- Home
- All questions
- Security architecture
CompTIA Security+ study material: Security architecture
92 questions of the 611 in the CompTIA Security+ quiz. Each opens with its answer, the reasoning and where that is written down.
Challenge yourself on this topic → Study as cards
The questions
- 74. A team chooses a cloud region purely on latency. Which consideration have they overlooked?
- 98. Why do redundant power and environmental monitoring belong in a contingency plan rather than only in daily operations?
- 117. A legacy control system cannot be patched and cannot be replaced this year. What does NIST expect the organisation to produce for it?
- 136. A team must assess a fragile industrial network without risking an outage. Which technique fits?
- 166. Which virtualisation weakness would affect every tenant sharing a host?
- 167. Which two weaknesses account for most cloud security incidents? Choose two.
- 212. An electronically controlled fire door loses power. Which design choice should govern its behaviour, and why?
- 231. What security benefit does defining infrastructure as code provide?
- 232. Under an immutable infrastructure model, how is a compromised host handled?
- 237. A two-node cluster is described as highly available, but both nodes attach to one storage array. What is the flaw?
- 238. An organisation runs every web server on the same operating system and vendor stack. Which resilience principle is missing?
- 239. A data centre has an uninterruptible power supply but no generator. Which outage is it unable to survive?
- 243. An air-gapped network has no connectivity to any other network. Where does its risk concentrate?
- 315. At every assurance level, what does NIST require of the channel between the claimant and the verifier?
- 340. Which two requirements does NIST place on remote access? Choose two.
- 342. What does zero trust replace as the basis for granting access?
- 343. In a zero trust architecture, which component sits in the data path and applies the verdict?
- 344. A user is granted access to the finance application under zero trust. What does this imply about the reporting database next door?
- 345. Why is "we have implemented zero trust" a poor summary of an organisation's position under the CISA maturity model?
- 346. An attacker compromises a workstation in the marketing VLAN. Which control most directly limits how far they can reach?
- 347. Two application servers sit on the same subnet but cannot communicate unless policy permits it. Which technique is in use?
- 352. In an 802.1X deployment, which role does the switch or wireless access point play?
- 355. A user's device falls out of compliance halfway through an authenticated session. Under zero trust, what should happen?
- 357. Why does the order of entries in a firewall access list matter?
- 361. Which external inputs may a zero trust policy engine consult when scoring a request?
- 362. What is the purpose of a jump server for administrative access?
- 365. An organisation enables split tunnelling on its VPN to reduce bandwidth. What is the security trade-off?
- 369. Which description of zero trust's effect on the perimeter is most accurate?
- 372. A request arrives from a server inside the corporate data centre. Under zero trust, how should it be treated?
- 373. Under zero trust's first tenet, which of the following counts as a resource?
- 374. Which two inputs feed a dynamic zero trust access decision? Choose two.
- 375. NIST divides the zero trust policy decision point into two logical components. Which pair?
- 376. Which two are recognised approaches to implementing a zero trust architecture? Choose two.
- 377. A zero trust enforcement point adds several seconds to every request. Why is this a design failure and not merely a performance issue?
- 378. Why does patching an industrial control system follow different rules from patching an office server?
- 379. Which two properties make Internet-of-Things devices difficult to secure? Choose two.
- 380. Under the cloud shared responsibility model, who is responsible for configuring identity permissions on a storage service?
- 381. How does the customer's responsibility change moving from infrastructure as a service to software as a service?
- 382. Why is isolation between containers weaker than between virtual machines?
- 383. An organisation places its public web servers between an external and an internal filtering layer. What is this design called, and what does it achieve?
- 384. What can a stateful firewall do that a stateless packet filter cannot without broad permissive rules?
- 385. An application tunnels its traffic over port 443 to avoid filtering. Which control identifies it anyway?
- 386. Which device can block a SQL injection attempt inside an otherwise permitted HTTPS session?
- 387. What risk does an intrusion prevention system carry that an intrusion detection system does not?
- 388. A team wants detection that can catch previously unseen attack behaviour and accepts more investigation effort. Which approach fits?
- 389. How does DNS filtering interrupt an intrusion before any connection is made?
- 390. Which device protects and load-balances inbound traffic to servers, as opposed to controlling outbound user traffic?
- 391. An organisation terminates TLS at its load balancer. What is the security trade-off?
- 392. Why is out-of-band management valuable during an incident?
- 393. Why does every TLS 1.3 handshake provide forward secrecy?
- 394. Which two features were removed in TLS 1.3? Choose two.
- 395. An API adopts TLS 1.3 zero-round-trip resumption for speed. Which request must not be sent as early data?
- 396. A site serves its login page over HTTPS and the rest over HTTP. Why is this insufficient?
- 397. Which mechanism closes the window opened by a user typing a bare hostname and being redirected from HTTP to HTTPS?
- 398. A phishing site presents a valid domain-validated certificate. What does this certificate actually prove?
- 399. What risk does a wildcard certificate concentrate?
- 400. What does a certificate signing request contain?
- 401. A browser warns about a self-signed certificate on an internal site. What is actually missing?
- 402. What does the three-two-one backup guidance require?
- 403. A team needs the fastest possible restore and accepts a long backup window. Which scheme fits?
- 404. Restoring from a differential backup scheme requires which media?
- 405. Why is a storage snapshot not a substitute for a backup?
- 406. An organisation relies on synchronous replication to a second site as its ransomware defence. What is the flaw?
- 407. An organisation needs to resume operations within an hour of a site loss and can fund it. Which alternate site type fits?
- 408. What is the tension in choosing the location of an alternate processing site?
- 409. Two data centres are twenty kilometres apart on the same power grid and flood plain. Which resilience property is not actually achieved?
- 410. A team selects a hot site before running the business impact analysis. What is the problem with that order?
- 411. A failover to an untested standby fails. Which two causes are most typical? Choose two.
- 412. What is the main security difference between wireless personal mode and enterprise mode?
- 413. Which weakness of WPA2 personal did WPA3 address by replacing the handshake?
- 414. An administrator disables broadcast of the wireless network name as a security measure. Why is this ineffective?
- 415. A team wants visibility into traffic without any chance of disrupting it. Which deployment fits?
- 416. An inline security appliance fails. Which design choice preserves control rather than availability?
- 417. A new storage medium has no vendor-supported sanitisation command. What follows for the organisation?
- 418. A patch programme covers operating systems and applications but not firmware. What is the consequence?
- 450. Why is an untrusted wireless network a threat vector even when both endpoints are patched?
- 480. Why does blocking by source address fail against a distributed denial-of-service attack?
- 481. An attacker sends small spoofed requests to a service that replies with much larger responses aimed at the victim. What is this technique?
- 482. A user reaches an attacker's server while the address bar still shows the expected domain name. Which manipulation explains this?
- 483. How does an attacker take an on-path position inside a local network segment?
- 484. An attacker sets up an access point broadcasting the same network name as the corporate wireless. Why is this effective?
- 485. What are the two uses of a wireless deauthentication attack?
- 512. What is the principal security weakness of base syslog for centralised logging?
- 545. Why do protocols such as TLS use asymmetric cryptography only to establish a symmetric session key?
- 550. A mobile application pins the certificate of its backend. What does this prevent, and what does it complicate?
- 557. Why can a protocol using only static long-term keys not provide forward secrecy?
- 606. Under zero trust, when is trust in a requester evaluated and with what privilege granted?
- 607. Which two are architecture models the exam expects to be compared? Choose two.
- 608. Besides forward secrecy, what did TLS 1.3 improve about the handshake?
- 609. An organisation's backup server is domain-joined and reachable with production administrator credentials. Why does this defeat the backup's purpose?
- 610. How does continuity of operations planning differ from information system contingency planning?
- 611. Which two systems fall under the definition of operational technology? Choose two.