CertKeen
CompTIABeta · expanding bank

CompTIA Security+ (SY0-701) Practice Exam

Practice questions for the CompTIA Security+ (SY0-701) exam: security control categories and types, the CIA triad and AAA, zero trust, deception technologies, change management, cryptography and PKI (certificates, hashing, salting, key stretching, digital signatures, tokenization); threat actors and motivations, threat vectors, application, malware, password, network, physical and cryptographic attacks, indicators of compromise and mitigations; security architecture across cloud, IaC, microservices, ICS and IoT, network device placement, firewalls, IDS/IPS, VPNs, SD-WAN and SASE, data states and protection, and resilience, backups, recovery sites and power; security operations including secure baselines and hardening, mobile and wireless security, asset disposal, vulnerability management, SIEM, SCAP, NetFlow and DLP, firewall rules, SPF/DKIM/DMARC email security, EDR/XDR, SSO, federation, MFA, PAM and access control models, SOAR automation, incident response and digital forensics; and security program management, including policies and procedures, data roles, risk analysis with SLE/ARO/ALE, risk strategies and registers, business impact metrics, privacy rights, third-party agreements (SLA, MOU, BPA, MSA), right-to-audit, penetration testing and security awareness. Every question includes a written explanation.

100 questions · 12 free preview

$19 · lifetime access
Try free sample

Studying more than one? every exam for $79

Free sample questions

  1. Sample · question 1 · Access control vestibule stops tailgating

    Staff at Hawthorne Research report that visitors sometimes slip into the lab behind employees who have badged in. Which physical control best prevents this by letting only one person through at a time?

    • A.A fence with warning signs
    • B.An access control vestibulecorrect
    • C.Motion-activated lighting
    • D.Bollards

    Why: An access control vestibule, sometimes called a mantrap, uses two interlocking doors so only one person passes after authenticating, which stops tailgating and piggybacking. Bollards stop vehicles rather than people on foot. Lighting and fencing with signs deter intruders but do not stop someone from following an authorized employee through a door.

    Open this question on its own page →
  2. Sample · question 2 · Trusted Platform Module characteristics

    Corrin Legal is enabling full-disk encryption on its laptops and relies on each laptop's Trusted Platform Module (TPM). Which TWO statements describe a TPM? (Select TWO.)

    • A.It is a hardware chip built into the device's motherboardcorrect
    • B.It is a cloud service that brokers user access to SaaS applications
    • C.It can securely store keys used for disk encryption and support boot integrity checkscorrect
    • D.It is a network appliance that manages keys for many servers in a data center
    • E.It is a software password vault installed by the user

    Why: A TPM is a dedicated chip on a single device that stores cryptographic keys, such as disk encryption keys, and records measurements that support secure and measured boot. A network appliance managing keys for many servers describes a hardware security module. Brokering SaaS access is a cloud access security broker, and a password vault is software, not tamper-resistant hardware.

    Open this question on its own page →
  3. Sample · question 3 · Blockchain open public ledger integrity

    A consortium of shipping firms records cargo hand-offs on a distributed ledger. Each block holds a hash of the previous block, and many participants keep copies. What security benefit does this design mainly provide?

    • A.Data can be deleted on request without leaving any trace
    • B.Users no longer need to authenticate to submit entries
    • C.Changes to past records are easy to detect because altering one block breaks the chain of hashescorrect
    • D.The records are automatically kept confidential from all participants

    Why: Because each block includes the hash of the one before and the ledger is copied across many participants, tampering with an old record changes its hash and breaks the chain, making the change evident. A public ledger is designed for transparency, so it does not keep records confidential by default. Authentication is still needed, and the append-only design makes silent deletion difficult rather than easy.

    Open this question on its own page →
  4. Sample · question 4 · Virtual machine escape vulnerability

    An attacker who controls one guest virtual machine on a shared host at Tellis Cloud exploits a hypervisor flaw to run code on the host and access other tenants' VMs. What is this called?

    • A.Resource reuse
    • B.Jailbreaking
    • C.Sideloading
    • D.VM escapecorrect

    Why: VM escape occurs when code inside a guest breaks out of its isolation to interact with the hypervisor or host, putting every VM on that host at risk. Resource reuse concerns leftover data in reassigned memory or storage. Sideloading and jailbreaking are mobile device risks.

    Open this question on its own page →
  5. Sample · question 5 · Jump server for administrative access

    Administrators at Dalgety Power must manage servers in a restricted network segment. Security wants all administrative sessions to pass through a single hardened, closely monitored host rather than connecting from each admin's workstation. What should be deployed?

    • A.A load balancer
    • B.A forward proxy for web browsing
    • C.A honeypot
    • D.A jump servercorrect

    Why: A jump server is a hardened, monitored system that administrators connect to first and then use to reach protected systems, which limits and logs access to a sensitive segment. A forward proxy handles outbound web traffic, and a load balancer spreads client requests across servers. A honeypot is a decoy meant to attract attackers.

    Open this question on its own page →
  6. Sample · question 6 · OAuth delegated authorization without passwords

    A scheduling app built by Mossgiel Software needs to read users' calendars from a large email provider. Users should approve access without ever giving their email password to the app. Which standard is designed for this?

    • A.LDAP
    • B.RADIUS
    • C.OAuthcorrect
    • D.Kerberos

    Why: OAuth lets a user authorize an application to access specific resources on their behalf using tokens, so the app never receives the user's password. RADIUS provides AAA for network access, and Kerberos issues tickets mainly within an enterprise domain. LDAP is a protocol for querying directory services.

    Open this question on its own page →
  7. Sample · question 7 · Non-disclosure agreement for consultants

    Before a consultant reviews Fenwick Biotech's unreleased drug research, the company wants a legally binding promise that the consultant will not share any of the information with others. Which agreement should be signed?

    • A.Statement of work (SOW)
    • B.Non-disclosure agreement (NDA)correct
    • C.Rules of engagement document
    • D.Acceptable use policy (AUP)

    Why: An NDA legally binds the signer to keep specified information confidential. Rules of engagement govern how an authorized security test is run, and a statement of work describes the deliverables of a specific engagement. An AUP governs how users may use the company's own IT resources.

    Open this question on its own page →
  8. Sample · question 8 · Passive reconnaissance from public sources

    During the first phase of an authorized assessment of Westray Foods, testers gather employee names from professional networking sites, read the company's job postings and look up public DNS records, without sending any traffic to Westray's systems. What kind of activity is this?

    • A.Passive reconnaissancecorrect
    • B.Active reconnaissance
    • C.Privilege escalation
    • D.Lateral movement

    Why: Passive reconnaissance collects information from public, open sources without interacting directly with the target's systems, so it is hard for the target to detect. Active reconnaissance, such as port scanning, sends traffic to the target. Privilege escalation and lateral movement happen after a foothold is gained.

    Open this question on its own page →
  9. Sample · question 9 · Mean time between failures reliability

    Hardware records at Selkirk Transit show that its ticketing kiosks run an average of 4,200 hours before a fault occurs. Which metric does this figure represent?

    • A.Mean time between failures (MTBF)correct
    • B.Recovery point objective (RPO)
    • C.Annualized rate of occurrence (ARO)
    • D.Mean time to repair (MTTR)

    Why: MTBF measures the average operating time between failures and indicates how reliable a component is. MTTR measures the average time to restore a failed component. ARO estimates how often a risk event occurs per year, and RPO is a target for acceptable data loss, so neither measures hardware reliability.

    Open this question on its own page →
  10. Sample · question 10 · Gap analysis against a framework

    Kinross Health wants to compare its current security controls with the requirements of a recognized framework to see which controls are missing before an audit. What is this assessment called?

    • A.Penetration test
    • B.Gap analysiscorrect
    • C.Root cause analysis
    • D.Business impact analysis

    Why: A gap analysis compares the current state of controls with a target state, such as a framework's requirements, and identifies what is missing. A penetration test tries to exploit weaknesses, and a business impact analysis estimates the operational and financial effects of an outage. Root cause analysis explains why a specific incident occurred.

    Open this question on its own page →
  11. Sample · question 11 · Offline backups for ransomware recovery

    After a competitor's network backups were encrypted along with its servers, Ballater Freight wants to be sure it can recover from a ransomware attack. Which backup practice best supports this?

    • A.Back up only the operating system files
    • B.Keep a single backup copy and overwrite it nightly
    • C.Keep backup copies offline or immutable so ransomware on the network cannot alter themcorrect
    • D.Store backups only on a mapped network drive on the file server

    Why: Offline or immutable backups cannot be encrypted or deleted by ransomware that spreads across the network, so clean data remains available for recovery. A mapped drive is reachable by the same malware. Backing up only OS files misses business data, and a single nightly-overwritten copy may already contain encrypted files when the attack is noticed.

    Open this question on its own page →
  12. Sample · question 12 · Steganography hiding data in images

    An investigator at Corsewall Electronics finds that an employee has been sending ordinary-looking vacation photos to a personal account. Analysis shows design files hidden inside the image data. Which technique was used?

    • A.Steganographycorrect
    • B.Salting
    • C.Key escrow
    • D.Tokenization

    Why: Steganography conceals data inside other files, such as images or audio, so the hidden content is not apparent. Tokenization replaces sensitive values with tokens, and key escrow stores copies of encryption keys with a trusted party. Salting adds random data to passwords before hashing.

    Open this question on its own page →

Like the sample?

Other practice exams