CompTIA Security+ SY0-701 Certification Exam | Complete
Practice Questions, Answers & Detailed Rationales
(2026/2027)
Question 1
Which type of security control is represented by a security guard posted
at the entrance of a corporate data center to verify employee
identification badges?
• A. Preventive physical control
• B. Detective technical control
• C. Corrective managerial control
• D. Deterrent administrative control
Correct Answer: A. Preventive physical control
Detailed Rationale: A security guard physically stationed at an entry
point actively prevents unauthorized access before it occurs, making it a
preventive physical control. Detective controls identify incidents after
they start, and corrective controls mitigate damage after an event.
Question 2
An organization implements security policies requiring dual
authorization and strict separation of duties to ensure that no single
individual has complete control over critical financial transactions.
Which core pillar of the CIA triad is primarily reinforced by these
measures?
• A. Confidentiality
, • B. Integrity
• C. Availability
• D. Non-repudiation
Correct Answer: B. Integrity
Detailed Rationale: Separation of duties and dual authorization ensure
that data and transactions are accurate, authorized, and free from
unauthorized or malicious alteration, thereby preserving data integrity.
Question 3
Which cryptographic concept ensures that a sender cannot successfully
deny having sent a message, and a receiver cannot deny having
received it?
• A. Hashing
• B. Salting
• C. Non-repudiation
• D. Tokenization
Correct Answer: C. Non-repudiation
Detailed Rationale: Non-repudiation uses digital signatures and
asymmetric cryptography to provide undeniable proof of data origin
and delivery, preventing either party from falsely denying the
transaction.
Question 4
In the AAA framework for identity and access management, what
function is performed when an enterprise RADIUS server reviews an
,authenticated user's profile to determine what directory folders and
network shares they are permitted to access?
• A. Authentication
• B. Accounting
• C. Auditing
• D. Authorization
Correct Answer: D. Authorization
Detailed Rationale: Authorization follows authentication and
determines what resources a verified subject is allowed to access or
modify based on access control lists and permissions.
Question 5
What is the primary architectural philosophy behind a Zero Trust
security model?
• A. Trust network devices that reside within the internal corporate
local area network perimeter.
• B. Never trust, always verify every user, device, and application
request regardless of their location.
• C. Rely entirely on perimeter firewalls to block external malicious
traffic while leaving internal traffic unmonitored.
• D. Assume all applications hosted in public cloud infrastructure are
inherently secure.
Correct Answer: B. Never trust, always verify every user, device, and
application request regardless of their location.
, Detailed Rationale: Zero Trust eliminates the concept of an implicit
trusted network perimeter, requiring continuous authentication,
authorization, and validation of every access request.
Question 6
During a formal change management review, an administrator submits
an implementation plan that includes a step-by-step procedure to
revert changes back to the original operational state if the software
patch fails during installation. What is this crucial element called?
• A. Risk acceptance document
• B. Backout plan
• C. Allow list
• D. Service level agreement
Correct Answer: B. Backout plan
Detailed Rationale: A backout (or rollback) plan provides a
documented, tested sequence of actions to restore systems to their
previous stable baseline if a change or patch causes unexpected
downtime or failure.
Question 7
Which cryptographic tool is specifically designed to provide secure
hardware-based generation and storage of cryptographic keys,
protecting them from software-based extraction or compromise?
• A. Certificate Revocation List (CRL)
• B. Trusted Platform Module (TPM)
• C. Online Certificate Status Protocol (OCSP)
Practice Questions, Answers & Detailed Rationales
(2026/2027)
Question 1
Which type of security control is represented by a security guard posted
at the entrance of a corporate data center to verify employee
identification badges?
• A. Preventive physical control
• B. Detective technical control
• C. Corrective managerial control
• D. Deterrent administrative control
Correct Answer: A. Preventive physical control
Detailed Rationale: A security guard physically stationed at an entry
point actively prevents unauthorized access before it occurs, making it a
preventive physical control. Detective controls identify incidents after
they start, and corrective controls mitigate damage after an event.
Question 2
An organization implements security policies requiring dual
authorization and strict separation of duties to ensure that no single
individual has complete control over critical financial transactions.
Which core pillar of the CIA triad is primarily reinforced by these
measures?
• A. Confidentiality
, • B. Integrity
• C. Availability
• D. Non-repudiation
Correct Answer: B. Integrity
Detailed Rationale: Separation of duties and dual authorization ensure
that data and transactions are accurate, authorized, and free from
unauthorized or malicious alteration, thereby preserving data integrity.
Question 3
Which cryptographic concept ensures that a sender cannot successfully
deny having sent a message, and a receiver cannot deny having
received it?
• A. Hashing
• B. Salting
• C. Non-repudiation
• D. Tokenization
Correct Answer: C. Non-repudiation
Detailed Rationale: Non-repudiation uses digital signatures and
asymmetric cryptography to provide undeniable proof of data origin
and delivery, preventing either party from falsely denying the
transaction.
Question 4
In the AAA framework for identity and access management, what
function is performed when an enterprise RADIUS server reviews an
,authenticated user's profile to determine what directory folders and
network shares they are permitted to access?
• A. Authentication
• B. Accounting
• C. Auditing
• D. Authorization
Correct Answer: D. Authorization
Detailed Rationale: Authorization follows authentication and
determines what resources a verified subject is allowed to access or
modify based on access control lists and permissions.
Question 5
What is the primary architectural philosophy behind a Zero Trust
security model?
• A. Trust network devices that reside within the internal corporate
local area network perimeter.
• B. Never trust, always verify every user, device, and application
request regardless of their location.
• C. Rely entirely on perimeter firewalls to block external malicious
traffic while leaving internal traffic unmonitored.
• D. Assume all applications hosted in public cloud infrastructure are
inherently secure.
Correct Answer: B. Never trust, always verify every user, device, and
application request regardless of their location.
, Detailed Rationale: Zero Trust eliminates the concept of an implicit
trusted network perimeter, requiring continuous authentication,
authorization, and validation of every access request.
Question 6
During a formal change management review, an administrator submits
an implementation plan that includes a step-by-step procedure to
revert changes back to the original operational state if the software
patch fails during installation. What is this crucial element called?
• A. Risk acceptance document
• B. Backout plan
• C. Allow list
• D. Service level agreement
Correct Answer: B. Backout plan
Detailed Rationale: A backout (or rollback) plan provides a
documented, tested sequence of actions to restore systems to their
previous stable baseline if a change or patch causes unexpected
downtime or failure.
Question 7
Which cryptographic tool is specifically designed to provide secure
hardware-based generation and storage of cryptographic keys,
protecting them from software-based extraction or compromise?
• A. Certificate Revocation List (CRL)
• B. Trusted Platform Module (TPM)
• C. Online Certificate Status Protocol (OCSP)