CompTIA Security+ (SY0-701) practice questions

256 free questions with answers and explanations.

Practice test
  1. 101.An accounts payable clerk receives an email that appears to come from the company's CFO, referencing a real ongoing vendor project and requesting an urgent wire transfer to a new bank account. The email address is one character off from the CFO's actual address. Which attack technique is being used?Threats, Vulnerabilities, and Mitigations
  2. 102.A manufacturer relies on a single overseas supplier for a critical microchip used in its flagship product. A geopolitical event disrupts the supplier's shipments, halting production for three months. Which type of risk does this scenario best illustrate?Security Program Management and Oversight
  3. 103.A security manager states that the frequency of a specific threat event, such as a server hardware failure, is expected to occur once every 5 years based on historical data. Which risk calculation term describes this value?Security Program Management and Oversight
  4. 104.An employee receives an email that appears to be from the company's shipping vendor, addressed to them by name and referencing a recent order number. The email asks the employee to click a link to 'confirm delivery details.' Which type of attack is this?Threats, Vulnerabilities, and Mitigations
  5. 105.A hospital's disaster recovery plan states that if the primary data center is destroyed, IT staff will need to procure new hardware, install operating systems, and restore data from offsite backups before operations can resume, a process expected to take several days. Which type of recovery site does this describe?Security Architecture
  6. 106.An analyst reviewing switch logs on a local network segment notices that a host is flooding the network with thousands of ARP replies mapping the gateway's IP address to the attacker's MAC address. What is the primary goal of this activity?Threats, Vulnerabilities, and Mitigations
  7. 107.A network administrator configures a file server so that only members of the Finance security group can open payroll spreadsheets, while all other authenticated employees are denied access to that folder. Which AAA function is being applied?General Security Concepts
  8. 108.During a penetration test, a tester gains access to a low-privilege web application account. The tester discovers that a scheduled maintenance script running with root/SYSTEM privileges reads a configuration file from a world-writable directory. By replacing that configuration file with malicious content, the tester causes the scheduled script to execute arbitrary code with root privileges. Which concept does this scenario best illustrate?Threats, Vulnerabilities, and Mitigations
  9. 109.A user sends a contract document to a business partner and wants the partner to be able to verify both that the document came from the user and that it was not altered in transit. The user creates a hash of the document and encrypts that hash using their own private key before sending it along with the document. What has the user created?General Security Concepts
  10. 110.An organization has 12 employees who each need to communicate securely with every other employee using a unique symmetric key per pair, with no key reuse. How many total symmetric keys are required?General Security Concepts
  11. 111.A newly hired CISO wants to create a high-level document that states management's overall intent and direction for the security program. The document will be approved by executive leadership and reviewed annually, but it will not contain specific technical instructions. Which document type should be created?Security Program Management and Oversight
  12. 112.A DevOps team adopts a deployment model where servers are never patched or modified after deployment; instead, any update requires building a new server image and replacing the running instance entirely. Which security architecture principle does this describe?Security Architecture
  13. 113.A security analyst reviews an incident where attackers encrypted a hospital's patient records and demanded payment in cryptocurrency for the decryption key. The attackers left no political message and appear to operate as a for-profit criminal enterprise with structured roles. Which type of threat actor is MOST likely responsible?Threats, Vulnerabilities, and Mitigations
  14. 114.A SOAR platform detects a malware alert from the EDR agent and automatically coordinates a response across multiple tools: it instructs the firewall to block the malicious IP, tells the EDR to isolate the infected host, and opens a ticket in the ITSM system, all as part of a single unified workflow. Which capability of the SOAR platform is best illustrated by coordinating actions across these different security tools?Security Operations
  15. 115.A company wants employees to authenticate once at their identity provider and then gain access to multiple cloud applications without re-entering credentials. Which technology enables this?Security Operations
  16. 116.A network architect is designing a corporate network and wants to place a public-facing web server so that it is reachable from the internet but isolated from the internal LAN if compromised. Which architecture BEST achieves this?Security Architecture
  17. 117.A browser displays a certificate error stating that it cannot build a valid path from a website's certificate up to a trusted root certificate authority. Which PKI concept explains why this validation failed?General Security Concepts
  18. 118.A penetration tester submits the string ' OR '1'='1 into a website's login username field and successfully bypasses authentication. Which vulnerability was exploited?Threats, Vulnerabilities, and Mitigations
  19. 119.After a ransomware incident has been eradicated and systems fully recovered, the incident response team holds a meeting to document the incident timeline, evaluate the effectiveness of the response, and update playbooks and detection rules. Which phase of the incident response process does this activity represent?Security Operations
  20. 120.A user reports that after clicking a link in an email, a pop-up appeared on a trusted banking website displaying their session cookie value. The link contained a script embedded in the URL parameters that the banking site reflected back into the page without sanitization. Which attack does this describe?Threats, Vulnerabilities, and Mitigations
  21. 121.Before beginning an authorized penetration test, the tester and client formally agree on the testing scope, permitted techniques, timing windows, and emergency contact procedures. Which document defines these parameters?Security Program Management and Oversight
  22. 122.A web application accepts a serialized object from a client-side cookie and reconstructs it into an executable object on the server without validation. An attacker modifies the serialized data to include malicious object properties, resulting in remote code execution on the server. Which vulnerability class does this best represent?Threats, Vulnerabilities, and Mitigations
  23. 123.A company's software vendor pushes a routine update to its widely used network monitoring tool. Weeks later, security teams discover the update contained a backdoor inserted by attackers who had compromised the vendor's build server. Which threat vector BEST describes how the organizations were compromised?Threats, Vulnerabilities, and Mitigations
  24. 124.Before an organization implements full-disk encryption on laptops, the risk of data exposure from a lost device is rated as High. After encryption is deployed, the remaining risk is rated as Low. What term describes the risk level that remains after the control is applied?Security Program Management and Oversight
  25. 125.An administrator makes an unapproved firewall rule change directly on a production server outside of the organization's standard request-and-approval workflow. The change causes an unexpected outage for a critical application. Which process failure most directly contributed to this incident?Security Operations
  26. 126.After reviewing a risk assessment, an organization's leadership decides that the cost of mitigating a low-probability, low-impact risk exceeds the potential loss, and no further action will be taken beyond monitoring. Which risk response strategy is being applied?Security Program Management and Oversight
  27. 127.During a change management review, a change advisory board rejects a proposed emergency patch deployment because the request does not include a documented plan for reverting the system if the patch causes failures. Which element is missing from the request?General Security Concepts
  28. 128.A DevOps team uses an Infrastructure as Code (IaC) template to provision a new cloud storage bucket. After deployment, a security audit finds the bucket is publicly readable by anyone on the internet. Which practice would have MOST effectively prevented this issue?Security Architecture
  29. 129.A large enterprise is redesigning its network security model after several breaches resulted from attackers moving freely once inside the perimeter. The new design requires continuous verification of every user and device, strict least-privilege access to individual resources, and no implicit trust based on network location. Which architecture is the enterprise implementing?Security Architecture
  30. 130.A security team integrates a step into the CI/CD pipeline that inspects container images for known CVEs in installed packages before allowing them to be pushed to the production registry. Which security practice does this represent?Security Architecture
  31. 131.An organization is decommissioning several hard drives that contained highly classified data. Company policy requires the drives be rendered completely unreadable and physically unusable before disposal. Which method BEST satisfies this requirement?Security Operations
  32. 132.A group defaces a government agency's website and replaces the homepage with a political manifesto protesting a new law. No data is stolen, and the group publicly claims responsibility on social media. Which type of threat actor is most likely responsible?Threats, Vulnerabilities, and Mitigations
  33. 133.During an active incident, the IR team discovers malware spreading laterally via SMB across multiple internal subnets. The team wants to stop further propagation immediately while still preserving the ability to monitor and analyze the malware's live behavior. Which containment strategy is most appropriate?Security Operations
  34. 134.A digital forensics examiner must create a forensic image of a suspect's storage drive while guaranteeing that no data on the original drive is modified during the acquisition process. Which piece of equipment should the examiner use?Security Operations
  35. 135.A hospital wants to protect patient records stored on file servers while the records are not actively being accessed or transmitted. Which control BEST protects the data in this state?Security Architecture
  36. 136.A security team notices a spike in DNS queries for domains that are nearly identical to the company's legitimate domain but with a single character transposed (e.g., compnay-example.com instead of company-example.com). Employees receiving emails from these lookalike domains are being tricked into wiring funds. Which technique is being used against the organization?Threats, Vulnerabilities, and Mitigations
  37. 137.A company is implementing a zero trust architecture. Which component is responsible for evaluating a request against policy and deciding whether to grant or deny access?General Security Concepts
  38. 138.A vulnerability scanner flags a web server as having a critical remote code execution vulnerability. During manual verification, the security analyst confirms the relevant patch was already applied and the specific vulnerable code path is unreachable. How should this finding be classified?Security Operations
  39. 139.An organization publishes a document that all employees must sign before receiving network access. The document defines permitted and prohibited uses of company systems, including personal use of email and prohibitions on installing unauthorized software. Which document is this?Security Program Management and Oversight
  40. 140.A PCI DSS assessment reveals that a legacy point-of-sale system cannot support encryption of stored cardholder data as normally required. To address this gap, the organization implements additional network segmentation, restrictive access controls, and enhanced monitoring around the legacy system. What type of control has the organization implemented?Security Program Management and Oversight
  41. 141.A development team needs realistic customer records to test a new application in a QA environment. To prevent exposure of actual PII while preserving the data's format and usability for testing, which technique should be used?Security Operations
  42. 142.A company's security team runs an automated scanner that identifies and lists known vulnerabilities on internal servers, including missing patches and outdated software versions, but does not attempt to exploit any of the findings. Which activity best describes this process?Security Program Management and Oversight
  43. 143.An administrator performs a full backup every Sunday night and a differential backup every other night of the week. The server fails on Thursday morning before that night's backup runs. How many backup sets must be restored to recover the most recent data?Security Architecture
  44. 144.A payment processor wants to reduce the scope of PCI DSS compliance by ensuring that actual credit card numbers are never stored in its application databases, while still allowing customer service representatives to reference past transactions by a substitute value. Which technique BEST achieves this?Security Architecture
  45. 145.A company's disaster recovery plan states that after a critical outage, the order-processing application must be back online within 4 hours to avoid violating contractual SLAs. Which term describes this 4-hour requirement?Security Architecture
  46. 146.During an active ransomware incident, the incident response team has identified the affected systems and confirmed the attack vector. According to standard incident response process, what should the team do NEXT?Security Operations
  47. 147.A network security appliance is deployed inline between the internet and the internal network. It is configured so that when it detects a known exploit signature in a packet stream, it immediately drops the malicious packets in real time before they reach the destination host. Which technology is being described?Security Operations
  48. 148.A user on a coffee shop's public Wi-Fi network reports that their browser displayed a certificate warning while accessing their bank's website. An analyst reviewing network traffic finds that an attacker's laptop is positioned between the user and the wireless access point, intercepting and relaying traffic while presenting a forged certificate. Which type of attack is described?Threats, Vulnerabilities, and Mitigations
  49. 149.A SaaS provider's enterprise customers require independent assurance regarding the design and operating effectiveness of the provider's security controls over a six-month period, without the report being made publicly available. Which type of report should the provider obtain?Security Program Management and Oversight
  50. 150.A company's data center floods on average once every 4 years, causing $250,000 in damage each time. What is the annualized loss expectancy (ALE) for this risk?Security Program Management and Oversight