Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 125 pages
Exam (elaborations)

CompTIA Security+ SY0-701 Certification Exam Practice Questions – Complete 2026 High-Yield Test Bank with Real Exam Scenarios and Detailed Explanations

Document preview thumbnail
Preview 4 out of 125 pages

Pass your IT security certification on the very first attempt with this comprehensive 2026 practice test bank explicitly mapped to the latest CompTIA Security+ SY0-701 objectives. This high-density study resource features realistic, scenario-based multiple-choice questions covering zero-trust architecture, hybrid cloud environments, threat vectors, and incident response operations. Every practice question includes detailed technical rationales for both correct and incorrect choices to ensure rapid concept mastery and peak exam readiness.

Content preview

CompTIA Security+ SY0-701 Certification Exam
Practice Questions 2026
Question 1
An organization wants to ensure that if a security incident occurs, they can demonstrate
that a specific user performed a specific action. Which security principle is the
organization trying to implement?

A. Confidentiality
B. Integrity
C. Non-repudiation
D. Availability

*Correct Answer: C. Non-repudiation. *

Rationale: Non-repudiation ensures that an individual cannot deny having performed a
specific action. This is typically achieved through digital signatures and comprehensive
audit logs .




Question 2
A security analyst is creating an inbound firewall rule to block a malicious IP address
(10.1.4.9) from accessing the organization's network. Which of the following rules fulfills
this request?

A. access-list inbound deny ip source 0.0.0.0/0 destination 10.1.4.9/32
B. access-list inbound deny ip source 10.1.4.9/32 destination 0.0.0.0/0
C. access-list inbound permit ip source 10.1.4.9/32 destination 0.0.0.0/0
D. access-list inbound permit ip source 0.0.0.0/0 destination 10.1.4.9/32

*Correct Answer: B. access-list inbound deny ip source 10.1.4.9/32 destination
0.0.0.0/0. *

Rationale: An inbound rule should block traffic originating from the malicious source IP
(10.1.4.9/32) to any destination (0.0.0.0/0) on the network. The "deny" action is required
with the attacker's IP as the source .

,Question 3
A company is expanding its threat surface program and inviting external security
researchers to test their internet-facing application in exchange for compensation. This
describes a:

A. Red team exercise
B. Bug bounty program
C. Penetration testing engagement
D. Vulnerability assessment

*Correct Answer: B. Bug bounty program. *

Rationale: A bug bounty program invites external security researchers to find and report
vulnerabilities in exchange for monetary compensation, effectively crowdsourcing security
testing .




Question 4
Which of the following is the correct final step of the incident response process?

A. Containment
B. Eradication
C. Recovery
D. Lessons learned

*Correct Answer: D. Lessons learned. *

Rationale: The incident response lifecycle includes detection, containment, eradication, and
recovery, but the final step is "lessons learned" where the organization reviews the incident
to improve future response .




Question 5
Which of the following provides the details about the terms and scope of a test with a
third-party penetration tester?

A. Rules of engagement
B. Supply chain analysis

,C. Right to audit clause
D. Due diligence

*Correct Answer: A. Rules of engagement. *

Rationale: Rules of engagement define the scope, boundaries, and specific terms of a
penetration test, including what systems can be tested, testing methods, and
communication protocols .




Question 6
An organization is using a VPN between its headquarters and a branch location. What
type of data is the VPN primarily protecting?

A. Data in use
B. Data in transit
C. Data at rest
D. Data sovereignty

*Correct Answer: B. Data in transit. *

Rationale: A VPN encrypts data as it travels across networks, protecting data in transit
(data moving between locations) from interception by unauthorized parties .




Question 7
Which of the following would be the most helpful in restoring data in the event of a
ransomware infection?

A. Load balancing
B. Geographic dispersion
C. Encryption
D. Backups

*Correct Answer: D. Backups. *

Rationale: Regular, tested backups are the most effective defense against ransomware,
allowing organizations to restore encrypted data without paying the ransom .

, Question 8
Which type of security control is an intrusion detection system (IDS)?

A. Deterrent control
B. Preventive control
C. Detective control
D. Corrective control

*Correct Answer: C. Detective control. *

Rationale: An IDS monitors network traffic for suspicious activity and alerts administrators,
making it a detective control. It detects threats after they occur rather than preventing
them .




Question 9
Which type of security control is an intrusion prevention system (IPS)?

A. Deterrent control
B. Preventive control
C. Detective control
D. Corrective control

*Correct Answer: B. Preventive control. *

Rationale: An IPS actively monitors and blocks malicious traffic, preventing attacks from
reaching their targets. Unlike an IDS, it takes action to stop threats .




Question 10
An attacker registers a domain name that is a common misspelling of a legitimate
banking website. This is known as:

A. Brand impersonation
B. Typosquatting

Document information

Uploaded on
August 10, 2026
Number of pages
125
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$33.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CornelWest
3.7
(250)
Sold
1580
Followers
1128
Items
12394
Last sold
2 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions