• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 39 pages
Exam (elaborations)

SY0-701 CompTIA Security+ (SY0-701) Ultimate Exam Prep – Complete Network Security & Cryptography Exam Prep, Practice Questions & Rationales

Document preview thumbnail
Preview 4 out of 39 pages

Prepare for the CompTIA Security+ SY0-701 certification exam with a comprehensive exam-prep resource covering essential cybersecurity concepts, network security, cryptography, threat detection, risk management, and security operations. Reinforce your understanding through practice questions, answers, and detailed rationales designed to support focused review of key Security+ exam domains. What’s Included: CompTIA Security+ SY0-701 certification exam review Practice questions with answers and detailed rationales Network security, architecture, and secure system design Cryptography, identity management, and access controls Threat detection, incident response, risk management, and security operations Use this resource alongside official CompTIA objectives and study materials to strengthen your cybersecurity knowledge and prepare for the SY0-701 certification exam.

Content preview

SY0-701: CompTIA Security+ (SY0-701) Ultimate Exam
Prep – Complete Network Security & Cryptography Study
Course Code: SY0-701
Name: CompTIA Security+ (SY0-701) Ultimate Exam Prep
Topic: Complete Network Security & Cryptography Study
Academic Year: 2026/2027




1. An infrastructure engineer is hardening a corporate web server to enforce
TLS 1.3. Which cryptographic improvement or feature represents a
fundamental security update in TLS 1.3 over legacy TLS 1.2 configurations?
A. Mandatory usage of static RSA key exchanges to streamline token
distribution.
B. Complete deprecation of static RSA and custom Diffie-Hellman
handshakes to enforce forward secrecy.
C. Integration of MD5-based message authentication codes for lower

, computing overhead.
D. Exclusive fallback support for SSL 3.0 backward compatibility.
CORRECT ANSWER: B
RATIONALE: TLS 1.3 completely removes support for static RSA key
exchange algorithms. By doing so, it mandates that all key exchanges must
use ephemeral mechanisms (like ECDHE or DHE), which inherently
provide perfect forward secrecy (PFS). This ensures that even if a server's
long-term private key is compromised in the future, past session traffic
cannot be decrypted. Distractors A, C, and D are incorrect because static
RSA lacks forward secrecy, MD5 is cryptographically broken and banned,
and SSL 3.0 is highly insecure and obsolete.
2. A network security analyst is monitoring outbound web traffic and notices a
user connecting to a remote site via HTTPS. The analyst wants to protect the
user's privacy by ensuring passive observers cannot read the destination
domain name in the initial plaintext handshake. Which modern capability or
extension solves this issue?
A. OCSP Stapling
B. HTTP Strict Transport Security (HSTS)
C. Encrypted Client Hello (ECH)
D. Extended Validation (EV) Certificates
CORRECT ANSWER: C
RATIONALE: Encrypted Client Hello (ECH), an extension integrated
with TLS 1.3, encrypts the Server Name Indication (SNI) component of the
initial client greeting. This prevents on-path network observers or ISP
monitors from determining which specific domain or website a user is
visiting. Distractor A is a certificate validation enhancement; distractor B
forces browsers to use HTTPS over HTTP; distractor D is a legacy
certificate validation type that does not hide handshake metadata.
3. When deploying a site-to-site IPsec VPN between two corporate gateways
across the public internet, a security architect must choose a protocol that
ensures packet data payload confidentiality, integrity, and source
authentication. Which protocol framework fulfills all these demands?
A. Authentication Header (AH)
B. Internet Key Exchange version 2 (IKEv2)

, C. Encapsulating Security Payload (ESP)
D. Layer 2 Tunneling Protocol (L2TP)
CORRECT ANSWER: C
RATIONALE: Encapsulating Security Payload (ESP) is the IPsec
protocol that provides confidentiality (encryption) along with data origin
authentication, integrity checking, and anti-replay protection. Distractor A
(AH) provides authentication and integrity but explicitly does not offer
confidentiality/encryption. Distractor B (IKEv2) manages the control-plane
key exchanges and security associations but does not transport user payload
packets. Distractor D (L2TP) is a tunneling protocol that lacks native
encryption entirely and relies on IPsec for protection.
4. A network security team is configuring an IPsec VPN tunnel to protect
communications between two remote branches. The entire original IP
packet, including its source and destination IP headers, must be completely
encrypted and placed within a new outer IP packet wrapper. Which
operational mode must be selected?
A. Transport Mode
B. Tunnel Mode
C. Promiscuous Mode
D. Pass-through Mode
CORRECT ANSWER: B
RATIONALE: Tunnel Mode encapsulates the entire original IP packet
(both payload and original headers) inside a brand new IP header, encrypting
the inner contents completely. This is the industry-standard mode for
gateway-to-gateway (site-to-site) VPN architectures. Distractor A (Transport
Mode) only encrypts the payload while leaving the original IP headers intact
and visible, making it typical for host-to-host links. Distractors C and D are
not valid IPsec operational encapsulation modes.
5. A security technician is troubleshooting a remote access failure and looks at
the network handshake logs. The system is attempting to establish security
associations (SAs) and generate dynamic symmetric keys over an untrusted
WAN. Which protocol's primary function is to handle this security
negotiation and key setup?
A. Internet Key Exchange (IKE)

, B. Simple Network Management Protocol (SNMP)
C. Secure Shell Version 2 (SSHv2)
D. Dynamic Host Configuration Protocol (DHCP)
CORRECT ANSWER: A
RATIONALE: Internet Key Exchange (IKE / IKEv2) is a component
of the IPsec suite designed to authenticate tunnel endpoints, negotiate
encryption parameters (ciphers, hashes), and establish the Security
Associations (SAs) required for secure data transit. Distractor B is used for
device monitoring; distractor C is for secure remote terminal access;
distractor D dynamically distributes IP addresses.
6. An administrator is configuring a corporate wireless network to meet the
highest security baselines. They replace the legacy WPA2 standard with
WPA3-Enterprise. Which specific cryptographic standard does WPA3
mandate to secure enterprise authentication mechanisms?
A. TKIP with RC4 key mixing
B. Simultaneous Authentication of Equals (SAE) or 192-bit CNSA-
compliant suites
C. Weak Initialization Vectors with 64-bit DES
D. Static WEP keys with Pre-Shared Passwords
CORRECT ANSWER: B
RATIONALE: WPA3-Enterprise mandates robust cryptographic
profiles, supporting up to a 192-bit cryptographic suite aligned with the
Commercial National Security Algorithm (CNSA) guidelines (utilizing
AES-GCM and SHA-384). For personal networks, WPA3 leverages
Simultaneous Authentication of Equals (SAE) to replace the vulnerable
WPA2 4-way pre-shared key handshake. Distractors A, C, and D reference
broken, deprecated cryptographic practices like TKIP, RC4, DES, and WEP.
7. A coffee shop chain wishes to deploy a public Wi-Fi network that requires
no user password entry but still ensures that data sent over the air between
each individual device and the access point is uniquely encrypted to prevent
local eavesdropping. Which WPA3 deployment feature should be
implemented?
A. WPA3-Personal with a shared passphrase
B. Opportunistic Wireless Encryption (OWE)

Document information

Uploaded on
October 9, 2026
Number of pages
39
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$11.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
142
Last sold
-



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions