16+ practice questions focused on Security — one of the most tested topics on the CompTIA A+ Core 2 220-1202 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Security PracticeA security analyst is reviewing a Windows 10 workstation that is suspected of being infected with malware. The analyst notices unusual network traffic and wants to identify the malware's persistence mechanism. Which of the following Windows locations should the analyst check? (Choose two.)
Explanation: The Registry Run key and the Startup folders are two of the most common autostart locations that malware uses to maintain persistence. The Run key causes programs to execute at user logon, and the Startup folders contain shortcuts that launch at logon. Both are frequently checked during malware removal to identify and disable malicious autostart entries.
A small office has a Windows 11 Pro workstation that is not joined to a domain. The office manager wants to ensure that files containing customer credit card numbers are encrypted at rest so that if the drive is removed, the data cannot be read. The workstation does not have a TPM chip. Which Windows feature should be enabled to meet this requirement?
Explanation: BitLocker with a startup PIN is the correct answer because it provides full volume encryption and can be enabled without a TPM by requiring a pre-boot PIN. This ensures that if the drive is removed, the data remains encrypted and inaccessible. EFS only encrypts individual files, Device Encryption requires a TPM, and Storage Spaces does not provide encryption.
A technician is hardening a Windows 11 workstation that will be used by a remote employee. The goal is to reduce the attack surface against malware delivered through email attachments and malicious websites. Which two of the following built-in Windows features should the technician enable to meet this goal? (Choose two.)
Explanation: The goal is to reduce the attack surface against malware arriving through email attachments and malicious websites. SmartScreen evaluates downloaded files and sites against reputation and blocks suspicious content, while Controlled folder access stops unauthorized applications from modifying protected user folders, limiting ransomware impact. RDP hardening, Windows Sandbox, and BitLocker address different risks and do not directly counter the named delivery vectors.
A security analyst is reviewing a Windows 11 event log and notices multiple failed logon attempts (Event ID 4625) for the built-in Administrator account from various source IP addresses. The account is currently disabled. Which of the following best describes what the analyst should do next?
Explanation: The analyst should block the source IP addresses at the firewall to stop the brute-force attack. The built-in Administrator account is disabled, so the attack is unsuccessful, but blocking the IPs prevents further attempts. Enabling the account or resetting its password is unnecessary and risky, and disabling auditing would remove valuable evidence. Blocking the source IPs is the most effective immediate response.
A user's Windows 11 computer is infected with malware that encrypts files and demands payment. The user has a recent full system image backup stored on an external drive that was connected during the infection. Which of the following is the best course of action?
Explanation: The external drive was connected during the infection, so it may also be infected. Disconnecting it and scanning it with antivirus ensures that the backup is clean before restoration. Paying the ransom is not recommended, and restoring immediately or scanning only the system could reintroduce malware. The best course is to secure and scan the backup first.
+11 more Security questions available
Practice all Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Security questions on the 220-1202 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Security is tested as part of the CompTIA A+ Core 2 220-1202 blueprint. Practicing with targeted Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free 220-1202 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Security practice session with instant scoring and detailed explanations.
Start Security Practice →