220-1202 · Original practice content · Last reviewed October 3, 2026

Security A+ Core 2 Practice Questions

Identify threats and apply practical authentication, access control, endpoint protection, and malware-remediation techniques.

Core 2: up to 90 questions in 90 minutes. Passing score: 700 on a 100–900 scale. Both Core 1 and Core 2 are required for CompTIA A+.

These short multiple-choice samples report practice accuracy, not official scaled scores, and do not simulate interactive performance-based questions.

This domain accounts for 28% of Core 2. Topics: authentication, permissions, endpoint hardening, malware removal, physical security, and common threats.

Take the interactive mixed quick-start test · Create a free account

Domain sample questions with answers

Security

Sample question 1

A data center wants an entry area with two doors where the second door cannot open until the first door has closed, so only one person passes at a time. Which physical security control meets this requirement?

  1. Video surveillance
  2. Motion sensors
  3. Bollards
  4. Access control vestibule
Show correct answer and explanation

Correct answer: D. Access control vestibule

D is correct because an access control vestibule traps each person between two interlocked doors, which stops tailgating and piggybacking. A records who enters but does not physically stop a second person from following the first. B detect movement in an area but do not physically limit how many people pass through an entrance. C are short posts that stop vehicles from reaching a building and do not control people passing through a door.

Security

Sample question 2

Which biometric device authenticates a user by scanning the pattern of blood vessels at the back of the eye?

  1. Retina scanner
  2. Palm print scanner
  3. Facial recognition camera
  4. Voice recognition system
Show correct answer and explanation

Correct answer: A. Retina scanner

A is correct because a retina scanner reads the unique pattern of blood vessels on the retina at the back of the eye. B reads the lines and features of the palm of the hand, not the eye. C measures the features and geometry of the face rather than structures inside the eye. D analyzes the characteristics of the user's speech, not the eye.

Security

Sample question 3

Which logical security component provides a central database of user accounts, computers, and groups that other systems query to authenticate and locate network resources?

  1. Mobile device management
  2. Data loss prevention
  3. Directory services
  4. Access control vestibule
Show correct answer and explanation

Correct answer: C. Directory services

C is correct because a directory service such as Active Directory stores identities and resources centrally so systems can look them up and authenticate users. A enrolls and enforces policies on phones and tablets rather than storing the organization's identities. B inspects data in use and in transit to stop sensitive information from leaving the organization. D is a physical two-door entry control and does not store account information.

Security

Sample question 4

A courthouse wants to detect knives and firearms carried by visitors before they pass the public entrance. Which security control should be installed?

  1. A badge reader
  2. A motion sensor
  3. An equipment lock
  4. A magnetometer
Show correct answer and explanation

Correct answer: D. A magnetometer

D is correct because a magnetometer (walk-through metal detector) detects metal objects such as weapons carried on a person. A checks whether a person holds a valid access badge but cannot detect weapons. B detects movement in an area but cannot tell whether a person carries a weapon. C secures a device such as a laptop to a desk and does not screen people for weapons.

Security

Sample question 5

A bank's telephone support line wants callers to authenticate by speaking a short passphrase that is compared with a stored sample of their speech. Which biometric technology does this use?

  1. Fingerprint scanner
  2. Facial recognition technology
  3. Retina scanner
  4. Voice recognition technology
Show correct answer and explanation

Correct answer: D. Voice recognition technology

D is correct because voice recognition compares the unique characteristics of a person's speech with an enrolled voiceprint. A requires the caller to touch a sensor, which is not possible over a phone call. B requires a camera image of the person's face, which a phone call does not provide. C requires the person's eye to be placed close to a scanner, which is not possible over a phone call.

Security

Sample question 6

Workers at a food processing plant wear thick gloves and need to authenticate at the production floor door without touching anything. Which biometric method is the BEST fit?

  1. Smart card reader
  2. Palm print scanner
  3. Facial recognition
  4. Fingerprint scanner
Show correct answer and explanation

Correct answer: C. Facial recognition

C is correct because facial recognition works contactlessly from a short distance and is not affected by the gloves the workers wear. A requires the worker to handle and present a card and is a possession factor, not biometric. B requires the worker to present a bare palm, which the gloves prevent. D requires a bare finger on the sensor, which the gloves prevent.

Security

Sample question 7

A help desk technician only needs to reset passwords for users in one department, but their account is a member of Domain Admins. Which security principle does this violate?

  1. Single sign-on
  2. Least privilege
  3. Zero Trust
  4. Data loss prevention
Show correct answer and explanation

Correct answer: B. Least privilege

B is correct because least privilege means granting only the access needed for the job, so password reset rights for one department are all this role needs. A lets a user sign in once to reach many systems and has nothing to do with excess permissions. C requires every access request to be verified continuously and is not specifically about the size of a role's permissions. D stops sensitive data from leaving the organization and does not govern administrative group membership.

Security

Sample question 8

A company's new policy states that no device or user is trusted because it is on the internal network, and every access request must be authenticated, authorized, and checked for device health. Which security model does this describe?

  1. Zero Trust
  2. Perimeter defense
  3. Single sign-on
  4. Least privilege
Show correct answer and explanation

Correct answer: A. Zero Trust

A is correct because Zero Trust removes implicit trust based on network location and verifies every request continuously. B trusts users and devices once they are inside the network firewall, which is the opposite of this policy. C reduces how often users authenticate, not how strictly each request is checked. D limits how much access is granted but does not by itself require verifying every request.

Security

Sample question 9

Several employees had their accounts compromised after attackers convinced a mobile carrier to move their phone numbers to new SIM cards. Which MFA method should the company replace FIRST?

  1. SMS text message codes
  2. Authenticator app TOTP codes
  3. Smart cards with a PIN
  4. Hardware security tokens
Show correct answer and explanation

Correct answer: A. SMS text message codes

A is correct because codes sent by SMS go to whoever controls the phone number, so a SIM swap lets the attacker receive them. B are generated on the enrolled device itself and are not delivered over the phone number. C require the physical card and are not tied to a mobile phone number. D generate or hold codes on a physical device that a SIM swap cannot take over.

Security

Sample question 10

A hospital wants to automatically block staff from emailing or uploading files that contain patient record numbers to outside recipients. Which solution should be deployed?

  1. Directory services
  2. Mobile device management
  3. Identity access management
  4. Data loss prevention
Show correct answer and explanation

Correct answer: D. Data loss prevention

D is correct because DLP inspects outgoing content for sensitive data patterns and blocks or alerts on transfers that violate policy. A store user and computer accounts but do not inspect or block outgoing data. B enforces settings on enrolled phones and tablets but does not inspect email content for patient data. C manages user identities and their access rights but does not inspect the content being sent.

Keep practicing

A+ Core 2 practice-test hub · Mixed quick start · CompTIA A+ Core 1 sample tests · CompTIA Security+ sample tests · CompTIA Network+ sample tests