Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free CompTIA Security+ Certification Exam (2026) SY0-701 Exam Questions

Page: 1 / 61 Total 907 questions

Want more questions? Get Premium Access.

Question 1

A company is utilizing an offshore team to help support the finance department. The company wants to keep the data secure by keeping it on a company device but does not want to provide equipment to the offshore team. Which of the following should the company implement to meet this requirement?

Correct Answer: A. VDI
Explanation:

Virtual Desktop Infrastructure (VDI) allows a company to host desktop environments on a centralized server. Offshore teams can access these virtual desktops remotely, ensuring that sensitive data stays within the company's infrastructure without the need to provide physical devices to the team. This solution is ideal for maintaining data security while enabling remote work, as all data processing occurs on the company's secure servers.

Reference =

CompTIA Security+ SY0-701 Course Content: VDI is discussed as a method for securely managing remote access to company resources without compromising data security.


Question 2

An employee recently resigned from a company. The employee was responsible for managing and supporting weekly batch jobs over the past five years. A few weeks after the employee resigned. one of the batch jobs talked and caused a major disruption. Which of the following would work best to prevent this type of incident from reoccurring?

Correct Answer: A. Job rotation
Explanation:

Job rotation is a security control that involves regularly moving employees to different roles within an organization. This practice helps prevent incidents where a single employee has too much control or knowledge about a specific job function, reducing the risk of disruption when an employee leaves. It also helps in identifying any hidden issues or undocumented processes that could cause problems after an employee's departure.


CompTIA Security+ SY0-701 Course Content: Domain 5: Security Program Management and Oversight, which includes job rotation as a method to ensure business continuity and reduce risks.

Question 3

Which of the following is the phase in the incident response process when a security analyst reviews roles and responsibilities?

Correct Answer: A. Preparation
Explanation:

Preparation is the phase in the incident response process when a security analyst reviews roles and responsibilities, as well as the policies and procedures for handling incidents. Preparation also involves gathering and maintaining the necessary tools, resources, and contacts for responding to incidents. Preparation can help a security analyst to be ready and proactive when an incident occurs, as well as to reduce the impact and duration of the incident.

Some of the activities that a security analyst performs during the preparation phase are:

Defining the roles and responsibilities of the incident response team members, such as the incident manager, the incident coordinator, the technical lead, the communications lead, and the legal advisor.

Establishing the incident response plan, which outlines the objectives, scope, authority, and procedures for responding to incidents, as well as the escalation and reporting mechanisms.

Developing the incident response policy, which defines the types and categories of incidents, the severity levels, the notification and reporting requirements, and the roles and responsibilities of the stakeholders.

Creating the incident response playbook, which provides the step-by-step guidance and checklists for handling specific types of incidents, such as denial-of-service, ransomware, phishing, or data breach.

Acquiring and testing the incident response tools, such as network and host-based scanners, malware analysis tools, forensic tools, backup and recovery tools, and communication and collaboration tools.

Identifying and securing the incident response resources, such as the incident response team, the incident response location, the evidence storage, and the external support.

Building and maintaining the incident response contacts, such as the internal and external stakeholders, the law enforcement agencies, the regulatory bodies, and the media.


CompTIA Security+ SY0-701 Certification Study Guide, Chapter 6: Architecture and Design, Section 6.4: Secure Systems Design, p. 279-280

CompTIA Security+ SY0-701 Certification Exam Objectives, Domain 3: Architecture and Design, Objective 3.5: Given a scenario, implement secure network architecture concepts, Sub-objective: Incident response, p. 16

Question 4

One of a company's vendors sent an analyst a security bulletin that recommends a BIOS update. Which of the following vulnerability types is being addressed by the patch?

Correct Answer: B. Firmware
Explanation:

Firmware is a type of software that is embedded in hardware devices, such as BIOS, routers, printers, or cameras. Firmware controls the basic functions and operations of the device, and can be updated or patched to fix bugs, improve performance, or enhance security. Firmware vulnerabilities are flaws or weaknesses in the firmware code that can be exploited by attackers to gain unauthorized access, modify settings, or cause damage to the device or the network. A BIOS update is a patch that addresses a firmware vulnerability in the basic input/output system of a computer, which is responsible for booting the operating system and managing the communication between the hardware and the software. The other options are not types of vulnerabilities, but rather categories of software or technology.


Question 5

A security manager created new documentation to use in response to various types of security incidents. Which of the following is the next step the manager should take?

Correct Answer: D. Conduct a tabletop exercise with the team.
Explanation:

A tabletop exercise is a simulated scenario that tests the effectiveness of a security incident response plan. It involves gathering the relevant stakeholders and walking through the steps of the plan, identifying any gaps or issues that need to be addressed. A tabletop exercise is a good way to validate the documentation created by the security manager and ensure that the team is prepared for various types of security incidents.


Question 6

A software developer released a new application and is distributing the application files through the developer's website. Which of the following should the developer post on the website to allow users to verify the integrity of the downloaded files?

Correct Answer: A. Hashes
Explanation:

The correct answer is A. Hashes.

A hash is a fixed-length value generated from data using a hashing algorithm. Developers often publish cryptographic hashes, such as SHA-256 hashes, so users can compare the published hash with the hash of the downloaded file. If the values match, the user has assurance that the file was not altered or corrupted after the hash was generated.

This aligns with CompTIA Security+ SY0-701 topics related to integrity, cryptographic concepts, and secure software distribution.

Why the other options are incorrect:

B . Certificates

Certificates are used to verify identity, support encryption, and enable trust in public key infrastructure. They may support code signing, but simply posting a certificate is not the standard method for users to manually verify file integrity.

C . Algorithms

Algorithms define the mathematical process used for hashing or encryption, but posting an algorithm alone does not allow users to verify a specific file's integrity.

D . Salting

Salting is commonly used with password hashing to defend against precomputed hash attacks, such as rainbow table attacks. It is not used for verifying downloaded file integrity.

Therefore, the developer should post hashes for the downloadable files.


Question 7

Which of the following is the first step to take when creating an anomaly detection process?

Correct Answer: B. Building a baseline
Explanation:

The first step in creating an anomaly detection process is building a baseline of normal behavior within the system. This baseline serves as a reference point to identify deviations or anomalies that could indicate a security incident. By understanding what normal activity looks like, security teams can more effectively detect and respond to suspicious behavior.

Reference =

CompTIA Security+ SY0-701 Course Content: Domain 04 Security Operations.

CompTIA Security+ SY0-601 Study Guide: Chapter on Monitoring and Baselines.


Question 8

A security team is setting up a new environment for hosting the organization's on-premises software application as a cloud-based service. Which of the following should the team ensure is in place in order for the organization to follow security best practices?

Correct Answer: A. Visualization and isolation of resources
Explanation:

When hosting an on-premises software application in a cloud-based service, ensuring visualization and isolation of resources is crucial for maintaining security best practices. This involves using virtualization techniques to create isolated environments (e.g., virtual machines or containers) for different applications and services, reducing the risk of cross-tenant attacks or resource leakage.

Network segmentation is important but pertains more to securing network traffic rather than isolating computing resources.

Data encryption is also essential but doesn't specifically address resource isolation in a cloud environment.

Strong authentication policies are critical for access control but do not address the need for isolating resources within the cloud environment.


Question 9

Which of the following best explains the benefit of using asymmetric encryption?

Correct Answer: D. It enables secure data exchanges without requiring both parties to share a private key.
Explanation:

Asymmetric encryption uses a mathematically related public key and private key pair. The major benefit is that parties can exchange data securely without both sides sharing the same private secret in advance. A public key can be distributed openly, while the private key remains protected by its owner. This supports secure key exchange, digital signatures, authentication, and confidentiality in protocols such as TLS and PKI-based systems. Identical keys are used in symmetric encryption, not asymmetric encryption. A shared secret key is also a symmetric encryption concept. Asymmetric encryption is generally slower than symmetric encryption, so option C is incorrect. Security+ expects candidates to distinguish asymmetric key pairs from symmetric shared-secret encryption.


Question 10

A security analyst reviews logs and finds a large number of malicious requests that have caused performance issues on the company's site. Which of the following would have most likely prevented this attack?

Correct Answer: D. WAF
Explanation:

The best answer is D. WAF.

A WAF (Web Application Firewall) is designed to inspect and filter malicious HTTP and HTTPS traffic aimed at a web application. If a site is receiving a large number of malicious requests that are causing performance problems, a WAF is the best control among these options because it can detect and block harmful web requests before they impact the application.

This can help mitigate attacks such as:

malicious web requests

application-layer abuse

some denial-of-service style request floods

common web exploits

Why the other options are incorrect:

A . IPSecIPSec secures network-layer communications, not malicious web request filtering.

B . TLSTLS encrypts data in transit, but it does not stop malicious requests.

C . SDNSoftware-defined networking helps manage network architecture, but it is not the most direct preventive control for malicious web traffic.

From a Security+ standpoint, malicious requests against a web application are best mitigated by a WAF, so D is correct.


Question 11

A systems administrator creates a script that validates OS version, patch levels, and installed applications when users log in. Which of the following examples best describes the purpose of this script?

Correct Answer: C. Baseline enforcement
Explanation:

Detailed

Baseline enforcement ensures that all systems adhere to predefined security configurations, such as approved OS versions and patch levels, improving compliance and reducing vulnerabilities. Reference: CompTIA Security+ SY0-701 Study Guide, Domain 4: Security Operations, Section: 'System Baselines and Monitoring'.


Question 12

Employees are missing features on company-provided tablets, affecting productivity. Management demands resolution in 48 hours. Which is the best solution?

Correct Answer: C. MDM
Explanation:

Mobile Device Management (MDM) allows administrators to configure, update, monitor, and push applications or features to company-provided mobile devices remotely and quickly. The requirement to restore missing features within 48 hours means IT needs centralized control and fast deployment---capabilities MDM provides.

With MDM, IT can:

Push required apps

Reconfigure devices

Enforce security policies

Restore missing features

Update OS and settings remotely

COPE (B) relates to ownership and usage policy, not configuration management. EDR (A) protects against malware but cannot restore missing productivity features. FDE (D) encrypts storage and is unrelated to application availability.

MDM is the only option allowing rapid, centralized remediation.

Thus, C is correct.


Question 13

A systems administrator wants to use a technical solution to explicitly define file permissions for the entire team. Which of the following should the administrator implement?

Correct Answer: A. ACL
Explanation:

An Access Control List (ACL) is a technical mechanism used to explicitly define permissions for files, folders, or other resources. ACLs specify which users or system processes are granted access to objects and what operations are allowed on given objects. This allows the administrator to centrally and granularly manage file permissions for a group or team.


CompTIA Security+ SY0-701 Official Study Guide, Domain 3.1, ''Access control lists (ACLs) are used to explicitly define permissions to files and resources for users and groups.''

Exam Objectives 3.1: ''Implement secure network architecture concepts.''

Question 14

Which of the following are the best security controls for controlling on-premises access? (Select two.)

Correct Answer: A. Swipe card; D. Biometric scanner
Explanation:

Detailed Swipe cards and biometric scanners are commonly used to control on-premises access due to their reliability and ability to restrict unauthorized entry. Swipe cards provide physical access control, while biometric scanners ensure identity verification. Reference: CompTIA Security+ SY0-701 Study Guide, Domain 1: General Security Concepts, Section: 'Physical Security Controls'.


Question 15

An administrator learns that users are receiving large quantities of unsolicited messages. The administrator checks the content filter and sees hundreds of messages sent to multiple users. Which of the following best describes this kind of attack?

Correct Answer: D. Phishing
Explanation:

The scenario describes a large number of unsolicited emails sent to multiple users. This is characteristic of phishing, which SY0-701 defines as mass-distributed fraudulent messages designed to trick recipients into clicking malicious links, downloading malware, or divulging sensitive information.

Phishing campaigns typically involve:

High volume

Non-targeted messaging

Use of spoofed addresses or fake content

Delivery through email systems

A watering-hole attack (A) compromises a legitimate website frequented by targets---not email. Typosquatting (B) relies on malicious websites with deceptive URLs. Business Email Compromise (C) involves highly targeted spear-phishing or impersonation attacks, not bulk email blasts.

Because this incident involves ''hundreds of messages'' delivered to ''multiple users,'' it clearly matches the characteristics of a phishing attack, not a sophisticated targeted attack type.

Phishing is the most common form of social engineering and is emphasized heavily in the Security+ exam due to its frequency and effectiveness.