Free Security+ Practice Test Questions
If you’re preparing for the Security+ SY0-401 exam, you might like to check your readiness with some free Security+ practice test questions. This page includes three free Security+ practice test questions from the following objective in the SY0-401 exam.
Master Security+ Performance Based Questions Video
Objective 3.2 Analyze and differentiate among types of attacks
- Man-in-the-middle
- DDoS
- DoS
- Replay
- Smurf attack
- Spoofing
- Spam
- Phishing
- Spim
- Vishing
- Spear phishing
- Xmas attack
- Pharming
- Privilege escalation
- Malicious insider threat
- DNS poisoning and ARP poisoning
- Transitive access
- Client-side attacks
The full explanations of all each of these free Security+ practice test questions are covered in the CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide. This study guide includes over 440 realistic Security+ practice test questions to help you pass the Security+ exam, the first time you take it.
“Passed exam with this book as my only source”
– Amazon reviewer for
CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide
Security+ Practice Test Question 1
Q. Bob reported receiving a message from his bank prompting him to call back about a credit card. When he called back, an automated recording prompted him to provide personal information to verify his identity and then provide details about his bank and credit card accounts. What type of attack is this?
A. Phishing
B. Whaling
C. Vishing
D. VoIP
Answer at end of post.
Learn by listening
Key points from the CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide
Over one hour and 20 minutes of audio from the “Remember This” blocks
Over three hours and 20 minutes of questions and answers on audio.
Security+ Practice Test Question 2
Q. Attackers sent a targeted email attack to the President of a company. What best describes this attack?
A. Phishing
B. Spam
C. Whaling
D. Botnet
Answer at end of post.
Available through LearnZapp on your mobile phone
Security+ Practice Test Question 3
Q. What can mitigate ARP poisoning attacks in a network?
A. Disable unused ports on a switch
B. Man-in-the-middle
C. DMZ
D. VLAN segregation
Answer at end of post.
These practice test questions are derived from the CompTIA Security+: Get Certified Get Ahead- SY0-401 Practice Test Questions book. It includes 275 realistic practice test questions with in-depth explanations for the CompTIA Security+ SY0-401 exam. If you’ve been studying for this exam and want to test your readiness, this book is for you.
It is also available as Kindle ebook for only $9.99 and the Kindle version also includes dozens of flash cards to help you reinforce key testable topics. You can download free Kindle apps from Amazon so that you can access the ebook from just about any platform including:
- Windows PC
- MAC
- iPhone
- iPad
- Android
- BlackBerry
- Windows Phone 7
You may also like to check out other the Security+ blogs and practice test questions from this link or individually here:
- Active Fingerprinting vs Passive Fingerprinting
- Ports
- Intrusion Detection Systems and Intrusion Prevention Systems
- DoS, Smurf, and Fraggle Attacks
- Three Factors of Authentication and Multifactor Authentication
SY0-401: Exam Answer 1
Q. Bob reported receiving a message from his bank prompting him to call back about a credit card. When he called back, an automated recording prompted him to provide personal information to verify his identity and then provide details about his bank and credit card accounts. What type of attack is this?
A. Phishing
B. Whaling
C. Vishing
D. VoIP
Answer C is correct. Vishing is a form of phishing that uses recorded voice over the telephone.
A is incorrect. Phishing sends e-mail to users with the purpose of tricking them into revealing personal information (such as bank account information).
B is incorrect. Whaling is a phishing attack that targets high-level executives.
D is incorrect. Voice over IP (VoIP) is a method used to send voice transmissions over a network. It is not an attack.
Objective: 3.2 Analyze and differentiate among types of attacks
All Security+ domain objectives are fully explained in the
CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide
SY0-401 Exam: Answer 2
Q.Attackers sent a targeted email attack to the President of a company. What BEST describes this attack?
A. Phishing
B. Spam
C. Whaling
D. Botnet
Answer C is correct. Whaling is a phishing attack that targets high-level executives and phishing is an email attack.
A is incorrect. Whaling is a phishing attack that targets high-level executives, while phishing is a wide-scale attack using email. This is a good example of how CompTIA often gives you two or more answers that could be correct but only one is the best answer.
B is incorrect. Spam is unsolicited email and phishing and whaling attacks are sent as spam, but spam itself isn’t a targeted attack.
D is incorrect. A botnet is a group of computers joined to a network and criminals control them with command and control servers.
Objective: 3.2 Analyze and differentiate among types of attacks
If you’re looking for more information on the CompTIA Security+ exam, click here.
The link provides a listing of relevant blogs on the Get Certified Get Ahead site.
SY0-401: Answer 3
Q. What can mitigate ARP poisoning attacks in a network?
A. Disable unused ports on a switch
B. Man-in-the-middle
C. DMZ
D. VLAN segregation
Answer D is correct. Address Resolution Protocol (ARP) poisoning attacks modify the hardware addresses in ARP cache to redirect traffic, and virtual local area network (VLAN) segregation can limit the scope of these attacks.
A is incorrect. Disabling unused physical ports on a switch is a good security practice, but it doesn’t prevent ARP poisoning attacks.
B is incorrect. A man-in-the middle attack can interrupt traffic, insert malicious code, and ARP poisoning is one way to launch a man-in-the middle attack.
C is incorrect. A DMZ provides access to services from Internet clients, while segmenting access to an internal network.
Objective: 3.2 Analyze and differentiate among types of attacks
If you want to take and pass the Security+ exam the first time you take it, check out the
CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide.
Success is within your reach.
Hi Dariil- For Q3, would you be kind enough to explain how a VLAN segregation can mitigate ARP cache poisoning attacks? I failed to understand it.
Thanks in advance.
First, mitigate indicates reduce here.
Second, think about how ARP works – it uses broadcasts and broadcasts do not pass routers, or to different VLANs configured on switches.
Imagine a switch has 24 ports. An ARP poisoning attack can hit 24 ports.
Now consider the same switch with three VLANs.
This becomes three different broadcast domains.
This limits the scope of any single ARP poisoning attack to 8 ports instead of 24.
As an aside, based on your Facebook posts, I’m thinking you’re ready. When do you test?
Hope this helps.
Question #2 has the right answer but the wrong explanation… IPsec (and its definition) has nothing to do with a question about Whaling. 🙂
Thanks. I fixed it.
In answer A explanation to question 2 “Whaling” should be removed since what you are explaining is Phishing instead.
By the way I really found your book very helpful and clear to use as a study guide. Inshallah I will be taking the test in the next week.
Hi Abu,
Thanks for the feedback, and the kind words about the book.
I modified the explanation to amplify the difference between generic phishing and targeted phishing (whaling).
This is a good example of how CompTIA often gives you two or more answers that could be correct but only one is the best answer. Phishing is generic, while whaling and spear phishing are targeted forms of phishing and there are multiple ways that CompTIA can ask you about them.
Good luck on the exam.