CompTIA Security+ (SY0-701) practice questions
256 free questions with answers and explanations.
- 201.A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains. This device automatically updates its block lists based on feeds from various threat intelligence sources and can also coordinate responses with other security tools. Which type of security tool is being described?Security Operations
- 202.A security team is implementing a new endpoint protection solution. They require a tool that provides behavioral analysis, malware detection without relying solely on signatures, and the ability to detect and respond to threats post-compromise. Which solution best fits these requirements?Security Operations
- 203.A security analyst is investigating a suspected malware infection on a critical server. Before performing any remediation actions, the analyst needs to ensure that all volatile data is captured in a specific order to preserve evidence. Which of the following data types should the analyst prioritize capturing FIRST?Security Operations
- 204.A security analyst is conducting a forensic investigation after a suspected intrusion. The analyst needs to preserve volatile data from a compromised Linux server before shutting it down for a full disk image. Which of the following should be collected FIRST?Security Operations
- 205.A company is redesigning its network architecture with a focus on zero trust principles. Instead of granting blanket access to users once they are on the corporate network, the new design requires that all access requests, regardless of source (internal or external), are continuously evaluated and verified before granting access to resources. Which zero trust principle is being primarily emphasized here?Security Operations
- 206.A company is redesigning its network architecture with a focus on zero trust principles. They are implementing a system that requires users and devices to be continuously authenticated, authorized, and validated for every access request, even after initial authentication. Which core zero trust principle is being applied?Security Operations
- 207.A security administrator needs to ensure that only authorized applications are allowed to execute on corporate workstations. Any attempt to run an unauthorized executable should be blocked. Which security control should be implemented?Security Operations
- 208.A security architect is designing a new cloud application and needs to implement granular access controls based on user attributes such as department, role, and current project, rather than just predefined roles. The system should dynamically grant or deny access to specific resources based on a combination of these attributes. Which access control model would BEST fit these requirements?Security Operations
- 209.A security analyst is reviewing a SIEM dashboard and notices a significant increase in outbound connections from internal workstations to IP addresses in a known hostile nation-state. This trend was identified by correlating internal log data with external threat intelligence feeds. Which type of threat intelligence is being utilized in this scenario?Security Operations
- 210.A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains, as identified by various threat intelligence feeds. This device will automatically update its blocklists from these feeds and apply the rules in real-time. Which enterprise security tool is being configured?Security Operations
- 211.A SOC analyst observes a sudden spike in login attempts from a single IP address to multiple user accounts on various internal systems. Many of these attempts are failing. Which type of attack is most likely occurring?Security Operations
- 212.A security analyst is conducting a forensic investigation after a suspected intrusion. To preserve the integrity of the collected evidence, the analyst calculates a cryptographic hash of a seized hard drive image before and after analysis. Which principle of digital forensics does this action primarily support?Security Operations
- 213.A security analyst is conducting a forensic investigation after a suspected intrusion. To maintain the integrity of digital evidence, the analyst must ensure that the original drive is not altered in any way during the acquisition process. Which tool should the analyst use to achieve this?Security Operations
- 214.A SOC analyst observes a sudden spike in login attempts from a single IP address to multiple user accounts within a short period. Many of these attempts are failing, but some are unexpectedly successful for accounts that were believed to be inactive. Which attack is most likely underway?Security Operations
- 215.A security team is regularly reviewing vulnerability scan reports. They frequently encounter findings related to outdated operating system versions and unpatched software on production servers. Which aspect of security operations is primarily failing in this scenario?Security Operations
- 216.A security analyst is investigating a persistent threat actor leveraging unknown malware. The analyst needs to understand the malware's capabilities, including its command-and-control (C2) communication patterns, without risking the production environment. Which of the following analysis techniques would be MOST appropriate for this scenario?Security Operations
- 217.A company is implementing a new security awareness program. They want to simulate real-world phishing attempts to gauge employee susceptibility and identify areas for further training without causing actual harm. What type of exercise would BEST achieve this goal?Security Operations
- 218.A security analyst is investigating a suspected data exfiltration event. The analyst discovers a specific IP address that was observed making unusually large outbound connections to an external server, followed by a sudden drop in network traffic from the internal host. The analyst then uses this IP address to search logs across the SIEM, firewall, and proxy servers to find other related activities. What type of information does this IP address represent in the context of a security investigation?Security Operations
- 219.A security analyst is investigating a suspected data exfiltration event. The analyst discovers large volumes of encrypted traffic originating from an internal server to an unknown external IP address during off-peak hours. Which of the following is the MOST likely indicator of compromise (IOC)?Security Operations
- 220.A security team is implementing new endpoint protection. They require a tool that provides continuous monitoring of endpoint activities, records all system events, and allows security analysts to perform advanced threat hunting and incident investigation across all managed devices. Which solution best fits these requirements?Security Operations
- 221.A security team is regularly reviewing vulnerability scan reports. They frequently encounter findings that are flagged as 'High' severity but, after manual inspection, are determined to pose no actual risk due to compensating controls or environmental factors. What process should the team implement to reduce the noise from these non-actionable findings in future reports?Security Operations
- 222.A security administrator is configuring access controls for a new application. The policy states that users can only access specific data if they are located within the corporate network, during business hours (9 AM to 5 PM), and belong to the 'Finance' group. Which access control model does this scenario BEST represent?Security Operations
- 223.A security administrator is configuring access controls for a new application. The policy states that 'users in the 'Managers' group can access any document marked 'Confidential' if their department matches the document's department attribute, and the current time is between 9 AM and 5 PM on a weekday.' Which access control model is being implemented?Security Operations
- 224.A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains, as identified by various threat intelligence feeds. This device also needs to inspect HTTP/HTTPS traffic for web application attacks like SQL injection and cross-site scripting. Which type of security control BEST combines these functionalities?Security Operations
- 225.A security team is regularly reviewing vulnerability scan reports. They frequently encounter findings that are reported as vulnerabilities but, after manual inspection, are determined to be false positives due to specific compensating controls or environmental factors. What process should the team implement to manage these recurring false positives effectively?Security Operations
- 226.A security team is implementing a security awareness program. They want to simulate real-world phishing attempts to educate employees on how to identify and report suspicious emails without causing actual harm. Which type of exercise would best achieve this goal?Security Operations
- 227.A security team is regularly reviewing vulnerability scan reports. They frequently encounter findings for critical systems that, upon manual inspection, are determined to be false positives due to compensating controls or environmental factors not understood by the scanner. This situation is leading to alert fatigue and wasted effort. Which aspect of vulnerability management needs improvement?Security Operations
- 228.A security analyst is reviewing a SIEM dashboard and notices a significant increase in outbound DNS queries from several internal workstations to unusual, newly registered domains. This activity occurs shortly after a successful phishing campaign targeting employees. What type of threat intelligence BEST describes the information about these suspicious domains?Security Operations
- 229.A security team is implementing a new endpoint protection solution. They require a tool that can not only detect known malware signatures but also identify and block malicious behaviors, even from previously unseen threats. Which type of solution BEST meets these requirements?Security Operations
- 230.A security analyst is conducting a forensic investigation after a suspected intrusion. To ensure the integrity and authenticity of the acquired evidence, the analyst calculates a cryptographic hash of the suspect's hard drive before and after creating a forensic image. What is the PRIMARY purpose of this action?Security Operations
- 231.A security analyst is investigating a suspected data exfiltration event. The analyst discovers a large volume of unusual outbound traffic to an unknown IP address, accompanied by several failed login attempts from an internal server to an external host. Which of the following best describes these findings?Security Operations
- 232.A company is implementing a security awareness program. They want to simulate real-world phishing attacks to assess employee susceptibility and provide targeted training based on the results. Which activity would best achieve this goal?Security Operations
- 233.A security administrator needs to ensure that only authorized applications are allowed to execute on critical servers, preventing unknown or malicious software from running. Which security control would best achieve this goal?Security Operations
- 234.A SOC analyst observes a sudden spike in failed login attempts from a single external IP address targeting multiple user accounts on the company's public-facing web server. This activity follows a pattern where the attacker systematically tries common username/password combinations across different accounts. What type of attack is MOST likely occurring?Security Operations
- 235.A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains. The device needs to automatically update its block list based on a continuously fed stream of threat intelligence indicators. Which security technology is most suitable for this requirement?Security Operations
- 236.A security architect is designing a new cloud application and needs to implement granular access controls where permissions are granted dynamically based on user attributes (e.g., department, role, location), resource attributes (e.g., data sensitivity, creation date), and environmental conditions (e.g., time of day, IP address). Which access control model should the architect choose?Security Operations
- 237.A company is redesigning its network architecture with a focus on zero trust principles. They want to ensure that every device, user, and application is continuously verified, regardless of its location (inside or outside the traditional network perimeter). Which core concept is central to achieving this goal?Security Operations
- 238.A company is redesigning its network architecture with a focus on zero trust principles. They want to ensure that access to resources is never implicitly trusted and is continuously verified, regardless of whether the user or device is inside or outside the traditional network perimeter. Which core concept of zero trust is being emphasized here?Security Operations
- 239.A security team is implementing new endpoint protection. They require a tool that provides advanced threat detection capabilities beyond traditional signature-based antivirus, including behavioral analysis, machine learning for unknown threats, and the ability to detect fileless malware. Which solution BEST meets these requirements?Security Operations
- 240.A security analyst is conducting a forensic investigation after a suspected intrusion. The analyst needs to collect volatile data from a compromised server. Which of the following data types should be collected FIRST due to its highly ephemeral nature?Security Operations
- 241.A security team is implementing new endpoint protection. They require a tool that provides continuous monitoring, real-time visibility into endpoint activities, threat hunting capabilities, and the ability to initiate remote response actions like isolating a compromised host. Which solution best meets these comprehensive requirements?Security Operations
- 242.A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains. This device automatically updates its block lists based on feeds from various threat intelligence sources. Which security control is being implemented?Security Operations
- 243.A security team is implementing a new security awareness program. They want to simulate real-world phishing attacks to gauge employee susceptibility and identify areas for further training. Which type of exercise should they conduct?Security Operations
- 244.A security analyst is reviewing a SIEM dashboard and notices a significant increase in outbound DNS queries to domains known to be associated with a recent malware campaign described in a public threat intelligence report. This type of information is most useful for which aspect of security operations?Security Operations
- 245.A SOC analyst observes a sudden spike in login attempts from a single IP address to multiple user accounts within a short period. Most of these attempts are failing, but some are successful. What type of attack is MOST likely occurring?Security Operations
- 246.A SOC analyst observes a sudden spike in login attempts from a single IP address to multiple user accounts on the corporate VPN. Many of these attempts are failing. What type of attack is MOST likely occurring?Security Operations
- 247.A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains. The device needs to automatically update its block list with new threat intelligence feeds. Which security tool would BEST facilitate this capability?Security Operations
- 248.A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains identified by various threat intelligence feeds. The device also needs to inspect encrypted traffic for malicious content and prevent common web application attacks like SQL injection. Which of the following enterprise security tools would be MOST suitable for this comprehensive set of requirements?Security Operations
- 249.A security team is implementing a new endpoint protection solution. They require a tool that provides behavioral analysis, machine learning capabilities to detect unknown threats, and the ability to isolate compromised endpoints. Which type of solution would best meet these requirements?Security Operations
- 250.A security administrator is implementing a new security solution that will automatically analyze incoming email attachments for malicious behavior in a safe, isolated environment before they reach user inboxes. Which type of analysis is being performed?Security Operations