Objective 1.2SY0-701

1.2 Summarize fundamental security concepts

Objective 1.2 sits in General Security Concepts, which carries 12% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

General Security ConceptsEasy

Which statement best describes the foundational principle of the Zero Trust security model?

Correct.

The concept

Every security model rests on an assumption about who deserves confidence at the outset. Older designs extend it by network position; the modern replacement withholds it until each individual attempt proves itself, every time, from anywhere.

Why this answer

The question asks for the foundation, and the foundation is the removal of default confidence. Nothing is presumed safe for sitting on the corporate network, and each attempt is authenticated and authorized on its own merits.

  • Correct. Nothing is presumed safe; verification precedes every grant.
  • BDescribes a perimeter-based model where internal traffic is assumed safe, the opposite of Zero Trust.
  • CDescribes a one-time verification model, which Zero Trust replaces with continuous verification.
  • DDescribes trust-by-default followed by reactive restriction, which Zero Trust replaces with trust-by-exception.
Read the sourceMicrosoft Learn: Zero Trust security model
Verified against learn.microsoft.com · 2026-07-27
zero trustfundamental concepts

Now you: objective 1.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

General Security ConceptsEasy

Traditional security models assume that assets inside the network perimeter are inherently safer than those outside. Which model directly challenges this assumption?

Sample question 2 of 3

General Security ConceptsModerate

A team defines the strategy, architecture, processes, and controls for identity and data security as part of a Zero Trust rollout. Which structured adoption component does this describe?

Sample question 3 of 3

General Security ConceptsModerate

A Zero Trust rollout succeeds at the technology level, but employees continue sharing login credentials to save time. Which factor does the Zero Trust model identify as introducing this exposure?

That’s 3 of the full Security+ bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practicing

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in General Security Concepts