CompTIA Security+ (SY0-701) practice questions
256 free questions with answers and explanations.
- 151.During a forensic investigation, an examiner transfers a seized laptop between two analysts. Which documentation must be updated to maintain evidentiary integrity?Security Operations
- 152.A hospital's radiology system runs on an operating system that can no longer be patched due to vendor support constraints. To reduce risk while keeping the system operational, the security team places it on an isolated VLAN with strict firewall rules and enhanced monitoring. What type of control is this VLAN isolation an example of?General Security Concepts
- 153.A 16-year-old downloads a freely available exploit toolkit from an online forum and uses it to deface a small business website without fully understanding how the underlying exploit code works. Which type of threat actor best describes this individual?Threats, Vulnerabilities, and Mitigations
- 154.A payment card processor asks a merchant to submit formal documentation, signed by a qualified security assessor, confirming that all applicable PCI DSS requirements have been met during the assessment period. What is this document called?Security Program Management and Oversight
- 155.A software vendor releases a security advisory stating that attackers are actively exploiting a flaw in their product for which no patch currently exists. Which term best describes this vulnerability?Threats, Vulnerabilities, and Mitigations
- 156.A hospital wants to let its analytics team query patient records to study treatment trends without exposing actual names or Social Security numbers, while still allowing the analysts to see realistic-looking but fictional values in those fields. Which technique BEST meets this need?Security Architecture
- 157.A change management process includes a category for routine, low-risk, pre-approved changes such as monthly antivirus signature updates, which do not require individual review by the change advisory board (CAB) each time. What type of change is this?General Security Concepts
- 158.A cloud architect configures a virtual private cloud (VPC) so that a compromised web application server in one subnet cannot initiate connections to a database subnet unless explicitly permitted by rules evaluated on every packet crossing the subnet boundary, including return traffic. Which cloud networking control is being described?Security Architecture
- 159.A cloud hosting provider's contract guarantees 99.9% uptime per year. Based on this guarantee, approximately how much total downtime is contractually permitted in a single year (365 days) before the provider is in breach?Security Program Management and Oversight
- 160.A caller identifies themselves as a technician from the company's IT helpdesk and tells an employee that their computer has been flagged for a critical security update. The caller convinces the employee to provide their network login credentials 'to verify identity' before proceeding. Which social engineering technique primarily describes the caller's approach?Threats, Vulnerabilities, and Mitigations
- 161.A vulnerability scan reports a finding with a CVSS v3.1 base score of 9.8. Based on this score, how should the security team prioritize remediation?Security Operations
- 162.An organization gathers department heads and IT leadership in a conference room to walk through a simulated ransomware scenario, discussing decisions and communication steps without performing any actual technical actions. Which activity is being conducted?Security Program Management and Oversight
- 163.An analyst reviewing web server logs finds a request to a system administration script containing the parameter value: '; cat /etc/shadow #'. The application passed this parameter directly into a shell command executed on the server. Which vulnerability does this best represent?Threats, Vulnerabilities, and Mitigations
- 164.A forensic analyst is correlating login events from a domain controller, a firewall, and a cloud application to build an accurate timeline of an attacker's activity across all three systems. The analyst discovers the timestamps are inconsistent by several minutes across devices. Which underlying configuration issue MOST likely caused this discrepancy?Security Operations
- 165.A security researcher analyzing a Windows application finds that it loads a required library by searching the current working directory before checking the trusted system directory. An attacker places a malicious library with the same filename in a folder the application will search first, causing the malicious code to execute with the application's privileges. Which attack technique is being described?Threats, Vulnerabilities, and Mitigations
- 166.A company wants to protect a public-facing e-commerce web application from SQL injection and cross-site scripting attacks without modifying the application's source code. Which tool should be deployed?Security Operations
- 167.A web application parses XML data submitted by users to generate reports. A penetration tester submits an XML document containing a DOCTYPE declaration that defines an external entity referencing the server's local '/etc/passwd' file, and the application's response includes the file's contents. Which vulnerability was exploited?Threats, Vulnerabilities, and Mitigations
- 168.During a red team engagement, testers who compromised a domain controller extract the krbtgt account's password hash and use it to forge Kerberos ticket-granting tickets, granting themselves domain admin access that persists even after the original compromised account's password is reset. Which attack was performed?Threats, Vulnerabilities, and Mitigations
- 169.A DevOps team deploys a containerized application on a Kubernetes cluster. Database credentials are currently stored as plaintext environment variables in the pod deployment YAML file. Which of the following changes would BEST improve the security of these credentials?Security Architecture
- 170.A forensic investigator is collecting evidence from a compromised server that must remain powered on for business continuity. Following the order of volatility, which data source should be collected FIRST?Security Operations
- 171.A company migrates a monolithic application into dozens of independently deployed microservices running in containers. Security engineers want every service-to-service call to be mutually authenticated and encrypted without requiring each development team to write custom TLS code. Which architectural solution BEST meets this requirement?Security Architecture
- 172.A penetration tester is given valid user credentials and a basic network diagram before the engagement begins, but is not provided source code or full administrative documentation. Which type of penetration test is being performed?Security Program Management and Oversight
- 173.A security architect is redesigning a data center network so that if an attacker compromises one virtual machine, they cannot easily move laterally to other VMs in the same subnet, even though those VMs previously trusted each other. Which approach BEST achieves this goal?Security Architecture
- 174.A multinational corporation processes customer data from the European Union in a cloud provider's data center located in another country. Legal counsel raises concerns that this may violate regulations requiring certain data to remain within specific geographic or legal boundaries. Which concept does this scenario primarily concern?Security Architecture
- 175.A security appliance inspects outbound email and automatically blocks messages containing credit card numbers before they leave the network. Which type of tool is being used?Security Operations
- 176.A company issues corporate smartphones to sales staff and needs the ability to remotely wipe data, enforce screen-lock policies, and push approved apps to all devices from a central console. Which solution BEST meets this requirement?Security Operations
- 177.A payroll administrator has legitimate access to the HR system to process employee salaries. Investigators discover the administrator quietly modified their own salary figures over several months, using their normal login credentials and avoiding any detection triggers. Which type of threat actor does this best describe?Threats, Vulnerabilities, and Mitigations
- 178.An analyst notices thousands of failed login attempts across multiple corporate accounts, each attempt using a different username and password combination pulled from a previously leaked data breach. Which type of attack is most likely occurring?Threats, Vulnerabilities, and Mitigations
- 179.A disgruntled system administrator, aware they are about to be terminated, embeds code into the company's payroll application that will delete all employee records if their user account is ever removed from Active Directory. Which malicious activity indicator best describes this scenario?Threats, Vulnerabilities, and Mitigations
- 180.A network administrator wants to allow remote administrators to securely access internal servers without exposing those servers directly to the internet. All SSH sessions to internal hosts must first pass through a single, tightly monitored intermediary system. Which solution should the administrator deploy?Security Architecture
- 181.During an active incident, a forensic analyst reviews NetFlow data and notices a workstation communicating with an unusual external IP over port 4444 shortly before a spike in outbound traffic to multiple internal hosts. Which activity does this pattern most likely indicate?Security Operations
- 182.During an asset inventory review, a security analyst discovers several production servers running an operating system version the vendor no longer supports. Which risk should the analyst prioritize addressing?Security Operations
- 183.A risk analyst creates a visual chart plotting each identified risk according to its likelihood on one axis and its impact on the other, using color coding (green, yellow, red) to indicate severity levels. What is this tool called?Security Program Management and Oversight
- 184.A security analyst is configuring account protections to stop brute-force password guessing. The analyst wants locked-out accounts to automatically become usable again after a set period, without requiring users to call the help desk. Which policy setting accomplishes this?Security Operations
- 185.A global SaaS provider replicates its production database synchronously across data centers in two different geographic regions so that a regional disaster does not cause data loss or extended downtime. Which resilience concept does this design primarily illustrate?Security Architecture
- 186.A vulnerability management program identified two findings: Finding X has a CVSS base score of 7.5 affecting an internal test server with no known exploit, and Finding Y has a CVSS base score of 6.8 affecting an internet-facing payment server with a public exploit available. Which finding should be remediated first?Security Operations
- 187.A retail chain wants to bring on a new inventory-management SaaS vendor. Before signing the contract, the security team requires the vendor to complete a security questionnaire, provide a recent SOC 2 report, and disclose any subcontractors who will process company data. After the contract is signed, the security team also schedules recurring quarterly reviews of the vendor's security posture for as long as the relationship continues. What does the ongoing quarterly review activity represent, in contrast to the pre-contract steps?Security Program Management and Oversight
- 188.A SOC analyst notices that a SIEM dashboard is generating hundreds of low-fidelity alerts daily, causing analysts to miss genuine threats. Which action would MOST effectively address this issue?Security Operations
- 189.A risk manager is building a document that will track every identified risk across the organization, along with its assigned owner, likelihood, impact rating, and current treatment status. Which of the following is the manager creating?Security Program Management and Oversight
- 190.A security researcher demonstrates that two different input files can be crafted to produce the identical output when processed by a hashing algorithm with a small digest size, allowing an attacker to substitute a malicious file for a legitimate one without detection. This scenario best illustrates which type of vulnerability?Threats, Vulnerabilities, and Mitigations
- 191.An organization anticipates litigation related to a data breach and must ensure that relevant emails and logs are not deleted or altered, even by automated retention policies. Which action should be taken?Security Operations
- 192.A company currently suffers a successful ransomware attack about once every 2 years, with an average loss of $400,000 per incident. Implementing a new EDR solution costing $50,000 annually is expected to reduce the occurrence to once every 5 years. Based on ALE analysis, what is the net financial benefit of implementing the control, and should it be implemented?Security Program Management and Oversight
- 193.A vulnerability management team wants scan results to include missing patches, misconfigured registry settings, and outdated software versions with high accuracy and minimal false positives. Which scan type should they use?Security Operations
- 194.A new IT director tells staff that patches must be applied within 30 days of release, exceeding the organization's documented minimum requirement of 90 days, because the director believes this reflects prudent security practice. Which concept does the director's action illustrate?Security Program Management and Oversight
- 195.A backup administrator is designing a data protection strategy to ensure recoverability from ransomware, hardware failure, and site disasters. Which strategy best follows industry best practice for backup redundancy?Security Architecture
- 196.A defense contractor stores highly classified research data on a network with no physical or wireless connection to the internet or any other network. Data must be manually transferred using approved removable media after being scanned for malware. Which architecture does this describe?Security Architecture
- 197.During an incident investigation, an analyst finds that an attacker extracted NTLM password hashes from a compromised workstation's memory and used them directly to authenticate to other systems without ever cracking the passwords. Which technique was used?Threats, Vulnerabilities, and Mitigations
- 198.A security analyst is briefing management on a recent breach in which attackers spent months quietly exfiltrating intellectual property from a defense contractor without triggering alerts. Which threat actor motivation is MOST consistent with this activity?Threats, Vulnerabilities, and Mitigations
- 199.A security architect wants privileged accounts to receive elevated permissions only for the duration of a specific task, after which access automatically expires. Which concept does this describe?Security Operations
- 200.A security analyst is investigating a suspected data exfiltration event. The analyst discovers a specific IP address that was observed making unusually large outbound connections to an external server, followed by a sudden drop in network traffic from the internal host. This IP address was previously unknown to the organization. What type of information does this IP address represent in the context of threat intelligence?Security Operations