Courseiva

220-1202 · topic practice

Security practice questions

Domain 4 (Security) covers physical and logical security for Windows endpoints and networks: malware types, social engineering, wireless and authentication protocols, hardening, and data destruction. Questions are scenario-based, asking you to diagnose a symptom or select the control that best fits a stated business or compliance requirement.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
16 questionsDomain: Security

What the exam tests

What to know about Security

Diagnose security symptoms and apply the correct Windows or network control: identify malware, verify certificate and DNS behavior, configure BitLocker and permissions, and select the right wireless authentication. Getting the threat-to-control mapping right matters most.

Malware identification and removal using Windows Defender, Task Manager, and msconfig

Wireless security protocols including WPA2/WPA3, RADIUS, and 802.1X authentication

Encryption and access controls such as BitLocker, EFS, NTFS permissions, and MFA

Browser certificate warnings, DNS poisoning, and on-path attack symptoms

Watch out for

Common Security exam traps

  • ▸Confusing authentication with authorization; 802.1X controls network access, while NTFS and share permissions govern file access after login.
  • ▸Choosing antivirus scanning when the symptom (redirected DNS, spoofed certificate) points to a network attack requiring DNS or certificate remediation.
  • ▸Assuming BitLocker alone satisfies compliance; without TPM, PIN, or startup key, the drive may still be accessible if removed.

Practice set

Security questions

16 questions · select your answer, then reveal the explanation

Question 1hardmulti select
Read the full Security explanation →

A security analyst is reviewing a Windows 10 workstation that is suspected of being infected with malware. The analyst notices unusual network traffic and wants to identify the malware's persistence mechanism. Which of the following Windows locations should the analyst check? (Choose two.)

Question 2mediummultiple choice
Read the full Security explanation →

A small office has a Windows 11 Pro workstation that is not joined to a domain. The office manager wants to ensure that files containing customer credit card numbers are encrypted at rest so that if the drive is removed, the data cannot be read. The workstation does not have a TPM chip. Which Windows feature should be enabled to meet this requirement?

Question 3mediummulti select
Read the full Security explanation →

A technician is hardening a Windows 11 workstation that will be used by a remote employee. The goal is to reduce the attack surface against malware delivered through email attachments and malicious websites. Which two of the following built-in Windows features should the technician enable to meet this goal? (Choose two.)

Question 4hardmultiple choice
Read the full Security explanation →

A security analyst is reviewing a Windows 11 event log and notices multiple failed logon attempts (Event ID 4625) for the built-in Administrator account from various source IP addresses. The account is currently disabled. Which of the following best describes what the analyst should do next?

Question 5mediummultiple choice
Read the full Security explanation →

A user's Windows 11 computer is infected with malware that encrypts files and demands payment. The user has a recent full system image backup stored on an external drive that was connected during the infection. Which of the following is the best course of action?

Question 6mediummultiple choice
Read the full wireless explanation →

A user reports that when they connect to the corporate Wi-Fi at a coffee shop, a browser warning appears stating the site's certificate is not trusted. The user is able to browse the internet but sees the warning on every HTTPS site. A technician suspects an on-path attack. Which of the following should the technician check FIRST to confirm the presence of an on-path attack?

Question 7easymultiple choice
Read the full Security explanation →

A technician is configuring a Windows 11 workstation for a small business that handles credit card payments. The owner wants to ensure that stored cardholder data cannot be read if the drive is removed and attached to another computer. Which Windows feature should the technician enable?

Question 8mediummultiple choice
Read the full Security explanation →

A user reports that when visiting a banking website, the browser displays a warning that the site's certificate is not trusted, even though the site worked yesterday. The technician verifies the system clock is correct and the network is functioning. Which of the following is the MOST likely cause?

Question 9hardmultiple choice
Read the full DHCP explanation →

A security analyst notices that several workstations on the same subnet are resolving popular banking domains to an IP address that belongs to an unknown server. The analyst confirms the DHCP server is legitimate and the DNS server settings have not been changed by Group Policy. Which of the following attacks is MOST likely occurring?

Question 10mediummultiple choice
Read the full Security explanation →

A technician is asked to dispose of several old company laptops that contain sensitive customer data. The company wants to ensure the data cannot be recovered while still allowing the laptops to be donated. Which of the following should the technician perform?

Question 11easymultiple choice
Read the full wireless explanation →

A user at a small office reports that whenever they connect to the corporate Wi-Fi in the break room, their laptop warns that the network is unsecured and other devices on the same network can see their traffic. The access point in the break room broadcasts an open SSID with no password. Which of the following should a technician configure on the access point to protect wireless traffic while keeping the SSID available to employees?

Question 12mediummultiple choice
Read the full DNS explanation →

An administrator receives an alert that a workstation is repeatedly making DNS queries for random-looking domain names and sending small amounts of data to external IP addresses every few minutes. The endpoint protection agent is installed and up to date, and no user is logged in. Which of the following is the MOST likely explanation for this behavior?

Question 13hardmulti select
Read the full Security explanation →

A security administrator is reviewing authentication methods for a company that wants to reduce the risk of credential theft while allowing employees to log in from personal mobile devices. Which two of the following should the administrator implement? (Choose two.)

Question 14mediummultiple choice
Read the full Security explanation →

A technician is asked to dispose of several old company laptops that contain customer records on their internal drives. The drives are traditional spinning magnetic disks, and the company wants to reuse the laptops internally after the data is removed. Which of the following is the BEST method to ensure the customer data cannot be recovered?

Question 15hardmultiple choice
Read the full Security explanation →

A security analyst notices that an employee's account is logging in successfully from two different countries within a five-minute window. The account uses a complex password, and the employee confirms they did not travel. The organization already requires multifactor authentication for all users. Which of the following is the MOST likely cause of the suspicious logins?

Question 16easymultiple choice
Read the full Security explanation →

A user reports that their Windows 11 laptop frequently displays a message that the battery is not charging and the system clock keeps resetting to an earlier date. The laptop is plugged into a known-good power outlet. Which of the following should a technician check first?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security sessions

Start a Security only practice session

Every question in these sessions is drawn from the Security domain — nothing else.

Related practice questions

Related 220-1202 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 220-1202 exam test about Security?
Diagnose security symptoms and apply the correct Windows or network control: identify malware, verify certificate and DNS behavior, configure BitLocker and permissions, and select the right wireless authentication. Getting the threat-to-control mapping right matters most.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 220-1202 topics?
Use the topic links above to move to related areas, or go back to the 220-1202 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 220-1202 exam covers. They are not copied from any real exam or dump site.