Domain 1.0 — General Security Concepts¶
← Back to Security+ overview · Domain weight: 12%
Q001. Control type: badge reader¶
A data center requires employees to scan a badge before entering the server room. What type of control is this primarily?
- A. Detective
- B. Preventive
- C. Corrective
- D. Compensating
Answer: B — Preventive
Why: The badge reader blocks unauthorized access before it occurs. A log from the badge reader may also support detection later, but its primary purpose is preventive.
Q002. Control type: security policy¶
A company publishes a policy requiring all removable media to be encrypted. Which control type best describes the policy itself?
- A. Directive
- B. Corrective
- C. Detective
- D. Physical
Answer: A — Directive
Why: A directive control tells users what behavior is required. Encryption software would be technical; the written rule is directive.
Q003. CIA triad: altered records¶
An attacker changes payroll direct-deposit account numbers in a database. Which part of the CIA triad is most directly violated?
- A. Confidentiality
- B. Integrity
- C. Availability
- D. Non-repudiation
Answer: B — Integrity
Why: Integrity means data remains accurate and unmodified except by authorized action.
Q004. CIA triad: ransomware outage¶
A file server is encrypted by ransomware and users cannot access shared files. Which CIA goal is most directly affected?
- A. Confidentiality
- B. Integrity
- C. Availability
- D. Obfuscation
Answer: C — Availability
Why: The primary business impact is that legitimate users cannot access needed resources.
Q005. Non-repudiation¶
A legal department wants proof that a specific executive approved a signed contract and cannot credibly deny it later. Which technology best supports this?
- A. Symmetric encryption
- B. Digital signature
- C. Tokenization
- D. Data masking
Answer: B — Digital signature
Why: A digital signature created with a private key supports integrity, authentication, and non-repudiation.
Q006. Authentication vs authorization¶
A user successfully enters a password, then is denied access to a payroll application because they are not in the HR group. What failed?
- A. Identification
- B. Authentication
- C. Authorization
- D. Accounting
Answer: C — Authorization
Why: Authentication proved identity. Authorization determines what that authenticated identity may access.
Q007. Accounting¶
Which control best supports accountability by recording who accessed a system and what actions they performed?
- A. Audit logging
- B. Encryption
- C. Load balancing
- D. Tokenization
Answer: A — Audit logging
Why: Accounting depends on reliable logs showing actions tied to identities.
Q008. Zero trust principle¶
A company removes broad network trust and requires device health checks, identity verification, and least-privilege access for each application request. What model is being applied?
- A. Implicit trust
- B. Zero trust
- C. Air gapping
- D. Security through obscurity
Answer: B — Zero trust
Why: Zero trust assumes no implicit trust based only on network location and continuously evaluates access decisions.
Q009. Least privilege¶
A database administrator needs read-only access to production logs but not write access to customer tables. Which principle applies?
- A. Separation of duties
- B. Least privilege
- C. Obfuscation
- D. Non-repudiation
Answer: B — Least privilege
Why: The user should receive only the minimum access needed to perform the task.
Q010. Separation of duties¶
One employee can create vendors, approve invoices, and release payments. What control weakness is present?
- A. Lack of separation of duties
- B. Weak encryption
- C. Poor availability
- D. Inadequate masking
Answer: A — Lack of separation of duties
Why: Critical financial steps should be split so one person cannot complete fraud end-to-end.
Q011. Change management¶
A firewall rule change is made directly in production without testing or approval and causes an outage. Which process would most directly reduce this risk?
- A. Change management
- B. Data classification
- C. Tokenization
- D. Threat hunting
Answer: A — Change management
Why: Change management provides review, approval, testing, backout planning, and documentation for changes.
Q012. Hashing vs encryption¶
A security engineer needs to verify that a downloaded ISO was not modified. Which mechanism is most appropriate?
- A. Hash comparison
- B. Symmetric encryption
- C. Data masking
- D. Steganography
Answer: A — Hash comparison
Why: Hashes provide integrity verification. Encryption protects confidentiality, not proof of unchanged content by itself.
Q013. Encryption at rest¶
A laptop may be stolen from an employee's car. Which control best protects the data if the laptop is powered off?
- A. Full-disk encryption
- B. Screen lock only
- C. IDS sensor
- D. DLP email rule
Answer: A — Full-disk encryption
Why: Full-disk encryption protects stored data if the physical device is lost or stolen.
Q014. PKI trust¶
A browser trusts a website certificate because the certificate chains back to a trusted root. Which system provides this trust model?
- A. RADIUS
- B. PKI
- C. Kerberos
- D. TACACS+
Answer: B — PKI
Why: Public key infrastructure uses certificate authorities, certificates, and trust chains.
Q015. Obfuscation¶
A developer renames variables and removes readable symbols before releasing client-side code. What is this mainly intended to do?
- A. Make reverse engineering harder
- B. Provide strong encryption
- C. Replace authentication
- D. Guarantee integrity
Answer: A — Make reverse engineering harder
Why: Obfuscation raises effort but is not equivalent to encryption or access control.
Q016. Physical deterrent¶
A sign outside a restricted area says "24-hour video monitoring." Which control type is the sign primarily?
- A. Preventive
- B. Detective
- C. Deterrent
- D. Corrective
Answer: C — Deterrent
Why: The sign discourages behavior. Cameras may be detective, but the sign itself is deterrent.
Q017. Compensating control¶
A legacy system cannot support MFA. The organization restricts access to a jump host, enables session recording, and limits access to a small admin group. What are these added measures?
- A. Compensating controls
- B. Corrective controls
- C. Open controls
- D. Inherent controls
Answer: A — Compensating controls
Why: They reduce risk when the preferred control cannot be implemented.
Q018. Data minimization¶
A sign-up form asks for Social Security numbers even though the service only needs an email address. Which privacy/security principle is being violated?
- A. Data minimization
- B. Non-repudiation
- C. Federation
- D. Hashing
Answer: A — Data minimization
Why: Collect only data needed for the stated purpose. Less stored sensitive data means less breach impact.
Q124. OAuth ID token versus access token¶
A developer uses an OAuth/OIDC access token as proof that the user authenticated and displays the username from it without validation. What is the best correction?
- A. Use the ID token for user authentication claims and validate issuer, audience, signature, and expiration
- B. Use the refresh token in the browser because it lasts longer
- C. Store the access token in localStorage and trust the username claim
- D. Disable token expiration to avoid reauthentication failures
Answer: A — Use the ID token for user authentication claims and validate issuer, audience, signature, and expiration
Why: OIDC adds identity on top of OAuth. ID tokens carry authentication claims and still require validation. Access tokens are primarily authorization artifacts for APIs.
Q125. SAML assertion signature placement¶
An enterprise SSO integration accepts unsigned SAML assertions if the outer response is signed. What attack class is this most likely to enable?
- A. XML signature wrapping
- B. DNS cache poisoning
- C. Pass-the-hash
- D. ARP spoofing
Answer: A — XML signature wrapping
Why: SAML/XML signature wrapping abuses parsing differences and unsigned or incorrectly validated assertion elements. The application must validate the exact signed assertion it consumes.
Q126. RADIUS versus TACACS+¶
A network team wants centralized admin login for routers and wants command authorization and accounting separated from authentication. Which protocol is usually the better fit?
- A. RADIUS
- B. TACACS+
- C. SNMPv3
- D. LDAP
Answer: B — TACACS+
Why: TACACS+ separates authentication, authorization, and accounting and is commonly used for network device administration. RADIUS is common for network access authentication.
Q127. ABAC decision inputs¶
Which authorization model is best when access depends on user department, device health, data classification, location, and time of day?
- A. DAC
- B. MAC
- C. ABAC
- D. Rule-based firewall ACL only
Answer: C — ABAC
Why: Attribute-based access control evaluates attributes of users, resources, actions, and environment. It maps well to conditional access and zero trust decisions.
Q128. HMAC use case¶
A service sends messages over an already encrypted channel but still needs to prove that each message came from a holder of a shared secret and was not modified. What should it use?
- A. Plain SHA-256 hash
- B. HMAC
- C. Base64 encoding
- D. Symmetric encryption without authentication
Answer: B — HMAC
Why: HMAC combines a cryptographic hash with a secret key to provide integrity and authenticity. A plain hash only detects accidental change if the expected hash is trusted.
Q129. AEAD versus encrypt-then-ignore¶
A developer encrypts JSON with AES-CBC but does not authenticate the ciphertext. What is the strongest design improvement?
- A. Use an AEAD mode such as AES-GCM or ChaCha20-Poly1305
- B. Base64 encode the ciphertext twice
- C. Use a shorter IV to save space
- D. Compress after encryption
Answer: A — Use an AEAD mode such as AES-GCM or ChaCha20-Poly1305
Why: AEAD provides confidentiality and integrity/authentication together. Unauthenticated CBC designs can be vulnerable to padding-oracle and tampering attacks.
Q130. Perfect forward secrecy¶
Which TLS property limits the damage if the server private key is stolen months after traffic was captured?
- A. Certificate pinning
- B. Perfect forward secrecy from ephemeral key exchange
- C. OCSP stapling
- D. Wildcard certificate usage
Answer: B — Perfect forward secrecy from ephemeral key exchange
Why: PFS uses ephemeral session keys so old sessions cannot be decrypted solely from a later theft of the server private key.
Q131. OCSP stapling¶
What problem does OCSP stapling primarily address?
- A. It lets a server provide recent certificate revocation status without every client querying the CA directly
- B. It encrypts DNS lookups
- C. It prevents SQL injection
- D. It replaces certificate expiration
Answer: A — It lets a server provide recent certificate revocation status without every client querying the CA directly
Why: OCSP stapling improves revocation checking privacy and performance by having the server staple a signed OCSP response during the TLS handshake.
Q132. Certificate pinning tradeoff¶
A mobile app pins a single leaf certificate. The certificate expires unexpectedly and users cannot connect. What was the design mistake?
- A. Pinning only one brittle certificate instead of a managed key/pin set with rotation strategy
- B. Using HTTPS
- C. Using certificate validation
- D. Using DNSSEC
Answer: A — Pinning only one brittle certificate instead of a managed key/pin set with rotation strategy
Why: Pinning can reduce rogue CA risk but creates operational fragility. Production pinning needs backup pins and a rotation/recovery plan.
Q133. Kerberos clock skew¶
Kerberos logins fail across many Linux servers after NTP drift. Why?
- A. Kerberos tickets depend on time windows to reduce replay attacks
- B. Kerberos requires DNS over HTTPS
- C. Kerberos cannot work with Linux
- D. Kerberos uses only local passwords
Answer: A — Kerberos tickets depend on time windows to reduce replay attacks
Why: Kerberos relies on timestamps and ticket lifetimes. Excessive clock skew causes authentication failures and helps prevent replay.
Q134. Password verifier storage¶
A web app stores salted SHA-256 password hashes. Which improvement is most appropriate?
- A. Use a slow password hashing/KDF algorithm such as Argon2id, bcrypt, scrypt, or PBKDF2 with appropriate cost
- B. Remove the salt so identical passwords match
- C. Encrypt passwords reversibly so support can recover them
- D. Use MD5 because it is shorter
Answer: A — Use a slow password hashing/KDF algorithm such as Argon2id, bcrypt, scrypt, or PBKDF2 with appropriate cost
Why: Password storage should resist offline guessing. Purpose-built password hashing/KDF functions are intentionally expensive and use salts.
Q135. CSPRNG requirement¶
Which item most clearly requires a cryptographically secure random number generator?
- A. TLS session key material
- B. Sorting filenames alphabetically
- C. Generating a UI color
- D. Choosing a log rotation filename
Answer: A — TLS session key material
Why: Key material, nonces, tokens, and password reset secrets need unpredictability. Ordinary pseudo-random functions are not sufficient for security-sensitive values.
Q136. Privacy: pseudonymization¶
A dataset replaces customer names with stable random IDs but keeps purchase history linkable across months. What is this best called?
- A. Pseudonymization
- B. Full anonymization
- C. Token replay
- D. Hash collision
Answer: A — Pseudonymization
Why: Pseudonymization reduces direct identifiability but can remain linkable and sometimes re-identifiable. True anonymization is much harder.
Q137. Break-glass account control¶
A cloud tenant has an emergency admin account excluded from normal conditional access. What control best reduces abuse risk?
- A. Strong offline credential storage, alerting on use, periodic test, and rapid post-use rotation
- B. Share the password with all admins
- C. Disable logging for privacy
- D. Use the same password as normal admin accounts
Answer: A — Strong offline credential storage, alerting on use, periodic test, and rapid post-use rotation
Why: Break-glass access is a resilience control, but it needs compensating monitoring, strict storage, rotation, and testing.
Q138. Verifier impersonation resistance¶
Which authentication method best resists a fake verifier that proxies a login attempt to the real service?
- A. FIDO2 security key/passkey using origin-bound public-key authentication
- B. SMS OTP
- C. Static password
- D. Security questions
Answer: A — FIDO2 security key/passkey using origin-bound public-key authentication
Why: Verifier impersonation resistance means the authenticator will not disclose reusable secrets to a fake verifier. Origin-bound public-key authentication is the strong example. (Related to Q110 in Domain 4, "phishing-resistant MFA" — same underlying fact, different framing. A near-duplicate question, "FIDO2 passkeys and phishing resistance," was dropped from this batch as redundant with this one.)
Q139. Mutual TLS¶
What does mutual TLS add compared with ordinary server-authenticated TLS?
- A. The client also presents a certificate and proves possession of its private key
- B. It disables encryption
- C. It replaces DNS
- D. It permits anonymous clients only
Answer: A — The client also presents a certificate and proves possession of its private key
Why: mTLS authenticates both server and client at the TLS layer, often used for service-to-service authentication.
Q140. Replay versus relay¶
An attacker captures a valid authentication message and sends the same message later to gain access. What attack type best fits?
- A. Replay
- B. Relay/on-path proxying
- C. Rainbow table
- D. Clickjacking
Answer: A — Replay
Why: Replay reuses a captured message. Relay forwards an active session or challenge in real time. Nonces, timestamps, and channel binding reduce replay risk.
Q141. Pepper in password storage¶
What is the main purpose of a password pepper?
- A. A server-side secret added to password hashing so the database alone is insufficient for offline cracking
- B. A public random value stored next to each hash
- C. A network segmentation tag
- D. A certificate revocation record
Answer: A — A server-side secret added to password hashing so the database alone is insufficient for offline cracking
Why: A salt is public and per-password; a pepper is secret and stored separately, often in app config or an HSM/KMS-backed secret.
Q142. Attestation in device trust¶
A conditional access system checks that a laptop booted with approved firmware and disk encryption before granting access. What concept is most relevant?
- A. Device posture/attestation
- B. Open relay
- C. NAT overload
- D. DNS sinkhole
Answer: A — Device posture/attestation
Why: Device posture and attestation use signals from hardware/software state to inform access decisions.
← Back to Security+ overview · Next: Domain 2 — Threats, Vulnerabilities, and Mitigations →