COMPTIA SECURITY+ 701 PRACTICE COMPLETE 2026-2027 EXAM
PAPER- REVISION QUESTIONS & SOLUTIONS
Cross-site scripting (XSS) attack
Target web applications
A company's web application was recently compromised, and customer data was stolen. The
company's cybersecurity team discovers that the attackers exploited a vulnerability in the
application's code to gain unauthorized access. What type of attack is this?
SQL injection attack
Man-in-the-middle attack
Cross-site scripting (XSS) attack
Zero-day vulnerability
SQL injection attack
- The scenario describes an SQL injection attack, where attackers exploit vulnerabilities in web
application code to gain unauthorized access to a database.
An organization's website has been receiving an unusually high volume of web traffic, which has
made the site unresponsive. The traffic appears to be coming from various sources and seems
to be overloading the server. What type of attack is this scenario indicating?
Phishing attack
Man-in-the-middle attack
Denial of Service (DoS) attack
Ransomware attack
Denial of Service (DoS) attack
- The scenario describes a Denial of Service (DoS) attack, where attackers flood a server or
network with excessive traffic to make services unavailable to legitimate users.
What is the primary purpose of a Denial of Service (DoS) attack?
A) To steal sensitive data from a network.
B) To gain unauthorized access to a system.
C) To disrupt or make a service unavailable to its users.
D) To intercept and eavesdrop on network communications.
,To disrupt or make a service unavailable to its users.
- A Denial of Service (DoS) attack aims to overwhelm a system or network, rendering its services
unavailable to legitimate users by flooding it with excessive traffic or other disruptive actions.
An employee has lost their company-issued smartphone, and it contained sensitive corporate
data. What kind of threat does this scenario illustrate?
Phishing attack
Insider threat
Physical security breach
Ransomware attack
Physical security breach
- The scenario illustrates a physical security breach where the loss of a device (in this case, a
smartphone) leads to the potential exposure of sensitive data.
A network administrator has implemented a firewall rule that allows only specific incoming
traffic from trusted IP addresses and denies all other incoming traffic. What security principle
does this rule exemplify?
Principle of least privilege
Defense in depth
Zero trust
Security by design
Principle of least privilege
- The firewall rule aligns with the principle of least privilege, where access is restricted to only
what is necessary for users or systems to perform their functions.
Defense in depth
Involves multiple layers of security controls
Security by design
Incorporating security from the beginning of system development.
Which attack involves a flood of connection requests with falsified IP addresses to overwhelm a
server?
SYN Flood
DDoS Attack
,Man-in-the-Middle (MitM)
DNS Spoofing
SYN Flood
- Overwhelms a server with connection requests using falsified or spoofed IP addresses,
consuming resources and rendering the server unavailable.
DNS Spoofing
Manipulates DNS records to redirect users.
A company is conducting a security audit and penetration testing on its network to identify and
rectify vulnerabilities before malicious actors can exploit them. What security practice is this
organization following?
Incident response
Security assessment
Security awareness training
Least privilege
Security assessment
- The organization is conducting a security assessment, specifically penetration testing, to
identify and rectify vulnerabilities in its network.
Incident reponse
The process of managing and mitigating security incidents.
Principle of Least Privilege
Providing minimum necessary access to perform tasks.
An organization has set up a dedicated network segment for guest wireless access, which is
isolated from its internal network. What security principle does this network segmentation align
with?
Principle of least privilege
Defense in depth
Network segmentation
Security by design
Network segmentation
- Network segmentation is the practice of dividing a network into isolated segments to enhance
security by controlling access and limiting the potential for lateral movement by attackers.
, An organization is setting up a disaster recovery site in a geographically distant location from its
primary data center. What type of disaster recovery strategy is this?
High availability
Cold site
Hot site
Warm site
Hot site
- A hot site is a disaster recovery strategy where a fully operational data center is set up in a
geographically distant location, ready to take over in case of a disaster. It offers the highest level
of availability.
High availability
About minimizing downtown for critical systems.
Cold Site
A facility with power and HVAC but lacks active equipment
Warm Site
A facility with some pre-configured equipment but not fully operational.
An attacker calls an employee, pretending to be a colleague from another department, and
requests sensitive information to complete a report. What type of social engineering technique
is this?
Impersonation
Tailgating
Phishing
Vishing
Impersonation
- Impersonation involves pretending to be someone the target knows and trusts to manipulate
them into disclosing sensitive information.
An attacker poses as a delivery person, carrying a package for a company, and convinces an
employee to let them into the building. Once inside, the attacker gains unauthorized access to
the company's network. What type of social engineering technique is this?
Tailgating
PAPER- REVISION QUESTIONS & SOLUTIONS
Cross-site scripting (XSS) attack
Target web applications
A company's web application was recently compromised, and customer data was stolen. The
company's cybersecurity team discovers that the attackers exploited a vulnerability in the
application's code to gain unauthorized access. What type of attack is this?
SQL injection attack
Man-in-the-middle attack
Cross-site scripting (XSS) attack
Zero-day vulnerability
SQL injection attack
- The scenario describes an SQL injection attack, where attackers exploit vulnerabilities in web
application code to gain unauthorized access to a database.
An organization's website has been receiving an unusually high volume of web traffic, which has
made the site unresponsive. The traffic appears to be coming from various sources and seems
to be overloading the server. What type of attack is this scenario indicating?
Phishing attack
Man-in-the-middle attack
Denial of Service (DoS) attack
Ransomware attack
Denial of Service (DoS) attack
- The scenario describes a Denial of Service (DoS) attack, where attackers flood a server or
network with excessive traffic to make services unavailable to legitimate users.
What is the primary purpose of a Denial of Service (DoS) attack?
A) To steal sensitive data from a network.
B) To gain unauthorized access to a system.
C) To disrupt or make a service unavailable to its users.
D) To intercept and eavesdrop on network communications.
,To disrupt or make a service unavailable to its users.
- A Denial of Service (DoS) attack aims to overwhelm a system or network, rendering its services
unavailable to legitimate users by flooding it with excessive traffic or other disruptive actions.
An employee has lost their company-issued smartphone, and it contained sensitive corporate
data. What kind of threat does this scenario illustrate?
Phishing attack
Insider threat
Physical security breach
Ransomware attack
Physical security breach
- The scenario illustrates a physical security breach where the loss of a device (in this case, a
smartphone) leads to the potential exposure of sensitive data.
A network administrator has implemented a firewall rule that allows only specific incoming
traffic from trusted IP addresses and denies all other incoming traffic. What security principle
does this rule exemplify?
Principle of least privilege
Defense in depth
Zero trust
Security by design
Principle of least privilege
- The firewall rule aligns with the principle of least privilege, where access is restricted to only
what is necessary for users or systems to perform their functions.
Defense in depth
Involves multiple layers of security controls
Security by design
Incorporating security from the beginning of system development.
Which attack involves a flood of connection requests with falsified IP addresses to overwhelm a
server?
SYN Flood
DDoS Attack
,Man-in-the-Middle (MitM)
DNS Spoofing
SYN Flood
- Overwhelms a server with connection requests using falsified or spoofed IP addresses,
consuming resources and rendering the server unavailable.
DNS Spoofing
Manipulates DNS records to redirect users.
A company is conducting a security audit and penetration testing on its network to identify and
rectify vulnerabilities before malicious actors can exploit them. What security practice is this
organization following?
Incident response
Security assessment
Security awareness training
Least privilege
Security assessment
- The organization is conducting a security assessment, specifically penetration testing, to
identify and rectify vulnerabilities in its network.
Incident reponse
The process of managing and mitigating security incidents.
Principle of Least Privilege
Providing minimum necessary access to perform tasks.
An organization has set up a dedicated network segment for guest wireless access, which is
isolated from its internal network. What security principle does this network segmentation align
with?
Principle of least privilege
Defense in depth
Network segmentation
Security by design
Network segmentation
- Network segmentation is the practice of dividing a network into isolated segments to enhance
security by controlling access and limiting the potential for lateral movement by attackers.
, An organization is setting up a disaster recovery site in a geographically distant location from its
primary data center. What type of disaster recovery strategy is this?
High availability
Cold site
Hot site
Warm site
Hot site
- A hot site is a disaster recovery strategy where a fully operational data center is set up in a
geographically distant location, ready to take over in case of a disaster. It offers the highest level
of availability.
High availability
About minimizing downtown for critical systems.
Cold Site
A facility with power and HVAC but lacks active equipment
Warm Site
A facility with some pre-configured equipment but not fully operational.
An attacker calls an employee, pretending to be a colleague from another department, and
requests sensitive information to complete a report. What type of social engineering technique
is this?
Impersonation
Tailgating
Phishing
Vishing
Impersonation
- Impersonation involves pretending to be someone the target knows and trusts to manipulate
them into disclosing sensitive information.
An attacker poses as a delivery person, carrying a package for a company, and convinces an
employee to let them into the building. Once inside, the attacker gains unauthorized access to
the company's network. What type of social engineering technique is this?
Tailgating