it?
- 222. An email gateway opens attachments in an isolated environment before delivery. Which control is this?
- 233. A monitoring team asks for an alert on repeated failed logins in an internal application, but the application emits no such event. What does this illustrate?
- 234. Which two attributes should an application security log entry carry to support correlation? Choose two.
- 246. What does configuration management provide that makes unauthorised change detectable?
- 353. A laptop fails a posture check because its endpoint agent is disabled. What should network access control do?
- 364. Which capability does a secrets platform give that a shared static password cannot?
- 387. What risk does an intrusion prevention system carry that an intrusion detection system does not?
- 388. A team wants detection that can catch previously unseen attack behaviour and accepts more investigation effort. Which approach fits?
- 411. A failover to an untested standby fails. Which two causes are most typical? Choose two.
- 415. A team wants visibility into traffic without any chance of disrupting it. Which deployment fits?
- 423. Why does analysing outbound traffic often reveal an intrusion the perimeter missed?
- 426. What do ATT&CK data sources tell a detection team?
- 442. On discovering ransomware, an administrator wants to wipe and rebuild the affected servers immediately. What should happen first?
- 445. How does an indicator of attack differ from an indicator of compromise?
- 448. What distinguishes threat hunting from alert triage?
- 455. Why does attachment sandboxing sit alongside link filtering rather than replacing it?
- 472. Why does process injection frustrate detection tools that judge activity by process name?
- 475. Why should a suspected rootkit infection not be investigated using tools running on the affected host?
- 478. Why does fileless malware evade a product that scans files on disk?
- 492. During an incident, defenders find their own administrative accounts have been disabled. Which ATT&CK tactic does this serve?
- 494. Which sequence lists the four phases of the NIST incident response lifecycle?
- 495. Which incident response phase most determines how well the other three go?
- 496. An engineer wants to reimage an infected server immediately to remove the malware. Why does NIST place containment before eradication?
- 497. Which two considerations does a containment strategy have to trade off? Choose two.
- 498. After eradication and recovery, what does NIST expect the team to do?
- 499. An organisation handles a major incident well but never holds a review afterwards. What has it lost?
- 500. Which dependency is most likely to delay an incident response if it was not settled in advance?
- 501. A responder spends hours attributing the attacking IP address during an active intrusion. What is NIST's guidance on this?
- 502. Three incidents are open at once. How should they be prioritised?
- 503. Which sequence describes the forensic process?
- 504. A responder is about to power down a compromised server for imaging. What should be captured first?
- 505. Why does the forensic process separate examination from analysis?
- 506. Why is forensic examination performed on a copy rather than the original media?
- 507. What does recomputing a hash of an evidence image months after acquisition demonstrate?
- 508. What does chain of custody add that a verified hash does not?
- 509. Litigation is anticipated and the retention schedule is about to delete relevant mailboxes. What must be issued?
- 510. An attacker wiped the endpoint's logs before leaving. Which evidence source may still show what was taken?
- 511. NIST expects log management duties to be assigned at two levels. Which two?
- 512. What is the principal security weakness of base syslog for centralised logging?
- 513. Why is log normalisation necessary before correlation?
- 514. An investigation cannot establish the order of events across three systems. Which prerequisite was most likely missing?
- 515. Why should logs be forwarded off the host promptly?
- 516. Why should log retention be planned against investigation needs rather than storage cost alone?
- 517. What does a security information and event management system add beyond centralised log storage?
- 518. A monitoring team is drowning in alerts nobody can act on. What is the underlying failure?
- 519. Which two capabilities does endpoint detection and response give an incident responder? Choose two.
- 520. What does extended detection and response add over endpoint detection and response?
- 521. What is the primary security benefit of orchestrating a response action rather than performing it manually?
- 522. A team scripts a repetitive hardening task. What new risk does this introduce?
- 523. Why do the credentials held by an automation platform deserve particular protection?
- 524. Which capability lets an organisation retain control of data on a device it does not own?
- 525. Under a bring-your-own-device policy, which approach separates corporate data from the owner's personal data?
- 526. Which monitoring approach continues to work when the network path to a host is down?
- 527. Which control alerts when a file that should never change is modified?
- 528. Which sequence describes the vulnerability management cycle the exam expects?
- 529. What question does root cause analysis ask that an incident timeline does not?
- 530. How do the questions asked by an incident responder and a forensic examiner differ?
- 596. Why does NIST advise building detection and analysis capability across the organisation rather than only in the security team?
- 597. Why does the forensic collection stage begin with identifying possible data sources?
- 598. Which two events should an application always log? Choose two.
- 599. Why do logs need their own access control and integrity protection?
- 600. What does the reporting step of the vulnerability management cycle achieve?
- 601. Which step of the secure baseline process do most programmes skip, and what is the result?