Courseiva

FC0-U71 · topic practice

Security practice questions

Security covers the concepts, threats, and controls tested on CompTIA Tech+ (FC0-U71). Expect scenario items on malware types, wireless encryption such as WPA2 and WPA3, threat versus vulnerability, authentication factors, and backup practices including the 3-2-1 rule, plus basic physical and logical security measures.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security

What the exam tests

What to know about Security

Be able to identify malware by behavior, choose the right wireless security mode, and explain threat versus vulnerability. The key skill is matching a scenario to the correct control, especially rotating credentials and applying the 3-2-1 backup rule.

Distinguishing malware types: virus, worm, trojan, ransomware, spyware, and phishing tactics

Wireless security modes: WPA2/WPA3-Personal versus Enterprise, and why shared passphrases fail

Difference between a threat, a vulnerability, and a risk in given scenarios

Backup best practices, including the 3-2-1 rule and restoring data after loss

Watch out for

Common Security exam traps

  • ▸Confusing a threat with a vulnerability: a threat exploits, a vulnerability is the weakness being exploited.
  • ▸Assuming WPA2-Personal passphrase changes remove access; a former user who knows it can still connect until the key rotates.
  • ▸Treating any single backup copy as sufficient; the 3-2-1 rule requires three copies, two media types, one offsite.

Practice set

Security questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Security explanation →

Which of the following is the best practice for creating strong passwords?

Question 2easymultiple choice
Read the full Security explanation →

Which of the following best describes the principle of confidentiality in the CIA triad?

Question 3mediummultiple choice
Read the full Security explanation →

A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The user suspects it is a phishing attempt. Which type of phishing attack is this most likely to be?

Question 4hardmultiple choice
Read the full Security explanation →

Which of the following encryption methods is used to protect data in transit over a public network, such as the internet?

Question 5hardmulti select
Read the full Security explanation →

An organization is implementing a defense-in-depth strategy. Which THREE of the following are considered security controls that can be used? (Choose THREE.)

Question 6easymultiple choice
Read the full Security explanation →

What is the primary purpose of a password manager?

Question 7mediummulti select
Read the full Security explanation →

A company is implementing physical security measures. Which two of the following are examples of physical security controls? (Select TWO.)

Question 8mediummultiple choice
Read the full Security explanation →

Which of the following best describes the principle of least privilege?

Question 9easymultiple choice
Read the full Security explanation →

What is the primary purpose of a password manager?

Question 10mediummulti select
Read the full Security explanation →

Which TWO of the following are examples of physical security measures? (Select TWO)

Question 11mediummultiple choice
Read the full Security explanation →

An employee receives an email that appears to be from the CEO, urgently requesting a wire transfer to an external vendor. The email address looks slightly off. Which type of social engineering attack is this?

Question 12mediummultiple choice
Read the full Security explanation →

Which of the following is an example of multi-factor authentication?

Question 13easymultiple choice
Read the full Security explanation →

Which of the following is a characteristic of a strong password?

Question 14mediummulti select
Read the full Security explanation →

A help desk technician receives a call from a user who says their computer is showing a message that files are encrypted and a ransom is demanded. Which TWO types of malware are most likely involved?

Question 15hardmulti select
Read the full Security explanation →

A company's IT policy mandates data backups following the 3-2-1 rule. Which TWO of the following practices align with this rule?

Question 16hardmultiple choice
Read the full Security explanation →

A security analyst is reviewing authentication logs and notices that an attacker tried many common passwords against a single user account in a short period. The account was not locked out, and the attacker eventually guessed the correct password. Which of the following should the analyst recommend to BEST prevent this type of attack in the future?

Question 17easymultiple choice
Read the full Security explanation →

Which of the following best describes the principle of confidentiality in the CIA triad?

Question 18mediummultiple choice
Read the full Security explanation →

A company implements a policy requiring employees to use a password and a one-time code sent to their mobile phone when logging into the corporate network. Which security concept is being employed?

Question 19mediummultiple choice
Read the full Security explanation →

A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The email contains urgent language and threats of account closure. What type of attack is this?

Question 20easymultiple choice
Read the full Security explanation →

Which of the following is the strongest password?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security sessions

Start a Security only practice session

Every question in these sessions is drawn from the Security domain — nothing else.

Related practice questions

Related FC0-U71 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the FC0-U71 exam test about Security?
Be able to identify malware by behavior, choose the right wireless security mode, and explain threat versus vulnerability. The key skill is matching a scenario to the correct control, especially rotating credentials and applying the 3-2-1 backup rule.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other FC0-U71 topics?
Use the topic links above to move to related areas, or go back to the FC0-U71 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the FC0-U71 exam covers. They are not copied from any real exam or dump site.