3.2 Given a scenario, apply security principles to secure enterprise infrastructure
Objective 3.2 sits in Security Architecture, which carries 18% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
The RADIUS server supporting 802.1X authentication becomes unreachable. Ports configured for inaccessible authentication bypass place clients into which state so network access continues?
The concept
Inaccessible authentication bypass, also called critical authentication or the AAA fail policy, keeps ports functional when the RADIUS server is down.
Why this answer
The switch grants access by placing the port in the critical-authentication state when the RADIUS server is unavailable.
- Correct: this matches the documented critical-authentication behavior.
- BThe restricted VLAN applies to a reachable server returning an invalid identity, not server unavailability.
- CThe guest VLAN applies to invalid MAC authorization, not RADIUS unavailability.
- DBlocking all traffic is the opposite outcome; inaccessible bypass keeps the port functional.
Now you: objective 3.2 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A network engineer plans subnets sized to exactly match today's VM count in each application tier, leaving no room for growth. What guidance should the engineer follow instead?
Sample question 2 of 3
A cloud team hosts several public IP resources that face the internet. Which control should they enable on the virtual network hosting those resources to reduce the impact of volumetric attacks?
Sample question 3 of 3
A guest VLAN and a restricted VLAN are both configured on a switch. One client fails MAC authentication bypass with an invalid MAC address, and a second 802.1X-capable client submits an invalid identity. Which VLAN assignment is correct for each client respectively?
That’s 3 of the full Security+ bank.
Keep going free: 10 questions per certification in bank practice, with no account.
Continue practicingRead the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.