Practice questions · Cybersecurity

CompTIA Security+ (SY0-701): Practice Questions

intermediate 150 questions

Original, syllabus-based practice questions for CompTIA Security+ (SY0-701). Each answer is explained, including why the other options are wrong. Filter by domain or difficulty. These are concept checks to test understanding - not real exam questions.

By The Exam Atlas Editorial Team · Verified 2026-05-31 · ~188 min

  1. General Security Concepts easy

    Which part of the CIA triad ensures that data has not been altered without authorization?

  2. General Security Concepts medium

    You want to verify a downloaded file has not been modified. What is most appropriate?

  3. General Security Concepts medium

    Which access-control model assigns permissions based on a user's job function?

  4. General Security Concepts easy

    Which statement best summarizes zero trust?

  5. Threats, Vulnerabilities & Mitigations easy

    A phishing attack that specifically targets a senior executive is called:

  6. Threats, Vulnerabilities & Mitigations medium

    An attacker exploits a software flaw before any patch is available. This is a:

  7. Threats, Vulnerabilities & Mitigations medium

    Which best mitigates SQL injection?

  8. Threats, Vulnerabilities & Mitigations hard

    After restoring from backups following a ransomware incident, which action most reduces recurrence?

  9. Threats, Vulnerabilities & Mitigations medium

    Which is an indicator of compromise (IoC)?

  10. Security Architecture medium

    Isolating public-facing web servers in their own network segment, separate from internal systems, is an example of:

  11. Security Architecture medium

    Which control primarily protects data in transit?

  12. Security Architecture hard

    A system must stay available even if one data center fails. Which contributes most?

  13. Security Operations easy

    Multifactor authentication improves security because it requires:

  14. Security Operations medium

    The principle of least privilege means:

  15. Security Operations medium

    In the common incident-response process, which phase immediately follows identification?

  16. Security Operations medium

    A SIEM primarily helps an analyst by:

  17. Security Operations hard

    To limit the damage if one user account is compromised and an attacker tries to move across systems, which helps most?

  18. Security Program Management medium

    A formal process to request, approve, document and review system changes is:

  19. Security Program Management medium

    Evaluating the security practices of a software supplier before using them is part of:

  20. Security Program Management easy

    The main purpose of security-awareness training is to:

  21. General Security Concepts easy

    Which part of the CIA triad ensures information is accessible when needed?

  22. Threats, Vulnerabilities & Mitigations medium

    Malware that encrypts a victim's files and demands payment to restore them is:

  23. Threats, Vulnerabilities & Mitigations medium

    An attacker tricks a user into running a program disguised as legitimate software. This is a:

  24. Threats, Vulnerabilities & Mitigations hard

    An attacker secretly intercepts and may alter traffic between two parties who believe they communicate directly. This is a:

  25. General Security Concepts medium

    Encrypting stored data so only authorized parties can read it primarily protects:

  26. Security Architecture medium

    Placing a firewall and a screened subnet (DMZ) between the internet and internal servers is an example of:

  27. Security Operations medium

    Applying a vendor's security patch promptly mainly reduces the risk from:

  28. Security Operations easy

    A strong password policy combined with account lockout after several failed attempts mainly defends against:

  29. Security Program Management medium

    A document that defines how an organization classifies and handles its data is a:

  30. Security Program Management medium

    Assessing the likelihood and impact of threats so controls can be prioritized is:

  31. General Security Concepts medium

    A company stamps every approved invoice with a signature that cannot later be denied by the signer. Which security goal does this primarily support?

  32. General Security Concepts easy

    Which type of security control is a security-awareness training program best classified as?

  33. General Security Concepts easy

    A door lock and a fence are examples of which control category by nature?

  34. General Security Concepts medium

    An organization deploys a SIEM specifically so it can prove what happened during an incident after the fact. Which control function is this?

  35. General Security Concepts hard

    In public key cryptography, which key should the recipient use to decrypt a message that was encrypted for them?

  36. General Security Concepts easy

    What is the primary purpose of a digital certificate issued by a certificate authority?

  37. General Security Concepts medium

    A developer adds a unique random value to each password before hashing so that identical passwords produce different hashes. This value is called a:

  38. General Security Concepts hard

    Which statement best describes the goal of key stretching algorithms such as PBKDF2 or bcrypt?

  39. General Security Concepts medium

    An online store substitutes each stored credit-card number with a non-sensitive surrogate value that has no mathematical relationship to the original. This technique is:

  40. General Security Concepts medium

    Which of the following best describes the purpose of a change advisory board (CAB) in change management?

  41. General Security Concepts medium

    Before a major change is approved, a team documents how they will revert if it fails. This documented fallback is called a:

  42. General Security Concepts hard

    In a zero trust architecture, the component that makes the allow-or-deny decision for an access request is the:

  43. General Security Concepts medium

    A security team uses a honeypot on its network. The primary purpose of a honeypot is to:

  44. General Security Concepts medium

    Which best describes the difference between hashing and encryption?

  45. General Security Concepts easy

    An organization wants to confirm that automated, repeatable steps replace error-prone manual configuration of new servers. Which benefit of automation does this describe?

  46. Threats, Vulnerabilities & Mitigations medium

    An attacker registers the domain 'paypa1.com' to fool users who misread it as the real service. This technique is:

  47. Threats, Vulnerabilities & Mitigations hard

    Employees of a specific company are compromised after visiting an industry news site that attackers had quietly infected. This is an example of a:

  48. Threats, Vulnerabilities & Mitigations easy

    Which threat actor is typically best funded, most patient, and motivated by long-term espionage?

  49. Threats, Vulnerabilities & Mitigations medium

    A disgruntled administrator plants code that will delete the payroll database if their account is ever disabled. This malicious code is a:

  50. Threats, Vulnerabilities & Mitigations easy

    Malware that self-replicates and spreads across a network with no user interaction is a:

  51. Threats, Vulnerabilities & Mitigations hard

    An attacker captures a user's session cookie and reuses it to access an application as that user without knowing the password. This is best described as:

  52. Threats, Vulnerabilities & Mitigations medium

    A web form lets an attacker inject a script that runs in other users' browsers when they view a page. This vulnerability is:

  53. Threats, Vulnerabilities & Mitigations hard

    Which attack writes more data into a memory region than it was allocated, potentially overwriting adjacent memory and allowing code execution?

  54. Threats, Vulnerabilities & Mitigations medium

    An attacker uses lists of usernames and passwords leaked from one breach to try logging into many other unrelated sites. This is:

  55. Threats, Vulnerabilities & Mitigations medium

    An attacker tries the single common password 'Spring2026!' against thousands of different accounts to avoid lockouts. This is:

  56. Threats, Vulnerabilities & Mitigations medium

    A vulnerability scan reports a flaw that does not actually exist on the target system. This result is a:

  57. Threats, Vulnerabilities & Mitigations hard

    A scanner fails to report a serious vulnerability that is actually present on the host. This is a:

  58. Threats, Vulnerabilities & Mitigations medium

    Which describes a supply chain attack?

  59. Threats, Vulnerabilities & Mitigations easy

    An attacker leaves USB drives loaded with malware in a company parking lot hoping employees plug them in. This social-engineering tactic relies on:

  60. Threats, Vulnerabilities & Mitigations easy

    Sending an urgent SMS text that pretends to be from a bank and asks the user to click a link is:

  61. Threats, Vulnerabilities & Mitigations easy

    An attacker follows an employee through a secured door without badging in. This physical attack is:

  62. Threats, Vulnerabilities & Mitigations medium

    Which best mitigates the threat of stolen passwords being reused, even when the password itself is correct?

  63. Threats, Vulnerabilities & Mitigations medium

    A team subscribes to a feed of known malicious IP addresses, file hashes, and domains to improve detection. This is best described as:

  64. Threats, Vulnerabilities & Mitigations hard

    Which of the following is the strongest indicator that an account may be compromised?

  65. Threats, Vulnerabilities & Mitigations easy

    An attacker overwhelms a target using many compromised devices across the internet to exhaust its resources. This is a:

  66. Threats, Vulnerabilities & Mitigations medium

    Which vulnerability arises when an application trusts data from the user without checking it, allowing unintended commands to run?

  67. Threats, Vulnerabilities & Mitigations hard

    An attacker exploits the gap between when a file's permissions are checked and when the file is used. This class of flaw is a:

  68. Threats, Vulnerabilities & Mitigations hard

    Which describes a 'living off the land' technique used by attackers?

  69. Threats, Vulnerabilities & Mitigations medium

    A purchased security appliance ships with the same default administrator password documented publicly. Failing to change it is an example of which vulnerability?

  70. Threats, Vulnerabilities & Mitigations easy

    Which mitigation most directly reduces the attack surface of a server?

  71. Threats, Vulnerabilities & Mitigations hard

    An attacker intercepts and resends a valid authentication message to gain access later. Adding a time-stamped, single-use value to each request best defends against this:

  72. Security Architecture hard

    In the shared responsibility model for Infrastructure as a Service (IaaS), who is generally responsible for patching the guest operating system?

  73. Security Architecture easy

    Which deployment model keeps an organization's most sensitive workloads on dedicated private infrastructure while using public cloud for less sensitive workloads?

  74. Security Architecture easy

    A company wants to protect data so that even if a laptop is stolen, the stored files cannot be read. Which control is most appropriate?

  75. Security Architecture medium

    Which technology lets multiple isolated operating systems run on one physical host, improving resource use but introducing the hypervisor as a security boundary?

  76. Security Architecture hard

    An organization needs to recover operations within four hours after a disaster. This four-hour target is the:

  77. Security Architecture hard

    An organization can tolerate losing at most fifteen minutes of data in a failure. This fifteen-minute value is the:

  78. Security Architecture medium

    Which backup strategy keeps three copies of data on two different media with one copy offsite?

  79. Security Architecture easy

    A recovery site that has hardware and data ready and can take over operations almost immediately is a:

  80. Security Architecture medium

    Placing a load balancer in front of several identical web servers primarily improves which property?

  81. Security Architecture easy

    Which device inspects traffic and can actively block malicious packets inline, rather than only alerting?

  82. Security Architecture hard

    Which firewall type makes decisions based on application-layer content and can understand specific protocols like HTTP, rather than only ports and IP addresses?

  83. Security Architecture medium

    A company segments its network so that the finance department's systems cannot directly reach the manufacturing floor's systems. The primary security benefit is:

  84. Security Architecture medium

    Which approach to data protection replaces or hides specific fields, such as showing only the last four digits of a card number, so unauthorized viewers see limited data?

  85. Security Architecture easy

    An air-gapped system is one that:

  86. Security Architecture easy

    Which is the best description of a virtual private network (VPN)?

  87. Security Architecture medium

    A security architect wants to ensure a single hardware component failure does not take down a critical server. Which approach directly addresses this?

  88. Security Architecture hard

    Which embedded-system characteristic most often makes them harder to secure than general-purpose computers?

  89. Security Architecture hard

    Which describes a microsegmentation strategy in a modern data center?

  90. Security Architecture easy

    An organization stores a duplicate copy of critical data at a geographically distant site so a regional disaster cannot destroy both copies. This practice supports:

  91. Security Architecture medium

    Which statement about a screened subnet (DMZ) is correct?

  92. Security Architecture easy

    Which control best protects the confidentiality of data being sent between a browser and a web server?

  93. Security Architecture medium

    An organization adopts infrastructure as code so environments are defined in version-controlled templates. A key security benefit is:

  94. Security Operations easy

    Which process removes unnecessary software, closes unused ports, and tightens settings to reduce a system's exposure?

  95. Security Operations medium

    A baseline configuration in security operations is best described as:

  96. Security Operations easy

    In identity and access management, what does provisioning refer to?

  97. Security Operations easy

    When an employee leaves the company, promptly disabling their accounts is called:

  98. Security Operations easy

    Which technology lets a user authenticate once and then access multiple connected applications without logging in again?

  99. Security Operations medium

    A company lets employees log in to a partner's cloud application using the company's own identity provider. This trust arrangement is:

  100. Security Operations hard

    Which IAM concept grants a user temporary elevated rights only for a specific task and time, then revokes them?

  101. Security Operations medium

    What is the main purpose of log aggregation in a security operations center?

  102. Security Operations hard

    Which tool automates and orchestrates routine incident-response actions, such as enriching alerts and isolating hosts, to speed up the SOC?

  103. Security Operations medium

    During incident response, which phase focuses on removing the threat, such as deleting malware and closing the exploited hole?

  104. Security Operations medium

    Which incident-response phase ensures that what was learned is fed back to improve future defenses?

  105. Security Operations hard

    Maintaining a documented chain of custody for collected evidence is most important to:

  106. Security Operations medium

    Which describes the purpose of a runbook (playbook) in security operations?

  107. Security Operations medium

    Vulnerability management most importantly includes which ongoing activity after scanning?

  108. Security Operations medium

    A CVSS score is used primarily to:

  109. Security Operations medium

    Which approach validates that a patch did not break functionality before it is deployed broadly?

  110. Security Operations medium

    Endpoint detection and response (EDR) primarily provides:

  111. Security Operations hard

    Which is the best reason to use time synchronization (NTP) across systems in a SOC?

  112. Security Operations medium

    An organization wants to prevent users from installing unapproved software. Which control achieves this most directly?

  113. Security Operations medium

    What is the primary purpose of data loss prevention (DLP) tools?

  114. Security Operations easy

    Which authentication factor category does a fingerprint belong to?

  115. Security Operations easy

    A one-time code generated by an authenticator app every thirty seconds is an example of which factor?

  116. Security Operations medium

    Which practice reduces the risk that a single administrator can perform a sensitive action unilaterally without oversight?

  117. Security Operations medium

    Forcing employees in sensitive roles to take time off so their activity can be reviewed by others is an example of:

  118. Security Operations hard

    Which monitoring approach watches for deviations from a known-good pattern of normal activity?

  119. Security Operations medium

    A security analyst proactively searches the environment for hidden threats that automated tools may have missed. This is called:

  120. Security Operations hard

    Which is the most secure way to handle a privileged service account's credentials?

  121. Security Operations medium

    After deploying a new secure baseline, what activity confirms systems still match it over time?

  122. Security Operations medium

    Which best describes the purpose of file integrity monitoring (FIM)?

  123. Security Operations medium

    A SOC defines that critical alerts must be triaged within fifteen minutes. This commitment is best tracked as a:

  124. Security Operations easy

    Which describes the principle behind 'defense in depth' applied to security operations?

  125. Security Operations hard

    What is the main benefit of network access control (NAC) when a device connects?

  126. Security Operations medium

    Which is the best first step when a workstation is suspected of active malware infection?

  127. Security Program Management medium

    Which document is a high-level statement of management's intent and direction for security?

  128. Security Program Management medium

    Which governance document specifies mandatory, measurable requirements, such as 'passwords must be at least 14 characters'?

  129. Security Program Management hard

    Calculating annualized loss expectancy (ALE) by multiplying single loss expectancy by annualized rate of occurrence is part of which approach?

  130. Security Program Management medium

    An organization buys cyber insurance to handle the financial impact of a possible breach. This is an example of risk:

  131. Security Program Management medium

    A company decides to stop offering a feature entirely because its risk is too high to manage. This is risk:

  132. Security Program Management medium

    Management reviews a residual risk and formally signs off to proceed without further controls. This is risk:

  133. Security Program Management easy

    Which agreement is a legally binding contract that defines confidentiality obligations between parties?

  134. Security Program Management hard

    A business impact analysis (BIA) primarily helps an organization:

  135. Security Program Management easy

    Which regulation governs the protection of personal data of individuals in the European Union?

  136. Security Program Management medium

    Which standard sets requirements for organizations that store, process, or transmit payment card data?

  137. Security Program Management easy

    An organization classifies data as Public, Internal, Confidential, and Restricted. The main purpose of data classification is to:

  138. Security Program Management hard

    Who is typically accountable for deciding how a specific set of data may be used and protected?

  139. Security Program Management medium

    Who is responsible for implementing and maintaining the technical controls that protect data according to the owner's requirements?

  140. Security Program Management medium

    An independent assessment that verifies whether controls meet a defined standard and are operating effectively is a(n):

  141. Security Program Management hard

    Which best distinguishes a penetration test from a vulnerability scan?

  142. Security Program Management medium

    A vendor provides a report attesting to its security controls so customers do not each have to audit it directly. A common example is a:

  143. Security Program Management medium

    When onboarding a new cloud provider, reviewing its certifications, breach history, and security posture is part of:

  144. Security Program Management hard

    Which metric expresses how often a given threat is expected to occur in a year for quantitative risk analysis?

  145. Security Program Management medium

    Which document records who is allowed to access what data and is reviewed periodically to remove unnecessary access?

  146. Security Program Management medium

    A company maps its controls to a recognized framework like the NIST Cybersecurity Framework primarily to:

  147. Security Program Management hard

    Which is the best example of measuring the effectiveness of a security-awareness program?

  148. Security Program Management easy

    An acceptable use policy (AUP) primarily defines:

  149. Security Program Management medium

    Which regulation primarily governs the protection of patient health information in the United States?

  150. Security Program Management medium

    What is the primary goal of an exit interview's security component when an employee leaves?

Practice questions FAQ

Are these real SY0-701 exam questions?
No. These are original study questions written to test understanding. They are not real exam questions, exam dumps, or copied from any provider.
How should I use these practice questions?
Answer each one, read the explanation (including why the wrong options are wrong), and use the per-domain score below to focus your revision on weak areas. Revisit before exam day.
How many questions should I do before the exam?
Enough to score consistently across every domain, alongside full-length practice from official or reputable providers. Understanding why each answer is right matters more than raw volume.
What score means I am ready?
A good signal is consistently scoring around 80% or higher across all domains on questions you have not seen before, and being able to explain why the wrong options are wrong.
Should I use exam dumps?
No. Dumps (real or leaked questions) breach provider policy, can void your certification, and do not build the understanding the exam actually tests.

Sources