COMPTIA SECURITY+ SY0-701
CERTIFICATION EXAM TEST BANK WITH
ACTUAL CORRECT QUESTIONS AND
VERIFIED DETAILED ANSWERS| CURRENTLY
TESTING VERSION | ALREADY GRADED
A+|NEWEST |2026-2027
In a recent high-profile cybersecurity incident, attackers targeted a multinational
corporation's executive team with personalized emails, tricking them into revealing
sensitive company data and financial information. What type of attack is this scenario
describing?
Ransomware attack
Whaling attack
Spear-phishing attack
DDoS attack
Whaling attack
- Where high-ranking individuals within an organization are targeted with
personalized emails to deceive them into revealing sensitive information.
Spear-phishing Attack
Targets specific individuals or organizations typically through malicious emails.
DDoS Attack (Disrupted Denial of Service)
Occurs when multiple systems flood the bandwidth or resources of a targeted system,
usually one or more web servers.
- Aims to disrupt services by overwhelming them with traffic
A security researcher discovered that a popular social media website had been
compromised by attackers. The attackers had injected malicious code into the site,
1|Page
,which infected the devices of users who visited the compromised pages. What type of
attack is this scenario describing?
Ransomware attack
Watering hole attack
Typosquatting attack
Spear-phishing attack
Watering hole attack
- Where attackers compromise a legitimate website that their intended victims
frequently visit, infecting visitors' devices with malware.
A cybercriminal registers domain names that are similar to well-known banking
websites but contain minor typographical errors. Users who mistype the URLs may be
redirected to these fraudulent sites, leading to potential credential theft. What kind of
attack is being depicted in this scenario?
Man-in-the-middle (MitM) attack
Typosquatting attack
Phishing attack
Watering hole attack
Typosquatting attack
- Where domain names with minor typographical errors are registered to deceive
users into visiting fraudulent websites.
An attacker goes through the company's trash bins, searching for discarded documents,
invoices, and other materials that might contain sensitive information. What kind of
physical security threat does this scenario illustrate?
Dumpster diving
Social engineering attack
Shoulder surfing
Physical intrusion
2|Page
,Dumpster diving
- Where an attacker searches through trash or discarded materials to obtain
sensitive information.
A company's security team discovered that a group of hackers had been scanning the
organization's network and systems, attempting to find vulnerabilities that could be
exploited. This prelude to an attack is a classic example of which cybersecurity activity?
Intrusion detection
Dumpster diving
Reconnaissance
Encryption
Reconnaissance
- Where attackers gather information about potential targets and vulnerabilities to
prepare for an attack.
Intrusion detection
Involves identifying and responding to unauthorized access or malicious activities after
an attack has started.
Which attack aims to manipulate a website to redirect users to a fraudulent site that
appears legitimate to steal their information?
SQL injection
Cross-Site Scripting (XSS)
DNS spoofing
URL hijacking
DNS Spoofing
- Manipulates the DNS records to redirect users to a fraudulent site, typically
appearing legitimate, intending to steal their information.
SQL Injection
Involves manipulating databases.
3|Page
, Cross-Site Scripting (XSS)
Involves injecting malicious scripts into a website.
Which type of attack involves the modification or interception of communication
between two parties without their knowledge?
Man-in-the-Middle (MitM)
Buffer overflow
Spoofing
Zero-day exploit
Man-in-the-Middle (MitM)
- MitM attacks intercept and manipulate communications between two parties
without their awareness, allowing attackers to eavesdrop or modify data.
Which attack involves falsifying the origin of an email to make it appear as though it's
from a trusted source?
Smurf attack
Phishing
Spoofing
Zero-day exploit
Spoofing
- Spoofing involves altering information to appear as if it comes from a legitimate
source, commonly seen in email addresses to deceive recipients.
What is the primary aim of a SQL injection attack?
Disrupting network connections
Altering DNS records
Gaining unauthorized access to a database
Executing ransomware
4|Page
CERTIFICATION EXAM TEST BANK WITH
ACTUAL CORRECT QUESTIONS AND
VERIFIED DETAILED ANSWERS| CURRENTLY
TESTING VERSION | ALREADY GRADED
A+|NEWEST |2026-2027
In a recent high-profile cybersecurity incident, attackers targeted a multinational
corporation's executive team with personalized emails, tricking them into revealing
sensitive company data and financial information. What type of attack is this scenario
describing?
Ransomware attack
Whaling attack
Spear-phishing attack
DDoS attack
Whaling attack
- Where high-ranking individuals within an organization are targeted with
personalized emails to deceive them into revealing sensitive information.
Spear-phishing Attack
Targets specific individuals or organizations typically through malicious emails.
DDoS Attack (Disrupted Denial of Service)
Occurs when multiple systems flood the bandwidth or resources of a targeted system,
usually one or more web servers.
- Aims to disrupt services by overwhelming them with traffic
A security researcher discovered that a popular social media website had been
compromised by attackers. The attackers had injected malicious code into the site,
1|Page
,which infected the devices of users who visited the compromised pages. What type of
attack is this scenario describing?
Ransomware attack
Watering hole attack
Typosquatting attack
Spear-phishing attack
Watering hole attack
- Where attackers compromise a legitimate website that their intended victims
frequently visit, infecting visitors' devices with malware.
A cybercriminal registers domain names that are similar to well-known banking
websites but contain minor typographical errors. Users who mistype the URLs may be
redirected to these fraudulent sites, leading to potential credential theft. What kind of
attack is being depicted in this scenario?
Man-in-the-middle (MitM) attack
Typosquatting attack
Phishing attack
Watering hole attack
Typosquatting attack
- Where domain names with minor typographical errors are registered to deceive
users into visiting fraudulent websites.
An attacker goes through the company's trash bins, searching for discarded documents,
invoices, and other materials that might contain sensitive information. What kind of
physical security threat does this scenario illustrate?
Dumpster diving
Social engineering attack
Shoulder surfing
Physical intrusion
2|Page
,Dumpster diving
- Where an attacker searches through trash or discarded materials to obtain
sensitive information.
A company's security team discovered that a group of hackers had been scanning the
organization's network and systems, attempting to find vulnerabilities that could be
exploited. This prelude to an attack is a classic example of which cybersecurity activity?
Intrusion detection
Dumpster diving
Reconnaissance
Encryption
Reconnaissance
- Where attackers gather information about potential targets and vulnerabilities to
prepare for an attack.
Intrusion detection
Involves identifying and responding to unauthorized access or malicious activities after
an attack has started.
Which attack aims to manipulate a website to redirect users to a fraudulent site that
appears legitimate to steal their information?
SQL injection
Cross-Site Scripting (XSS)
DNS spoofing
URL hijacking
DNS Spoofing
- Manipulates the DNS records to redirect users to a fraudulent site, typically
appearing legitimate, intending to steal their information.
SQL Injection
Involves manipulating databases.
3|Page
, Cross-Site Scripting (XSS)
Involves injecting malicious scripts into a website.
Which type of attack involves the modification or interception of communication
between two parties without their knowledge?
Man-in-the-Middle (MitM)
Buffer overflow
Spoofing
Zero-day exploit
Man-in-the-Middle (MitM)
- MitM attacks intercept and manipulate communications between two parties
without their awareness, allowing attackers to eavesdrop or modify data.
Which attack involves falsifying the origin of an email to make it appear as though it's
from a trusted source?
Smurf attack
Phishing
Spoofing
Zero-day exploit
Spoofing
- Spoofing involves altering information to appear as if it comes from a legitimate
source, commonly seen in email addresses to deceive recipients.
What is the primary aim of a SQL injection attack?
Disrupting network connections
Altering DNS records
Gaining unauthorized access to a database
Executing ransomware
4|Page