Courseiva

220-1201 · topic practice

Security practice questions

Practise CompTIA A+ Core 1 220-1201 Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Security

What the exam tests

What to know about Security

Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Security questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Review the full routing breakdown →

A technician is setting up a temporary network for a conference where attendees' laptops need to share files directly without any central access point or router. The conference room has no existing network infrastructure. Which network type should be configured, and what is a potential security risk?

Question 2easymultiple choice
Read the full wireless explanation →

A user reports that their laptop can connect to the internet via Ethernet but cannot connect to any Wi-Fi networks. The wireless adapter is enabled and shows available networks, but connecting always fails. What is the most likely cause?

Question 3easymultiple choice
Read the full Security explanation →

A technician is configuring a new workstation for a secure environment. The policy requires that only signed operating systems can boot. Which UEFI feature should be enabled?

Question 4easymultiple choice
Read the full Security explanation →

A company uses a cloud-based customer relationship management (CRM) application. The vendor handles all updates, security patches, and infrastructure maintenance. Which cloud service model does this represent?

Question 5mediummultiple choice
Read the full Security explanation →

A technician is configuring a new server and needs to ensure that only signed operating system bootloaders can be loaded. Which UEFI feature should be enabled?

Question 6easymultiple choice
Read the full Security explanation →

A technician needs to boot a laptop from a USB drive to run a diagnostic tool. The USB is plugged in but the system skips it and boots from the internal SSD. Which UEFI setting is most likely preventing the USB boot?

Question 7easymultiple choice
Read the full wireless explanation →

A user reports that their smartphone can connect to Wi-Fi at home but not at the office. Other devices connect fine to the office Wi-Fi. What is the most likely cause?

Question 8hardmultiple choice
Open the full VLAN trunking answer →

A technician is troubleshooting a network where users on one floor cannot communicate with users on another floor. Both floors are connected to the same switch via separate VLANs configured for security. What additional device is needed to allow communication between the VLANs?

Question 9hardmultiple choice
Read the full Security explanation →

A technician upgrades a workstation from Windows 10 to Windows 11, but the installation fails with an error that the system does not support TPM 2.0. The CPU is compatible. What must the technician do in UEFI to resolve this?

Question 10mediummultiple choice
Read the full Security explanation →

A user reports that they can receive emails but cannot send any. The email client is configured with SMTP on port 25. The IT team confirms that port 25 is blocked by the ISP. Which alternative port should be used for SMTP submission?

Question 11mediummultiple choice
Read the full DHCP explanation →

A technician is troubleshooting a network where a user's computer cannot obtain an IP address via DHCP. The computer is connected to a switch, and other devices on the same switch work fine. The technician checks the switch and sees that the port is up and the link light is green. What should the technician check next?

Question 12hardmultiple choice
Read the full wireless explanation →

A technician is deploying a fleet of tablets that must connect to a corporate network using 802.1X authentication with certificates. After configuring the Wi-Fi profile, some tablets fail to connect. The technician verifies the SSID and security settings are correct. What is the most likely missing configuration?

Question 13hardmultiple choice
Read the full Security explanation →

A technician is tasked with securing a workstation that will be used in a public kiosk. The requirement is that the system must only boot from the internal SSD and must prevent booting from USB drives or optical media. Which UEFI security feature should be configured?

Question 14hardmultiple choice
Read the full Security explanation →

A company uses a public cloud IaaS provider. The security team discovers that a virtual machine's data disk was accidentally deleted by an administrator. They need to recover the data from a snapshot taken 24 hours ago. The snapshot is stored in the same cloud region. What is the most efficient recovery method?

Question 15mediummultiple choice
Read the full wireless explanation →

A technician is setting up a new wireless network for a small office. The office has three access points (APs) that should allow seamless roaming. The technician configures all APs with the same SSID and security settings. What additional configuration is necessary to prevent clients from staying connected to a weak signal?

Question 16hardmultiple choice
Read the full VPN explanation →

A technician is configuring a network printer for secure printing using IPsec. After enabling IPsec on the printer and the print server, print jobs fail to reach the printer. The technician can ping the printer from the server. Which protocol negotiation step is most likely failing?

Question 17hardmultiple choice
Read the full Security explanation →

A technician is troubleshooting a network where users on one floor cannot access a server on another floor. Both floors are connected via a single fiber optic link. The technician checks the link and sees the switch port shows 'err-disabled' status. What is the most likely cause of this state?

Question 18hardmultiple choice
Read the full Security explanation →

A technician is configuring a kiosk tablet that must connect to a wired Ethernet network for security reasons. The tablet only has a USB-C port. The network drop provides an RJ45 connection. Which of the following should the technician use to achieve a wired connection?

Question 19mediummultiple choice
Read the full Security explanation →

During a network security audit, a technician finds that an employee is using a protocol that allows remote control of a computer with full graphical interface but without encryption. Which protocol should be replaced with a more secure alternative?

Question 20hardmultiple choice
Read the full Security explanation →

A company is migrating its fleet of 100 desktops from Windows 10 to Windows 11. The IT department needs to enable TPM 2.0 and Secure Boot on each system via the UEFI. Some older systems have TPM disabled by default. Which UEFI setting must be changed to enable TPM?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security sessions

Start a Security only practice session

Every question in these sessions is drawn from the Security domain — nothing else.

Related practice questions

Related 220-1201 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 220-1201 exam test about Security?
Security questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 220-1201 topics?
Use the topic links above to move to related areas, or go back to the 220-1201 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 220-1201 exam covers. They are not copied from any real exam or dump site.