Skip to content

Domain 1.0 — General Security Concepts

← Back to Security+ overview · Domain weight: 12%

Q001. Control type: badge reader

A data center requires employees to scan a badge before entering the server room. What type of control is this primarily?

  • A. Detective
  • B. Preventive
  • C. Corrective
  • D. Compensating

Answer: B — Preventive

Why: The badge reader blocks unauthorized access before it occurs. A log from the badge reader may also support detection later, but its primary purpose is preventive.


Q002. Control type: security policy

A company publishes a policy requiring all removable media to be encrypted. Which control type best describes the policy itself?

  • A. Directive
  • B. Corrective
  • C. Detective
  • D. Physical

Answer: A — Directive

Why: A directive control tells users what behavior is required. Encryption software would be technical; the written rule is directive.


Q003. CIA triad: altered records

An attacker changes payroll direct-deposit account numbers in a database. Which part of the CIA triad is most directly violated?

  • A. Confidentiality
  • B. Integrity
  • C. Availability
  • D. Non-repudiation

Answer: B — Integrity

Why: Integrity means data remains accurate and unmodified except by authorized action.


Q004. CIA triad: ransomware outage

A file server is encrypted by ransomware and users cannot access shared files. Which CIA goal is most directly affected?

  • A. Confidentiality
  • B. Integrity
  • C. Availability
  • D. Obfuscation

Answer: C — Availability

Why: The primary business impact is that legitimate users cannot access needed resources.


Q005. Non-repudiation

A legal department wants proof that a specific executive approved a signed contract and cannot credibly deny it later. Which technology best supports this?

  • A. Symmetric encryption
  • B. Digital signature
  • C. Tokenization
  • D. Data masking

Answer: B — Digital signature

Why: A digital signature created with a private key supports integrity, authentication, and non-repudiation.


Q006. Authentication vs authorization

A user successfully enters a password, then is denied access to a payroll application because they are not in the HR group. What failed?

  • A. Identification
  • B. Authentication
  • C. Authorization
  • D. Accounting

Answer: C — Authorization

Why: Authentication proved identity. Authorization determines what that authenticated identity may access.


Q007. Accounting

Which control best supports accountability by recording who accessed a system and what actions they performed?

  • A. Audit logging
  • B. Encryption
  • C. Load balancing
  • D. Tokenization

Answer: A — Audit logging

Why: Accounting depends on reliable logs showing actions tied to identities.


Q008. Zero trust principle

A company removes broad network trust and requires device health checks, identity verification, and least-privilege access for each application request. What model is being applied?

  • A. Implicit trust
  • B. Zero trust
  • C. Air gapping
  • D. Security through obscurity

Answer: B — Zero trust

Why: Zero trust assumes no implicit trust based only on network location and continuously evaluates access decisions.


Q009. Least privilege

A database administrator needs read-only access to production logs but not write access to customer tables. Which principle applies?

  • A. Separation of duties
  • B. Least privilege
  • C. Obfuscation
  • D. Non-repudiation

Answer: B — Least privilege

Why: The user should receive only the minimum access needed to perform the task.


Q010. Separation of duties

One employee can create vendors, approve invoices, and release payments. What control weakness is present?

  • A. Lack of separation of duties
  • B. Weak encryption
  • C. Poor availability
  • D. Inadequate masking

Answer: A — Lack of separation of duties

Why: Critical financial steps should be split so one person cannot complete fraud end-to-end.


Q011. Change management

A firewall rule change is made directly in production without testing or approval and causes an outage. Which process would most directly reduce this risk?

  • A. Change management
  • B. Data classification
  • C. Tokenization
  • D. Threat hunting

Answer: A — Change management

Why: Change management provides review, approval, testing, backout planning, and documentation for changes.


Q012. Hashing vs encryption

A security engineer needs to verify that a downloaded ISO was not modified. Which mechanism is most appropriate?

  • A. Hash comparison
  • B. Symmetric encryption
  • C. Data masking
  • D. Steganography

Answer: A — Hash comparison

Why: Hashes provide integrity verification. Encryption protects confidentiality, not proof of unchanged content by itself.


Q013. Encryption at rest

A laptop may be stolen from an employee's car. Which control best protects the data if the laptop is powered off?

  • A. Full-disk encryption
  • B. Screen lock only
  • C. IDS sensor
  • D. DLP email rule

Answer: A — Full-disk encryption

Why: Full-disk encryption protects stored data if the physical device is lost or stolen.


Q014. PKI trust

A browser trusts a website certificate because the certificate chains back to a trusted root. Which system provides this trust model?

  • A. RADIUS
  • B. PKI
  • C. Kerberos
  • D. TACACS+

Answer: B — PKI

Why: Public key infrastructure uses certificate authorities, certificates, and trust chains.


Q015. Obfuscation

A developer renames variables and removes readable symbols before releasing client-side code. What is this mainly intended to do?

  • A. Make reverse engineering harder
  • B. Provide strong encryption
  • C. Replace authentication
  • D. Guarantee integrity

Answer: A — Make reverse engineering harder

Why: Obfuscation raises effort but is not equivalent to encryption or access control.


Q016. Physical deterrent

A sign outside a restricted area says "24-hour video monitoring." Which control type is the sign primarily?

  • A. Preventive
  • B. Detective
  • C. Deterrent
  • D. Corrective

Answer: C — Deterrent

Why: The sign discourages behavior. Cameras may be detective, but the sign itself is deterrent.


Q017. Compensating control

A legacy system cannot support MFA. The organization restricts access to a jump host, enables session recording, and limits access to a small admin group. What are these added measures?

  • A. Compensating controls
  • B. Corrective controls
  • C. Open controls
  • D. Inherent controls

Answer: A — Compensating controls

Why: They reduce risk when the preferred control cannot be implemented.


Q018. Data minimization

A sign-up form asks for Social Security numbers even though the service only needs an email address. Which privacy/security principle is being violated?

  • A. Data minimization
  • B. Non-repudiation
  • C. Federation
  • D. Hashing

Answer: A — Data minimization

Why: Collect only data needed for the stated purpose. Less stored sensitive data means less breach impact.


Q124. OAuth ID token versus access token

A developer uses an OAuth/OIDC access token as proof that the user authenticated and displays the username from it without validation. What is the best correction?

  • A. Use the ID token for user authentication claims and validate issuer, audience, signature, and expiration
  • B. Use the refresh token in the browser because it lasts longer
  • C. Store the access token in localStorage and trust the username claim
  • D. Disable token expiration to avoid reauthentication failures

Answer: A — Use the ID token for user authentication claims and validate issuer, audience, signature, and expiration

Why: OIDC adds identity on top of OAuth. ID tokens carry authentication claims and still require validation. Access tokens are primarily authorization artifacts for APIs.


Q125. SAML assertion signature placement

An enterprise SSO integration accepts unsigned SAML assertions if the outer response is signed. What attack class is this most likely to enable?

  • A. XML signature wrapping
  • B. DNS cache poisoning
  • C. Pass-the-hash
  • D. ARP spoofing

Answer: A — XML signature wrapping

Why: SAML/XML signature wrapping abuses parsing differences and unsigned or incorrectly validated assertion elements. The application must validate the exact signed assertion it consumes.


Q126. RADIUS versus TACACS+

A network team wants centralized admin login for routers and wants command authorization and accounting separated from authentication. Which protocol is usually the better fit?

  • A. RADIUS
  • B. TACACS+
  • C. SNMPv3
  • D. LDAP

Answer: B — TACACS+

Why: TACACS+ separates authentication, authorization, and accounting and is commonly used for network device administration. RADIUS is common for network access authentication.


Q127. ABAC decision inputs

Which authorization model is best when access depends on user department, device health, data classification, location, and time of day?

  • A. DAC
  • B. MAC
  • C. ABAC
  • D. Rule-based firewall ACL only

Answer: C — ABAC

Why: Attribute-based access control evaluates attributes of users, resources, actions, and environment. It maps well to conditional access and zero trust decisions.


Q128. HMAC use case

A service sends messages over an already encrypted channel but still needs to prove that each message came from a holder of a shared secret and was not modified. What should it use?

  • A. Plain SHA-256 hash
  • B. HMAC
  • C. Base64 encoding
  • D. Symmetric encryption without authentication

Answer: B — HMAC

Why: HMAC combines a cryptographic hash with a secret key to provide integrity and authenticity. A plain hash only detects accidental change if the expected hash is trusted.


Q129. AEAD versus encrypt-then-ignore

A developer encrypts JSON with AES-CBC but does not authenticate the ciphertext. What is the strongest design improvement?

  • A. Use an AEAD mode such as AES-GCM or ChaCha20-Poly1305
  • B. Base64 encode the ciphertext twice
  • C. Use a shorter IV to save space
  • D. Compress after encryption

Answer: A — Use an AEAD mode such as AES-GCM or ChaCha20-Poly1305

Why: AEAD provides confidentiality and integrity/authentication together. Unauthenticated CBC designs can be vulnerable to padding-oracle and tampering attacks.


Q130. Perfect forward secrecy

Which TLS property limits the damage if the server private key is stolen months after traffic was captured?

  • A. Certificate pinning
  • B. Perfect forward secrecy from ephemeral key exchange
  • C. OCSP stapling
  • D. Wildcard certificate usage

Answer: B — Perfect forward secrecy from ephemeral key exchange

Why: PFS uses ephemeral session keys so old sessions cannot be decrypted solely from a later theft of the server private key.


Q131. OCSP stapling

What problem does OCSP stapling primarily address?

  • A. It lets a server provide recent certificate revocation status without every client querying the CA directly
  • B. It encrypts DNS lookups
  • C. It prevents SQL injection
  • D. It replaces certificate expiration

Answer: A — It lets a server provide recent certificate revocation status without every client querying the CA directly

Why: OCSP stapling improves revocation checking privacy and performance by having the server staple a signed OCSP response during the TLS handshake.


Q132. Certificate pinning tradeoff

A mobile app pins a single leaf certificate. The certificate expires unexpectedly and users cannot connect. What was the design mistake?

  • A. Pinning only one brittle certificate instead of a managed key/pin set with rotation strategy
  • B. Using HTTPS
  • C. Using certificate validation
  • D. Using DNSSEC

Answer: A — Pinning only one brittle certificate instead of a managed key/pin set with rotation strategy

Why: Pinning can reduce rogue CA risk but creates operational fragility. Production pinning needs backup pins and a rotation/recovery plan.


Q133. Kerberos clock skew

Kerberos logins fail across many Linux servers after NTP drift. Why?

  • A. Kerberos tickets depend on time windows to reduce replay attacks
  • B. Kerberos requires DNS over HTTPS
  • C. Kerberos cannot work with Linux
  • D. Kerberos uses only local passwords

Answer: A — Kerberos tickets depend on time windows to reduce replay attacks

Why: Kerberos relies on timestamps and ticket lifetimes. Excessive clock skew causes authentication failures and helps prevent replay.


Q134. Password verifier storage

A web app stores salted SHA-256 password hashes. Which improvement is most appropriate?

  • A. Use a slow password hashing/KDF algorithm such as Argon2id, bcrypt, scrypt, or PBKDF2 with appropriate cost
  • B. Remove the salt so identical passwords match
  • C. Encrypt passwords reversibly so support can recover them
  • D. Use MD5 because it is shorter

Answer: A — Use a slow password hashing/KDF algorithm such as Argon2id, bcrypt, scrypt, or PBKDF2 with appropriate cost

Why: Password storage should resist offline guessing. Purpose-built password hashing/KDF functions are intentionally expensive and use salts.


Q135. CSPRNG requirement

Which item most clearly requires a cryptographically secure random number generator?

  • A. TLS session key material
  • B. Sorting filenames alphabetically
  • C. Generating a UI color
  • D. Choosing a log rotation filename

Answer: A — TLS session key material

Why: Key material, nonces, tokens, and password reset secrets need unpredictability. Ordinary pseudo-random functions are not sufficient for security-sensitive values.


Q136. Privacy: pseudonymization

A dataset replaces customer names with stable random IDs but keeps purchase history linkable across months. What is this best called?

  • A. Pseudonymization
  • B. Full anonymization
  • C. Token replay
  • D. Hash collision

Answer: A — Pseudonymization

Why: Pseudonymization reduces direct identifiability but can remain linkable and sometimes re-identifiable. True anonymization is much harder.


Q137. Break-glass account control

A cloud tenant has an emergency admin account excluded from normal conditional access. What control best reduces abuse risk?

  • A. Strong offline credential storage, alerting on use, periodic test, and rapid post-use rotation
  • B. Share the password with all admins
  • C. Disable logging for privacy
  • D. Use the same password as normal admin accounts

Answer: A — Strong offline credential storage, alerting on use, periodic test, and rapid post-use rotation

Why: Break-glass access is a resilience control, but it needs compensating monitoring, strict storage, rotation, and testing.


Q138. Verifier impersonation resistance

Which authentication method best resists a fake verifier that proxies a login attempt to the real service?

  • A. FIDO2 security key/passkey using origin-bound public-key authentication
  • B. SMS OTP
  • C. Static password
  • D. Security questions

Answer: A — FIDO2 security key/passkey using origin-bound public-key authentication

Why: Verifier impersonation resistance means the authenticator will not disclose reusable secrets to a fake verifier. Origin-bound public-key authentication is the strong example. (Related to Q110 in Domain 4, "phishing-resistant MFA" — same underlying fact, different framing. A near-duplicate question, "FIDO2 passkeys and phishing resistance," was dropped from this batch as redundant with this one.)


Q139. Mutual TLS

What does mutual TLS add compared with ordinary server-authenticated TLS?

  • A. The client also presents a certificate and proves possession of its private key
  • B. It disables encryption
  • C. It replaces DNS
  • D. It permits anonymous clients only

Answer: A — The client also presents a certificate and proves possession of its private key

Why: mTLS authenticates both server and client at the TLS layer, often used for service-to-service authentication.


Q140. Replay versus relay

An attacker captures a valid authentication message and sends the same message later to gain access. What attack type best fits?

  • A. Replay
  • B. Relay/on-path proxying
  • C. Rainbow table
  • D. Clickjacking

Answer: A — Replay

Why: Replay reuses a captured message. Relay forwards an active session or challenge in real time. Nonces, timestamps, and channel binding reduce replay risk.


Q141. Pepper in password storage

What is the main purpose of a password pepper?

  • A. A server-side secret added to password hashing so the database alone is insufficient for offline cracking
  • B. A public random value stored next to each hash
  • C. A network segmentation tag
  • D. A certificate revocation record

Answer: A — A server-side secret added to password hashing so the database alone is insufficient for offline cracking

Why: A salt is public and per-password; a pepper is secret and stored separately, often in app config or an HSM/KMS-backed secret.


Q142. Attestation in device trust

A conditional access system checks that a laptop booted with approved firmware and disk encryption before granting access. What concept is most relevant?

  • A. Device posture/attestation
  • B. Open relay
  • C. NAT overload
  • D. DNS sinkhole

Answer: A — Device posture/attestation

Why: Device posture and attestation use signals from hardware/software state to inform access decisions.


← Back to Security+ overview · Next: Domain 2 — Threats, Vulnerabilities, and Mitigations →