COMPTIA SECURITY+ 701 STUDY GUIDE COMPLETE 2026-2027 EXAM
PAPER- REVISION QUESTIONS & SOLUTIONS
Which of the following standards provides information on privacy and managing PII?
The ISO (International Organization for Standardization) 27701 standard extends the ISO 27001
and 27002 standards to include detailed management of PII (Personally Identifiable
Information) and data privacy
CIA triad (Confidentiality, Integrity, Availability)
Elizabeth, a security administrator, is concerned about the potential for data exfiltration using
external storage drives. Which of the following would be the BEST way to prevent this method
of data exfiltration?
. Create an operating system security policy to prevent the use of removable media
An insurance company has created a set of policies to handle data breaches. The security team
has been given this set of requirements based on these policies: • Access records from all
devices must be saved and archived • Any data access outside of normal working hours must be
immediately reported • Data access must only occur inside of the country • Access logs and
audit reports must be created from a single database Which of the following should be
implemented by the security team to meet these requirements?
A. Restrict login access by IP address and GPS location, E. Consolidate all logs on a SIEM, and G.
Enable time-of-day restrictions on the authentication server
AAA Of Security
Authentication, Authorization, and Accounting
Checksums
Method to verify the integrity of data during transmission
Digital Signatures
Ensure Both Integrity of data during transaction
Server Redundancy
, Involves using multiple servers in a load balanced or failover configuration so that if one is
overloaded or fails, the other servers can take over the load to continue supporting your end
users
Network Redundancy
Ensures that if one network path fails, the data can travel through another route
data redundancy
involves storing data in multiple places
Power Redundancy
involves using backup power sources, like generators and ups systems
Non-repudiation
provides undeniable proof in the world of digital transactions. Cant deny participation or
authenticity of their actions
Syslog servers
used to aggregate logs from various network devices and systems so that system administrators
can analyze them to detect patterns or anomalies in the organizations systems
Technical Controls
"technology", hardware, and software mechanisms that are implemented to manage and
reduce risks
Managerial Controls
("Managing" things) also referred to administrative controls, involve the strategic planning and
governance side of security
Operational Controls
Procedures and measures that are designed to protect data on a day to day basis. Are mainly
governed by internal processes and human actions
Preventive
Proactive measures implemented to thwart potentical security threats or breaches
Deterrent Controls
Discourage potential attackers by making the effort seem less appealing or more challenging
PAPER- REVISION QUESTIONS & SOLUTIONS
Which of the following standards provides information on privacy and managing PII?
The ISO (International Organization for Standardization) 27701 standard extends the ISO 27001
and 27002 standards to include detailed management of PII (Personally Identifiable
Information) and data privacy
CIA triad (Confidentiality, Integrity, Availability)
Elizabeth, a security administrator, is concerned about the potential for data exfiltration using
external storage drives. Which of the following would be the BEST way to prevent this method
of data exfiltration?
. Create an operating system security policy to prevent the use of removable media
An insurance company has created a set of policies to handle data breaches. The security team
has been given this set of requirements based on these policies: • Access records from all
devices must be saved and archived • Any data access outside of normal working hours must be
immediately reported • Data access must only occur inside of the country • Access logs and
audit reports must be created from a single database Which of the following should be
implemented by the security team to meet these requirements?
A. Restrict login access by IP address and GPS location, E. Consolidate all logs on a SIEM, and G.
Enable time-of-day restrictions on the authentication server
AAA Of Security
Authentication, Authorization, and Accounting
Checksums
Method to verify the integrity of data during transmission
Digital Signatures
Ensure Both Integrity of data during transaction
Server Redundancy
, Involves using multiple servers in a load balanced or failover configuration so that if one is
overloaded or fails, the other servers can take over the load to continue supporting your end
users
Network Redundancy
Ensures that if one network path fails, the data can travel through another route
data redundancy
involves storing data in multiple places
Power Redundancy
involves using backup power sources, like generators and ups systems
Non-repudiation
provides undeniable proof in the world of digital transactions. Cant deny participation or
authenticity of their actions
Syslog servers
used to aggregate logs from various network devices and systems so that system administrators
can analyze them to detect patterns or anomalies in the organizations systems
Technical Controls
"technology", hardware, and software mechanisms that are implemented to manage and
reduce risks
Managerial Controls
("Managing" things) also referred to administrative controls, involve the strategic planning and
governance side of security
Operational Controls
Procedures and measures that are designed to protect data on a day to day basis. Are mainly
governed by internal processes and human actions
Preventive
Proactive measures implemented to thwart potentical security threats or breaches
Deterrent Controls
Discourage potential attackers by making the effort seem less appealing or more challenging