Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 68 pages
Exam (elaborations)

COMPTIA SECURITY+ SY0-701 CERTIFICATION EXAM – QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | EXAM TESTBANK | PLUS RATIONALES | DOWNLOAD AND PASS | LATEST EXAM UPDATE 2026/2027

Document preview thumbnail
Preview 4 out of 68 pages

COMPTIA SECURITY+ SY0-701 CERTIFICATION EXAM – QUESTIONS AND ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | EXAM TESTBANK | PLUS RATIONALES | DOWNLOAD AND PASS | LATEST EXAM UPDATE 2026/2027

Content preview

COMPTIA SECURITY+ SY0-701 CERTIFICATION EXAM – QUESTIONS AND
ANSWERS | VERIFIED AND WELL DETAILED ANSWERS | EXAM TESTBANK | PLUS
RATIONALES | DOWNLOAD AND PASS | LATEST EXAM UPDATE 2026/2027

Core Domains

1. General Security Concepts
2. Threats, Vulnerabilities, and Mitigations
3. Security Architecture
4. Security Operations
5. Security Program Management and Oversight
6. Cryptography and PKI
7. Identity and Access Management (IAM)
8. Network Security
9. Cloud and Virtualization Security
10. Compliance and Operational Security

Introduction

This comprehensive examination is designed to rigorously assess a candidate's
knowledge and skills required for the CompTIA Security+ SY0-701 certification. It
covers a broad spectrum of foundational and applied security principles,
emphasizing real-world application and critical decision-making. The assessment
utilizes a mix of multiple-choice and scenario-based questions to evaluate your
understanding of core domains, from threat mitigation and security architecture to
identity management and cryptography. Success on this exam demonstrates your
ability to identify and respond to security incidents, implement robust security
controls, and uphold professional and ethical standards within an organization. This
test bank provides verified answers with detailed rationales to solidify your
comprehension and ensure exam readiness.

,════════════════════════════════════
SECTION ONE: QUESTIONS 1–50
════════════════════════════════════

1. A security analyst is configuring a new firewall to protect a small business
network. The primary goal is to block all inbound traffic that was not explicitly
requested by internal hosts, while allowing all outbound traffic. Which type of
firewall policy best achieves this objective?

A. Implicit deny
B. Stateful inspection
C. Application-based policy
D. Network Address Translation (NAT)

🟢 Correct Answer: B. Stateful inspection

🔴 Explanation: A stateful inspection firewall tracks the state of active
connections and allows outbound traffic, but only permits inbound traffic that is
part of an established, legitimate connection. This is exactly the described
scenario. An implicit deny is a rule, not a type of firewall. Application-based
policies filter traffic based on applications, and NAT is a technique for IP address
translation, not the policy itself.

2. Which of the following is the MOST significant risk associated with using
default credentials on network devices?

A. Increased network latency
B. Unauthorized access to the device
C. Inability to perform firmware updates
D. Loss of data during a power outage

🟢 Correct Answer: B. Unauthorized access to the device

,🔴 Explanation: Default credentials are widely known and easily exploitable,
providing a direct path for malicious actors to gain unauthorized administrative
access to the device. This is a primary security vulnerability. The other options are
not direct security risks caused by default credentials.

3. An organization is implementing a new policy requiring employees to use a
smart card in conjunction with a PIN to access secure facilities. This is an
example of which type of authentication?

A. Multifactor authentication
B. Biometric authentication
C. Single-factor authentication
D. Authorization

🟢 Correct Answer: A. Multifactor authentication

🔴 Explanation: Multifactor authentication (MFA) requires two or more
independent factors: a smart card (something you have) and a PIN (something
you know). This is a core concept in IAM. Single-factor uses only one, and
biometrics use something you are. Authorization is about permissions, not the act
of authenticating.

4. A company wants to ensure that only approved USB drives can be connected
to its computers to mitigate the risk of malware. Which security control should
be implemented?

A. Application whitelisting
B. Endpoint detection and response (EDR)
C. Device control
D. Data loss prevention (DLP)

🟢 Correct Answer: C. Device control

, 🔴 Explanation: Device control is specifically designed to manage and restrict the
use of peripherals like USB drives, SD cards, and other external media. This is a
direct control for this scenario. Application whitelisting controls software, EDR is
for threat detection, and DLP focuses on preventing data exfiltration.

5. A security administrator is reviewing logs and discovers that an employee
has been visiting gambling and adult websites during work hours. This is a
violation of company policy. What type of security control is being enforced to
detect this activity?

A. Administrative control
B. Technical control
C. Physical control
D. Deterrent control

🟢 Correct Answer: B. Technical control

🔴 Explanation: The activity was detected by logging and monitoring systems,
which are technical controls. The policy itself is an administrative control, but the
detection of the violation relies on technical controls. Deterrent controls are
meant to discourage action, and physical controls are tangible barriers.

6. Which of the following describes a scenario where an attacker intercepts
communication between two parties and relays the messages, potentially
altering them, while both parties believe they are communicating directly?

A. Replay attack
B. Man-in-the-middle attack
C. Denial-of-service attack
D. Phishing attack

🟢 Correct Answer: B. Man-in-the-middle attack

Document information

Uploaded on
August 21, 2026
Number of pages
68
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$23.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
tutorlorghon
4.7
(254)
Sold
780
Followers
19
Items
6672
Last sold
12 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions