Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 69 pages
Exam (elaborations)

COMPTIA SECURITY+ SY – EXAM-STYLE QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | 2026/27 LATEST UPDATE | EXAM PREP | STUDY GUIDE | PRACTICE TEST

Document preview thumbnail
Preview 4 out of 69 pages

COMPTIA SECURITY+ SY – EXAM-STYLE QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | 2026/27 LATEST UPDATE | EXAM PREP | STUDY GUIDE | PRACTICE TEST

Content preview

COMPTIA SECURITY+ SY0-701 2026 – EXAM-STYLE QUESTIONS AND
ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES |
GUARANTEED PASS | 2026/27 LATEST UPDATE | EXAM PREP | STUDY GUIDE |
PRACTICE TEST

SECTION ONE: QUESTIONS 1–50




1. A security analyst is reviewing network logs and observes a high volume of
outbound traffic on port 53 from an internal server that is not configured as a
DNS resolver. The destination IP addresses are associated with known
command-and-control infrastructure. Which of the following is the most likely
explanation for this traffic?

A. A misconfigured DHCP server is causing incorrect DNS settings to be
distributed.
B. A DNS amplification attack is being launched from the compromised server.
C. The server is exfiltrating data using DNS tunneling to a remote attacker.
D. A legitimate application is performing recursive DNS lookups for updates.

Correct Answer: C. The server is exfiltrating data using DNS tunneling to a
remote attacker.

Rationale: DNS tunneling is a common technique used to exfiltrate data or
establish covert communication channels. It involves encapsulating data within
DNS queries and responses, often targeting port 53 which is typically allowed
through firewalls. Option A is incorrect because a misconfigured DHCP server
would affect client configuration, not cause a server to send high-volume outbound
DNS traffic to C2 servers. Option B describes a reflection/amplification attack,

,which would be inbound to the server, not outbound, and would target a victim.
Option D is unlikely as the server is not a DNS resolver and the destination IPs are
known malicious, ruling out legitimate activity.




2. An organization is implementing a new access control policy to ensure that
users are granted only the permissions necessary to perform their job
functions. Which of the following best describes the principle being enforced?

A. Separation of duties
B. Defense in depth
C. The principle of least privilege
D. Role-Based Access Control

Correct Answer: C. The principle of least privilege

Rationale: The principle of least privilege dictates that users, applications, and
systems should be granted only the minimum permissions required to complete
their assigned tasks. This limits the potential damage from accidents, errors, or
compromise. Option A refers to dividing critical tasks among multiple individuals to
prevent fraud. Option B is a security strategy that uses multiple layers of defense.
Option D is a model for implementing access controls, but the underlying principle
being described is least privilege.




3. A company's Chief Information Security Officer (CISO) has mandated that all
data at rest on employee laptops be protected. A security administrator is
tasked with implementing a solution that will render the data unreadable if the

,device is lost or stolen and can be centrally managed. Which of the following is
the BEST solution?

A. Implement a full-disk encryption (FDE) solution using a Trusted Platform
Module (TPM) for key storage.
B. Deploy a network access control (NAC) solution to quarantine non-compliant
devices.
C. Use a data loss prevention (DLP) agent to monitor outbound data transfers.
D. Install a host-based intrusion prevention system (HIPS) to monitor for
unauthorized file access.

Correct Answer: A. Implement a full-disk encryption (FDE) solution using a
Trusted Platform Module (TPM) for key storage.

Rationale: Full-disk encryption (FDE) encrypts the entire hard drive, ensuring that
data remains protected if the device is physically compromised. TPM provides
secure hardware-based storage for the encryption keys, strengthening the solution.
Option B is a network-level control that does not protect data on a lost laptop.
Option C is for monitoring and preventing data leaks, not for data protection at
rest. Option D is a detection mechanism, not a preventative control for data
confidentiality in this scenario.




4. A user receives an email that appears to be from their bank, requesting them
to click a link and verify their account details due to a suspected security
breach. The email uses the bank's official logo and correctly addresses the user
by their name. Which of the following types of social engineering attacks is
this?

, A. Vishing
B. Phishing
C. Smishing
D. Spear phishing

Correct Answer: B. Phishing

Rationale: Phishing is a broad social engineering attack where an attacker
attempts to trick a wide audience into revealing sensitive information or performing
an action. The use of a logo and addressing the user by name are common tactics
to make the message appear legitimate. Option A (vishing) is voice-based. Option C
(smishing) is SMS-based. Option D (spear phishing) is a more targeted version of
phishing directed at a specific individual or organization, and while this is targeted,
the term "spear" is more appropriate for highly personalized attacks, while this
scenario describes a more generic, albeit sophisticated, phishing attempt.




5. During a security assessment, a penetration tester identifies that a web
application is vulnerable to SQL injection. Which of the following would be the
BEST mitigation strategy to implement at the application level?

A. Implement a web application firewall (WAF).
B. Disable unnecessary database user accounts.
C. Use parameterized queries.
D. Increase the complexity of database passwords.

Correct Answer: C. Use parameterized queries.

Document information

Uploaded on
August 6, 2026
Number of pages
69
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$21.29

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
27
Last sold
-


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions