CompTIA Security+ (SY0-701) practice questions

256 free questions with answers and explanations.

Practice test
  1. 1.A developer stores user passwords by first appending a unique random value to each password before hashing it, and storing that random value alongside the hash. What is the primary security benefit of this technique?General Security Concepts
  2. 2.A company's e-commerce server is valued at $80,000. Security analysts determine that a successful ransomware attack on this server would result in an exposure factor of 25%. What is the single loss expectancy (SLE) for this threat?Security Program Management and Oversight
  3. 3.A developer writes a serverless function that is triggered whenever a file is uploaded to a storage bucket. During a review, a security engineer notices the function's execution role has full administrative permissions across the entire cloud account. Which principle is being violated?Security Architecture
  4. 4.A financial firm's board sets a specific limit stating that no more than 2 hours of downtime per quarter is acceptable for critical trading systems. This specific, measurable limit is best described as the organization's risk:Security Program Management and Oversight
  5. 5.A compliance officer requires that all authentication logs be retained for a minimum of seven years to satisfy regulatory audit requirements, even though the SIEM's active storage only holds 90 days of searchable data. Which practice should the organization implement to meet this requirement?Security Operations
  6. 6.During a risk assessment, a risk manager records a specific risk, its likelihood, and its potential impact, but leaves the 'risk owner' field unassigned. Why is assigning a risk owner important to the risk management process?Security Program Management and Oversight
  7. 7.A penetration tester is provided with the target's network diagrams, application source code, and valid user credentials prior to beginning the engagement. Which type of penetration test is being performed?Security Program Management and Oversight
  8. 8.A financial services firm requires that, in the event of a regional data center outage, transaction processing must resume within 15 minutes with almost no data loss. Which disaster recovery site strategy BEST meets this requirement?Security Architecture
  9. 9.An employee resigns and their last day is today. Which action should the IT department prioritize as part of the offboarding process?Security Operations
  10. 10.An organization's threat intelligence team observes that employees at a manufacturing firm frequently visit a niche industry forum for technical specifications. Attackers compromise that forum and inject malicious code that only executes against visitors from the firm's IP range. Which type of attack is this?Threats, Vulnerabilities, and Mitigations
  11. 11.A user connects to a Wi-Fi network named 'Airport_Free_WiFi' that appears identical to the legitimate airport network but has a slightly stronger signal. After connecting, the user's traffic is intercepted. Which attack has most likely occurred?Threats, Vulnerabilities, and Mitigations
  12. 12.A company redesigns its data center entrance so that an employee must badge into a small enclosed space, wait for the outer door to close, and then badge again before the inner door opens. What is this physical security control called?General Security Concepts
  13. 13.A penetration tester is hired to simulate a real-world external attacker and is given only the company's public domain name. The tester has no internal documentation, credentials, or architecture diagrams before the engagement begins. Which type of penetration test is being performed?Security Program Management and Oversight
  14. 14.A retail company that processes credit card payments must implement security controls required by the Payment Card Industry Data Security Standard (PCI DSS), which is enforced through merchant agreements rather than government law. This is best classified as which type of compliance requirement?Security Program Management and Oversight
  15. 15.A network administrator is redesigning a corporate office network. Guest Wi-Fi users, employee workstations, and VoIP phones must all be logically separated so that a compromise on one group cannot directly reach the others, while sharing the same physical switches. Which technology BEST accomplishes this?Security Architecture
  16. 16.A security analyst investigating a compromised endpoint finds that a legitimate, digitally signed system process (svchost.exe) has an unusually large memory footprint and is making outbound connections to an unfamiliar IP address, but no new files were written to disk. Which technique most likely explains this behavior?Threats, Vulnerabilities, and Mitigations
  17. 17.A financial company requires that the employee who initiates a wire transfer request cannot also be the employee who approves and releases the transfer. Which security principle does this control enforce?Security Operations
  18. 18.A penetration tester crafts the following input for a corporate directory search field: *)(uid=*))(|(uid=*. After submission, the application returns all user records instead of just the intended search result. Which type of injection attack does this represent?Threats, Vulnerabilities, and Mitigations
  19. 19.An analyst plots each identified risk on a chart using descriptive labels such as 'High,' 'Medium,' and 'Low' for both likelihood and impact, rather than assigning specific dollar values. Which risk assessment approach is being used?Security Program Management and Oversight
  20. 20.An organization is implementing an asset management program for its IT equipment. Which practice would BEST help the organization track hardware throughout its entire lifecycle, from procurement to disposal?Security Operations
  21. 21.A hospital's IT system automatically grants all users assigned the title "Nurse" access to the patient scheduling application, while users assigned "Billing Clerk" automatically receive access to the invoicing system. Access is not evaluated based on any other contextual factor. Which access control model is being used?Security Operations
  22. 22.An organization determines that fully mitigating a particular risk would cost more than the potential loss itself. Instead of implementing additional controls, the organization purchases a cyber insurance policy to cover potential financial losses from that risk. Which risk treatment strategy has been applied?Security Program Management and Oversight
  23. 23.An employee uses a personal cloud storage account to sync work files because the corporate file-sharing tool is slow, without informing the IT department. This practice creates a security risk primarily due to which threat vector?Threats, Vulnerabilities, and Mitigations
  24. 24.An organization implements automated tools that continuously scan cloud configurations against a defined security baseline and generate real-time alerts whenever a resource drifts out of compliance. Which concept does this practice represent?Security Program Management and Oversight
  25. 25.A software company launches a program that invites external security researchers to find and responsibly report vulnerabilities in its public-facing applications in exchange for monetary rewards based on severity. Which term best describes this program?Security Program Management and Oversight
  26. 26.A file transfer application generates a SHA-256 checksum for a file before sending it and requires the recipient to compare it against a checksum computed after download. Which security principle is being enforced by this checksum comparison?General Security Concepts
  27. 27.A CFO receives a phone call from someone claiming to be the company's CEO, urgently requesting an immediate wire transfer to a new vendor account to close a confidential acquisition. The caller's voice closely resembles the CEO's, and the request pressures the CFO to bypass normal approval procedures. Which combination of threat vector and technique best describes this attack?Threats, Vulnerabilities, and Mitigations
  28. 28.A SIEM correlation rule triggers an alert when a single source IP generates 10 or more failed authentication attempts against the same user account within any 5-minute sliding window. The following failed login events are logged for user "jsmith" from one IP address: 3 attempts at 09:00, 4 attempts at 09:01, 2 attempts at 09:03, and 3 attempts at 09:05. Did the correlation rule trigger, and why?Security Operations
  29. 29.A digital forensics examiner creates a bit-for-bit image of a seized hard drive and calculates a SHA-256 hash of both the original and the image. What is the PRIMARY purpose of this hashing step in maintaining chain of custody?Security Operations
  30. 30.A company wants to determine which business processes are most critical to resume first after a disruption, along with the maximum acceptable downtime for each. Which activity should the company perform?Security Program Management and Oversight
  31. 31.A user who is authenticated to an online banking portal unknowingly visits a malicious website that contains a hidden form auto-submitting a funds transfer request to the bank's server using the user's active session cookie. Which attack does this describe?Threats, Vulnerabilities, and Mitigations
  32. 32.In a zero trust architecture, a user's request to access a financial application is evaluated by policy logic and then a decision must actually be carried out on the network, such as opening or blocking a session. Which component performs this enforcement action?General Security Concepts
  33. 33.A security team wants to automatically isolate an infected endpoint from the network, disable the compromised user account, and open a ticket whenever the EDR platform detects ransomware behavior, all without analyst intervention. Which capability BEST supports this requirement?Security Operations
  34. 34.A SOC analyst configures a monitoring platform to build a baseline of typical login times, data access volume, and file transfer patterns for each employee. When a user account suddenly downloads ten times its normal data volume at 3 a.m. from an unusual location, the platform generates a high-risk alert even though no signature-based rule was triggered. Which technology enables this capability?Security Operations
  35. 35.A development team wants to prevent SQL injection attacks against a customer-facing web application without altering the application's business logic. Which of the following is the MOST effective mitigation to implement in the application's database access layer?Threats, Vulnerabilities, and Mitigations
  36. 36.A malware analyst receives a suspicious executable and needs to examine its embedded strings, imported library functions, and file header structure without ever executing the code, in order to minimize risk to the analysis environment. Which technique should the analyst use?Security Operations
  37. 37.An organization's internal audit team reviews financial controls each quarter, while an outside CPA firm independently reviews the same controls annually and issues a report to the board and external stakeholders. What is the primary advantage of the external audit compared to the internal audit?Security Program Management and Oversight
  38. 38.A financial services firm requires that all customer data transmitted between its mobile app and backend API servers cannot be read even if intercepted on public Wi-Fi networks. Which control category directly addresses this requirement?Security Architecture
  39. 39.A backup policy requires full backups every 12 hours. A production database server fails 9 hours after the most recent successful backup completed. The organization's disaster recovery plan defines an RPO of 12 hours. What is the actual amount of data lost, and does it satisfy the defined RPO?Security Architecture
  40. 40.A vulnerability management team supports thousands of laptops that frequently connect from home networks, hotel Wi-Fi, and coffee shops, rarely joining the corporate network directly. The team needs continuous, up-to-date vulnerability data regardless of the laptops' network location. Which scanning approach best meets this need?Security Operations
  41. 41.A company wants to ensure that only corporate laptops with up-to-date antivirus signatures and the latest OS patches are permitted to join the internal network, while non-compliant devices are automatically placed into a quarantine VLAN. Which technology should be implemented?Security Operations
  42. 42.During an incident response, a security team discovers that a compromised Linux server's kernel-level components have been modified to hide malicious processes and network connections from standard system utilities. Which type of malware is most likely responsible?Threats, Vulnerabilities, and Mitigations
  43. 43.After restoring services from a widespread outage caused by a misconfigured firewall rule, the incident response team wants to determine the underlying reason the misconfiguration was deployed without review. Which activity should the team perform?Security Operations
  44. 44.A compliance team requires immediate alerts whenever critical operating system files, such as boot configuration files or system binaries, are modified without an approved change ticket. Which control should be implemented to meet this requirement?Security Operations
  45. 45.An e-commerce platform designs its web tier for high availability using an N+1 redundancy model. Each server can handle 250 concurrent sessions, and the platform must support a peak load of 1,000 concurrent sessions. How many servers should be deployed?Security Architecture
  46. 46.A security team runs a tool nightly that compares each server's current configuration settings against the organization's approved secure image and generates an alert whenever a setting no longer matches the standard. What is this process called?Security Operations
  47. 47.An organization wants administrators to check out credentials from a centralized vault for a limited session, with all password rotations and usage automatically logged for audit purposes, rather than administrators memorizing static passwords. Which solution best meets this requirement?Security Operations
  48. 48.A security architect is redesigning network access controls under a zero trust model. Instead of relying on a flat internal network where any authenticated device can reach any server, the architect wants to isolate each application workload so that lateral movement between systems requires explicit policy approval for every connection. Which approach BEST achieves this goal?Security Operations
  49. 49.A security manager posts signs at building entrances stating that all areas are monitored by video surveillance, even though only some cameras are active. Which type of control does this represent?General Security Concepts
  50. 50.Two government agencies want to formally document their mutual intent to share threat intelligence and collaborate on incident response, but neither party wants to create a legally binding contract with enforceable penalties. Which document BEST fits this situation?Security Program Management and Oversight