Study. uk . com
  1. Home
  2. All questions
  3. Security architecture

CompTIA Security+ study material: Security architecture

92 questions of the 611 in the CompTIA Security+ quiz. Each opens with its answer, the reasoning and where that is written down.

Challenge yourself on this topic → Study as cards

The questions

  1. 74. A team chooses a cloud region purely on latency. Which consideration have they overlooked?
  2. 98. Why do redundant power and environmental monitoring belong in a contingency plan rather than only in daily operations?
  3. 117. A legacy control system cannot be patched and cannot be replaced this year. What does NIST expect the organisation to produce for it?
  4. 136. A team must assess a fragile industrial network without risking an outage. Which technique fits?
  5. 166. Which virtualisation weakness would affect every tenant sharing a host?
  6. 167. Which two weaknesses account for most cloud security incidents? Choose two.
  7. 212. An electronically controlled fire door loses power. Which design choice should govern its behaviour, and why?
  8. 231. What security benefit does defining infrastructure as code provide?
  9. 232. Under an immutable infrastructure model, how is a compromised host handled?
  10. 237. A two-node cluster is described as highly available, but both nodes attach to one storage array. What is the flaw?
  11. 238. An organisation runs every web server on the same operating system and vendor stack. Which resilience principle is missing?
  12. 239. A data centre has an uninterruptible power supply but no generator. Which outage is it unable to survive?
  13. 243. An air-gapped network has no connectivity to any other network. Where does its risk concentrate?
  14. 315. At every assurance level, what does NIST require of the channel between the claimant and the verifier?
  15. 340. Which two requirements does NIST place on remote access? Choose two.
  16. 342. What does zero trust replace as the basis for granting access?
  17. 343. In a zero trust architecture, which component sits in the data path and applies the verdict?
  18. 344. A user is granted access to the finance application under zero trust. What does this imply about the reporting database next door?
  19. 345. Why is "we have implemented zero trust" a poor summary of an organisation's position under the CISA maturity model?
  20. 346. An attacker compromises a workstation in the marketing VLAN. Which control most directly limits how far they can reach?
  21. 347. Two application servers sit on the same subnet but cannot communicate unless policy permits it. Which technique is in use?
  22. 352. In an 802.1X deployment, which role does the switch or wireless access point play?
  23. 355. A user's device falls out of compliance halfway through an authenticated session. Under zero trust, what should happen?
  24. 357. Why does the order of entries in a firewall access list matter?
  25. 361. Which external inputs may a zero trust policy engine consult when scoring a request?
  26. 362. What is the purpose of a jump server for administrative access?
  27. 365. An organisation enables split tunnelling on its VPN to reduce bandwidth. What is the security trade-off?
  28. 369. Which description of zero trust's effect on the perimeter is most accurate?
  29. 372. A request arrives from a server inside the corporate data centre. Under zero trust, how should it be treated?
  30. 373. Under zero trust's first tenet, which of the following counts as a resource?
  31. 374. Which two inputs feed a dynamic zero trust access decision? Choose two.
  32. 375. NIST divides the zero trust policy decision point into two logical components. Which pair?
  33. 376. Which two are recognised approaches to implementing a zero trust architecture? Choose two.
  34. 377. A zero trust enforcement point adds several seconds to every request. Why is this a design failure and not merely a performance issue?
  35. 378. Why does patching an industrial control system follow different rules from patching an office server?
  36. 379. Which two properties make Internet-of-Things devices difficult to secure? Choose two.
  37. 380. Under the cloud shared responsibility model, who is responsible for configuring identity permissions on a storage service?
  38. 381. How does the customer's responsibility change moving from infrastructure as a service to software as a service?
  39. 382. Why is isolation between containers weaker than between virtual machines?
  40. 383. An organisation places its public web servers between an external and an internal filtering layer. What is this design called, and what does it achieve?
  41. 384. What can a stateful firewall do that a stateless packet filter cannot without broad permissive rules?
  42. 385. An application tunnels its traffic over port 443 to avoid filtering. Which control identifies it anyway?
  43. 386. Which device can block a SQL injection attempt inside an otherwise permitted HTTPS session?
  44. 387. What risk does an intrusion prevention system carry that an intrusion detection system does not?
  45. 388. A team wants detection that can catch previously unseen attack behaviour and accepts more investigation effort. Which approach fits?
  46. 389. How does DNS filtering interrupt an intrusion before any connection is made?
  47. 390. Which device protects and load-balances inbound traffic to servers, as opposed to controlling outbound user traffic?
  48. 391. An organisation terminates TLS at its load balancer. What is the security trade-off?
  49. 392. Why is out-of-band management valuable during an incident?
  50. 393. Why does every TLS 1.3 handshake provide forward secrecy?
  51. 394. Which two features were removed in TLS 1.3? Choose two.
  52. 395. An API adopts TLS 1.3 zero-round-trip resumption for speed. Which request must not be sent as early data?
  53. 396. A site serves its login page over HTTPS and the rest over HTTP. Why is this insufficient?
  54. 397. Which mechanism closes the window opened by a user typing a bare hostname and being redirected from HTTP to HTTPS?
  55. 398. A phishing site presents a valid domain-validated certificate. What does this certificate actually prove?
  56. 399. What risk does a wildcard certificate concentrate?
  57. 400. What does a certificate signing request contain?
  58. 401. A browser warns about a self-signed certificate on an internal site. What is actually missing?
  59. 402. What does the three-two-one backup guidance require?
  60. 403. A team needs the fastest possible restore and accepts a long backup window. Which scheme fits?
  61. 404. Restoring from a differential backup scheme requires which media?
  62. 405. Why is a storage snapshot not a substitute for a backup?
  63. 406. An organisation relies on synchronous replication to a second site as its ransomware defence. What is the flaw?
  64. 407. An organisation needs to resume operations within an hour of a site loss and can fund it. Which alternate site type fits?
  65. 408. What is the tension in choosing the location of an alternate processing site?
  66. 409. Two data centres are twenty kilometres apart on the same power grid and flood plain. Which resilience property is not actually achieved?
  67. 410. A team selects a hot site before running the business impact analysis. What is the problem with that order?
  68. 411. A failover to an untested standby fails. Which two causes are most typical? Choose two.
  69. 412. What is the main security difference between wireless personal mode and enterprise mode?
  70. 413. Which weakness of WPA2 personal did WPA3 address by replacing the handshake?
  71. 414. An administrator disables broadcast of the wireless network name as a security measure. Why is this ineffective?
  72. 415. A team wants visibility into traffic without any chance of disrupting it. Which deployment fits?
  73. 416. An inline security appliance fails. Which design choice preserves control rather than availability?
  74. 417. A new storage medium has no vendor-supported sanitisation command. What follows for the organisation?
  75. 418. A patch programme covers operating systems and applications but not firmware. What is the consequence?
  76. 450. Why is an untrusted wireless network a threat vector even when both endpoints are patched?
  77. 480. Why does blocking by source address fail against a distributed denial-of-service attack?
  78. 481. An attacker sends small spoofed requests to a service that replies with much larger responses aimed at the victim. What is this technique?
  79. 482. A user reaches an attacker's server while the address bar still shows the expected domain name. Which manipulation explains this?
  80. 483. How does an attacker take an on-path position inside a local network segment?
  81. 484. An attacker sets up an access point broadcasting the same network name as the corporate wireless. Why is this effective?
  82. 485. What are the two uses of a wireless deauthentication attack?
  83. 512. What is the principal security weakness of base syslog for centralised logging?
  84. 545. Why do protocols such as TLS use asymmetric cryptography only to establish a symmetric session key?
  85. 550. A mobile application pins the certificate of its backend. What does this prevent, and what does it complicate?
  86. 557. Why can a protocol using only static long-term keys not provide forward secrecy?
  87. 606. Under zero trust, when is trust in a requester evaluated and with what privilege granted?
  88. 607. Which two are architecture models the exam expects to be compared? Choose two.
  89. 608. Besides forward secrecy, what did TLS 1.3 improve about the handshake?
  90. 609. An organisation's backup server is domain-joined and reachable with production administrator credentials. Why does this defeat the backup's purpose?
  91. 610. How does continuity of operations planning differ from information system contingency planning?
  92. 611. Which two systems fall under the definition of operational technology? Choose two.