CompTIA Security+ Certification Exam 2026
Latest Comprehensive Study Guide
Cybersecurity Review | Verified Answers |
Success Preparation Workbook
Exam Reference: CompTIA Security+ SY0-701
Question Format: Multiple-choice questions covering all five exam domains with
detailed rationales for each answer.
Exam Domains & Weighting:
• Domain 1.0: General Security Concepts — 12%
• Domain 2.0: Threats, Vulnerabilities, and Mitigations — 22%
• Domain 3.0: Security Architecture — 18%
• Domain 4.0: Security Operations — 28%
• Domain 5.0: Security Program Management and Oversight — 20%
DOMAIN 1.0: GENERAL SECURITY CONCEPTS (12%)
Question 1
A security administrator is implementing controls to protect sensitive customer
data. Which of the following controls is designed to deter potential attackers by
making the system appear less attractive?
A) Deterrent control
B) Preventive control
C) Detective control
D) Corrective control
Answer: A
,Rationale: Deterrent controls are designed to discourage potential attackers from
attempting to compromise a system. Examples include warning banners, security
cameras, and visible security measures. Preventive controls (B) actually block
attacks (e.g., firewalls, encryption). Detective controls (C) identify and log attacks
(e.g., IDS, logging). Corrective controls (D) restore systems after an incident (e.g.,
backups, patches).
Question 2
An organization is implementing a Zero Trust architecture. Which of the following
principles is the foundation of Zero Trust?
A) Trust but verify all internal traffic
B) Never trust, always verify
C) Trust internal networks and verify external networks
D) Verify once and trust forever
Answer: B
Rationale: Zero Trust is built on the principle of "never trust, always verify." This
means no user, device, or network segment is inherently trusted, regardless of
location. Continuous verification of identity, device health, and access rights is
required for every access request. Option A contradicts Zero Trust by suggesting
internal traffic is trusted. Option C reflects traditional perimeter-based security.
Option D violates the continuous verification requirement.
Question 3
Which of the following cryptographic concepts ensures that a message has not
been altered during transmission?
A) Confidentiality
B) Integrity
C) Availability
D) Non-repudiation
Answer: B
Rationale: Integrity ensures that data has not been modified or altered during
transmission or storage. This is typically achieved through hashing algorithms and
,digital signatures. Confidentiality (A) ensures data is not read by unauthorized
parties (encryption). Availability (C) ensures data is accessible when needed. Non-
repudiation (D) ensures a sender cannot deny sending a message.
Question 4
A company is implementing multifactor authentication (MFA) for all user
accounts. Which of the following combinations represents something you have and
something you are?
A) Password and PIN
B) Smart card and fingerprint
C) Security question and password
D) One-time token and security question
Answer: B
Rationale: Multifactor authentication requires two or more authentication factors.
"Something you have" (Type 2) includes smart cards, security tokens, or mobile
devices. "Something you are" (Type 3) includes biometrics like fingerprints, retina
scans, or facial recognition. Password and PIN (A) are both "something you know"
(Type 1). Security questions (C) and one-time tokens (D) with security questions
are also Type 1 factors.
Question 5
Which of the following is an example of a technical control?
A) Security awareness training
B) Acceptable use policy
C) Firewall rule
D) Security guard
Answer: C
Rationale: Technical controls (also called logical controls) are implemented
through technology and include firewalls, encryption, access control lists (ACLs),
and intrusion detection systems. Security awareness training (A) is an
administrative/management control. Acceptable use policy (B) is also an
administrative control. Security guards (D) are physical controls.
, Question 6
A security analyst is reviewing change management procedures. Which of the
following is the MOST important reason for having a formal change management
process?
A) To reduce the cost of changes
B) To ensure changes are approved and do not introduce security vulnerabilities
C) To speed up the implementation of changes
D) To track who requested each change
Answer: B
Rationale: The primary purpose of change management is to ensure that changes
are properly authorized, tested, and implemented without introducing security
vulnerabilities or causing unintended system disruptions. While cost reduction (A),
speed (C), and tracking (D) may be secondary benefits, security and stability are
the main concerns.
Question 7
Which of the following best describes the concept of "defense in depth"?
A) Using a single, strong security control
B) Implementing multiple layers of security controls
C) Focusing only on perimeter security
D) Relying solely on encryption
Answer: B
Rationale: Defense in depth is a security strategy that uses multiple layers of
security controls so that if one layer fails, others continue to provide protection.
This includes technical, administrative, and physical controls working together. A
single control (A) is insufficient. Perimeter-only security (C) is an outdated
approach. Encryption alone (D) is just one layer.
Question 8
A company wants to ensure that employees can only access the minimum
Latest Comprehensive Study Guide
Cybersecurity Review | Verified Answers |
Success Preparation Workbook
Exam Reference: CompTIA Security+ SY0-701
Question Format: Multiple-choice questions covering all five exam domains with
detailed rationales for each answer.
Exam Domains & Weighting:
• Domain 1.0: General Security Concepts — 12%
• Domain 2.0: Threats, Vulnerabilities, and Mitigations — 22%
• Domain 3.0: Security Architecture — 18%
• Domain 4.0: Security Operations — 28%
• Domain 5.0: Security Program Management and Oversight — 20%
DOMAIN 1.0: GENERAL SECURITY CONCEPTS (12%)
Question 1
A security administrator is implementing controls to protect sensitive customer
data. Which of the following controls is designed to deter potential attackers by
making the system appear less attractive?
A) Deterrent control
B) Preventive control
C) Detective control
D) Corrective control
Answer: A
,Rationale: Deterrent controls are designed to discourage potential attackers from
attempting to compromise a system. Examples include warning banners, security
cameras, and visible security measures. Preventive controls (B) actually block
attacks (e.g., firewalls, encryption). Detective controls (C) identify and log attacks
(e.g., IDS, logging). Corrective controls (D) restore systems after an incident (e.g.,
backups, patches).
Question 2
An organization is implementing a Zero Trust architecture. Which of the following
principles is the foundation of Zero Trust?
A) Trust but verify all internal traffic
B) Never trust, always verify
C) Trust internal networks and verify external networks
D) Verify once and trust forever
Answer: B
Rationale: Zero Trust is built on the principle of "never trust, always verify." This
means no user, device, or network segment is inherently trusted, regardless of
location. Continuous verification of identity, device health, and access rights is
required for every access request. Option A contradicts Zero Trust by suggesting
internal traffic is trusted. Option C reflects traditional perimeter-based security.
Option D violates the continuous verification requirement.
Question 3
Which of the following cryptographic concepts ensures that a message has not
been altered during transmission?
A) Confidentiality
B) Integrity
C) Availability
D) Non-repudiation
Answer: B
Rationale: Integrity ensures that data has not been modified or altered during
transmission or storage. This is typically achieved through hashing algorithms and
,digital signatures. Confidentiality (A) ensures data is not read by unauthorized
parties (encryption). Availability (C) ensures data is accessible when needed. Non-
repudiation (D) ensures a sender cannot deny sending a message.
Question 4
A company is implementing multifactor authentication (MFA) for all user
accounts. Which of the following combinations represents something you have and
something you are?
A) Password and PIN
B) Smart card and fingerprint
C) Security question and password
D) One-time token and security question
Answer: B
Rationale: Multifactor authentication requires two or more authentication factors.
"Something you have" (Type 2) includes smart cards, security tokens, or mobile
devices. "Something you are" (Type 3) includes biometrics like fingerprints, retina
scans, or facial recognition. Password and PIN (A) are both "something you know"
(Type 1). Security questions (C) and one-time tokens (D) with security questions
are also Type 1 factors.
Question 5
Which of the following is an example of a technical control?
A) Security awareness training
B) Acceptable use policy
C) Firewall rule
D) Security guard
Answer: C
Rationale: Technical controls (also called logical controls) are implemented
through technology and include firewalls, encryption, access control lists (ACLs),
and intrusion detection systems. Security awareness training (A) is an
administrative/management control. Acceptable use policy (B) is also an
administrative control. Security guards (D) are physical controls.
, Question 6
A security analyst is reviewing change management procedures. Which of the
following is the MOST important reason for having a formal change management
process?
A) To reduce the cost of changes
B) To ensure changes are approved and do not introduce security vulnerabilities
C) To speed up the implementation of changes
D) To track who requested each change
Answer: B
Rationale: The primary purpose of change management is to ensure that changes
are properly authorized, tested, and implemented without introducing security
vulnerabilities or causing unintended system disruptions. While cost reduction (A),
speed (C), and tracking (D) may be secondary benefits, security and stability are
the main concerns.
Question 7
Which of the following best describes the concept of "defense in depth"?
A) Using a single, strong security control
B) Implementing multiple layers of security controls
C) Focusing only on perimeter security
D) Relying solely on encryption
Answer: B
Rationale: Defense in depth is a security strategy that uses multiple layers of
security controls so that if one layer fails, others continue to provide protection.
This includes technical, administrative, and physical controls working together. A
single control (A) is insufficient. Perimeter-only security (C) is an outdated
approach. Encryption alone (D) is just one layer.
Question 8
A company wants to ensure that employees can only access the minimum