Diagnose security symptoms and apply the correct Windows or network control: identify malware, verify certificate and DNS behavior, configure BitLocker and permissions, and select the right wireless authentication. Getting the threat-to-control mapping right matters most.
Start practicing
Security — choose a session length
Free · No account required
Domain overview
Domain 4 (Security) covers physical and logical security for Windows endpoints and networks: malware types, social engineering, wireless and authentication protocols, hardening, and data destruction. Questions are scenario-based, asking you to diagnose a symptom or select the control that best fits a stated business or compliance requirement.
Exam objectives
Malware identification and removal using Windows Defender, Task Manager, and msconfig
Wireless security protocols including WPA2/WPA3, RADIUS, and 802.1X authentication
Encryption and access controls such as BitLocker, EFS, NTFS permissions, and MFA
Browser certificate warnings, DNS poisoning, and on-path attack symptoms
Confusing authentication with authorization; 802.1X controls network access, while NTFS and share permissions govern file access after login.
Choosing antivirus scanning when the symptom (redirected DNS, spoofed certificate) points to a network attack requiring DNS or certificate remediation.
Assuming BitLocker alone satisfies compliance; without TPM, PIN, or startup key, the drive may still be accessible if removed.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A user reports that when they connect to the corporate Wi-Fi at a coffee shop, a browser warning appears stating the site's certificate is not trusted. The user is able to browse the internet but sees the warning on every HTTPS site. A technician suspects an on-path attack. Which of the following should the technician check FIRST to confirm the presence of an on-path attack?
2A technician is configuring a Windows 11 workstation for a small business that handles credit card payments. The owner wants to ensure that stored cardholder data cannot be read if the drive is removed and attached to another computer. Which Windows feature should the technician enable?
3A user reports that when visiting a banking website, the browser displays a warning that the site's certificate is not trusted, even though the site worked yesterday. The technician verifies the system clock is correct and the network is functioning. Which of the following is the MOST likely cause?
4A security analyst notices that several workstations on the same subnet are resolving popular banking domains to an IP address that belongs to an unknown server. The analyst confirms the DHCP server is legitimate and the DNS server settings have not been changed by Group Policy. Which of the following attacks is MOST likely occurring?
5A technician is asked to dispose of several old company laptops that contain sensitive customer data. The company wants to ensure the data cannot be recovered while still allowing the laptops to be donated. Which of the following should the technician perform?
6A user at a small office reports that whenever they connect to the corporate Wi-Fi in the break room, their laptop warns that the network is unsecured and other devices on the same network can see their traffic. The access point in the break room broadcasts an open SSID with no password. Which of the following should a technician configure on the access point to protect wireless traffic while keeping the SSID available to employees?
7An administrator receives an alert that a workstation is repeatedly making DNS queries for random-looking domain names and sending small amounts of data to external IP addresses every few minutes. The endpoint protection agent is installed and up to date, and no user is logged in. Which of the following is the MOST likely explanation for this behavior?
8A security administrator is reviewing authentication methods for a company that wants to reduce the risk of credential theft while allowing employees to log in from personal mobile devices. Which two of the following should the administrator implement? (Choose two.)
9A technician is asked to dispose of several old company laptops that contain customer records on their internal drives. The drives are traditional spinning magnetic disks, and the company wants to reuse the laptops internally after the data is removed. Which of the following is the BEST method to ensure the customer data cannot be recovered?
10A security analyst notices that an employee's account is logging in successfully from two different countries within a five-minute window. The account uses a complex password, and the employee confirms they did not travel. The organization already requires multifactor authentication for all users. Which of the following is the MOST likely cause of the suspicious logins?
11A user reports that their Windows 11 laptop frequently displays a message that the battery is not charging and the system clock keeps resetting to an earlier date. The laptop is plugged into a known-good power outlet. Which of the following should a technician check first?
Diagnose security symptoms and apply the correct Windows or network control: identify malware, verify certificate and DNS behavior, configure BitLocker and permissions, and select the right wireless authentication. Getting the threat-to-control mapping right matters most.
The Courseiva 220-1202 question bank contains 11 questions in the Security domain, covering the 28% of the exam attributed to this domain in the official CompTIA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included