Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 54 pages
Exam (elaborations)

CompTIA Security+ SY0-701: Complete Practice Question Bank with Rationales (2026/2027 Edition)

Document preview thumbnail
Preview 4 out of 54 pages

CompTIA Security+ SY0-701: Complete Practice Question Bank with Rationales (2026/2027 Edition)

Content preview

CompTIA Security+ SY0-701:
Complete Practice Question Bank
with Rationales (2026/2027 Edition)

Question 1
A business development team reports that files are missing from the
database system and the server login screens are showing a lock symbol
requiring users to contact an email address to access the system and data.
Which type of attack is the company facing?

A. Rootkit
B. Ransomware
C. Spyware
D. Bloatware

Answer : B. Ransomware

Rationale: Ransomware is malware that encrypts files and displays a ransom
note demanding payment for decryption. The lock symbol and contact email
are classic indicators of a ransomware infection .




Question 2
During a security incident, the security operations team identified sustained
network traffic from a malicious IP address: 10.1.4.9. A security analyst is
creating an inbound firewall rule to block this IP. Which ACL fulfills this
request?

,A. access-list inbound deny ip source 0.0.0.0/0 destination 10.1.4.9/32
B. access-list inbound deny ip source 10.1.4.9/32 destination 0.0.0.0/0
C. access-list inbound permit ip source 10.1.4.9/32 destination 0.0.0.0/0
D. access-list inbound permit ip source 0.0.0.0/0 destination 10.1.4.9/32

Answer : B. access-list inbound deny ip source 10.1.4.9/32 destination
0.0.0.0/0

Rationale: For an inbound rule, the source is the external malicious IP and the
destination is the internal network (0.0.0.0/0 represents any destination). The
rule must deny (block) traffic from the malicious source .




Question 3
Which threat actor is most likely to use common hacking tools found on
the internet to attempt to remotely compromise an organization's web
server?

A. Organized crime
B. Insider threat
C. Unskilled attacker
D. Nation-state

Answer : C. Unskilled attacker

Rationale: Unskilled attackers (script kiddies) typically use readily available
tools and exploits found on the internet without deep technical
understanding. They lack the sophisticated custom tools used by nation-
states or organized crime .

,Question 4
A systems administrator wants to set up a system that makes it difficult or
impossible to deny that someone has performed an action. What is the
administrator trying to accomplish?

A. Non-repudiation
B. Adaptive identity
C. Security zones
D. Deception and disruption

Answer : A. Non-repudiation

Rationale: Non-repudiation ensures that an individual cannot deny having
performed a specific action. This is typically achieved through digital
signatures, audit logs, and authentication systems .




Question 5
Which type of control decreases the likelihood of a cybersecurity breach
occurring?

A. Corrective
B. Transfer
C. Detective
D. Preventive

Answer : D. Preventive

Rationale: Preventive controls are designed to stop security incidents before
they occur. Examples include firewalls, access controls, and encryption.
Corrective controls fix issues after detection, detective controls identify
incidents, and transfer controls shift risk .

, Question 6
A company is expanding its threat surface program by allowing researchers
to security test the company's internet-facing application and
compensating them based on vulnerabilities discovered. What best
describes this program?

A. Open-source intelligence
B. Bug bounty
C. Red team
D. Penetration testing

Answer : B. Bug bounty

Rationale: A bug bounty program invites external security researchers to find
and report vulnerabilities in exchange for monetary rewards. This differs from
penetration testing, which is typically a contracted, time-bound engagement .




Question 7
What is the final step of the incident response process?

A. Containment
B. Lessons learned
C. Eradication
D. Detection

Answer : B. Lessons learned

Rationale: The incident response lifecycle (NIST SP 800-61) includes
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and

Document information

Uploaded on
August 7, 2026
Number of pages
54
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$20.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
3
Followers
0
Items
891
Last sold
2 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions