Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 111 pages
Exam (elaborations)

CompTIA Security+ SY0-701: Exam Prep with 200+ Questions & Rationales

Document preview thumbnail
Preview 4 out of 111 pages

Ace the CompTIA Security+ SY0-701 certification exam with this comprehensive practice guide featuring over 200 questions mirroring the actual exam format. Covering all domains including threats and vulnerabilities, architecture and design, implementation, operations and incident response, and governance/risk/compliance—this resource is updated for the exam objectives. Each question includes expert rationales explaining correct answers and why incorrect options are wrong, helping you understand the reasoning behind every answer. Perfect for IT professionals, security analysts, and anyone pursuing cybersecurity certification. Features questions on network security, identity management, cryptography, PKI, risk management, and the latest threat intelligence. Get certified with confidence!

Content preview

1|Page




CompTIA Security+ (SY0-701) – CompTIA – 2026–2027
Edition Exam Preparation With Complete Questions And
Correct Answers With Rationales Already Graded
A+Brand New Version!!



1. A security analyst is implementing a new wireless network and must
ensure that data transmitted over the air is protected with the highest
level of encryption available for enterprise environments. Which of the
following protocols should the analyst deploy?
A) WEP
B) WPA
C) WPA2 with TKIP
D) WPA3 with SAE
Answer: D
Explanation: WPA3 with Simultaneous Authentication of Equals (SAE)
provides the most robust encryption and authentication for wireless
networks. It replaces the Pre-Shared Key (PSK) method of WPA2 with a
more secure key exchange resistant to offline dictionary attacks. WEP is
obsolete, WPA is outdated, and WPA2 with TKIP is less secure than the
AES-based encryption of WPA3.

,2|Page


2. A company wants to ensure that a single compromised employee
credential does not allow an attacker to access all sensitive internal
systems. Which access control principle is specifically designed to
mitigate this risk?
A) Principle of least privilege
B) Separation of duties
C) Mandatory Access Control
D) Role-Based Access Control
Answer: A
Explanation: The principle of least privilege ensures that users are
granted only the minimum necessary permissions to perform their job
functions. By limiting access, a compromised account cannot be used to
access systems or data beyond the user's legitimate scope, thereby
containing the potential damage.


3. An organization is required to maintain detailed logs of all user
authentication attempts, including successful and failed logins, for a
period of five years. Which of the following best describes this
requirement?
A) Data retention policy
B) Data classification policy
C) Acceptable use policy
D) Password policy
Answer: A

,3|Page


Explanation: A data retention policy dictates how long an organization
must keep certain types of data, often for regulatory, legal, or
operational reasons. The requirement to keep authentication logs for
five years falls directly under such a policy, specifying the retention
period for these specific records.


4. A security administrator is configuring a firewall to prevent external
attackers from discovering which internal services are running. Which
of the following techniques is most effective at hiding the presence of
open ports?
A) Stateful inspection
B) Packet filtering
C) Port address translation (PAT)
D) Implicit deny
Answer: C
Explanation: Port Address Translation (PAT), a form of Network Address
Translation (NAT), hides internal port numbers by mapping them to a
single public IP address with different source ports. This obscures the
internal service structure from external scans. While packet filtering and
stateful inspection control traffic, PAT actively conceals port details.


5. An employee accidentally emails a file containing customers'
personally identifiable information (PII) to an unauthorized external
recipient. The security team is notified and must determine the scope
of the data exposure. What is the FIRST step in the incident response
process in this scenario?

, 4|Page


A) Eradication
B) Containment
C) Detection and analysis
D) Recovery
Answer: C
Explanation: The incident response process begins with detection and
analysis. The security team must first confirm that an incident has
occurred and gather initial details about the event, such as what data
was exposed, who the unauthorized recipient is, and how the exposure
happened, before moving to containment or eradication.


6. A developer needs to securely store API keys and database
passwords used by a cloud application. Which of the following is the
MOST secure method for managing these secrets?
A) Hardcoding them in the application source code
B) Storing them in a configuration file with restricted file permissions
C) Using a dedicated secrets management service (e.g., HashiCorp
Vault, AWS Secrets Manager)
D) Encrypting them with a symmetric key stored in the same source
code repository
Answer: C
Explanation: Secrets management services are designed specifically to
store, access, and rotate secrets securely. They offer centralized
management, auditing, encryption at rest and in transit, and fine-
grained access control, eliminating the risks associated with hardcoding

Document information

Uploaded on
August 16, 2026
Number of pages
111
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$25.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
2
Followers
2
Items
1446
Last sold
1 month ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions