220-1202 · domain
Security
Domain 4 (Security) covers physical and logical security for Windows endpoints and networks: malware types, social engineering, wireless and authentication protocols, hardening, and data destruction. Questions are scenario-based, asking you to diagnose a symptom or select the control that best fits a stated business or compliance requirement.
Focused practice
Practice Security questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Security
Diagnose security symptoms and apply the correct Windows or network control: identify malware, verify certificate and DNS behavior, configure BitLocker and permissions, and select the right wireless authentication. Getting the threat-to-control mapping right matters most.
Watch out for
Common Security exam traps
- ▸Confusing authentication with authorization; 802.1X controls network access, while NTFS and share permissions govern file access after login.
- ▸Choosing antivirus scanning when the symptom (redirected DNS, spoofed certificate) points to a network attack requiring DNS or certificate remediation.
- ▸Assuming BitLocker alone satisfies compliance; without TPM, PIN, or startup key, the drive may still be accessible if removed.
Question index
All Security questions (11)
Click any question to see the full explanation, or start a practice session above.
A user reports that when visiting a banking website, the browser displays a warning that the site's certificate is not trusted, even though the site worked yesterday. The technician verifies the system clock is correct and the network is functioning. Which of the following is the MOST likely cause?
Medium2A technician is asked to dispose of several old company laptops that contain sensitive customer data. The company wants to ensure the data cannot be recovered while still allowing the laptops to be donated. Which of the following should the technician perform?
Medium3A user reports that when they connect to the corporate Wi-Fi at a coffee shop, a browser warning appears stating the site's certificate is not trusted. The user is able to browse the internet but sees the warning on every HTTPS site. A technician suspects an on-path attack. Which of the following should the technician check FIRST to confirm the presence of an on-path attack?
Medium4A user at a small office reports that whenever they connect to the corporate Wi-Fi in the break room, their laptop warns that the network is unsecured and other devices on the same network can see their traffic. The access point in the break room broadcasts an open SSID with no password. Which of the following should a technician configure on the access point to protect wireless traffic while keeping the SSID available to employees?
Easy5A technician is asked to dispose of several old company laptops that contain customer records on their internal drives. The drives are traditional spinning magnetic disks, and the company wants to reuse the laptops internally after the data is removed. Which of the following is the BEST method to ensure the customer data cannot be recovered?
Medium6A security analyst notices that an employee's account is logging in successfully from two different countries within a five-minute window. The account uses a complex password, and the employee confirms they did not travel. The organization already requires multifactor authentication for all users. Which of the following is the MOST likely cause of the suspicious logins?
Hard7A technician is configuring a Windows 11 workstation for a small business that handles credit card payments. The owner wants to ensure that stored cardholder data cannot be read if the drive is removed and attached to another computer. Which Windows feature should the technician enable?
Easy8A security administrator is reviewing authentication methods for a company that wants to reduce the risk of credential theft while allowing employees to log in from personal mobile devices. Which two of the following should the administrator implement? (Choose two.)
Hard9A user reports that their Windows 11 laptop frequently displays a message that the battery is not charging and the system clock keeps resetting to an earlier date. The laptop is plugged into a known-good power outlet. Which of the following should a technician check first?
Easy10An administrator receives an alert that a workstation is repeatedly making DNS queries for random-looking domain names and sending small amounts of data to external IP addresses every few minutes. The endpoint protection agent is installed and up to date, and no user is logged in. Which of the following is the MOST likely explanation for this behavior?
Medium11A security analyst notices that several workstations on the same subnet are resolving popular banking domains to an IP address that belongs to an unknown server. The analyst confirms the DHCP server is legitimate and the DNS server settings have not been changed by Group Policy. Which of the following attacks is MOST likely occurring?
HardOther domains
All 220-1202 exam domains
Frequently asked questions
- What does the Security domain cover on the 220-1202 exam?
- Diagnose security symptoms and apply the correct Windows or network control: identify malware, verify certificate and DNS behavior, configure BitLocker and permissions, and select the right wireless authentication. Getting the threat-to-control mapping right matters most.
- How many questions are in this domain?
- This page lists all 11 Security questions in the 220-1202 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.