CompTIA Security+ SY0-701 Practice Exam | Comprehensive
Questions, Correct Answers & Detailed Explanations
2026/2027
Question 1
Which threat actor type is typically motivated by ideological beliefs,
political agendas, or social change rather than direct financial gain?
• A. Hacktivist
• B. Insider threat
• C. Organized crime syndicate
• D. Nation-state actor
Correct Answer: A. Hacktivist
Detailed Rationale: Hacktivists launch cyber attacks to promote political
agendas, social causes, or ideological beliefs, whereas organized crime
and cybercriminals are primarily driven by monetary gain.
Question 2
An organization discovers that a contractor has retained active
administrative privileges months after completing their project
assignment. Which security principle was violated?
• A. Least privilege and account lifecycle management
• B. Defense-in-depth
• C. Non-repudiation
, • D. Symmetric encryption
Correct Answer: A. Least privilege and account lifecycle management
Detailed Rationale: Failing to revoke access upon contract termination
violates both the principle of least privilege and proper account
deprecation and offboarding workflows.
Question 3
What type of physical security control is represented by motion-
activated floodlights installed around the perimeter of a corporate
campus during nighttime hours?
• A. Detective physical control
• B. Deterrent physical control
• C. Preventive technical control
• D. Corrective administrative control
Correct Answer: B. Deterrent physical control
Detailed Rationale: Bright security lighting deters potential intruders by
increasing the risk of visual detection before they attempt unauthorized
entry.
Question 4
Which framework element defines the maximum acceptable amount of
time that a business application can remain offline during a disaster
before causing catastrophic harm to the organization?
• A. Recovery Time Objective (RTO)
• B. Recovery Point Objective (RPO)
, • C. Single Loss Expectancy (SLE)
• D. Annualized Loss Expectancy (ALE)
Correct Answer: A. Recovery Time Objective (RTO)
Detailed Rationale: RTO specifies the target time window within which
business processes and IT systems must be restored following a
disruption.
Question 5
What risk response strategy is being implemented when an enterprise
purchases comprehensive cyber insurance to transfer the financial
impact of a potential data breach to a third party?
• A. Risk mitigation
• B. Risk avoidance
• C. Risk transference
• D. Risk acceptance
Correct Answer: C. Risk transference
Detailed Rationale: Cyber insurance transfers financial liability and risk
consequences to an external insurance carrier in exchange for premium
payments.
Question 6
An information security manager decides that the cost of implementing
specialized physical security controls for a remote, low-value storage
shed outweighs the potential financial loss of the assets inside. The
organization chooses to live with the risk. What risk strategy is this?
, • A. Risk acceptance
• B. Risk avoidance
• C. Risk mitigation
• D. Risk transference
Correct Answer: A. Risk acceptance
Detailed Rationale: Risk acceptance occurs when an organization
formally acknowledges a risk and decides that the cost of remediation
exceeds the potential impact.
Question 7
Which security assessment technique involves automated testing tools
scanning a target network or application to compile an inventory of
known vulnerabilities and misconfigurations?
• A. Penetration testing
• B. Vulnerability scanning
• C. Fuzzing
• D. Source code static analysis
Correct Answer: B. Vulnerability scanning
Detailed Rationale: Vulnerability scanners use signature and version
checks to automate the identification of known security weaknesses
without actively attempting destructive exploitation.
Question 8
What is the primary difference between quantitative and qualitative risk
assessments?
Questions, Correct Answers & Detailed Explanations
2026/2027
Question 1
Which threat actor type is typically motivated by ideological beliefs,
political agendas, or social change rather than direct financial gain?
• A. Hacktivist
• B. Insider threat
• C. Organized crime syndicate
• D. Nation-state actor
Correct Answer: A. Hacktivist
Detailed Rationale: Hacktivists launch cyber attacks to promote political
agendas, social causes, or ideological beliefs, whereas organized crime
and cybercriminals are primarily driven by monetary gain.
Question 2
An organization discovers that a contractor has retained active
administrative privileges months after completing their project
assignment. Which security principle was violated?
• A. Least privilege and account lifecycle management
• B. Defense-in-depth
• C. Non-repudiation
, • D. Symmetric encryption
Correct Answer: A. Least privilege and account lifecycle management
Detailed Rationale: Failing to revoke access upon contract termination
violates both the principle of least privilege and proper account
deprecation and offboarding workflows.
Question 3
What type of physical security control is represented by motion-
activated floodlights installed around the perimeter of a corporate
campus during nighttime hours?
• A. Detective physical control
• B. Deterrent physical control
• C. Preventive technical control
• D. Corrective administrative control
Correct Answer: B. Deterrent physical control
Detailed Rationale: Bright security lighting deters potential intruders by
increasing the risk of visual detection before they attempt unauthorized
entry.
Question 4
Which framework element defines the maximum acceptable amount of
time that a business application can remain offline during a disaster
before causing catastrophic harm to the organization?
• A. Recovery Time Objective (RTO)
• B. Recovery Point Objective (RPO)
, • C. Single Loss Expectancy (SLE)
• D. Annualized Loss Expectancy (ALE)
Correct Answer: A. Recovery Time Objective (RTO)
Detailed Rationale: RTO specifies the target time window within which
business processes and IT systems must be restored following a
disruption.
Question 5
What risk response strategy is being implemented when an enterprise
purchases comprehensive cyber insurance to transfer the financial
impact of a potential data breach to a third party?
• A. Risk mitigation
• B. Risk avoidance
• C. Risk transference
• D. Risk acceptance
Correct Answer: C. Risk transference
Detailed Rationale: Cyber insurance transfers financial liability and risk
consequences to an external insurance carrier in exchange for premium
payments.
Question 6
An information security manager decides that the cost of implementing
specialized physical security controls for a remote, low-value storage
shed outweighs the potential financial loss of the assets inside. The
organization chooses to live with the risk. What risk strategy is this?
, • A. Risk acceptance
• B. Risk avoidance
• C. Risk mitigation
• D. Risk transference
Correct Answer: A. Risk acceptance
Detailed Rationale: Risk acceptance occurs when an organization
formally acknowledges a risk and decides that the cost of remediation
exceeds the potential impact.
Question 7
Which security assessment technique involves automated testing tools
scanning a target network or application to compile an inventory of
known vulnerabilities and misconfigurations?
• A. Penetration testing
• B. Vulnerability scanning
• C. Fuzzing
• D. Source code static analysis
Correct Answer: B. Vulnerability scanning
Detailed Rationale: Vulnerability scanners use signature and version
checks to automate the identification of known security weaknesses
without actively attempting destructive exploitation.
Question 8
What is the primary difference between quantitative and qualitative risk
assessments?