Prep Test Bank – ideal review test bank with real
exam questions and correct answers / CompTIA
Security+ SY0-701 Certification Latest Exam
Prep Test Bank *2026-2027*
In a recent high-profile cybersecurity incident, attackers targeted a multinational
corporation's executive team with personalized emails, tricking them into revealing
sensitive company data and financial information. What type of attack is this
scenario describing?
Ransomware attack
Whaling attack
Spear-phishing attack
DDoS attack
Whaling attack
- Where high-ranking individuals within an organization are targeted with
personalized emails to deceive them into revealing sensitive information.
At a business conference, an attendee discovers their Bluetooth-enabled device has
received unsolicited business card data from an unknown source. What kind of
wireless attack might this scenario indicate?
Bluejacking attack
Man-in-the-middle attack
Wardriving attack
Bluesnarfing attack
1
,Bluejacking attack
- This scenario indicates a Bluejacking attack, where unsolicited messages or
business card data is sent to Bluetooth-enabled devices without the users' consent.
In a public library, a hacker placed a device to capture wireless network traffic,
allowing them to collect login credentials and personal information from users
connecting to the library's public Wi-Fi. What kind of wireless attack does this
scenario represent?
Packet sniffing attack
Evil twin attack
Rogue access point attack
Wardriving attack
Packet sniffing attack
- Where a device captures and analyzes wireless network traffic, enabling the theft
of sensitive user information.
Wardriving
The act of searching for Wi-Fi networks while driving.
A small business recently conducted a vulnerability scan on its network and found
multiple weaknesses in its web server, leaving it susceptible to SQL injection
attacks. What should be the immediate response to address these vulnerabilities?
A) Consider upgrading the network infrastructure to mitigate the vulnerabilities.
B) Perform another vulnerability scan to verify the findings and their severity.
C) Implement security measures or patches to fix the SQL injection vulnerabilities.
D) Ignore the vulnerabilities as they may not pose an immediate threat.
Implement security measures or patches to fix the SQL injection vulnerabilities.
- Upon discovering SQL injection vulnerabilities in the web server, the immediate
response should involve implementing security measures or patches to fix these
vulnerabilities and enhance security.
During a network security assessment, the scanning tool flags an outdated software
version as a high-severity risk. After manual investigation, it's revealed that the
software's vulnerability has been patched. What type of detection is this likely to
be?
2
,False positive
False negative
True positive
True negative
False positive
- The scanning tool misidentifies the patched vulnerability as a high-severity risk,
indicating a false positive.
Incorrect answer explanations:
B) A false negative would involve missing an actual vulnerability, not an already
patched one.
C) True positive indicates correctly identifying an actual vulnerability.
D) True negative denotes accurately identifying the absence of a vulnerability.
A user downloads and installs what appears to be a legitimate software application,
but it contains hidden malicious code that compromises the security of the user's
system. What type of malicious software does this scenario describe?
Worm
Trojan
Spyware
Ransomware
Trojan
- A type of malicious software disguised as a legitimate program but containing
hidden malicious functionality.
A piece of malicious software spreads across a network by exploiting
vulnerabilities in software and making copies of itself on other devices. What type
of malicious software does this scenario describe?
Trojan
Worm
Spyware
Adware
3
, Worm
- A type of self-replicating malware that spreads across networks without user
intervention.
A user unknowingly installs software on their computer that secretly monitors their
online activities, records keystrokes, and sends this information to a remote server.
What type of malicious software does this scenario describe?
Worm
Trojan
Spyware
Ransomware
Spyware
- Designed to gather and transmit user information without the user's knowledge.
Why is it important to regularly review and update secure baselines in response to
evolving cybersecurity threats?
To increase system performance
To satisfy regulatory compliance
To adapt to changing threat landscapes
To reduce the need for security training
To adapt to changing threat landscapes
- Regularly reviewing and updating secure baselines allows organizations to adapt
to new and evolving cybersecurity threats. This proactive approach helps ensure
that systems remain resilient against emerging risks.
How can secure baselines facilitate a rapid and consistent response across multiple
systems?
A) By disabling all network connections
B) By restoring systems from a previous backup
C) By providing a predefined security configuration
D) By updating antivirus software on all systems
By providing a predefined security configuration
- Secure baselines offer predefined security configurations. In response to a
4