CompTIA Security+ Exam Prep 2026 Updated
Practice Questions, Comprehensive Cybersecurity
Certification Review, Detailed Explanations, Verified
Answers, Success Workbook
EXAM OVERVIEW
SY0-701 Domains & Weights:
Domain Weight
1.0 General Security Concepts 12%
2.0 Threats, Vulnerabilities, and Mitigations 22%
3.0 Security Architecture 18%
4.0 Security Operations 28%
5.0 Security Program Management and Oversight 20%
The exam emphasizes current trends including automation, zero trust, risk analysis,
IoT, cloud environments, and operational technology.
DOMAIN 1.0: GENERAL SECURITY CONCEPTS (12%)
Question 1
An organization is implementing a new security policy that requires all employees
to use complex passwords that are changed every 90 days. Which security
principle is this policy primarily supporting?
,A. Integrity
B. Availability
C. Confidentiality
D. Non-repudiation
Answer: C. Confidentiality
Rationale: Confidentiality ensures that data is accessible only to authorized
individuals. Complex password policies protect confidentiality by ensuring only
authorized users can access sensitive data. Integrity (A) focuses on preventing
unauthorized modification of data. Availability (B) ensures systems and data are
accessible when needed. Non-repudiation (D) provides proof of the origin of an
action (e.g., digital signatures), not access restriction.
Question 2
A security administrator is implementing controls to protect a data center. Which
of the following is an example of a detective control?
A. Mantrap at the entrance
B. Video surveillance cameras
C. Fire suppression system
D. Encryption of data at rest
Answer: B. Video surveillance cameras
Rationale: Detective controls are designed to identify and record security events
after they occur. Video surveillance cameras record activities, allowing detection
and investigation of security incidents. A mantrap (A) is
a physical/preventive control that restricts physical access. Fire suppression (C) is
a corrective control that responds to fires. Encryption (D) is a preventive control
that protects data confidentiality.
Question 3
Which of the following BEST describes the concept of "least privilege"?
A. All users should have administrative access to simplify IT support
B. Users should have the minimum levels of access necessary to perform their job
functions
,C. Privileges should be granted based on seniority within the organization
D. Users should share accounts to reduce licensing costs
Answer: B. Users should have the minimum levels of access necessary to
perform their job functions
Rationale: Least privilege limits user access rights to only what is essential for
their role, reducing the attack surface and limiting potential damage from
compromised accounts. Granting administrative access to all users (A) violates
security best practices. Access should be based on job requirements, not tenure (C).
Shared accounts (D) violate accountability principles.
Question 4
A company is implementing defense-in-depth. Which of the following represents
the correct layered approach?
A. Single firewall at the network perimeter
B. Firewall, IDS, antivirus, and encryption at multiple layers
C. Only endpoint protection on all workstations
D. Physical security only at the data center
Answer: B. Firewall, IDS, antivirus, and encryption at multiple layers
Rationale: Defense-in-depth uses multiple layers of security controls throughout
the environment so that if one layer fails, others continue to provide protection. A
single firewall (A) provides only one layer. Endpoint protection alone (C) ignores
network and data layers. Physical security only (D) ignores logical security
controls.
Question 5
A security architect is installing a mantrap at the entrance to a data center. Which
type of security control is this?
A. Technical control
B. Administrative control
C. Physical control
D. Detective control
Answer: C. Physical control
, Rationale: A mantrap is a physical security control—a small space with two
interlocking doors that prevents tailgating and allows identification of individuals
before granting access. Technical controls (A) include firewalls and encryption.
Administrative controls (B) include policies and procedures. Detective controls (D)
identify incidents after they occur.
Question 6
An organization wants to ensure that data cannot be modified by unauthorized
users. Which security goal is being addressed?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Answer: B. Integrity
Rationale: Integrity ensures that data is accurate and has not been tampered with
or modified by unauthorized individuals. Confidentiality (A) protects against
unauthorized disclosure. Availability (C) ensures systems are accessible.
Authentication (D) verifies identity.
Question 7
Which of the following is an example of "something you are" in multifactor
authentication?
A. Password
B. Smart card
C. Fingerprint scan
D. PIN
Answer: C. Fingerprint scan
Rationale: Biometric factors like fingerprints, retina scans, and voice recognition
are "something you are." Passwords (A) and PINs (D) are "something you know."
Smart cards (B) are "something you have."
Practice Questions, Comprehensive Cybersecurity
Certification Review, Detailed Explanations, Verified
Answers, Success Workbook
EXAM OVERVIEW
SY0-701 Domains & Weights:
Domain Weight
1.0 General Security Concepts 12%
2.0 Threats, Vulnerabilities, and Mitigations 22%
3.0 Security Architecture 18%
4.0 Security Operations 28%
5.0 Security Program Management and Oversight 20%
The exam emphasizes current trends including automation, zero trust, risk analysis,
IoT, cloud environments, and operational technology.
DOMAIN 1.0: GENERAL SECURITY CONCEPTS (12%)
Question 1
An organization is implementing a new security policy that requires all employees
to use complex passwords that are changed every 90 days. Which security
principle is this policy primarily supporting?
,A. Integrity
B. Availability
C. Confidentiality
D. Non-repudiation
Answer: C. Confidentiality
Rationale: Confidentiality ensures that data is accessible only to authorized
individuals. Complex password policies protect confidentiality by ensuring only
authorized users can access sensitive data. Integrity (A) focuses on preventing
unauthorized modification of data. Availability (B) ensures systems and data are
accessible when needed. Non-repudiation (D) provides proof of the origin of an
action (e.g., digital signatures), not access restriction.
Question 2
A security administrator is implementing controls to protect a data center. Which
of the following is an example of a detective control?
A. Mantrap at the entrance
B. Video surveillance cameras
C. Fire suppression system
D. Encryption of data at rest
Answer: B. Video surveillance cameras
Rationale: Detective controls are designed to identify and record security events
after they occur. Video surveillance cameras record activities, allowing detection
and investigation of security incidents. A mantrap (A) is
a physical/preventive control that restricts physical access. Fire suppression (C) is
a corrective control that responds to fires. Encryption (D) is a preventive control
that protects data confidentiality.
Question 3
Which of the following BEST describes the concept of "least privilege"?
A. All users should have administrative access to simplify IT support
B. Users should have the minimum levels of access necessary to perform their job
functions
,C. Privileges should be granted based on seniority within the organization
D. Users should share accounts to reduce licensing costs
Answer: B. Users should have the minimum levels of access necessary to
perform their job functions
Rationale: Least privilege limits user access rights to only what is essential for
their role, reducing the attack surface and limiting potential damage from
compromised accounts. Granting administrative access to all users (A) violates
security best practices. Access should be based on job requirements, not tenure (C).
Shared accounts (D) violate accountability principles.
Question 4
A company is implementing defense-in-depth. Which of the following represents
the correct layered approach?
A. Single firewall at the network perimeter
B. Firewall, IDS, antivirus, and encryption at multiple layers
C. Only endpoint protection on all workstations
D. Physical security only at the data center
Answer: B. Firewall, IDS, antivirus, and encryption at multiple layers
Rationale: Defense-in-depth uses multiple layers of security controls throughout
the environment so that if one layer fails, others continue to provide protection. A
single firewall (A) provides only one layer. Endpoint protection alone (C) ignores
network and data layers. Physical security only (D) ignores logical security
controls.
Question 5
A security architect is installing a mantrap at the entrance to a data center. Which
type of security control is this?
A. Technical control
B. Administrative control
C. Physical control
D. Detective control
Answer: C. Physical control
, Rationale: A mantrap is a physical security control—a small space with two
interlocking doors that prevents tailgating and allows identification of individuals
before granting access. Technical controls (A) include firewalls and encryption.
Administrative controls (B) include policies and procedures. Detective controls (D)
identify incidents after they occur.
Question 6
An organization wants to ensure that data cannot be modified by unauthorized
users. Which security goal is being addressed?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Answer: B. Integrity
Rationale: Integrity ensures that data is accurate and has not been tampered with
or modified by unauthorized individuals. Confidentiality (A) protects against
unauthorized disclosure. Availability (C) ensures systems are accessible.
Authentication (D) verifies identity.
Question 7
Which of the following is an example of "something you are" in multifactor
authentication?
A. Password
B. Smart card
C. Fingerprint scan
D. PIN
Answer: C. Fingerprint scan
Rationale: Biometric factors like fingerprints, retina scans, and voice recognition
are "something you are." Passwords (A) and PINs (D) are "something you know."
Smart cards (B) are "something you have."