Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 48 pages
Exam (elaborations)

CompTIA Security+ SY0-701 Exam Prep | Threats, Vulnerabilities, Security Operations & Risk Management Practice Questions and answers 2026/2027

Document preview thumbnail
Preview 4 out of 48 pages

CompTIA Security+ SY0-701 Exam Prep | Threats, Vulnerabilities, Security Operations & Risk Management Practice Questions and answers 2026/2027

Content preview

CompTIA Security+ SY0-701 Exam Prep | Threats,
Vulnerabilities, Security Operations & Risk Management
Practice Questions and answers 2026/2027


Question 1
What social engineering attack uses targeted, personalized
communication—such as referencing specific projects or job roles—to
deceive high-profile individuals within an organization?
• A. Spear phishing
• B. Mass spam mailing
• C. Common credential stuffing
• D. Wardriving reconnaissance
Correct Answer: A. Spear phishing
Detailed Rationale: Spear phishing customizes attack lures using
reconnaissance gathered on a specific target individual or group to
increase the likelihood of success.
Question 2
What type of malware masquerades as legitimate, useful software
while secretly installing malicious backdoors or payloads on a victim's
system?
• A. Trojan horse
• B. Logic bomb
• C. Polymorphic worm

, • D. Autonomous botnet
Correct Answer: A. Trojan horse
Detailed Rationale: Trojans disguise their true malicious intent behind
appealing or functional software interfaces, tricking users into executing
them voluntarily.
Question 3
What software vulnerability occurs when an application writes data past
the allocated boundaries of a fixed-length memory buffer, potentially
allowing arbitrary code execution?
• A. Buffer overflow
• B. SQL injection
• C. Cross-site scripting
• D. Race condition
Correct Answer: A. Buffer overflow
Detailed Rationale: Buffer overflows happen when input data exceeds
storage capacity, corrupting adjacent memory space and allowing
attackers to hijack instruction pointers.
Question 4
What advanced threat actor group is typically sponsored by a nation-
state, possesses high financial backing, and conducts prolonged,
stealthy espionage campaigns against targets?
• A. Advanced Persistent Threat (APT)
• B. Script kiddie collective

, • C. Hacktivist syndicate
• D. Insider threat actor
Correct Answer: A. Advanced Persistent Threat (APT)
Detailed Rationale: APTs utilize sophisticated multi-stage attack
methodologies, maintaining long-term access within victim networks
for intelligence gathering.
Question 5
What term describes the complete sum of all potential exposure points,
vulnerabilities, and pathways that an attacker can exploit within an
organization's IT environment?
• A. Attack surface
• B. Threat intelligence feed
• C. Security baseline
• D. Air-gapped boundary
Correct Answer: A. Attack surface
Detailed Rationale: The attack surface encompasses all hardware,
software, network connections, and human elements exposed to
potential security threats.
Question 6
What password attack method utilizes automated lists of common
words and phrases to guess user credentials across systems?
• A. Dictionary attack
• B. Rainbow table lookup

, • C. Birthday paradox attack
• D. Side-channel sniffing
Correct Answer: A. Dictionary attack
Detailed Rationale: Dictionary attacks test precompiled lists of likely
passwords, exploiting weak human password selection habits.
Question 7
What web application vulnerability allows attackers to inject malicious
database query syntax into input fields to manipulate backend data
retrieval?
• A. SQL Injection (SQLi)
• B. Cross-Site Scripting (XSS)
• C. Directory traversal
• D. Buffer overflow
Correct Answer: A. SQL Injection (SQLi)
Detailed Rationale: SQLi occurs when user input is improperly sanitized
or parameterized, allowing attackers to execute arbitrary SQL
statements on the database server.
Question 8
What type of Cross-Site Scripting (XSS) attack involves malicious script
being permanently stored on a target server (such as in a forum post)
and executed whenever other users view the page?
• A. Stored (Persistent) XSS
• B. Reflected (Non-persistent) XSS

Document information

Uploaded on
August 17, 2026
Number of pages
48
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CreativeWrites
3.6
(21)
Sold
93
Followers
3
Items
8251
Last sold
2 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions