Certified Security Principles Exam Prep
Free practice questions

Free C)SP Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

These 10 free C)SP questions are organized by exam domain, so you can see how each part of the Certified Security Principles blueprint is tested. Reveal the answer and explanation under each question.

Domain 2: Introduction to IT Security

Question 1

A reconciliation detects an unauthorized change to a supplier's bank account. Records stayed available, access was limited to approved viewers, and the change is attributable to one employee. Which security property failed?

Show answer & explanation

Correct answer: B - Integrity

Domain 3: Risk Management

Question 2

Two validated findings compete for the next remediation window. An internet-facing VPN gateway has a CVSS v4.0 Base score of 8.7, an applicable exploit path, and vendor-confirmed exploitation in the wild. A disconnected laboratory system with no production data has a Base score of 9.6. Either fix can be completed in the window, but not both. Which assessment appropriately combines severity with operational risk?

Show answer & explanation

Correct answer: A - The gateway finding is High severity; remediate the gateway first.

Question 3

A loss scenario affects an asset valued at $480,000, with 25% of that value lost per occurrence. The event is expected once every four years. A control costing $9,000 per year would reduce the expected frequency to once every twenty years without changing the loss per occurrence. On expected annual financial return alone, how should the control be evaluated?

Show answer & explanation

Correct answer: C - Approve it: the expected net annual benefit is $15,000.

Domain 4: Understanding of Cryptography

Question 4

Third-party mirrors distribute a vendor's software updates. Customers must detect altered updates and verify who released them, but must not gain the ability to create updates other customers would accept as the vendor's. Which cryptographic mechanism fits?

Show answer & explanation

Correct answer: C - A digital signature verified with the vendor's trusted public key.

Question 5

Using the same browser and TLS settings, an administrator can connect to hr.example.net but certificate validation fails at payroll.example.net. Both names reach the same HTTPS server. Its certificate chain is trusted, its validity dates include today, and its Subject Alternative Name contains only hr.example.net. The evidence points to:

Show answer & explanation

Correct answer: D - A mismatch between the hostname and the certificate identity.

Domain 6: Managing Data Security

Question 6

'The cloud provider owns the servers, so it must patch our guest OS.' An administrator makes this claim about customer-installed virtual machines in IaaS, with no managed operating-system service. Which responsibility split correctly assigns patching of the guest OS and the underlying hypervisor?

Show answer & explanation

Correct answer: B - The customer patches the guest OS; the provider patches the hypervisor.

Domain 7: Managing Network Security

Question 7

A stateful firewall evaluates new connections from top to bottom and stops at the first matching rule. The complete rules for access to a web server are: 1. DENY any source to 10.40.20.15, TCP destination port 443. 2. ALLOW proxy 10.40.10.5 to 10.40.20.15, TCP destination port 443. 3. DENY all remaining traffic. No existing connection applies. Which single edit permits the proxy's HTTPS connections while keeping other sources blocked?

Show answer & explanation

Correct answer: A - Move rule 2 ahead of rule 1.

Domain 9: Application Security for Non-Developers

Question 8

A customer signs in to a billing portal and opens invoice 4821. Changing the invoice number in the request to 4822 returns another customer's invoice. Both requests use a valid session and HTTPS. Where must the missing control be enforced to prevent this disclosure?

Show answer & explanation

Correct answer: D - On the server, by checking the user's permission for each requested invoice.

Domain 10: Understanding Mobile Device Security (IoT)

Question 9

An employee leaves the company while retaining a personally owned phone. Corporate apps and cached work files are confined to a managed work profile. The phone is online, corporate sessions have been revoked, and policy authorizes removal of work data but not personal data. What should the administrator do with the phone?

Show answer & explanation

Correct answer: D - Remove the managed work profile and confirm that removal completed.

Domain 11: Managing Day to Day Security

Question 10

A workstation is encrypting files on a shared drive. The analyst has identified its network connection and has authority to isolate it. Other workstations are unaffected, and the file server supports ongoing business operations. Which action best limits further damage while preserving the workstation's volatile evidence?

Show answer & explanation

Correct answer: B - Isolate the workstation from the network while leaving it powered on.

The rest of the C)SP blueprint

The C)SP exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more C)SP questions with explanations.

Continue in the free practice test →

View plans