Skip to content

Security Operations Questions

Practice questions for Security Operations topic in CompTIA Security+. 28 questions covering this domain.

28 questions4 easy14 medium10 hard
Q1
medium

A company wants to prevent employees from accidentally or intentionally sending sensitive customer data such as credit card numbers outside the organi...

Q2
hard

During incident response, a forensic analyst needs to preserve evidence from a compromised server without altering any data on the system. Which actio...

Q3
medium

A security operations center (SOC) analyst wants to correlate security events from firewalls, servers, and endpoint agents in a single platform to ide...

Q4
medium

A security analyst is implementing multi-factor authentication for a remote access solution. Which combination of authentication factors represents TR...

Q5
hard

A security analyst receives an alert that a user account has been locked out after multiple failed login attempts, followed immediately by a successfu...

Q6
easy

Which security technology monitors network traffic for known attack signatures and malicious patterns and can actively block detected threats?

Q7
medium

An organization wants to automate the response to common security incidents — such as isolating a compromised endpoint when malware is detected — with...

Q8
hard

A security analyst is investigating a security event and needs to establish the order in which events occurred across multiple systems with potentiall...

Q9
medium

A security engineer wants to enforce that all devices connecting to the corporate wireless network have up-to-date antivirus and OS patches installed ...

Q10
medium

A security team needs to control and monitor administrative access to critical servers, including recording all privileged sessions. Which solution is...

Q11
hard

A threat hunter discovers that an attacker used PowerShell's `Invoke-WebRequest` to download a malicious payload directly into memory without writing ...

Q12
hard

A SOC analyst is reviewing endpoint detection and response (EDR) alerts. The tool flags a process that is executing from `C:\Users\Public\` and making...

Q13
easy

Which identity and access management (IAM) technology allows users to authenticate once and gain access to multiple applications without re-entering c...

Q14
medium

A security analyst wants to harden a newly deployed Linux server by disabling all services that are not required for its intended function. Which hard...

Q15
hard

A forensic analyst is examining a disk image and needs to determine when a specific file was last accessed, modified, and created. Which data source p...

Q16
hard

A penetration tester successfully escalates privileges from a standard user account to domain administrator on a Windows domain after exploiting a mis...

Q17
medium

A company wants to ensure that security operations run continuously and that a complex security event detected at 3 AM on a Saturday is responded to p...

Q18
hard

A threat intelligence team receives an indicator of compromise (IoC) — a specific IP address associated with a known threat actor's C2 infrastructure....

Q19
easy

Which security tool scans systems and applications to identify known vulnerabilities, missing patches, and misconfigurations?

Q20
medium

An organization wants to prevent sensitive files from being copied to USB drives from managed endpoints. Which security control MOST directly enforces...

Sign in to see all 28 questions

Create a free account to browse all questions — completely free during our launch phase.