CompTIA Security+ is one of the most widely recognised entry-level cyber security certifications in the UK, and many junior security roles list it as desirable or essential. But passing the exam and performing well in an interview are different skills: employers want to see that you can apply the concepts, not just recall definitions. This guide maps the Security+ domains to the questions you will actually be asked.
Why employers value Security+
Security+ signals a broad, vendor-neutral grounding in security fundamentals. In an interview it is a starting point, not a finish line — expect to be pushed on how you would apply each concept to a real scenario. Treat every definition question as an invitation to give an example.
Threats, attacks and vulnerabilities
- What is the difference between a vulnerability, a threat and a risk? A vulnerability is a weakness; a threat is something that could exploit it; risk is the likelihood and impact combined.
- Explain phishing, spear phishing and whaling. Give a real indicator you would look for.
- What is a zero-day? Why is it dangerous, and how do you defend against something with no patch?
- Describe common malware types. Ransomware, trojans, worms, rootkits — and one detection idea for each.
Architecture and design
- What is defence in depth? Layered controls so no single failure is catastrophic.
- Explain network segmentation and why it limits blast radius.
- What is a DMZ and what belongs in it?
- What is the principle of least privilege, and how would you enforce it?
Cryptography and PKI
- Explain symmetric vs asymmetric encryption, with a use case for each.
- How does TLS establish a secure connection? Certificate validation, key exchange, session keys.
- What is hashing and how does it differ from encryption? One-way vs reversible; where you use each.
- What is a digital certificate and who issues it?
Identity and access management
- What is multi-factor authentication and why is 'something you have' stronger than 'something you know'?
- Explain the difference between authentication, authorisation and accounting (AAA).
- What is the difference between RBAC and ABAC?
Operations and incident response
- What are the phases of incident response? Map to the NIST lifecycle.
- What is the difference between a SIEM and a SOAR?
- How would you securely dispose of data on decommissioned hardware?
Governance, risk and compliance
- What is the difference between a policy, a standard and a procedure?
- Name a regulation relevant to UK organisations. UK GDPR and the Data Protection Act 2018 are strong examples.
- What is a risk assessment and what goes into it? For deeper coverage of this domain, see our GRC interview questions guide.
Behavioural and motivation questions
- Why do you want to work in cyber security?
- How do you keep learning? Reference labs, communities and hands-on practice.
- Tell me about a time you solved a technical problem. Use the STAR method.
How to stand out
Bring evidence of applied skills — a home lab, a write-up, a CTF, or a project. Pair your Security+ with the fundamentals in our SOC analyst and network security guides, and plan your next steps with the cyber security career path.
Practise this with Missiora
Reading about questions is not the same as answering them under pressure. Rehearse a realistic, role-specific mock with AI Interview™, decode a real job advert with Job Intelligence™, close skill gaps with Career Coach, and build verifiable proof of your progress in your Career Passport™. If you know who is interviewing you, Interview Panel Intelligence™ helps you prepare for their likely focus. See the parent guide, Cyber Security Interview Questions, for the full picture.
