Be able to identify malware by behavior, choose the right wireless security mode, and explain threat versus vulnerability. The key skill is matching a scenario to the correct control, especially rotating credentials and applying the 3-2-1 backup rule.
Start practicing
Security — choose a session length
Free · No account required
Domain overview
Security covers the concepts, threats, and controls tested on CompTIA Tech+ (FC0-U71). Expect scenario items on malware types, wireless encryption such as WPA2 and WPA3, threat versus vulnerability, authentication factors, and backup practices including the 3-2-1 rule, plus basic physical and logical security measures.
Exam objectives
Distinguishing malware types: virus, worm, trojan, ransomware, spyware, and phishing tactics
Wireless security modes: WPA2/WPA3-Personal versus Enterprise, and why shared passphrases fail
Difference between a threat, a vulnerability, and a risk in given scenarios
Backup best practices, including the 3-2-1 rule and restoring data after loss
Confusing a threat with a vulnerability: a threat exploits, a vulnerability is the weakness being exploited.
Assuming WPA2-Personal passphrase changes remove access; a former user who knows it can still connect until the key rotates.
Treating any single backup copy as sufficient; the 3-2-1 rule requires three copies, two media types, one offsite.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which of the following best describes the principle of confidentiality in the CIA triad?
2A company implements a policy requiring employees to use a password and a one-time code sent to their mobile phone when logging into the corporate network. Which security concept is being employed?
3A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The email contains urgent language and threats of account closure. What type of attack is this?
4Which of the following is the strongest password?
5A security analyst discovers that a file on a server has been modified without authorization. However, the system logs show that the modification was made by an authenticated user who had legitimate access to the file. Which aspect of the CIA triad has been violated?
6Which of the following malware types is characterized by self-replication without needing to attach to a host file?
7A company wants to ensure that sensitive documents are not readable if a laptop is stolen. Which of the following provides the best protection?
8What is the primary purpose of a password manager?
9An attacker gains physical access to a building by following an employee through a secured door without using a badge. This is an example of which social engineering technique?
10A user downloads a free game from an untrusted website. After installation, the user's computer begins displaying pop-up advertisements frequently. Which type of malware is most likely installed?
11An organization uses a security model where users are granted the minimum permissions necessary to perform their job functions. This model is known as:
12Which TWO of the following are effective measures to protect against ransomware attacks? (Select two.)
13Which THREE of the following are examples of multi-factor authentication? (Select three.)
14Which TWO of the following are recommended practices for physical security in an office environment? (Select two.)
15Which of the following best describes the principle of least privilege?
16A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The user notices the email address is slightly misspelled (e.g., 'support@bankk.com' instead of 'support@bank.com'). Which type of attack is this?
17An organization implements a security control that requires users to swipe a smart card and then enter a PIN to access a secure facility. Which combination of authentication factors does this represent?
18Which of the following is a characteristic of a worm in the context of malware?
19A company wants to protect its network from unauthorized external access. Which of the following devices should be configured to filter traffic based on port and protocol?
20An employee is tailgated into a secure office building by someone without a badge. Which type of security threat does this represent?
21An organization adopts the 3-2-1 backup rule. Which of the following practices aligns with this rule?
22A security analyst is explaining the CIA triad to new employees. Which scenario best illustrates a breach of integrity?
23Which of the following is a best practice for creating a strong password?
24A small business owner wants to protect customer data stored on laptops in case the devices are stolen. Which encryption method provides the best protection for the entire hard drive?
25Which of the following is a key difference between a vulnerability and a threat in cybersecurity?
26A company implements a policy where employees must lock their computer screen when leaving their desk. Which security principle does this practice support?
27Which TWO of the following are examples of social engineering attacks? (Select TWO.)
28Which THREE of the following are effective methods to protect against malware infections? (Select THREE.)
29Which TWO of the following are characteristics of a strong password? (Select TWO.)
30An organization implements a security policy where users must provide a password and a one-time code generated by a mobile app to log in. Which type of authentication is being used?
31Which of the following is a characteristic of a strong password?
32A company requires all employees to use a smart card and a PIN to access the building. This is an example of which concept?
33A security analyst discovers that a file on a server has been modified without authorization. Which element of the CIA triad has been compromised?
34Which type of malware is designed to replicate itself and spread to other computers without needing to attach to a host file?
35Which of the following is the best practice for backing up data according to the 3-2-1 rule?
36An attacker gains physical access to a secure area by following an authorized employee through a door that requires a badge. This social engineering technique is known as:
37A user reports that their computer has been displaying unwanted pop-up advertisements frequently. Which type of malware is most likely responsible?
38Which of the following is an example of a physical security control?
39A company wants to implement the principle of least privilege for its employees. Which TWO of the following actions align with this principle? (Choose TWO.)
40Which TWO of the following are examples of multi-factor authentication? (Choose TWO.)
41Which element of the CIA triad is primarily concerned with ensuring that data is not accessed by unauthorized individuals?
42A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The user notices the sender's email address is slightly misspelled. Which type of threat is this?
43An organization requires employees to use a password and a one-time code sent to their mobile phone when logging into the network. Which security principle is being implemented?
44Which of the following is the best practice for creating a strong password?
45A security analyst is explaining the difference between a threat and a vulnerability. Which statement accurately describes this difference?
46Which type of malware is disguised as legitimate software but performs malicious actions?
47A company wants to ensure that data on lost laptops cannot be accessed. Which technology should be used?
48An employee calls the help desk claiming to be a manager from another department and requests a password reset. This is an example of which social engineering technique?
49A user is concerned about connecting to a public Wi-Fi network at a coffee shop. Which security measure can best protect their data?
50A company's backup strategy requires three copies of data, on two different media types, with one copy offsite. Which backup rule does this follow?
51Which of the following is an example of something you are in multi-factor authentication?
52An IT administrator is hardening a server. Which three of the following actions should be taken to improve security? (Select THREE.)
53A user receives a suspicious email with an attachment claiming to be an invoice. Which three practices should the user follow? (Select THREE.)
54Which component of the CIA triad ensures that data cannot be modified by unauthorized users?
55A user receives an email that appears to be from their bank, asking them to click a link and verify their account. The email contains urgent language and a generic greeting. Which type of security threat is this?
56A company implements a policy where employees must swipe their ID card and then enter a PIN to access the server room. Which two authentication factors are being used?
57An employee allows a delivery person to enter a secure office building by holding the door open. The delivery person does not have an access badge. Which social engineering attack is this?
58A security administrator wants to protect data at rest on a laptop that may be lost or stolen. Which of the following is the BEST solution?
59Which backup strategy involves keeping three copies of data on two different media types with one copy offsite?
60What is the primary purpose of a network firewall?
61Which type of malware attaches to legitimate files and spreads when those files are executed?
62A company requires employees to use a one-time code from a smartphone app in addition to their password to log into the corporate VPN. This is an example of:
63What is the primary risk of using public Wi-Fi without a VPN?
64Which THREE of the following are characteristics of a strong password? (Select THREE)
65Which TWO of the following are types of malware? (Select TWO)
66Which of the following best describes the 'Confidentiality' component of the CIA triad?
67A company is implementing a backup strategy. Which of the following best adheres to the 3-2-1 backup rule?
68An organization wants to ensure that employees only have access to the data necessary to perform their job functions. Which principle should be applied?
69A security analyst notices that a user's computer is running slowly and displaying many pop-up ads. Which type of malware is most likely causing this?
70Which of the following is the primary purpose of hashing a password before storing it in a database?
71What is the difference between a threat and a vulnerability?
72An employee is working from a coffee shop and needs to access company files. Which of the following is the most secure method?
73Which of the following is a characteristic of a worm compared to a virus?
74What is the primary purpose of a firewall?
75A company is developing a security policy. Which THREE of the following are examples of physical security controls?
76Which TWO of the following are best practices for password security?
77A user receives an email from their bank asking them to click a link and verify their account information. The email contains spelling errors and the sender's address looks suspicious. Which type of social engineering attack is this?
78Which TWO of the following are examples of multi-factor authentication?
79Which TWO of the following are characteristics of ransomware?
80Which THREE of the following are best practices for password security?
81A security analyst is evaluating risks to the company's network. According to the risk formula (Risk = Likelihood × Impact), which THREE of the following are considered vulnerabilities?
82Which TWO of the following are examples of physical security controls?
83A user wants to protect their laptop in case it is stolen. Which TWO of the following measures would help protect the confidentiality of the data?
84A small accounting firm's wireless network currently uses WPA2-Personal with a shared passphrase that all 20 employees know. The office manager reports that a former contractor who was given the passphrase can still connect to the Wi-Fi from the parking lot. The firm wants each user to authenticate with their own unique credentials and wants to be able to revoke access for one person without disrupting everyone else. Which wireless security method should the firm implement?
85A small office wants to prevent unauthorized people from connecting to its wireless network while still allowing visitors to use Wi-Fi. The office manager enables WPA3-Personal on the access point. Which requirement does this configuration satisfy?
86A technician is configuring a Windows workstation for a finance employee. The employee needs to read and update customer records but should not be able to change the folder's permissions or take ownership. Which NTFS permission should the technician assign?
87A small accounting firm stores client tax records on a shared network folder. The owner wants to ensure that only the three staff members who prepare taxes can open those files, while other employees can still access the general office folder. Which security concept should the owner apply to the tax records folder?
88A small business owner installs a wireless access point in a coffee shop for customers. The owner wants to prevent strangers outside the building from reading the wireless traffic of paying customers. Which security feature should be enabled on the access point?
89A user's web browser displays a warning that the connection to an online store is not private because the site's certificate cannot be validated. The user asks a technician what the warning means. Which explanation is MOST accurate?
90An employee at a marketing agency connects a personal smartphone to the corporate guest Wi-Fi to check social media. The phone has no screen lock and runs an outdated operating system. The IT administrator is concerned this device could serve as an entry point into the corporate network. Which term BEST describes the risk introduced by this device?
91An employee at a marketing firm plugs an unknown USB flash drive found in the parking lot into a workstation to identify its owner. Within minutes, files on a shared network folder begin to be renamed with a .locked extension and a ransom note appears. Which type of malware most likely caused this behavior?
92A small office wants to prevent unauthorized individuals from connecting to its wireless network. The office manager enables WPA3-Personal and configures a pre-shared key. Which additional step BEST reduces the risk of unauthorized access?
93A help desk technician is reviewing security practices with a new employee who works remotely. Which TWO of the following actions BEST reduce the risk of a malware infection on the employee's workstation? (Choose two.)
94A small business owner wants to secure the wireless network at a retail store. The owner wants customers to have internet access without needing a password, but also wants to keep the internal point-of-sale (POS) network separate and protected. Which of the following should the owner configure?
95A small office's wireless router still ships with the administrator username and default password printed in its manual. A technician is asked to harden the device before it goes into production. Which action BEST addresses this specific risk?
96A hospital's pharmacy system requires that every time a pharmacist adjusts a medication order, the system records who made the change, the exact time, and the previous value. Auditors later need to prove that no record was altered after the fact. Which security principle is the hospital primarily implementing?
97An IT technician is configuring a new employee's laptop. The employee will handle payroll data and must access the payroll application from home. The company requires that the connection be encrypted and that the employee's device prove its identity before access is granted. Which technology BEST meets these requirements?
98An attacker sets up a fake wireless access point named "Cafe_Free_WiFi" in a coffee shop and uses it to capture the traffic of customers who connect. Which type of attack is this?
99A technician is asked to dispose of several old hard drives that contained customer records. The drives still function and the company wants to reuse them in a different department. Which action BEST protects the data while allowing reuse?
100A user is creating a new password for an online banking account. The bank requires a minimum of 12 characters and recommends using a passphrase. Which of the following passwords BEST follows current security best practices?
101A new employee at a software company receives a laptop and must follow the organization's security policy when choosing credentials and handling them day to day. Which TWO of the following practices align with standard authentication security guidance? (Choose two.)
102A help desk technician is coaching a new employee on how to recognize social engineering attempts that arrive by phone and text message rather than email. Which TWO characteristics should the technician tell the employee to treat as warning signs? (Choose two.)
103A small business owner wants to let visitors use the office Wi-Fi without giving them access to the company's file server or networked printers. Which of the following is the BEST way to accomplish this?
104A small business owner wants to keep a record of the software installed on each employee laptop and receive an alert if unauthorized software is installed later. The owner asks a technician for the BEST tool to accomplish this. Which of the following should the technician recommend?
105A security administrator is reviewing authentication logs and notices hundreds of failed login attempts against many user accounts from a single external IP address within a few minutes. No accounts were successfully accessed. Which type of attack is occurring?
106A user's workstation has become slow and shows unexpected pop-up windows even when no browser is open. A technician suspects malware and wants to reduce the risk of further compromise while investigating. Which TWO actions should the technician take FIRST? (Choose two.)
107A security analyst is reviewing access logs and notices that an employee in the marketing department was able to read files in the human resources shared folder. The employee's account should only have access to marketing resources. Which security principle was violated?
108A warehouse supervisor reports that an unknown person wearing a delivery uniform walked through the open loading dock, entered the server room, and left with a backup drive. The company wants to prevent unauthorized entry into the server room without rebuilding the entire facility. Which control should be implemented FIRST?
109A user is creating an account on a shopping website and is asked to choose a password. Which of the following passwords BEST follows current security guidance for resisting brute-force and dictionary attacks?
110An employee working from a coffee shop connects a laptop to an open wireless network to check webmail. The employee wants to prevent other patrons on that same network from capturing the login credentials in transit. Which technology BEST provides this protection?
111A user is working from a coffee shop and needs to access the corporate file server. The user connects to the coffee shop's open Wi-Fi network and wants to ensure that the data transmitted between the laptop and the corporate network cannot be read by others on the same network. Which of the following should the user implement?
112A user is setting up a new smartphone for work and wants to reduce the risk of unauthorized access if the device is lost. Which two measures should the user implement? (Choose two.)
113An organization's security policy requires that users prove their identity with something they know and something they have when accessing the payroll system from outside the office. A user enters a password and then a code generated by a mobile app. Which security concept does this scenario illustrate?
114A user receives a text message claiming to be from a package delivery service, saying a package could not be delivered and asking the user to click a link to reschedule. The user is unsure if the message is legitimate. Which TWO of the following actions should the user take to verify the message and avoid becoming a victim? (Choose two.)
115A technician is helping a small office set up basic physical security for its server closet. Which TWO of the following are physical security controls that would protect the equipment in the closet? (Choose two.)
116A finance team member must share a spreadsheet containing customer account numbers with an external auditor. The team member wants to ensure that only the intended recipient can read the file contents. Which action BEST accomplishes this?
117A user is browsing the web on a public Wi-Fi network at a coffee shop and needs to check a personal bank account. The bank's website address begins with https. Which statement BEST describes how the user's connection is protected?
118A user's web browser warns that the connection to an online store is not private because the site's certificate cannot be validated. The user ignores the warning and enters payment card details anyway. Which type of attack is the user MOST at risk of in this situation?
119An administrator reviews a server's audit log and finds a long series of failed login attempts against many different usernames, all originating from a single external address within a few minutes. No attempt succeeded. Which term BEST describes this activity?
120A user is setting up a new smartphone and wants to protect the data on it in case the device is lost or stolen. The user wants to ensure that if the phone falls into the wrong hands, the data cannot be easily accessed. Which of the following should the user enable FIRST?
121A help desk technician receives a call from someone claiming to be a company vice president who is traveling and urgently needs their password reset over the phone. The caller's number matches an internal extension. Which action should the technician take FIRST?
122A user is setting up a new wireless router for a home office and wants to secure the wireless network. Which TWO of the following should the user configure to help prevent unauthorized access? (Choose two.)
123A technician is asked to dispose of several old hard drives that contain sensitive company data. The technician wants to ensure that the data cannot be recovered by anyone who obtains the drives. Which of the following methods is the MOST secure?
Be able to identify malware by behavior, choose the right wireless security mode, and explain threat versus vulnerability. The key skill is matching a scenario to the correct control, especially rotating credentials and applying the 3-2-1 backup rule.
The Courseiva FC0-U71 question bank contains 123 questions in the Security domain, covering the 19% of the exam attributed to this domain in the official CompTIA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included