,
, CompTIA Security+ SY0-701 Certification Exam Practice Tests, 2025–2026Comprehensive Cybersecurity
Competency Assessment
SECTION 1: GENERAL SECURITY CONCEPTS (Questions 1-10)
**Question 1**
A security analyst is implementing a control that prevents an employee from accessing files that are not
directly related to their job responsibilities. Which security principle is the analyst implementing?
A) Separation of duties
B) Defense in depth
C) Principle of least privilege
D) Role-based access control
**Answer:** C) Principle of least privilege
**rAtionAle:** The principle of least privilege dictates that users and processes should be granted
only the minimum levels of access necessary to perform their job functions. This limits the potential
damage from accidental errors, malicious insider actions, or compromised accounts. This differs from
separation of duties (splitting critical tasks among multiple people), defense in depth (layered security),
and RBAC (a method for implementing least privilege).
---
**Question 2**
A security team has implemented a layered security approach including firewalls, IDS/IPS, antivirus, and
endpoint detection and response (EDR). This strategy is best described as:
A) Single point of failure
, CompTIA Security+ SY0-701 Certification Exam Practice Tests, 2025–2026Comprehensive Cybersecurity
Competency Assessment
SECTION 1: GENERAL SECURITY CONCEPTS (Questions 1-10)
**Question 1**
A security analyst is implementing a control that prevents an employee from accessing files that are not
directly related to their job responsibilities. Which security principle is the analyst implementing?
A) Separation of duties
B) Defense in depth
C) Principle of least privilege
D) Role-based access control
**Answer:** C) Principle of least privilege
**rAtionAle:** The principle of least privilege dictates that users and processes should be granted
only the minimum levels of access necessary to perform their job functions. This limits the potential
damage from accidental errors, malicious insider actions, or compromised accounts. This differs from
separation of duties (splitting critical tasks among multiple people), defense in depth (layered security),
and RBAC (a method for implementing least privilege).
---
**Question 2**
A security team has implemented a layered security approach including firewalls, IDS/IPS, antivirus, and
endpoint detection and response (EDR). This strategy is best described as:
A) Single point of failure