Security

Worth 28% of the CompTIA A+ (Core 2) (220-1202) exam. CertClue has 108 questions on this objective.

What this objective covers

Malware Types and How Each Behaves

Objective 2.4 asks you to summarise malware types and removal methods. Questions describe behaviour and ask for the name, so learn each type by what it does rather than its definition.

Exam tip. The distinguishing detail is usually how it spread. No user interaction plus rapid network-wide spread is a worm, every time.

Social Engineering Attacks and Threats

Objective 2.5 compares social engineering attacks. They differ by channel and by target, so identify the delivery method described and the specificity of the target.

Exam tip. Read for the channel first, then the specificity. A targeted email to a named executive is whaling, not generic phishing, even if the content looks the same.

Physical Security Measures and Their Purposes

Objective 2.1 asks you to summarise security measures. Split them into physical controls that stop entry, and logical controls that stop access, then match each to the threat it addresses.

Exam tip. Distinguish preventive from detective controls. A camera never prevents anything, so it is wrong whenever the question asks how to stop an event rather than investigate it.

Securing SOHO Wired and Wireless Networks

Objective 2.10 covers applying security settings to a small network. The expected answers favour changing defaults, using the strongest encryption available, and segmenting untrusted devices.

Exam tip. WPS is a frequent distractor. It is a convenience feature with a well-known PIN weakness, so enabling it is never the secure recommendation.

Authentication Factors and Multifactor Authentication

Multifactor authentication requires factors of different kinds. Two passwords are not multifactor. Know the three classic factors and which real-world methods belong to each.

Exam tip. Check that the two things are genuinely different categories. Password plus PIN is the classic trap answer and is not multifactor authentication.

Configuring Browser Security Settings

Objective 2.11 covers browser hardening. Questions focus on where extensions come from, what certificate warnings mean, and which settings control tracking and pop-ups.

Exam tip. A user who believes incognito mode makes them anonymous online is a common scenario. The correct explanation is that it only prevents local storage of history and cookies.

The Malware Removal Procedure in Order

Objective 2.6 tests the SOHO malware removal steps, and the exam asks them in sequence. The order matters: quarantine before you clean, and disable System Restore before you remediate.

Exam tip. Educating the user is always the last step, and disconnecting from the network is always among the first. Questions frequently ask what comes first or last specifically.

Wireless Security Protocols and Authentication

Objective 2.3 compares wireless security protocols. Know the chronological order of strength and which encryption each uses, because questions ask for the strongest available option.

Exam tip. Enterprise mode is the answer whenever the requirement involves individual accountability or removing one user's access without changing everyone's passphrase.

Windows Security Settings, UAC and BitLocker

Objective 2.2 covers applying basic Windows security. Focus on account types, User Account Control, encryption options and the difference between Defender's components.

Exam tip. Disabling User Account Control is never the correct answer to a permissions problem. Choose elevation, a group membership change, or a managed deployment instead.

Workstation Security and Hardening Techniques

Objective 2.7 covers practical hardening. These are the routine measures expected on every managed workstation, and questions ask which single measure addresses a stated risk.

Exam tip. When a question describes an unattended machine being misused, the specific control is a screen lock timeout, not a stronger password.

Securing Mobile Devices

Objective 2.8 covers mobile-specific security. The key controls are screen locks, encryption, remote wipe and restricting where applications come from.

Exam tip. Try to locate before wiping when the device is merely misplaced. Remote wipe is the answer only when the data is genuinely at risk or the device is unrecoverable.

Data Destruction and Disposal Methods

Objective 2.9 compares destruction methods. The decision hinges on whether the media will be reused and how sensitive the data is, and solid-state media behaves differently from magnetic.

Exam tip. Degaussing an SSD is a guaranteed wrong answer. Solid-state media requires secure erase, crypto erase, or physical destruction.

Common Threats and Vulnerabilities on the Desktop

Beyond named malware and social engineering, Core 2 expects awareness of the technical attacks and weaknesses that affect end-user systems.

Exam tip. End-of-life software questions never have patching as the answer, because no patches are issued. Expect replacement, isolation or compensating controls instead.

Practice questions

Free, with the answer and the reasoning. No account needed.

1. After setting up a new wireless router, which of the following is a security best practice a technician should perform before deploying it?

  • A. Enable WPS for all users
  • B. Change the default administrator passwordcorrect
  • C. Leave the default SSID and admin password unchanged for simplicity
  • D. Disable all encryption for easier troubleshooting

Changing the default administrator password is a fundamental best practice, since default credentials for common router models are widely known and easily exploited. Leaving defaults unchanged, disabling encryption, and enabling WPS all weaken security rather than strengthen it.

2. Users routinely leave their workstations unlocked when stepping away, and documents have been accessed without permission. What control addresses this most directly?

  • A. More frequent password expiry
  • B. Disabling USB ports
  • C. A short screen lock timeout enforced by policycorrect
  • D. A longer minimum password length

An enforced lock timeout secures an unattended session automatically without relying on users remembering. Password length and expiry govern credential strength rather than unattended access, and disabling USB addresses data transfer instead.

3. A data center wants to prevent an unauthorized person from following an authorized employee through a secure door before it closes. Which physical security measure specifically addresses this?

  • A. Encryption
  • B. Mantrapcorrect
  • C. Cable lock
  • D. Privacy screen

A mantrap is a small enclosed space with two interlocking doors that only allows one person through at a time, specifically designed to prevent tailgating into secure areas. A cable lock secures a physical device from theft, a privacy screen prevents visual shoulder surfing, and encryption protects data rather than physical entry.

Work the whole objective

The full CompTIA A+ (Core 2) bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.

Take the free CompTIA A+ (Core 2) practice test

The other CompTIA A+ (Core 2) objectives