ACTUAL EXAM QUESTIONS
CompTIA Security+ SY0-701 Certification Examination - Domain 1.0 Focus | Core Domains: Security Controls
(Technical, Managerial, Operational, Physical), Governance, Risk, and Compliance (GRC) Concepts, Security
Policies & Procedures, The CIA Triad & Non-Repudiation, Threat Actors & Vectors, Attack Surfaces & Vectors,
Threat Intelligence Sources, Research Sources, and Security Automation & Orchestration | IT Security Certification
Focus | Exam Domain-Specific Question Bank Format
Exam Structure
The CompTIA Security+ (SY0-701) certification exam consists of a maximum of 90 questions, including
multiple-choice and performance-based types. Domain 1.0: General Security Concepts comprises
approximately 12% of the total exam content.
Introduction
This question bank focuses exclusively on CompTIA Security+ SY0-701 Domain 1.0: General Security Concepts
for the 2026/2027 certification cycle. The content aligns with the official CompTIA exam objectives, testing
foundational knowledge of security principles, control types, governance frameworks, and threat landscape concepts
essential for all subsequent security domains.
Answer Format
All correct answers and security concepts are presented in bold and green, followed by detailed rationales that
reference the official CompTIA Security+ SY0-701 exam objectives, define key terminology, and explain the
practical application of general security principles.
1. Which principle of the CIA triad ensures that information is not disclosed to
unauthorized individuals?
A. A. Integrity
B. B. Availability
C. C. Confidentiality
D. D. Authentication
C. Confidentiality
Confidentiality ensures that data is accessible only to those authorized to have access. It is enforced
through encryption, access controls, and secure authentication mechanisms, as outlined in CompTIA
Security+ Domain 1.1.
2. A firewall that filters traffic based on IP addresses and port numbers is an example of
what type of control?
A. A. Managerial
, B. B. Physical
C. C. Technical
D. D. Operational
C. Technical
Technical controls are implemented via hardware or software to protect systems and data. Firewalls,
intrusion detection systems, and encryption are all technical controls, per Domain 1.2.
3. Which concept ensures that a user cannot deny having performed an action, such as
sending an email?
A. A. Integrity
B. B. Non-repudiation
C. C. Availability
D. D. Confidentiality
B. Non-repudiation
Non-repudiation provides proof of the origin and delivery of data, preventing denial of actions. Digital
signatures and audit logs support non-repudiation, a key concept in Domain 1.1.
4. Which of the following is a primary source of threat intelligence?
A. A. Industry blogs
B. B. Vendor security advisories
C. C. Internal SIEM logs
D. D. All of the above
D. All of the above
Threat intelligence can be derived from internal sources (e.g., SIEM logs) and external sources (e.g.,
vendor advisories, industry blogs). CompTIA Domain 1.6 emphasizes using diverse intelligence feeds for
proactive defense.
5. A hacker group that targets government agencies to steal classified information is most
likely a:
A. A. Script kiddie
B. B. Hacktivist
C. C. Nation-state actor
D. D. Organized crime group
C. Nation-state actor
, Nation-state actors are typically sponsored by governments and engage in espionage or sabotage. Their
targets include government and critical infrastructure, aligning with Domain 1.4 threat actor profiles.
6. Reducing the number of open ports on a server is an example of:
A. A. Patch management
B. B. Attack surface reduction
C. C. Network segmentation
D. D. Defense in depth
B. Attack surface reduction
Attack surface reduction minimizes potential entry points by disabling unnecessary services, closing
unused ports, and removing unneeded software, as emphasized in Domain 1.5.
7. A company-wide mandate requiring data encryption at rest is an example of a:
A. A. Procedure
B. B. Guideline
C. C. Policy
D. D. Standard
C. Policy
Policies are high-level organizational statements that define security requirements. Encryption
mandates are typically established in security policies, which are then supported by standards and
procedures (Domain 1.3).
8. Compliance with PCI DSS is an example of which GRC component?
A. A. Governance
B. B. Risk
C. C. Compliance
D. D. Audit
C. Compliance
Compliance involves adhering to external laws, regulations, and standards such as PCI DSS, HIPAA, or
GDPR. It is a core pillar of GRC, as defined in Domain 1.3.
9. Which system assigns unique identifiers to publicly known cybersecurity
vulnerabilities?