CompTIA Security+ 2026 Practice Questions and Answers
with Detailed Rationales – SY0-701 Exam Prep
1. Which security principle ensures that information is accessible to authorized users
when needed?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: C. Availability
Rationale: Availability ensures systems, applications, and data remain accessible to
authorized users when required. Confidentiality protects information from unauthorized
disclosure, while integrity protects against unauthorized modification.
2. An attacker sends an email that impersonates a company’s CEO and asks an
employee to purchase gift cards. What type of attack is this?
A. Phishing
B. DDoS
C. SQL injection
D. Password spraying
Answer: A. Phishing
Rationale: Phishing uses deceptive communications to manipulate victims into
performing an action or revealing information. Impersonating an executive is a common
social-engineering technique.
3. Which control is primarily designed to prevent unauthorized physical access to a
server room?
A. Firewall
B. Mantrap
C. SIEM
D. IDS
Answer: B. Mantrap
,Rationale: A mantrap is a physical security control that uses two or more interlocking
doors to control entry. Firewalls, SIEMs, and IDSs are primarily logical or technical
controls.
4. Which authentication factor is a fingerprint?
A. Something you know
B. Something you have
C. Something you are
D. Somewhere you are
Answer: C. Something you are
Rationale: Biometrics such as fingerprints, facial recognition, and iris scans are
categorized as “something you are.”
5. A company requires users to enter a password and then approve a login notification
on their smartphone. What security mechanism is being used?
A. Single sign-on
B. Multifactor authentication
C. Federation
D. Passwordless authentication
Answer: B. Multifactor authentication
Rationale: MFA requires authentication using two or more different factor categories. A
password represents something you know, while approval through a registered device
represents something you have.
6. Which attack attempts to make a service unavailable by overwhelming it with traffic
from many compromised systems?
A. DDoS
B. Credential stuffing
C. Shoulder surfing
D. Tailgating
Answer: A. DDoS
Rationale: A distributed denial-of-service attack uses multiple systems to generate
excessive traffic or requests against a target, potentially making the service unavailable.
,7. What is the primary purpose of encryption?
A. Increase network bandwidth
B. Protect data confidentiality
C. Improve system availability
D. Remove malware
Answer: B. Protect data confidentiality
Rationale: Encryption transforms readable plaintext into ciphertext so unauthorized
parties cannot easily understand the information.
8. Which security technology can analyze logs from multiple systems and correlate
security events?
A. SIEM
B. UPS
C. NAC
D. HSM
Answer: A. SIEM
Rationale: A Security Information and Event Management system collects and
correlates security-related logs and events from multiple sources to help identify
suspicious activity.
9. What is the primary purpose of a vulnerability scan?
A. Exploit every discovered vulnerability
B. Identify potential security weaknesses
C. Encrypt sensitive files
D. Replace a firewall
Answer: B. Identify potential security weaknesses
Rationale: Vulnerability scanning identifies weaknesses in systems, applications,
networks, and configurations. A penetration test goes further by attempting controlled
exploitation.
10. Which attack injects malicious SQL statements into an application’s database
query?
, A. XSS
B. SQL injection
C. Buffer overflow
D. ARP poisoning
Answer: B. SQL injection
Rationale: SQL injection occurs when attacker-controlled input is improperly
incorporated into SQL queries, potentially allowing unauthorized database access or
manipulation.
11. Which principle gives users only the permissions necessary to perform their jobs?
A. Separation of duties
B. Least privilege
C. Non-repudiation
D. Open access
Answer: B. Least privilege
Rationale: Least privilege minimizes potential damage by ensuring users, applications,
and services receive only the access required to perform their authorized functions.
12. Which technology is designed to detect suspicious network activity and generate
alerts without necessarily blocking the traffic?
A. IPS
B. IDS
C. Firewall
D. Proxy
Answer: B. IDS
Rationale: An Intrusion Detection System monitors activity and generates alerts when
suspicious behavior is detected. An IPS can actively block or prevent malicious traffic.
13. Which technology is designed to actively prevent detected malicious network traffic?
A. IDS
B. IPS
C. SIEM
with Detailed Rationales – SY0-701 Exam Prep
1. Which security principle ensures that information is accessible to authorized users
when needed?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: C. Availability
Rationale: Availability ensures systems, applications, and data remain accessible to
authorized users when required. Confidentiality protects information from unauthorized
disclosure, while integrity protects against unauthorized modification.
2. An attacker sends an email that impersonates a company’s CEO and asks an
employee to purchase gift cards. What type of attack is this?
A. Phishing
B. DDoS
C. SQL injection
D. Password spraying
Answer: A. Phishing
Rationale: Phishing uses deceptive communications to manipulate victims into
performing an action or revealing information. Impersonating an executive is a common
social-engineering technique.
3. Which control is primarily designed to prevent unauthorized physical access to a
server room?
A. Firewall
B. Mantrap
C. SIEM
D. IDS
Answer: B. Mantrap
,Rationale: A mantrap is a physical security control that uses two or more interlocking
doors to control entry. Firewalls, SIEMs, and IDSs are primarily logical or technical
controls.
4. Which authentication factor is a fingerprint?
A. Something you know
B. Something you have
C. Something you are
D. Somewhere you are
Answer: C. Something you are
Rationale: Biometrics such as fingerprints, facial recognition, and iris scans are
categorized as “something you are.”
5. A company requires users to enter a password and then approve a login notification
on their smartphone. What security mechanism is being used?
A. Single sign-on
B. Multifactor authentication
C. Federation
D. Passwordless authentication
Answer: B. Multifactor authentication
Rationale: MFA requires authentication using two or more different factor categories. A
password represents something you know, while approval through a registered device
represents something you have.
6. Which attack attempts to make a service unavailable by overwhelming it with traffic
from many compromised systems?
A. DDoS
B. Credential stuffing
C. Shoulder surfing
D. Tailgating
Answer: A. DDoS
Rationale: A distributed denial-of-service attack uses multiple systems to generate
excessive traffic or requests against a target, potentially making the service unavailable.
,7. What is the primary purpose of encryption?
A. Increase network bandwidth
B. Protect data confidentiality
C. Improve system availability
D. Remove malware
Answer: B. Protect data confidentiality
Rationale: Encryption transforms readable plaintext into ciphertext so unauthorized
parties cannot easily understand the information.
8. Which security technology can analyze logs from multiple systems and correlate
security events?
A. SIEM
B. UPS
C. NAC
D. HSM
Answer: A. SIEM
Rationale: A Security Information and Event Management system collects and
correlates security-related logs and events from multiple sources to help identify
suspicious activity.
9. What is the primary purpose of a vulnerability scan?
A. Exploit every discovered vulnerability
B. Identify potential security weaknesses
C. Encrypt sensitive files
D. Replace a firewall
Answer: B. Identify potential security weaknesses
Rationale: Vulnerability scanning identifies weaknesses in systems, applications,
networks, and configurations. A penetration test goes further by attempting controlled
exploitation.
10. Which attack injects malicious SQL statements into an application’s database
query?
, A. XSS
B. SQL injection
C. Buffer overflow
D. ARP poisoning
Answer: B. SQL injection
Rationale: SQL injection occurs when attacker-controlled input is improperly
incorporated into SQL queries, potentially allowing unauthorized database access or
manipulation.
11. Which principle gives users only the permissions necessary to perform their jobs?
A. Separation of duties
B. Least privilege
C. Non-repudiation
D. Open access
Answer: B. Least privilege
Rationale: Least privilege minimizes potential damage by ensuring users, applications,
and services receive only the access required to perform their authorized functions.
12. Which technology is designed to detect suspicious network activity and generate
alerts without necessarily blocking the traffic?
A. IPS
B. IDS
C. Firewall
D. Proxy
Answer: B. IDS
Rationale: An Intrusion Detection System monitors activity and generates alerts when
suspicious behavior is detected. An IPS can actively block or prevent malicious traffic.
13. Which technology is designed to actively prevent detected malicious network traffic?
A. IDS
B. IPS
C. SIEM