Security+ Practice Test Modules 2-5

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Catherine Halcomb
Catherine Halcomb
Community Contributor
Quizzes Created: 3793 | Total Attempts: 6,983,203
| Questions: 20 | Updated: Sep 24, 2026
Please wait...
Question 1 / 21
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. Which of the following is capable of automatically implementing a security baseline for every virtual machine that is deployed?

Explanation

Ansible is an automation tool that can manage and configure systems, including virtual machines, by using playbooks to define security baselines. It allows for the automatic deployment of these configurations, ensuring that every virtual machine adheres to specified security policies. This capability streamlines the process of maintaining security compliance across multiple environments, making it an effective choice for organizations looking to enforce consistent security measures automatically.

Submit
Please wait...
About This Quiz
Security+ Practice Test Modules 2-5 - Quiz

This assessment focuses on key cybersecurity concepts and practices, such as risk management, compliance, and security measures. It evaluates your understanding of essential topics like encryption, supply chain risk analysis, and incident response. This knowledge is crucial for professionals looking to enhance their security posture and ensure compliance with regulations.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Which of the following best emphasizes the need to develop new encryption methods given recent developments in quantum computing?

Explanation

Recent advancements in quantum computing pose a significant threat to traditional encryption methods, particularly those relying on large value algorithms, such as RSA and ECC. Quantum computers can potentially break these algorithms much faster than classical computers, rendering them ineffective for securing sensitive data. As quantum capabilities improve, the reliance on these large value encryption methods creates vulnerabilities that could be exploited, highlighting the urgent need for the development of new, quantum-resistant encryption techniques to ensure data security in the future.

Submit

3. An administrator receives a phone call from someone with a voice very similar to the CEO claiming they have been kidnapped and require a wire transfer. Which of the following best describes this type of attack?

Explanation

This scenario exemplifies a deep fake attack, where advanced technology is used to create a realistic imitation of the CEO's voice. Cybercriminals leverage this technique to deceive individuals into believing they are communicating with someone of authority, manipulating them into taking actions like wire transfers. Unlike traditional impersonation, which may involve simple voice mimicry or social engineering, deep fakes employ sophisticated audio manipulation, making it harder to detect the fraud and increasing the risk of successful exploitation.

Submit

4. Which of the following mechanisms should be suggested to minimize the impact of future encrypted data after a previously used encryption key was exposed?

Explanation

Perfect forward secrecy (PFS) ensures that session keys are not compromised even if the long-term encryption key is exposed. By generating unique session keys for each communication session, PFS protects past communications from being decrypted in the future, as each key is ephemeral and not derived from the long-term key. This mechanism minimizes the impact of key exposure by ensuring that even if one key is compromised, it does not jeopardize the confidentiality of previously encrypted data. Thus, it enhances overall security in encrypted communications.

Submit

5. Which of the following does input sanitization best mitigate for a large language model?

Explanation

Input sanitization is crucial in preventing prompt injection attacks, where malicious inputs are crafted to manipulate a language model's responses. By filtering and validating inputs before they reach the model, sanitization reduces the risk of unintended outputs that could arise from harmful or misleading prompts. This ensures that the model operates within expected parameters, maintaining the integrity and safety of its responses, while other issues like model poisoning or low traceability are less directly impacted by input sanitization.

Submit

6. Which of the following aspects of a threat scenario are necessary for an analyst to effectively utilize the Diamond Model of Intrusion Analysis?

Explanation

In the Diamond Model of Intrusion Analysis, "Capability" refers to the resources and skills that an adversary possesses to execute an attack. Understanding the attacker’s capabilities is crucial for analysts to assess the potential impact and likelihood of a threat. This aspect helps in identifying the tools and techniques used by the attacker, thus allowing for more effective threat detection and response strategies. Without a clear understanding of the adversary's capabilities, analysts may struggle to accurately evaluate the threat landscape.

Submit

7. Which of the following best describes the reason for integrating a CASB for an organization with globally distributed employees?

Explanation

Integrating a Cloud Access Security Broker (CASB) is crucial for organizations with globally distributed employees as it ensures that only approved applications can communicate with the organization's data and resources. This capability enhances security by preventing unauthorized access and data breaches, especially in environments where employees might use various devices and networks. By focusing on application-level security, a CASB helps maintain compliance and protects sensitive information across different locations, making it essential for managing risks associated with remote work.

Submit

8. An organization is developing a web-based storage application that must maintain high performance and availability while mitigating security threats. Which two solutions best fit these needs? (Pick two)

Explanation

A Cloud Access Security Broker (CASB) enhances security by providing visibility and control over data and applications in the cloud, helping to mitigate security threats. A Content Delivery Network (CDN) improves performance and availability by distributing content closer to users, reducing latency and ensuring faster load times. Together, these solutions address the dual needs of maintaining high performance while safeguarding against security vulnerabilities in a web-based storage application.

Submit

9. Which of the following methods would most likely help identify syntax errors within code development environments?

Explanation

Linting is a static code analysis tool that checks source code for programming errors, bugs, stylistic errors, and suspicious constructs. It analyzes the code without executing it, helping developers identify syntax errors and enforce coding standards. By providing real-time feedback and suggestions, linting improves code quality and reduces the likelihood of runtime errors. This makes it an essential tool in development environments, particularly for maintaining clean and error-free code.

Submit

10. A recent audit failed because developers could push application builds into production without review. Which of the following should be reviewed to prevent future audit failures?

Explanation

Implementing branch protection ensures that any code changes must undergo a review process before being merged into the main branch. This adds a layer of oversight, requiring code reviews and approvals, which helps catch potential issues and prevents unvetted code from being deployed into production. By enforcing these rules, organizations can maintain code quality, enhance security, and comply with audit requirements, thereby reducing the risk of future audit failures.

Submit

11. A project manager needs to track the various roles involved in an upcoming project. Which of the following should be used?

Explanation

A RACI Matrix is a tool that defines roles and responsibilities within a project by categorizing them into four types: Responsible, Accountable, Consulted, and Informed. This clarity helps project managers track who is involved in specific tasks and ensures that all team members understand their contributions and obligations. By using a RACI Matrix, a project manager can effectively manage stakeholder engagement and improve communication, which is crucial for the successful execution of the project.

Submit

12. Which of the following NIST BCP phases establishes the identification and prioritization of critical systems and functions?

Explanation

A business impact analysis (BIA) is essential for identifying and prioritizing critical systems and functions within an organization. This phase assesses the potential effects of disruptions on operations, helping to determine which functions are vital for business continuity. By understanding the impact of various risks, organizations can effectively allocate resources to protect their most critical assets, ensuring they can maintain essential operations during and after a crisis.

Submit

13. An organization is prioritizing risk remediation. A full remediation was not possible, but mitigations were applied to reduce likelihood of impact. What should the organization do next?

Explanation

After applying mitigations, it is essential for the organization to evaluate the remaining risk, known as residual risk. This assessment helps determine the effectiveness of the mitigations and the level of risk that still exists. Understanding residual risk allows the organization to make informed decisions about whether further actions are needed, prioritize future remediation efforts, and communicate the current risk posture to stakeholders. This step ensures that the organization remains aware of potential vulnerabilities and can continue to manage risk effectively.

Submit

14. An organization needs a solution that can monitor risk management information and periodically send email reminders for management tasks. Which of the following best meets these needs?

Explanation

A Governance, Risk, and Compliance (GRC) tool is specifically designed to integrate and manage risk management processes, ensuring compliance with regulations and standards. It provides features for monitoring risk information, automating workflows, and sending periodic email reminders for management tasks. This makes it the most suitable option for an organization looking to effectively manage risks while ensuring timely communication and reminders related to risk management activities.

Submit

15. Which of the following is used to assess compliance with both internal and external requirements?

Explanation

An audit report is a formal document that evaluates an organization's adherence to internal policies and external regulations. It provides an objective assessment of compliance, identifying areas of risk and opportunities for improvement. By reviewing financial statements, operational processes, and regulatory obligations, audit reports ensure that organizations meet required standards, making them essential for governance and accountability. This comprehensive evaluation helps stakeholders understand the effectiveness of internal controls and compliance measures.

Submit

16. Following the acquisition of Company B, Company A must assess how the merger affects its cybersecurity exposure. Which two methods best evaluate the potential expansion of the attack surface? (Select two)

Explanation

To effectively evaluate the potential expansion of the attack surface following the merger, it is crucial to conduct a structural assessment of Company B's network infrastructure. This allows Company A to identify vulnerabilities and security gaps in the existing setup. Additionally, recording all third-party integrations utilized by Company B is essential, as these connections can introduce new risks and points of entry for cyber threats. Together, these methods provide a comprehensive view of the cybersecurity landscape post-acquisition, enabling better risk management and mitigation strategies.

Submit

17. An organization is seeking to integrate a trusted, complex security solution sourced from various regions and is concerned with customer perception. Which of the following best demonstrates that associated risks are manageable?

Explanation

Publishing vendor management procedures that include appliance test results showcases a proactive approach to risk management. It demonstrates transparency and accountability in the organization's security practices, reassuring customers that thorough testing and evaluation of security solutions have been conducted. This not only highlights the organization's commitment to maintaining high security standards but also fosters trust by showing that risks associated with the integrated solution are actively monitored and managed. Such documentation can effectively alleviate customer concerns regarding the complexity and reliability of the security measures in place.

Submit

18. Of the following regulations, which is most relevant when a user requests their data be completely scrubbed from corporate systems?

Explanation

GDPR, or the General Data Protection Regulation, is a comprehensive data protection law in the European Union that emphasizes individuals' rights over their personal data. It mandates that organizations must delete a user's data upon request, known as the "right to erasure" or "right to be forgotten." This regulation ensures that individuals have control over their data and can request its complete removal from corporate systems, making it the most relevant regulation for data scrubbing requests.

Submit

19. A bank encrypts its customers' account information at rest. This best accomplishes which business goal?

Explanation

Encrypting customer account information at rest primarily serves to protect sensitive data from unauthorized access. By implementing encryption, the bank reduces the risk of data breaches, thereby minimizing potential legal and financial liabilities associated with privacy violations. This proactive measure helps ensure that even if data is compromised, it remains unreadable without the proper decryption keys, thereby safeguarding both customer information and the bank's reputation. Ultimately, this approach aligns with the goal of reducing responsibility for any privacy breaches that may occur.

Submit

20. An exploit was discovered through third-party components containing known vulnerabilities. Which method best detects such vulnerabilities before deployment?

Explanation

Conducting a thorough supply chain risk analysis prior to development helps identify and evaluate potential vulnerabilities in third-party components before they are integrated into a product. This proactive approach allows organizations to assess the security posture of suppliers, ensuring that known vulnerabilities are addressed and mitigated early in the development process. By understanding the risks associated with external components, companies can make informed decisions, reducing the likelihood of deploying products with exploitable weaknesses.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (20)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
Which of the following is capable of automatically implementing a...
Which of the following best emphasizes the need to develop new...
An administrator receives a phone call from someone with a voice very...
Which of the following mechanisms should be suggested to minimize the...
Which of the following does input sanitization best mitigate for a...
Which of the following aspects of a threat scenario are necessary for...
Which of the following best describes the reason for integrating a...
An organization is developing a web-based storage application that...
Which of the following methods would most likely help identify syntax...
A recent audit failed because developers could push application builds...
A project manager needs to track the various roles involved in an...
Which of the following NIST BCP phases establishes the identification...
An organization is prioritizing risk remediation. A full remediation...
An organization needs a solution that can monitor risk management...
Which of the following is used to assess compliance with both internal...
Following the acquisition of Company B, Company A must assess how the...
An organization is seeking to integrate a trusted, complex security...
Of the following regulations, which is most relevant when a user...
A bank encrypts its customers' account information at rest. This best...
An exploit was discovered through third-party components containing...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!