CompTIA Security+ SY0-701 Exam Prep | Complete Practice
Tests, Questions & Detailed Rationales 2026/2027
Question 1
What three core principles form the foundation of the CIA triad in
information security?
• A. Confidentiality, Integrity, and Availability
• B. Control, Inspection, and Authorization
• C. Compliance, Identification, and Auditing
• D. Confidentiality, Isolation, and Authentication
Correct Answer: A. Confidentiality, Integrity, and Availability
Detailed Rationale: The CIA triad represents the three primary pillars of
information security: ensuring data privacy (Confidentiality), preventing
unauthorized tampering (Integrity), and maintaining system/data
accessibility (Availability).
Question 2
What security concept dictates that users and systems should be
granted only the minimum level of access necessary to perform their
legitimate job functions?
• A. Principle of Least Privilege
• B. Separation of Duties
• C. Defense in Depth
• D. Mandatory Access Control
,Correct Answer: A. Principle of Least Privilege
Detailed Rationale: Least privilege restricts user permissions to the
bare minimum required for tasks, reducing the potential blast radius of
compromised accounts or insider threats.
Question 3
What architectural strategy uses multiple layers of distinct defensive
controls so that if one security mechanism fails, subsequent layers still
protect the asset?
• A. Defense in Depth (Layered Security)
• B. Single Point of Failure
• C. Security through Obscurity
• D. Flat Network Segmentation
Correct Answer: A. Defense in Depth (Layered Security)
Detailed Rationale: Defense in depth relies on overlapping controls
(e.g., firewalls, EDR, multi-factor authentication, and training) to thwart
attackers even if a perimeter control is bypassed.
Question 4
What security model assumes that no user or device—inside or outside
the perimeter—should be trusted by default, requiring continuous
verification of identity and device health?
• A. Zero Trust Architecture
• B. Perimeter Security Model
• C. Implicit Trust Zone
, • D. Open Network Architecture
Correct Answer: A. Zero Trust Architecture
Detailed Rationale: Zero Trust eliminates implicit trust based solely on
network location ("never trust, always verify"), requiring strict
authentication and context-aware authorization for every access
request.
Question 5
What type of physical security control actively delays, deters, or
prevents unauthorized physical intrusion, such as a high-security fence,
security guard, or mantrap?
• A. Preventive physical control
• B. Detective physical control
• C. Corrective physical control
• D. Compensating physical control
Correct Answer: A. Preventive physical control
Detailed Rationale: Preventive physical controls are designed to stop an
intrusion before it happens, whereas detective controls (like CCTV
cameras or motion sensors) identify breaches after they occur.
Question 6
What physical security entry control system uses two interlocking doors
and requires the first door to close completely before the second door
can open, preventing piggybacking?
• A. Mantrap (or Airlock)
, • B. Turnstile
• C. Bollard
• D. Faraday cage
Correct Answer: A. Mantrap (or Airlock)
Detailed Rationale: Mantraps control physical access by trapping
individuals in a secure vestibule between two doors until identity
verification is completed.
Question 7
What cryptographic property ensures that data has not been altered,
modified, or tampered with in transit or at rest?
• A. Integrity
• B. Confidentiality
• C. Availability
• D. Non-repudiation
Correct Answer: A. Integrity
Detailed Rationale: Integrity mechanisms (such as cryptographic
hashing and digital signatures) guarantee that information remains
exact and unmodified from its original state.
Question 8
What legal and security concept prevents a sender from successfully
denying having sent a message or performed a transaction?
• A. Non-repudiation
• B. Obfuscation
Tests, Questions & Detailed Rationales 2026/2027
Question 1
What three core principles form the foundation of the CIA triad in
information security?
• A. Confidentiality, Integrity, and Availability
• B. Control, Inspection, and Authorization
• C. Compliance, Identification, and Auditing
• D. Confidentiality, Isolation, and Authentication
Correct Answer: A. Confidentiality, Integrity, and Availability
Detailed Rationale: The CIA triad represents the three primary pillars of
information security: ensuring data privacy (Confidentiality), preventing
unauthorized tampering (Integrity), and maintaining system/data
accessibility (Availability).
Question 2
What security concept dictates that users and systems should be
granted only the minimum level of access necessary to perform their
legitimate job functions?
• A. Principle of Least Privilege
• B. Separation of Duties
• C. Defense in Depth
• D. Mandatory Access Control
,Correct Answer: A. Principle of Least Privilege
Detailed Rationale: Least privilege restricts user permissions to the
bare minimum required for tasks, reducing the potential blast radius of
compromised accounts or insider threats.
Question 3
What architectural strategy uses multiple layers of distinct defensive
controls so that if one security mechanism fails, subsequent layers still
protect the asset?
• A. Defense in Depth (Layered Security)
• B. Single Point of Failure
• C. Security through Obscurity
• D. Flat Network Segmentation
Correct Answer: A. Defense in Depth (Layered Security)
Detailed Rationale: Defense in depth relies on overlapping controls
(e.g., firewalls, EDR, multi-factor authentication, and training) to thwart
attackers even if a perimeter control is bypassed.
Question 4
What security model assumes that no user or device—inside or outside
the perimeter—should be trusted by default, requiring continuous
verification of identity and device health?
• A. Zero Trust Architecture
• B. Perimeter Security Model
• C. Implicit Trust Zone
, • D. Open Network Architecture
Correct Answer: A. Zero Trust Architecture
Detailed Rationale: Zero Trust eliminates implicit trust based solely on
network location ("never trust, always verify"), requiring strict
authentication and context-aware authorization for every access
request.
Question 5
What type of physical security control actively delays, deters, or
prevents unauthorized physical intrusion, such as a high-security fence,
security guard, or mantrap?
• A. Preventive physical control
• B. Detective physical control
• C. Corrective physical control
• D. Compensating physical control
Correct Answer: A. Preventive physical control
Detailed Rationale: Preventive physical controls are designed to stop an
intrusion before it happens, whereas detective controls (like CCTV
cameras or motion sensors) identify breaches after they occur.
Question 6
What physical security entry control system uses two interlocking doors
and requires the first door to close completely before the second door
can open, preventing piggybacking?
• A. Mantrap (or Airlock)
, • B. Turnstile
• C. Bollard
• D. Faraday cage
Correct Answer: A. Mantrap (or Airlock)
Detailed Rationale: Mantraps control physical access by trapping
individuals in a secure vestibule between two doors until identity
verification is completed.
Question 7
What cryptographic property ensures that data has not been altered,
modified, or tampered with in transit or at rest?
• A. Integrity
• B. Confidentiality
• C. Availability
• D. Non-repudiation
Correct Answer: A. Integrity
Detailed Rationale: Integrity mechanisms (such as cryptographic
hashing and digital signatures) guarantee that information remains
exact and unmodified from its original state.
Question 8
What legal and security concept prevents a sender from successfully
denying having sent a message or performed a transaction?
• A. Non-repudiation
• B. Obfuscation