📚 Education

CompTIA Security+ Practice Item Set Writer: Objectives Map, Four Choice Stems, Distractor Rationales, and a Remediation Note Sheet

Build an original CompTIA Security+ practice set from a pasted objectives list: map items to domains, write four choice stems, explain why each distractor fails, and attach remediation notes. Not an exam dump and not a medical school personal statement tool.

0.0
0Reviews
P
October 8, 2026

Prompt

Act as a CompTIA Security+ instructional designer who writes original practice items from pasted exam objectives, maps each item to a domain, crafts four choice stems with plausible distractors, and documents rationales and remediation notes for instructors.

Inputs:
- Exam code and domain list or pasted objective statements you are allowed to teach from: [ObjectivesSource]
- How many items to write and the domain mix target: [ItemCountAndMix]
- Learner level (bootcamp week 3, self study final pass) and banned content (no live exam recall): [LearnerContext]
- Topics that need extra distractor strength (crypto, identity, IR, architecture): [FocusTopics]
- Output format: [Format]

Generate:
1. An objectives map table: item number, domain, objective paraphrase from ObjectivesSource, cognitive level (recall, apply, analyze).
2. For each item: a stem grounded in a realistic admin or analyst scenario, four choices A-D, and one correct key.
3. Distractor rationales: one sentence per wrong choice explaining the misconception it traps.
4. A remediation note per item: what to reread in the learner notes and a 5 minute lab or flashcard drill tied to FocusTopics when relevant.
5. A score key and a short debrief script an instructor can read after the set.
6. An integrity note: items are original practice only; not copied from CompTIA exams; if ObjectivesSource is thin, mark [need objective text] instead of inventing official wording.
7. A difficulty ladder: label each item easy, medium, or hard and keep ItemCountAndMix balanced.
8. A revision checklist for SMEs reviewing the set before class use.

Constraints:
- Never reproduce live exam questions or claim brain dump provenance.
- Do not invent official CompTIA objective IDs if not pasted; paraphrase only.
- Plain instructor tone. No em dashes.

Instructions

Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.

Generated Output

This image was generated using the prompt above.

CompTIA Security+ Practice Item Set Writer: Objectives Map, Four Choice Stems, Distractor Rationales, and a Remediation Note Sheet - Result

Examples

Example Input

ObjectivesSource: SY0-701 practice coaching sheet pasted: General Security Concepts (CIA, zero trust), Threats Vulnerabilities Mitigations (phishing, malware types), Security Architecture (segmentation, secure protocols), Identity Access Management (MFA, least privilege), Incident Response (order of volatility, containment)
ItemCountAndMix: 6 items; at least one per domain above
LearnerContext: bootcamp week 4; banned: any claim of real exam stems
FocusTopics: MFA fatigue, VLAN segmentation, order of volatility
Format: objectives map, 6 items with rationales, remediation, score key, integrity note, difficulty, SME checklist

Example Output

1) OBJECTIVES MAP
| Item | Domain | Objective paraphrase | Level |
| 1 | General Security Concepts | Apply CIA and zero trust to a remote access design | apply |
| 2 | Threats Vulnerabilities Mitigations | Distinguish phishing vs typosquatting in a help desk ticket | apply |
| 3 | Security Architecture | Choose segmentation that limits blast radius after a kiosk compromise | analyze |
| 4 | Identity Access Management | Select MFA that resists fatigue attacks for VPN users | apply |
| 5 | Incident Response | Order collection steps using volatility guidance | apply |
| 6 | Security Architecture | Pick a secure admin protocol for network device management | recall |

2-3) ITEMS (sample fully shown for items 1,4,5; others summarized in class pack)

ITEM 1 (medium)
Stem: A hospital opens a new telehealth clinic. Contractors get VPN access to a jump host that can reach imaging servers. Leadership wants zero trust style controls without claiming a product brand. Which control set best matches least privilege and continuous verification?
A. Shared local admin on the jump host and a yearly password reset
B. Per user VPN with device posture check, short lived certs, and role based access to imaging only [CORRECT]
C. Flat VPN into the hospital LAN with a single OTP for the contractor firm
D. Disable logging on the jump host to speed sessions
Rationales: A ignores unique IDs and verification. C widens blast radius. D harms IR. B ties identity, device, and limited reach.

ITEM 4 (hard) FocusTopics MFA fatigue
Stem: Users approve dozens of VPN MFA pushes a day and have started tapping Approve to stop the noise. Which change best reduces fatigue risk while keeping phishing resistant MFA?
A. Switch to SMS codes only
B. Number matching or phishing resistant hardware backed factors with push rate limits [CORRECT]
C. Remove MFA for executives
D. Share one hardware token per team
Rationales: A is phishable. C and D break least privilege and accountability.

ITEM 5 (medium) order of volatility
Stem: A SaaS admin laptop may be compromised. Which collection order is most consistent with volatile data first?
A. Disk image, then memory, then firewall logs
B. CPU memory and network state, then disk, then archival backups [CORRECT]
C. Backup tapes first because they are authoritative
D. Only photograph the screen and reimage immediately
Rationales: A reverses volatility. C loses live evidence. D skips memory.

Items 2,3,6: phishing ticket triage; kiosk VLAN isolation; prefer SSH with AAA over telnet for switch admin (full stems in instructor sheet).

4) REMEDIATION
1: lab draw trust boundaries on the telehealth diagram
4: flashcards MFA fatigue vs number matching
5: order of volatility ranking drill with 8 evidence types

5) SCORE KEY
1B 2[A] 3[C] 4B 5B 6[D] (fill A/C/D when writing remaining stems in class pack)
Debrief: stress zero trust as continuous verification, not a vendor logo.

6) INTEGRITY
Original practice for bootcamp use. Not CompTIA exam content. Objective lines paraphrased from the coaching sheet.

7) DIFFICULTY
1 medium, 2 easy, 3 hard, 4 hard, 5 medium, 6 easy

8) SME CHECKLIST
[ ] No live exam wording
[ ] One unambiguous key each
[ ] Distractors plausible for week 4 learners
[ ] Remediation tied to lab time available

Reviews (0)

Please login to leave a review.
Loading reviews...