CompTIA Security+ (SY0-701) practice questions

256 free questions with answers and explanations.

Practice test
  1. 151.During a forensic investigation, an examiner transfers a seized laptop between two analysts. Which documentation must be updated to maintain evidentiary integrity?Security Operations
  2. 152.A hospital's radiology system runs on an operating system that can no longer be patched due to vendor support constraints. To reduce risk while keeping the system operational, the security team places it on an isolated VLAN with strict firewall rules and enhanced monitoring. What type of control is this VLAN isolation an example of?General Security Concepts
  3. 153.A 16-year-old downloads a freely available exploit toolkit from an online forum and uses it to deface a small business website without fully understanding how the underlying exploit code works. Which type of threat actor best describes this individual?Threats, Vulnerabilities, and Mitigations
  4. 154.A payment card processor asks a merchant to submit formal documentation, signed by a qualified security assessor, confirming that all applicable PCI DSS requirements have been met during the assessment period. What is this document called?Security Program Management and Oversight
  5. 155.A software vendor releases a security advisory stating that attackers are actively exploiting a flaw in their product for which no patch currently exists. Which term best describes this vulnerability?Threats, Vulnerabilities, and Mitigations
  6. 156.A hospital wants to let its analytics team query patient records to study treatment trends without exposing actual names or Social Security numbers, while still allowing the analysts to see realistic-looking but fictional values in those fields. Which technique BEST meets this need?Security Architecture
  7. 157.A change management process includes a category for routine, low-risk, pre-approved changes such as monthly antivirus signature updates, which do not require individual review by the change advisory board (CAB) each time. What type of change is this?General Security Concepts
  8. 158.A cloud architect configures a virtual private cloud (VPC) so that a compromised web application server in one subnet cannot initiate connections to a database subnet unless explicitly permitted by rules evaluated on every packet crossing the subnet boundary, including return traffic. Which cloud networking control is being described?Security Architecture
  9. 159.A cloud hosting provider's contract guarantees 99.9% uptime per year. Based on this guarantee, approximately how much total downtime is contractually permitted in a single year (365 days) before the provider is in breach?Security Program Management and Oversight
  10. 160.A caller identifies themselves as a technician from the company's IT helpdesk and tells an employee that their computer has been flagged for a critical security update. The caller convinces the employee to provide their network login credentials 'to verify identity' before proceeding. Which social engineering technique primarily describes the caller's approach?Threats, Vulnerabilities, and Mitigations
  11. 161.A vulnerability scan reports a finding with a CVSS v3.1 base score of 9.8. Based on this score, how should the security team prioritize remediation?Security Operations
  12. 162.An organization gathers department heads and IT leadership in a conference room to walk through a simulated ransomware scenario, discussing decisions and communication steps without performing any actual technical actions. Which activity is being conducted?Security Program Management and Oversight
  13. 163.An analyst reviewing web server logs finds a request to a system administration script containing the parameter value: '; cat /etc/shadow #'. The application passed this parameter directly into a shell command executed on the server. Which vulnerability does this best represent?Threats, Vulnerabilities, and Mitigations
  14. 164.A forensic analyst is correlating login events from a domain controller, a firewall, and a cloud application to build an accurate timeline of an attacker's activity across all three systems. The analyst discovers the timestamps are inconsistent by several minutes across devices. Which underlying configuration issue MOST likely caused this discrepancy?Security Operations
  15. 165.A security researcher analyzing a Windows application finds that it loads a required library by searching the current working directory before checking the trusted system directory. An attacker places a malicious library with the same filename in a folder the application will search first, causing the malicious code to execute with the application's privileges. Which attack technique is being described?Threats, Vulnerabilities, and Mitigations
  16. 166.A company wants to protect a public-facing e-commerce web application from SQL injection and cross-site scripting attacks without modifying the application's source code. Which tool should be deployed?Security Operations
  17. 167.A web application parses XML data submitted by users to generate reports. A penetration tester submits an XML document containing a DOCTYPE declaration that defines an external entity referencing the server's local '/etc/passwd' file, and the application's response includes the file's contents. Which vulnerability was exploited?Threats, Vulnerabilities, and Mitigations
  18. 168.During a red team engagement, testers who compromised a domain controller extract the krbtgt account's password hash and use it to forge Kerberos ticket-granting tickets, granting themselves domain admin access that persists even after the original compromised account's password is reset. Which attack was performed?Threats, Vulnerabilities, and Mitigations
  19. 169.A DevOps team deploys a containerized application on a Kubernetes cluster. Database credentials are currently stored as plaintext environment variables in the pod deployment YAML file. Which of the following changes would BEST improve the security of these credentials?Security Architecture
  20. 170.A forensic investigator is collecting evidence from a compromised server that must remain powered on for business continuity. Following the order of volatility, which data source should be collected FIRST?Security Operations
  21. 171.A company migrates a monolithic application into dozens of independently deployed microservices running in containers. Security engineers want every service-to-service call to be mutually authenticated and encrypted without requiring each development team to write custom TLS code. Which architectural solution BEST meets this requirement?Security Architecture
  22. 172.A penetration tester is given valid user credentials and a basic network diagram before the engagement begins, but is not provided source code or full administrative documentation. Which type of penetration test is being performed?Security Program Management and Oversight
  23. 173.A security architect is redesigning a data center network so that if an attacker compromises one virtual machine, they cannot easily move laterally to other VMs in the same subnet, even though those VMs previously trusted each other. Which approach BEST achieves this goal?Security Architecture
  24. 174.A multinational corporation processes customer data from the European Union in a cloud provider's data center located in another country. Legal counsel raises concerns that this may violate regulations requiring certain data to remain within specific geographic or legal boundaries. Which concept does this scenario primarily concern?Security Architecture
  25. 175.A security appliance inspects outbound email and automatically blocks messages containing credit card numbers before they leave the network. Which type of tool is being used?Security Operations
  26. 176.A company issues corporate smartphones to sales staff and needs the ability to remotely wipe data, enforce screen-lock policies, and push approved apps to all devices from a central console. Which solution BEST meets this requirement?Security Operations
  27. 177.A payroll administrator has legitimate access to the HR system to process employee salaries. Investigators discover the administrator quietly modified their own salary figures over several months, using their normal login credentials and avoiding any detection triggers. Which type of threat actor does this best describe?Threats, Vulnerabilities, and Mitigations
  28. 178.An analyst notices thousands of failed login attempts across multiple corporate accounts, each attempt using a different username and password combination pulled from a previously leaked data breach. Which type of attack is most likely occurring?Threats, Vulnerabilities, and Mitigations
  29. 179.A disgruntled system administrator, aware they are about to be terminated, embeds code into the company's payroll application that will delete all employee records if their user account is ever removed from Active Directory. Which malicious activity indicator best describes this scenario?Threats, Vulnerabilities, and Mitigations
  30. 180.A network administrator wants to allow remote administrators to securely access internal servers without exposing those servers directly to the internet. All SSH sessions to internal hosts must first pass through a single, tightly monitored intermediary system. Which solution should the administrator deploy?Security Architecture
  31. 181.During an active incident, a forensic analyst reviews NetFlow data and notices a workstation communicating with an unusual external IP over port 4444 shortly before a spike in outbound traffic to multiple internal hosts. Which activity does this pattern most likely indicate?Security Operations
  32. 182.During an asset inventory review, a security analyst discovers several production servers running an operating system version the vendor no longer supports. Which risk should the analyst prioritize addressing?Security Operations
  33. 183.A risk analyst creates a visual chart plotting each identified risk according to its likelihood on one axis and its impact on the other, using color coding (green, yellow, red) to indicate severity levels. What is this tool called?Security Program Management and Oversight
  34. 184.A security analyst is configuring account protections to stop brute-force password guessing. The analyst wants locked-out accounts to automatically become usable again after a set period, without requiring users to call the help desk. Which policy setting accomplishes this?Security Operations
  35. 185.A global SaaS provider replicates its production database synchronously across data centers in two different geographic regions so that a regional disaster does not cause data loss or extended downtime. Which resilience concept does this design primarily illustrate?Security Architecture
  36. 186.A vulnerability management program identified two findings: Finding X has a CVSS base score of 7.5 affecting an internal test server with no known exploit, and Finding Y has a CVSS base score of 6.8 affecting an internet-facing payment server with a public exploit available. Which finding should be remediated first?Security Operations
  37. 187.A retail chain wants to bring on a new inventory-management SaaS vendor. Before signing the contract, the security team requires the vendor to complete a security questionnaire, provide a recent SOC 2 report, and disclose any subcontractors who will process company data. After the contract is signed, the security team also schedules recurring quarterly reviews of the vendor's security posture for as long as the relationship continues. What does the ongoing quarterly review activity represent, in contrast to the pre-contract steps?Security Program Management and Oversight
  38. 188.A SOC analyst notices that a SIEM dashboard is generating hundreds of low-fidelity alerts daily, causing analysts to miss genuine threats. Which action would MOST effectively address this issue?Security Operations
  39. 189.A risk manager is building a document that will track every identified risk across the organization, along with its assigned owner, likelihood, impact rating, and current treatment status. Which of the following is the manager creating?Security Program Management and Oversight
  40. 190.A security researcher demonstrates that two different input files can be crafted to produce the identical output when processed by a hashing algorithm with a small digest size, allowing an attacker to substitute a malicious file for a legitimate one without detection. This scenario best illustrates which type of vulnerability?Threats, Vulnerabilities, and Mitigations
  41. 191.An organization anticipates litigation related to a data breach and must ensure that relevant emails and logs are not deleted or altered, even by automated retention policies. Which action should be taken?Security Operations
  42. 192.A company currently suffers a successful ransomware attack about once every 2 years, with an average loss of $400,000 per incident. Implementing a new EDR solution costing $50,000 annually is expected to reduce the occurrence to once every 5 years. Based on ALE analysis, what is the net financial benefit of implementing the control, and should it be implemented?Security Program Management and Oversight
  43. 193.A vulnerability management team wants scan results to include missing patches, misconfigured registry settings, and outdated software versions with high accuracy and minimal false positives. Which scan type should they use?Security Operations
  44. 194.A new IT director tells staff that patches must be applied within 30 days of release, exceeding the organization's documented minimum requirement of 90 days, because the director believes this reflects prudent security practice. Which concept does the director's action illustrate?Security Program Management and Oversight
  45. 195.A backup administrator is designing a data protection strategy to ensure recoverability from ransomware, hardware failure, and site disasters. Which strategy best follows industry best practice for backup redundancy?Security Architecture
  46. 196.A defense contractor stores highly classified research data on a network with no physical or wireless connection to the internet or any other network. Data must be manually transferred using approved removable media after being scanned for malware. Which architecture does this describe?Security Architecture
  47. 197.During an incident investigation, an analyst finds that an attacker extracted NTLM password hashes from a compromised workstation's memory and used them directly to authenticate to other systems without ever cracking the passwords. Which technique was used?Threats, Vulnerabilities, and Mitigations
  48. 198.A security analyst is briefing management on a recent breach in which attackers spent months quietly exfiltrating intellectual property from a defense contractor without triggering alerts. Which threat actor motivation is MOST consistent with this activity?Threats, Vulnerabilities, and Mitigations
  49. 199.A security architect wants privileged accounts to receive elevated permissions only for the duration of a specific task, after which access automatically expires. Which concept does this describe?Security Operations
  50. 200.A security analyst is investigating a suspected data exfiltration event. The analyst discovers a specific IP address that was observed making unusually large outbound connections to an external server, followed by a sudden drop in network traffic from the internal host. This IP address was previously unknown to the organization. What type of information does this IP address represent in the context of threat intelligence?Security Operations