Interactive Domain 1 practice questions load here — covering CIA triad, controls, crypto. Each answer is revealed with a full explanation and its source after you respond.
JavaScript is required for the interactive quiz. You can still browse all of CompTIA Security+ while JavaScript loads.
Want all five domains under exam conditions? Take a full 90-question mock →
Every other Security+ domain assumes you already speak the language of security, and General Security Concepts — 12% of the SY0-701 exam — is where that fluency is tested. You are expected to compare security control categories and types — technical, managerial, operational, and physical, paired with preventive, deterrent, detective, corrective, compensating, and directive functions — and to recognize where each fits a scenario. An access control vestibule, for instance, is a physical preventive control, while a warning banner is directive.
The cryptography questions here stay conceptual rather than mathematical. You should be able to explain how a digital signature provides integrity and non-repudiation by signing a hash with a private key, why ephemeral keys give you perfect forward secrecy, where a SAN certificate differs from a wildcard, and how key storage hardware such as a TPM or HSM protects private keys. Certificate revocation through CRLs and OCSP also appears.
Zero trust gets real weight: know the split between the control plane and the data plane, and what a policy enforcement point actually does inline with a session. Round it out with the three A's of AAA — authentication, authorization, and accounting — change management steps like impact analysis and backout plans, and deception tools such as honeypots and honeytokens. The practice questions below mirror these objectives directly.
The terms that show up most on Domain 1 questions — one line each.
Practice the other domains, or go deeper with the full study materials.