COMPTIA SECURITY+ SY0-701 COMPLETE 2026-2027 EXAM PAPER-
REVISION QUESTIONS & SOLUTIONS
Tailgating
When an unauthorized person follows you into a secure area WITHOUT your knowledge.
Input sanitization
The most basic practice a programmer can use to protect a web app from injection attacks.
Buffer overflow
A type of attack in which malware overwrites memory addresses with its own code.
' or 1=1--
The most basic SQL injection statement.
Sideloading
The act of installing software outside of approved channels.
Cross-site Request Forgery
A web app attack that abuses a server's trust in an already authenticated client.
Password spraying
The act of trying the same password against multiple user accounts.
Credential stuffing
The act of trying the same username and password combination against multiple websites.
Container
A lightweight "virtual machine" for a single application.
Air-gapping
The most secure way to separate a sensitive system from the rest of the network.
Fail Open
A system failure mode meant to protect human life.
False Positive
A condition where an IDS reports a false alarm.
, False Negative
A condition where an IDS fails to report an actual security incident.
Data at rest
The data state when the data resides on removable media.
Jump Server
A secure computer that an external user must first connect to, in order to then connect to the
private network.
Tabletop walkthrough
The simplest, quickest way for a team to review a disaster recovery plan.
Data masking
A common way to secure credit card data in which only the last four digits are seen.
hashing
The use of a cryptographic algorithm to produce a fixed-length output that can be used to verify
data integrity.
CVSS
The scoring system used to quantitatively measure the criticality of a vulnerability.
6514
The secure syslog port
139, 445
The two SMB ports.
IDS
A system that monitors the network for known signature-based attacks.
IPS
A security system that can stop network traffic from zero day attacks.
DLP
A system that can monitor and control the movement of data on your network.
Least privilege
REVISION QUESTIONS & SOLUTIONS
Tailgating
When an unauthorized person follows you into a secure area WITHOUT your knowledge.
Input sanitization
The most basic practice a programmer can use to protect a web app from injection attacks.
Buffer overflow
A type of attack in which malware overwrites memory addresses with its own code.
' or 1=1--
The most basic SQL injection statement.
Sideloading
The act of installing software outside of approved channels.
Cross-site Request Forgery
A web app attack that abuses a server's trust in an already authenticated client.
Password spraying
The act of trying the same password against multiple user accounts.
Credential stuffing
The act of trying the same username and password combination against multiple websites.
Container
A lightweight "virtual machine" for a single application.
Air-gapping
The most secure way to separate a sensitive system from the rest of the network.
Fail Open
A system failure mode meant to protect human life.
False Positive
A condition where an IDS reports a false alarm.
, False Negative
A condition where an IDS fails to report an actual security incident.
Data at rest
The data state when the data resides on removable media.
Jump Server
A secure computer that an external user must first connect to, in order to then connect to the
private network.
Tabletop walkthrough
The simplest, quickest way for a team to review a disaster recovery plan.
Data masking
A common way to secure credit card data in which only the last four digits are seen.
hashing
The use of a cryptographic algorithm to produce a fixed-length output that can be used to verify
data integrity.
CVSS
The scoring system used to quantitatively measure the criticality of a vulnerability.
6514
The secure syslog port
139, 445
The two SMB ports.
IDS
A system that monitors the network for known signature-based attacks.
IPS
A security system that can stop network traffic from zero day attacks.
DLP
A system that can monitor and control the movement of data on your network.
Least privilege