Wednesday, November 21, 2012

Free Security+ Practice Test Questions 2.1


If you're preparing for the Security+ SY0-301 exam, you might like to check your readiness with a few free practice test questions. This page includes three free practice test questions from the following objective in the SY0-301 exam.

Objective 2.1 Explain risk related concepts

  • Control Types
  •   Technical
  •   Management
  •   Operational
  • False positives
  • Importance of policies in reducing risk
  •   Privacy policy
  •   Acceptable use
  •   Security policy
  •   Mandatory vacations
  •   Job rotation
  •   Separation of duties
  •   Least privilege
  • Risk calculation
  •   Likelihood
  •   ALE
  •   Impact
  • Quantitative vs. qualitative
  • Risk-avoidance, transference, acceptance, mitigation, deterrence
  • Risks associated to Cloud Computing and Virtualization
The full explanations of all these questions are covered in the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide.  This study guide includes over 450 realistic practice test questions to help you pass the Security+ exam, the first time you take it.

Practice Test Question 1

Q. Of the following choices, what type of control is least privilege?
A. Corrective
B. Technical
C. Detective
D. Preventative

Answer at end of post.

Learn by listening 
Key points from the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide
Over one hour and 20 minutes of audio from the "Remember This" blocks
Over three hours and 20 minutes of questions and answers on audio

Practice Test Question 2

Q. What is the purpose of risk mitigation?

A. Reduce the chances that a threat will exploit a vulnerability
B. Reduce the chances that a vulnerability will exploit a threat
C. Eliminate risk
D. Eliminate threats

Answer at end of post.
Realistic practice test questions for the Security+ SY0-301 exam
Available through LearnZapp on your mobile phone

Practice Test Question 3

Q.  An organization has purchased fire insurance to manage the risk of a potential fire. What method are they using?

A. Risk acceptance
B. Risk avoidance
C. Risk  deterrence
D. Risk mitigation
E. Risk transference

Answer at end of post.

These practice test questions are from the CompTIA Security+: Get Certified Get Ahead- SY0-301 Practice Test Questions book. It includes 275 realistic practice test questions with in-depth explanations for the CompTIA Security+ SY0-301 exam. If you've been studying for this exam and want to test your readiness, this book is for you.
It is also available as Kindle ebook for only $9.99 and the Kindle version also includes dozens of flash cards to help you reinforce key testable topics. You can download free Kindle apps from Amazon so that you can access the ebook from just about any platform including:
  • Windows PC
  • MAC
  • iPhone
  • iPad
  • Android
  • BlackBerry
  • Windows Phone 7

You may also like to check out other the Security+ blogs and practice test questions from this link or individually here:

SY0-301: Exam Answer 1

Q. Of the following choices, what type of control is least privilege?
A. Corrective
B. Technical
C. Detective
D. Preventative

Answer B is correct. The principle of least privilege is a technical control and ensures that users have only the rights and permissions needed to perform the job, and no more.
A is incorrect. A corrective control attempts to reverse the effects of a problem.
C is incorrect. A detective control (such as a security audit) detects when a vulnerability has been exploited.
D is incorrect. A preventative control attempts to prevent an incident from occurring.

Objective: 2.1 Explain risk related concepts

All Security+ domain objectives are fully explained in the
CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide

SY0-301 Exam: Answer 2

Q. What is the purpose of risk mitigation?

A. Reduce the chances that a threat will exploit a vulnerability
B. Reduce the chances that a vulnerability will exploit a threat
C. Eliminate risk
D. Eliminate threats

Answer A is correct. Risk mitigation reduces the chances that a threat will exploit a vulnerability.

B is incorrect. Risk is the likelihood that a threat (such as an attacker) will exploit a vulnerability (any weakness). A vulnerability cannot exploit a threat.
C is incorrect.You cannot eliminate risk.
D is incorrect. You cannot eliminate threats.

Objective: 2.1 Explain risk related concepts


If you're looking for more information on the CompTIA Security+ exam, click here.
The link provides a listing of relevant blogs on the Get Certified Get Ahead site.

SY0-301: Answer 3

Q.  An organization has purchased fire insurance to manage the risk of a potential fire. What method are they using?

A. Risk acceptance
B. Risk avoidance
C. Risk  deterrence
D. Risk mitigation
E. Risk transference

Answer E is correct. Purchasing insurance is a common method of risk transference.
A is incorrect. Organizations often accept a risk when the cost of the control exceeds the cost of the risk.
B is incorrect. An organization can avoid a risk by not providing a service or participating in a risky activity.
C is incorrect. Risk deterrence attempts to discourage attacks with preventative controls such as a security guard.
D is incorrect: Risk mitigation reduces risks through internal controls.

Objective: 2.1 Explain risk related concepts

If you want to take and pass the Security+ exam the first time you take it, check out the
CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide.

Success is within your reach.


Get Certified Get Ahead