Cambo

CompTIA Security+ Quiz & Practice Questions

Take a free practice quiz or point your phone at any Security+ question for an instant, explained answer — threats, architecture, and operations, without the guesswork.

Try it free

Three steps, a few seconds each.

01

Snap a photo

Point your phone at the question — on a screen, a printout, anywhere.

02

Get the answer

Cambo reads the question and answers it in a few seconds.

03

See the explanation

Read the reasoning behind the answer so it actually sticks.

Looking for the official training, not practice questions? comptia.org — Security+ Certification ↗

Taking it right now? Snap a photo of any question you get stuck on — get the answer in seconds.

Try it free

Built for exactly this kind of question.

Security+ questions often present several controls that all sound like reasonable security measures, and the exam's performance-based questions ask you to apply the right control to a specific scenario rather than just recall a definition. Cambo reads the exact scenario and explains why one control is the best fit, not just which letter to pick.

Test yourself with real practice questions.

A company wants to ensure that if one authentication factor is compromised, an attacker still cannot access an account. Which control BEST achieves this?

  1. AA complex password policy
  2. BMultifactor authentication
  3. CAn account lockout policy
  4. DSingle sign-on
Tap the card to reveal the answer
Answer
BMultifactor authentication
Multifactor authentication — requiring a second, independent factor means a compromised password alone isn't enough to gain access.

A security analyst notices repeated failed logins from a single IP address in a short time window, followed by a successful login. This is most consistent with which attack?

  1. AA brute-force attack
  2. BSQL injection
  3. CCross-site scripting
  4. DAn on-path (man-in-the-middle) attack
Tap the card to reveal the answer
Answer
AA brute-force attack
A brute-force attack — repeated failed attempts followed by a success is the classic signature of an attacker guessing credentials until one works.

Which security principle ensures a user is granted only the access necessary to perform their job?

  1. ADefense in depth
  2. BLeast privilege
  3. CZero trust
  4. DSeparation of duties
Tap the card to reveal the answer
Answer
BLeast privilege
Least privilege — restricting access rights to only what's needed reduces the damage an account can cause if it's compromised.

After detecting a ransomware infection on a single workstation, what should the incident responder do FIRST?

  1. ARestore the workstation from backup immediately
  2. BIsolate the affected system from the network
  3. CNotify all employees company-wide
  4. DWipe and reimage the drive
Tap the card to reveal the answer
Answer
BIsolate the affected system from the network
Isolate the affected system from the network — containment comes before eradication or recovery, to stop the ransomware from spreading further.

A company's policy requires that no single employee can both request and approve a purchase. This is an example of which concept?

  1. ALeast privilege
  2. BSeparation of duties
  3. CNon-repudiation
  4. DDefense in depth
Tap the card to reveal the answer
Answer
BSeparation of duties
Separation of duties — dividing critical tasks between different people reduces the risk of fraud or error by any one individual.

Which document defines the maximum acceptable time a system can be down after an incident before causing unacceptable business impact?

  1. ARecovery Point Objective (RPO)
  2. BRecovery Time Objective (RTO)
  3. CService Level Agreement (SLA)
  4. DBusiness Impact Analysis (BIA)
Tap the card to reveal the answer
Answer
BRecovery Time Objective (RTO)
Recovery Time Objective (RTO) — it specifies the maximum tolerable downtime, guiding how fast systems must be restored after a disruption.
1 / 6
2 / 6
3 / 6
4 / 6
5 / 6
6 / 6

Questions, answered.

How many questions are on the Security+ exam?

+

Up to 90 questions in 90 minutes, mixing multiple-choice questions with hands-on performance-based questions (PBQs).

What score do I need to pass Security+?

+

750 on a scaled range of 100 to 900 — CompTIA weights questions by difficulty, so the passing score isn't a fixed percentage of questions answered correctly.

What are the five Security+ domains?

+

General Security Concepts, Threats/Vulnerabilities/Mitigations, Security Architecture, Security Operations, and Security Program Management and Oversight, weighted roughly 12%, 22%, 18%, 28%, and 20%.

Is Cambo affiliated with CompTIA?

+

No. Cambo is an independent study tool and isn't produced, endorsed, or affiliated with CompTIA.

Do I need any prerequisites to take Security+?

+

No official prerequisite — CompTIA recommends Network+ certification and around two years of security or systems administration experience, but neither is required to register.

How many times can I retake Security+?

+

There's no cap on attempts, but you must wait 14 calendar days after a second (or later) failed attempt, and each attempt requires a new exam voucher.

Other practice pages.

Example quizzes that you are forced to take

DoD & Military Training 19+
Workplace Compliance 12+
Career & Aptitude Tests 8+
Professional Certifications 8+
State Licensing & Exams 7+
Course & Campus Study Tools 27+
Campus Study Hubs 24+