pg. 1 2025 CompTIA Sec+ Practice Assessment with 200 real exam prep questions and correct verified answers/ CompTIA Sec+ latest exam prep test bank 2025 (brand new!)
A large multinational company adopts a new standard to enhance its information security management system. The company operates across different regions, so the chosen standard must be internationally recognized. The company wants the standard to provide a comprehensive framework to ensure adequate and proportionate security controls. Which of the following standards would be MOST suitable for the company's needs?
ISO/IEC 27001
At a medium-scale software development firm, significant modifications to several critical applications employees use daily are on the horizon. Considering the principles of change management, what should the primary focus be during the implementation phase of these changes?Scheduling service restarts during non-business hours to minimize application downtime What type of data is information that can easily be understood and interpreted without additional processing or translation?Human-readable data A cybersecurity analyst for a large organization is enhancing the company's security posture. The analyst notices increased alerts related to a particular known exploit in the company's server software. The company's intrusion detection system (IDS) uses a predefined set of rules, provided by security personnel, to identify events that are unacceptable. What type of detection method is the company using in this scenario?Signature-based detection Considering common threat vectors and attack surfaces, which statement BEST describes the primary risk, from a cybersecurity perspective, with using unsupported systems and applications? 1 / 4
pg. 2 Unsupported systems no longer receive vendor updates or patches, making their attack surfaces more susceptible to known exploits.A multinational corporation is sending sensitive data to various regional offices securely. What is an optimal cryptographic method to employ in this situation?Symmetric encryption for data and asymmetric for key exchange A manufacturing organization identifies its server maintenance and repair process as a mission-essential function. The company experienced three server failures in the last year, each failure taking approximately six hours to repair and restore operations. A standard operational year is usually assumed to be 8,760 hours (24*365). Given the company's performance metrics and assuming operations run all day and every day, what are the annual MTBF and MTTR for the organization's server maintenance and repair process?MTBF: 2,920 hours/failure, MTTR: 6 hours At a healthcare technology company, a cybersecurity alert flagged an unusual pattern of data traffic from one of its key database servers. Initial analysis indicates a potential data breach that is not yet conclusively confirmed. The server contains sensitive patient data. If confirmed, it could have severe legal and reputational implications for the company. What steps should the incident response team take to better understand the situation?Conduct a detailed analysis of the alert using threat intelligence and incident response playbooks An IT architect of a medium-sized e-commerce business is planning to optimize their system's capacity and lower operating costs. As part of this, the architect is considering a clustering solution for the servers, with the key objective being maximum capacity and seamless customer experience. Which type of clustering setup would BEST meet the needs of this e-commerce business?Active/Active Clustering
PBQ: 1.Best suited to assign access based on job roles?
- foundational in securing sensitive patient data?
- authentication for securing highly sensitive client information?
Doctor Access? 2 / 4
pg. 3 Nurse Access?External Auditor Access?
1. RBAC
- Implicit Deny
- Biometric Authentication
Doctor Access: VPN, Database Editor, Multifactor Authentication
Nurse Access: Secure Web Portal, Database Viewer, Passwords
External Audit Access: Temporary Secure Web Portal, External Consultant, OTP
An organization recently hired a new employee who passed all the necessary background checks and completed the recruitment process successfully. The organization wants to ensure that the new employee's integration into the company is as smooth and secure as possible. Which of the following procedures would be MOST appropriate to apply in this situation?Onboarding The company's system has recently detected suspicious network activity, signaling a possible cybersecurity incident. The incident response team has assembled, and after going through the detection and analysis phases, the containment phase of the incident response process has started. In this phase, what is the primary objective?Limiting the scope and magnitude of the incident An organization has decommissioned several laptops used for handling sensitive data. Which of the following should be the primary step to ensure data security and compliance with regulations before repurposing or disposing of these devices?Initiating a secure data destruction process A newly established organization has decided to implement Virtual LANs (VLANs) for segmenting workstation computer hosts from Voice over Internet Protocol (VoIP) handsets. The organization is using two VLANs that map to two
subnets: 10.1.32.0/24 for workstation computers and 10.1.40.0/24 for VoIP
handsets. In this setup, what could be a potential security advantage?Enhanced control over communication between VLANs. 3 / 4
pg. 4 A software engineer discovers a flaw in one of its products that could allow nefarious attackers to gain unauthorized access to the system on which it is running. What vulnerability signifies that developers must immediately fix the problem or widespread damage could ensue before a patch is available.Zero-day A technology company experiences several security vulnerabilities with its online application, leading to customer complaints and legal threats. In response, the board of directors decides to outsource the maintenance and associated liabilities of the application to a third party. Which risk management strategy is the company primarily implementing?Risk transference A multinational firm headquartered in San Francisco, California, serves customers from various countries, including European Union countries. The company collects, processes, and stores substantial amounts of personal data. With which of the following legal regulations must the company's governance committee ensure compliance?Both General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) An organization considers a new third-party vendor to provide critical technology solutions. It is nearing the final stages of the vendor selection process and wants to ensure a robust assessment of the vendor's security practices and risk management capabilities. Provided approval is granted, which method would be MOST suitable for the organization to gain an in-depth understanding of the vendor's security controls, identify potential vulnerabilities in its systems, and validate the effectiveness of its security measures?Conduct a penetration test After an extensive security audit, a medium-sized corporation discovers several of its company laptops contain malware. The malware is most likely the result of the use of unauthorized USB storage devices. The chief information security officer (CISO) wants to prevent similar incidents in the future. Which of the following options would best mitigate this risk?Deploy port control software and restrict the use of USB storage devices
- / 4