CompTIA Security+ 701 Practice Exams
Study online at https://quizlet.com/_eqj9sb
1. In a corporate office, employees are re- Physical control
quired to use their access cards to enter - The use of access cards to enter different sec-
different sections of the building. What tions of the building is an example of physical
type of control is being implemented in control, as it restricts and controls physical access
this scenario? to specific areas.
Detective control
Preventive control
Physical control
Corrective control
2. Detective controls Help to identify and respond to security inci-
dents after they have occurred.
- ex. security cameras
3. Preventive controls Aim to stop security incidents before they occur.
4. Corrective controls Implemented in response to identified security
incidents.
5. A financial institution implements en- Technical control
cryption for all sensitive data transmit- - Encryption is a technical control that involves
ted between its branches to ensure the use of technology to protect sensitive data
confidentiality. What type of control is during transmission, ensuring its confidentiality.
being applied here?
Technical control
Administrative control
Physical control
Operational control
6. Administrative controls involve policies, procedures, and training to
shape behavior.
, CompTIA Security+ 701 Practice Exams
Study online at https://quizlet.com/_eqj9sb
7. Physical controls Restrict access to physical areas and assets.
8. Operational control Focus on day-to-day processes and procedures
to ensure the security of information systems.
9. A company encrypts sensitive cus- Confidentiality
tomer data to prevent unauthorized ac- - Encrypting sensitive customer data helps main-
cess. What security principle does this tain confidentiality by protecting it from unau-
primarily address? thorized access.
Confidentiality
Integrity
Availability
Accountability
10. Integrity Ensures that data remains accurate and unal-
tered.
11. Availability Focuses on ensuring that resources are accessi-
ble when needed.
12. Accountability Is about tracking actions and identifying respon-
sible parties.
13. A system administrator implements Availability
regular backups to ensure that critical - Regular backups contribute to the ability of
data can be restored in the event of a critical data by ensuring it can be stores in case
hardware failure. Which security princi- of a hardware failure or data loss.
ple does this align with?
Confidentiality
Integrity
, CompTIA Security+ 701 Practice Exams
Study online at https://quizlet.com/_eqj9sb
Availability
Non-repudiation
14. Confidentiality Is about preventing unauthorized access to sen-
sitive information.
15. Non-repudiation Focuses on ensuring that a party cannot deny its
actions.
16. A security mechanism is implemented Integrity
to verify that data remains unchanged - Verifying data integrity ensures that it re-
during transmission over a network. mains unchanged during transmission, guard-
Which security principle is being em- ing against unauthorized alterations.
phasized?
Confidentiality
Integrity
Availability
Authentication
17. In a network environment, what AAA Accounting
component is responsible for tracking - Involves tracking user activities and resource
the activities of users and monitoring usage for the purpose of billing, auditing, and
resource usage? security monitoring.
Authentication
Authorization
Accounting
Auditing
18. Auditing Involves the analysis of logs and records to en-
sure compliance and detect security incidents.
19. Authorization
, CompTIA Security+ 701 Practice Exams
Study online at https://quizlet.com/_eqj9sb
Determines the user's access rights and permis-
sions after successful authentication.
20. Authentication Involves verifying the identity of a user.
21. In a multi-factor authentication system, One-time password
which of the following is an example of - Something you know refers to knowl-
something you know? edge-based factors, such as a password or PIN,
and a one-time password is an example of this.
Fingerprint scan
One-time password
Smart card
Retina scan
22. Something you are A biometric factor
- ex. fingerprint scan, retina scan
23. Something you have A possession-based factor
- ex. smart card
24. What is a common outcome of a gap Establishment of a remediation plan
analysis process in the context of cyber- - A common outcome of gap analysis is the iden-
security? tification of security gaps and the development
of a remediation plan to address these gaps.
A) Development of a risk management
plan Incorrect Answers Explanation:
B) Implementation of compensating A) While gap analysis contributes to risk assess-
controls ment, developing a risk management plan is a
C) Creation of a security policy broader process.
D) Establishment of a remediation plan B) Compensating controls may be part of the re-
mediation plan but are not the primary outcome
of a gap analysis.
C) A security policy may be reviewed during gap
Study online at https://quizlet.com/_eqj9sb
1. In a corporate office, employees are re- Physical control
quired to use their access cards to enter - The use of access cards to enter different sec-
different sections of the building. What tions of the building is an example of physical
type of control is being implemented in control, as it restricts and controls physical access
this scenario? to specific areas.
Detective control
Preventive control
Physical control
Corrective control
2. Detective controls Help to identify and respond to security inci-
dents after they have occurred.
- ex. security cameras
3. Preventive controls Aim to stop security incidents before they occur.
4. Corrective controls Implemented in response to identified security
incidents.
5. A financial institution implements en- Technical control
cryption for all sensitive data transmit- - Encryption is a technical control that involves
ted between its branches to ensure the use of technology to protect sensitive data
confidentiality. What type of control is during transmission, ensuring its confidentiality.
being applied here?
Technical control
Administrative control
Physical control
Operational control
6. Administrative controls involve policies, procedures, and training to
shape behavior.
, CompTIA Security+ 701 Practice Exams
Study online at https://quizlet.com/_eqj9sb
7. Physical controls Restrict access to physical areas and assets.
8. Operational control Focus on day-to-day processes and procedures
to ensure the security of information systems.
9. A company encrypts sensitive cus- Confidentiality
tomer data to prevent unauthorized ac- - Encrypting sensitive customer data helps main-
cess. What security principle does this tain confidentiality by protecting it from unau-
primarily address? thorized access.
Confidentiality
Integrity
Availability
Accountability
10. Integrity Ensures that data remains accurate and unal-
tered.
11. Availability Focuses on ensuring that resources are accessi-
ble when needed.
12. Accountability Is about tracking actions and identifying respon-
sible parties.
13. A system administrator implements Availability
regular backups to ensure that critical - Regular backups contribute to the ability of
data can be restored in the event of a critical data by ensuring it can be stores in case
hardware failure. Which security princi- of a hardware failure or data loss.
ple does this align with?
Confidentiality
Integrity
, CompTIA Security+ 701 Practice Exams
Study online at https://quizlet.com/_eqj9sb
Availability
Non-repudiation
14. Confidentiality Is about preventing unauthorized access to sen-
sitive information.
15. Non-repudiation Focuses on ensuring that a party cannot deny its
actions.
16. A security mechanism is implemented Integrity
to verify that data remains unchanged - Verifying data integrity ensures that it re-
during transmission over a network. mains unchanged during transmission, guard-
Which security principle is being em- ing against unauthorized alterations.
phasized?
Confidentiality
Integrity
Availability
Authentication
17. In a network environment, what AAA Accounting
component is responsible for tracking - Involves tracking user activities and resource
the activities of users and monitoring usage for the purpose of billing, auditing, and
resource usage? security monitoring.
Authentication
Authorization
Accounting
Auditing
18. Auditing Involves the analysis of logs and records to en-
sure compliance and detect security incidents.
19. Authorization
, CompTIA Security+ 701 Practice Exams
Study online at https://quizlet.com/_eqj9sb
Determines the user's access rights and permis-
sions after successful authentication.
20. Authentication Involves verifying the identity of a user.
21. In a multi-factor authentication system, One-time password
which of the following is an example of - Something you know refers to knowl-
something you know? edge-based factors, such as a password or PIN,
and a one-time password is an example of this.
Fingerprint scan
One-time password
Smart card
Retina scan
22. Something you are A biometric factor
- ex. fingerprint scan, retina scan
23. Something you have A possession-based factor
- ex. smart card
24. What is a common outcome of a gap Establishment of a remediation plan
analysis process in the context of cyber- - A common outcome of gap analysis is the iden-
security? tification of security gaps and the development
of a remediation plan to address these gaps.
A) Development of a risk management
plan Incorrect Answers Explanation:
B) Implementation of compensating A) While gap analysis contributes to risk assess-
controls ment, developing a risk management plan is a
C) Creation of a security policy broader process.
D) Establishment of a remediation plan B) Compensating controls may be part of the re-
mediation plan but are not the primary outcome
of a gap analysis.
C) A security policy may be reviewed during gap