1
CompTIA Security+ SY0-
701 Advanced Practice
Examination v2.0
Comprehensive 150-
Question Multiple-Choice
Assessment - Second
Edition a well detailed
one written
, 2
and graded A+
upgraded
Exam Title: CompTIA Security+ SY0-701 Advanced Practice Examination v2.0: In-Depth
Assessment of Cybersecurity Principles, Threat Mitigation, Security Architecture, Operations,
Governance, and Emerging Technologies for IT Security Professionals
Difficulty Level: Advanced / Hard / Mixed
Target Audience: IT professionals with 2+ years of security experience, candidates pursuing
CompTIA Security+ certification, network security administrators, and cybersecurity
practitioners seeking to validate advanced security knowledge across the five SY0-701 domains.
Exam Format: 150 multiple-choice questions, single correct answer per question
Time Allotment: 150 minutes (recommended)
Domain 1: General Security Concepts
Question 1
A security architect is designing a system where users must authenticate using a smart card and
a PIN. This is an example of which authentication category?
A) Single-factor authentication
B) Two-factor authentication using possession and knowledge
C) Two-factor authentication using knowledge and inherence
D) Multifactor authentication using possession, knowledge, and inherence
, 3
-” detailed answer 100 % correct :-”B) Two-factor authentication using possession
and knowledge
Rationale: Two-factor authentication requires two distinct authentication factors. A smart card
represents "something you have" (possession factor), while a PIN represents "something you
know" (knowledge factor). The combination of two different factors provides stronger security
than using two factors from the same category.
Question 2
Which security principle states that security mechanisms should be simple and easy to use to
encourage adoption?
A) Least privilege
B) Defense in depth
C) Psychological acceptability
D) Separation of duties
-” detailed answer 100 % correct :-”C) Psychological acceptability
Rationale: Psychological acceptability is a security principle that states security mechanisms
should be easy to use and not overly burdensome to users. When security controls are too
complex or restrictive, users may try to bypass them, creating security vulnerabilities. The
principle emphasizes usability as a critical component of security design.
Question 3
An organization is implementing a policy that requires all employees to lock their workstations
when leaving their desks. This control is primarily designed to prevent:
A) Unauthorized physical access to the facility
B) Unauthorized access to the user's logged-in session
C) Data loss due to hardware failure
D) Network performance degradation
-” detailed answer 100 % correct :-”B) Unauthorized access to the user's logged-in
session
, 4
Rationale: Workstation locking prevents unauthorized individuals from accessing a user's
logged-in session when the user is away from their desk. This protects against session hijacking,
unauthorized data access, and malicious actions performed using the user's credentials.
Question 4
Which of the following is an example of a "corrective" security control?
A) Intrusion detection system
B) Firewall rules blocking malicious traffic
C) Restoring data from backups after a ransomware attack
D) Security awareness training for employees
-” detailed answer 100 % correct :-”C) Restoring data from backups after a
ransomware attack
Rationale: Corrective controls are implemented to restore systems, data, or operations after a
security incident has occurred. Restoring data from backups is a corrective action that
remediates the effects of a ransomware attack by recovering encrypted or corrupted data.
Question 5
The principle of "least privilege" should be applied to which of the following?
A) Users only
B) Users and processes only
C) Users, processes, and systems
D) Administrative accounts only
-” detailed answer 100 % correct :-”C) Users, processes, and systems
Rationale: The principle of least privilege applies to all entities in a computing environment—
users, processes, applications, and systems. Each should be granted only the minimum
permissions necessary to perform its authorized functions. This limits the potential damage
from compromised accounts, malicious code, or system errors.
Question 6
What is the primary purpose of implementing "role-based access control" (RBAC)?
CompTIA Security+ SY0-
701 Advanced Practice
Examination v2.0
Comprehensive 150-
Question Multiple-Choice
Assessment - Second
Edition a well detailed
one written
, 2
and graded A+
upgraded
Exam Title: CompTIA Security+ SY0-701 Advanced Practice Examination v2.0: In-Depth
Assessment of Cybersecurity Principles, Threat Mitigation, Security Architecture, Operations,
Governance, and Emerging Technologies for IT Security Professionals
Difficulty Level: Advanced / Hard / Mixed
Target Audience: IT professionals with 2+ years of security experience, candidates pursuing
CompTIA Security+ certification, network security administrators, and cybersecurity
practitioners seeking to validate advanced security knowledge across the five SY0-701 domains.
Exam Format: 150 multiple-choice questions, single correct answer per question
Time Allotment: 150 minutes (recommended)
Domain 1: General Security Concepts
Question 1
A security architect is designing a system where users must authenticate using a smart card and
a PIN. This is an example of which authentication category?
A) Single-factor authentication
B) Two-factor authentication using possession and knowledge
C) Two-factor authentication using knowledge and inherence
D) Multifactor authentication using possession, knowledge, and inherence
, 3
-” detailed answer 100 % correct :-”B) Two-factor authentication using possession
and knowledge
Rationale: Two-factor authentication requires two distinct authentication factors. A smart card
represents "something you have" (possession factor), while a PIN represents "something you
know" (knowledge factor). The combination of two different factors provides stronger security
than using two factors from the same category.
Question 2
Which security principle states that security mechanisms should be simple and easy to use to
encourage adoption?
A) Least privilege
B) Defense in depth
C) Psychological acceptability
D) Separation of duties
-” detailed answer 100 % correct :-”C) Psychological acceptability
Rationale: Psychological acceptability is a security principle that states security mechanisms
should be easy to use and not overly burdensome to users. When security controls are too
complex or restrictive, users may try to bypass them, creating security vulnerabilities. The
principle emphasizes usability as a critical component of security design.
Question 3
An organization is implementing a policy that requires all employees to lock their workstations
when leaving their desks. This control is primarily designed to prevent:
A) Unauthorized physical access to the facility
B) Unauthorized access to the user's logged-in session
C) Data loss due to hardware failure
D) Network performance degradation
-” detailed answer 100 % correct :-”B) Unauthorized access to the user's logged-in
session
, 4
Rationale: Workstation locking prevents unauthorized individuals from accessing a user's
logged-in session when the user is away from their desk. This protects against session hijacking,
unauthorized data access, and malicious actions performed using the user's credentials.
Question 4
Which of the following is an example of a "corrective" security control?
A) Intrusion detection system
B) Firewall rules blocking malicious traffic
C) Restoring data from backups after a ransomware attack
D) Security awareness training for employees
-” detailed answer 100 % correct :-”C) Restoring data from backups after a
ransomware attack
Rationale: Corrective controls are implemented to restore systems, data, or operations after a
security incident has occurred. Restoring data from backups is a corrective action that
remediates the effects of a ransomware attack by recovering encrypted or corrupted data.
Question 5
The principle of "least privilege" should be applied to which of the following?
A) Users only
B) Users and processes only
C) Users, processes, and systems
D) Administrative accounts only
-” detailed answer 100 % correct :-”C) Users, processes, and systems
Rationale: The principle of least privilege applies to all entities in a computing environment—
users, processes, applications, and systems. Each should be granted only the minimum
permissions necessary to perform its authorized functions. This limits the potential damage
from compromised accounts, malicious code, or system errors.
Question 6
What is the primary purpose of implementing "role-based access control" (RBAC)?