CompTIA Security+ (SY0-701) practice questions
256 free questions with answers and explanations.
- 51.A systems administrator is preparing a new server image for production. To reduce the attack surface, which action should be taken as part of the hardening process?Security Operations
- 52.A software vendor wants to share proprietary source code with a client's security team so they can perform a source code review, but the vendor is concerned about the client disclosing the code to competitors. Which document should be signed before the review begins?Security Program Management and Oversight
- 53.A security engineer is reviewing mitigations for a memory-corruption vulnerability in a compiled application. The engineer wants a defense that randomizes the memory addresses of key application areas (stack, heap, libraries) each time the program runs, making it harder for an attacker to reliably predict the location of injected shellcode. Which mitigation technique does this describe?Threats, Vulnerabilities, and Mitigations
- 54.A developer discovers that a legacy C application crashes when a user enters a string longer than the allocated 256-byte array for a login field, and further testing shows the crash can be leveraged to execute arbitrary code. Which vulnerability type does this describe?Threats, Vulnerabilities, and Mitigations
- 55.A storage administrator configures a RAID 5 array using five 2TB disks to protect against disk failure while maximizing usable capacity. How much usable storage capacity does this array provide, and how many simultaneous disk failures can it tolerate?Security Architecture
- 56.A penetration tester compromises a low-privilege domain account and then requests service tickets for several service principal names (SPNs) from the domain controller. The tester extracts the encrypted portions of these tickets and attempts to crack them offline to recover service account passwords. Which attack technique is being performed?Threats, Vulnerabilities, and Mitigations
- 57.After a six-month phishing simulation and awareness campaign, click rates on simulated phishing emails dropped from 25% to 8%, while the rate of employees reporting suspicious emails to security increased from 5% to 30%. Which conclusion best reflects the effectiveness of the awareness program?Security Program Management and Oversight
- 58.A SOC is evaluating endpoint protection tools and wants a solution that provides behavioral analysis, automated threat containment, and detailed telemetry for forensic investigation, beyond simple signature matching. Which tool best fits this requirement?Security Operations
- 59.A network administrator notices that users attempting to reach the company's legitimate banking portal are being redirected to a fraudulent site that harvests credentials, even though the URL typed into the browser is correct. Which attack technique is most likely responsible?Threats, Vulnerabilities, and Mitigations
- 60.A browser needs to verify in real time whether a website's certificate has been revoked, without downloading a large revocation list. Which protocol is used for this purpose?General Security Concepts
- 61.A cloud security architect configures an access policy that grants a user access to a financial application only if all of the following are true at the time of the request: the user's department attribute equals "Finance," the device is corporate-managed, the request occurs during business hours, and the user's location is within the United States. The policy engine evaluates these conditions dynamically at each access attempt. Which access control model is being implemented?Security Operations
- 62.A network engineer implements a solution where a centralized controller programmatically manages traffic flow rules across all switches and routers via a control plane separated from the data plane, allowing dynamic reconfiguration of the network through software policies. Which technology is being described?Security Architecture
- 63.An organization is deploying a public key infrastructure and wants a dedicated component to verify the identity of certificate requesters by checking government-issued identification and organizational documents before forwarding approved requests to the certificate authority for signing. Which PKI component should perform this identity verification role?General Security Concepts
- 64.An organization's data classification policy defines four levels: Public, Internal, Confidential, and Restricted. A marketing intern accidentally uploads a spreadsheet containing customer Social Security numbers to a folder labeled 'Internal' that is accessible to all employees. Which classification level should this data have been assigned?Security Architecture
- 65.A U.S.-based company with $60 million in annual global revenue suffers a data breach affecting EU residents' personal data and is found to have violated GDPR. Regulators state the maximum applicable fine tier is 4% of annual global revenue. What is the maximum potential fine under this tier?Security Program Management and Oversight
- 66.A company migrates its web application to a public cloud provider using Infrastructure as a Service (IaaS). Under the shared responsibility model, which of the following security tasks remains the customer's responsibility?Security Architecture
- 67.A company requires VPN users to enter a password and then approve a push notification sent to their registered smartphone before a session is established. Which two authentication factors are being combined?Security Operations
- 68.A government agency requires that a copy of every employee's private encryption key be securely stored with a trusted third party so that encrypted data can still be decrypted if an employee loses their key or leaves the organization unexpectedly. What is this practice called?General Security Concepts
- 69.An organization installs a second internet service provider (ISP) link and a backup generator to ensure systems remain accessible during outages. Which pillar of the CIA triad is primarily being addressed?General Security Concepts
- 70.A facilities manager wants to prevent vehicles from ramming into the entrance of a data center while still allowing pedestrian foot traffic. Which physical security control should be installed?General Security Concepts
- 71.An organization requires that all vendor patches be deployed first to a staging environment that mirrors production, where they are validated for compatibility and stability before being pushed to live servers. Which phase of the patch management process does this describe?Security Operations
- 72.A company wants contractual assurance that it can review a cloud service provider's security controls, logs, and processes at any time during the contract term to verify compliance. Which contractual element should be negotiated into the agreement?Security Program Management and Oversight
- 73.An e-commerce site experiences a surge in traffic during a holiday sale. To maintain availability and distribute incoming requests evenly across multiple web servers while automatically routing around any server that fails a health check, which component should be deployed?Security Architecture
- 74.A database administrator performs a full backup of a critical server every Sunday at midnight. On each subsequent day of the week, a backup job runs that captures only the data changed since the previous day's backup. On Thursday, the server fails and must be restored. How many backup sets must the administrator restore to fully recover the data?Security Operations
- 75.During a forensic examination of an NTFS file system, an investigator needs to determine the exact time the contents of a specific file were last altered, as opposed to when the file was merely opened or when its metadata record was updated. Which timestamp within the file's MAC(E) times should the investigator rely on?Security Operations
- 76.A SOC analyst notices that a workstation is sending small, encrypted outbound connections to the same external IP address every 60 seconds, regardless of user activity, even overnight when the machine is idle. Which of the following BEST describes this activity?Threats, Vulnerabilities, and Mitigations
- 77.A company's compliance officer requires that sensitive financial data remain encrypted even while it is being processed in memory by a cloud application, protecting it from a compromised hypervisor or malicious cloud administrator. Which concept addresses this requirement?Security Architecture
- 78.A security team places a fake set of database credentials inside a production configuration file that is never actually used. If those credentials are ever used to attempt a login, an alert is triggered. What is this technique called?General Security Concepts
- 79.A web server log shows repeated requests containing strings such as '../../../../etc/passwd' appended to a file-download parameter. Which type of vulnerability is being exploited?Threats, Vulnerabilities, and Mitigations
- 80.A security team deploys multiple interconnected fake servers, workstations, and network shares that mimic a real corporate environment to study attacker techniques and tools in detail. What is this deployment called?General Security Concepts
- 81.A security architect redesigns an internal corporate network so that even devices already inside the perimeter firewall must separately authenticate and be authorized before communicating with servers in a different internal zone, effectively isolating each zone from the others. Which zero trust concept does this design implement?General Security Concepts
- 82.A financial institution must ensure that private encryption keys used to protect customer data are generated, stored, and used only within tamper-resistant hardware, and are never exposed in plaintext to the operating system. Which of the following solutions BEST meets this requirement?Security Architecture
- 83.A web application uses TLS certificates issued by a public certificate authority. After a private key compromise is discovered, the security team immediately notifies the CA, which adds the certificate's serial number to a published list that browsers can check to reject the compromised certificate before its scheduled expiration. Which mechanism does this describe?Security Operations
- 84.A company runs a critical application on a two-node cluster configured in an active/passive failover arrangement. The active node fails unexpectedly. Which of the following BEST describes what happens next in this configuration?Security Architecture
- 85.A company wants to test its incident response plan without impacting live systems by having stakeholders discuss their roles during a simulated ransomware scenario. Which exercise type is being described?Security Operations
- 86.Before signing a contract with a new cloud storage vendor, a company requires the vendor to provide security certifications, financial stability documentation, and a completed security questionnaire. Which process is the company performing?Security Program Management and Oversight
- 87.A security team deploys a server on an isolated VLAN that mimics a production database, complete with fake customer records. The system has no legitimate business use and exists solely to attract and monitor attacker activity. Which type of control has been implemented?Security Operations
- 88.A security engineer writes a script that automatically queries a threat intelligence API, cross-references indicators of compromise against SIEM logs, and generates a ticket if a match is found, all without human intervention. Which benefit of security automation does this scenario primarily demonstrate?Security Operations
- 89.A SOC has fully deployed automated alerting and EDR tools, yet a security analyst proactively formulates a hypothesis that an APT group may already be present in the network and begins manually searching endpoint and network logs for subtle indicators that automated tools missed. Which activity is the analyst performing?Security Operations
- 90.A retail company's primary data center processes 20,000 transactions per hour. Management determines that after a disaster, the alternate site must be operational within 12 hours, but partially configured servers and periodically updated data are acceptable at that site to reduce ongoing costs. Which type of recovery site best fits this requirement?Security Architecture
- 91.A security researcher finds that a file-permission-checking function in an application checks whether a user has access to a file, but a brief delay occurs before the file is actually opened. An attacker exploits this delay by swapping the file with a symbolic link to a sensitive file after the check but before the open. Which vulnerability class does this represent?Threats, Vulnerabilities, and Mitigations
- 92.A security team notices thousands of rapid, sequential login attempts against a single user account, cycling through every possible four-digit PIN. Which type of attack is occurring?Threats, Vulnerabilities, and Mitigations
- 93.A hospital encrypts all patient records stored on its database servers so that even if an attacker steals the physical hard drives, the data cannot be read without the decryption key. Which principle of the CIA triad is primarily being protected by this control?General Security Concepts
- 94.A company decides that the risk of operating an outdated third-party payment plugin is too high due to known vulnerabilities and a lack of vendor patches. Rather than accept, mitigate, or transfer the risk, the company removes the plugin entirely and switches to a different payment processing method. Which risk response strategy does this represent?Security Program Management and Oversight
- 95.An organization exposes several backend microservices to external partners through a single entry point that enforces authentication, throttles excessive requests, and routes calls to the correct internal service. Which component is being described?Security Architecture
- 96.A financial application allows users to enter a numeric value for a wire transfer amount. A tester enters a value larger than 2,147,483,647 into the field, and the resulting transfer processes for a negative amount instead. Which vulnerability MOST likely caused this behavior?Threats, Vulnerabilities, and Mitigations
- 97.A SOC analyst receives a suspicious email attachment and wants to observe its behavior, including registry modifications and outbound network connections, before deciding whether to block it organization-wide. The analyst detonates the file inside an isolated virtual machine with no access to production systems. Which technique is being used?Security Operations
- 98.A penetration tester begins an engagement by searching public DNS records, WHOIS databases, and employee social media profiles without sending any packets to the target's network. Which activity is the tester performing?Security Program Management and Oversight
- 99.A company's public-facing API allows users to submit search queries. After a marketing campaign drives a surge in legitimate traffic, the API server becomes unresponsive. Investigation reveals that a single endpoint fails to release memory after each request, and available server memory steadily decreases until the process crashes. Which condition best explains this outage?Threats, Vulnerabilities, and Mitigations
- 100.A security analyst reviews logs showing exactly which employee accessed a specific file and at what time. This capability is an example of which element of the AAA framework?General Security Concepts