CompTIA Security+ SY0-701 – Practice Exam Bank
(Original Practice Questions – Not Actual CompTIA Items)
Instructions:
One best answer per question.
Correct answer: bold.
Rationale: italics.
Domain 1: General Security Concepts (1–30)
1. Which of the following best describes the CIA triad?
A. Confidentiality, Integrity, Availability
B. Control, Identity, Authentication
C. Compliance, Inspection, Auditing
D. Cryptography, Identity, Authorization
Answer: A
Rationale: The CIA triad is Confidentiality, Integrity, and Availability.
2. A company requires that only authorized users can view sensitive data. This is primarily an
example of:
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: A
Rationale: Confidentiality ensures data is accessible only to authorized users.
3. Ensuring that data has not been altered in transit is primarily an example of:
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Answer: B
Rationale: Integrity ensures data is accurate and unaltered.
4. Which of the following best describes “availability” in security?
A. Data is encrypted at rest
B. Systems and data are accessible to authorized users when needed
, C. Users are authenticated via MFA
D. Logs are retained for 1 year
Answer: B
Rationale: Availability ensures timely and reliable access to systems and data.
5. A security control that deters an attacker from attempting an attack is best described as a:
A. Preventive control
B. Detective control
C. Deterrent control
D. Corrective control
Answer: C
Rationale: Deterrent controls discourage potential attackers (e.g., warning signs,
policies).
6. Which of the following is an example of a preventive control?
A. Firewall blocking unauthorized traffic
B. IDS alerting on suspicious traffic
C. Backup restoration after ransomware
D. Log review
Answer: A
Rationale: Firewalls prevent unauthorized access; they are preventive.
7. An intrusion detection system (IDS) that alerts on suspicious activity is primarily a:
A. Preventive control
B. Detective control
C. Deterrent control
D. Corrective control
Answer: B
Rationale: IDS detects and alerts; it does not block traffic by itself.
8. Restoring systems from backups after a ransomware attack is an example of a:
A. Preventive control
B. Detective control
C. Corrective control
D. Deterrent control
Answer: C
Rationale: Corrective controls restore normal operations after an incident.
9. Which of the following best describes “defense in depth”?
A. Relying on a single strong control
B. Layering multiple security controls across people, processes, and technology
, C. Using only encryption
D. Outsourcing all security
Answer: B
Rationale: Defense in depth uses multiple layers of controls.
10. A policy that requires employees to lock their workstations when away is primarily a:
A. Technical control
B. Physical control
C. Administrative control
D. Detective control
Answer: C
Rationale: Policies and procedures are administrative controls.
11. Which of the following is a technical control?
A. Security awareness training
B. Firewall rules
C. Guard at the entrance
D. Background checks
Answer: B
Rationale: Firewalls are technical (logical) controls.
12. A guard at a data center entrance is primarily a:
A. Technical control
B. Physical control
C. Administrative control
D. Detective control
Answer: B
Rationale: Guards are physical security controls.
13. Which of the following best describes “zero trust”?
A. Trust all internal users by default
B. Never trust, always verify; enforce least privilege and micro-segmentation
C. Trust external partners completely
D. Use only perimeter firewalls
Answer: B
Rationale: Zero trust assumes no implicit trust and verifies every access request.
14. In a zero trust architecture, access decisions are primarily based on:
A. Network location only
B. Identity, device posture, and context
C. Physical location only
D. Time of day only
, Answer: B
Rationale: Zero trust uses identity, device health, and context for access decisions.
15. Which of the following is a key principle of least privilege?
A. Users have maximum access by default
B. Users have only the access necessary to perform their job functions
C. All users share the same admin account
D. Access is never reviewed
Answer: B
Rationale: Least privilege limits access to what is required for the role.
16. A company implements MFA for all remote access. This primarily improves:
A. Confidentiality only
B. Integrity only
C. Authentication strength
D. Physical security
Answer: C
Rationale: MFA strengthens authentication by requiring multiple factors.
17. Which of the following is an example of “security through obscurity”?
A. Using strong encryption
B. Hiding a service on a non-standard port without other controls
C. Implementing MFA
D. Using role-based access control
Answer: B
Rationale: Relying on hiding details (e.g., non-standard ports) without real
controls is security through obscurity.
18. Which of the following best describes “risk appetite”?
A. The total amount of risk an organization is willing to accept
B. The cost of all security controls
C. The number of incidents per year
D. The number of employees
Answer: A
Rationale: Risk appetite is the level of risk an organization is willing to tolerate.
19. A company decides to purchase cyber insurance to cover potential losses from a data breach.
This is an example of:
A. Risk avoidance
B. Risk mitigation
C. Risk transfer
D. Risk acceptance
(Original Practice Questions – Not Actual CompTIA Items)
Instructions:
One best answer per question.
Correct answer: bold.
Rationale: italics.
Domain 1: General Security Concepts (1–30)
1. Which of the following best describes the CIA triad?
A. Confidentiality, Integrity, Availability
B. Control, Identity, Authentication
C. Compliance, Inspection, Auditing
D. Cryptography, Identity, Authorization
Answer: A
Rationale: The CIA triad is Confidentiality, Integrity, and Availability.
2. A company requires that only authorized users can view sensitive data. This is primarily an
example of:
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: A
Rationale: Confidentiality ensures data is accessible only to authorized users.
3. Ensuring that data has not been altered in transit is primarily an example of:
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Answer: B
Rationale: Integrity ensures data is accurate and unaltered.
4. Which of the following best describes “availability” in security?
A. Data is encrypted at rest
B. Systems and data are accessible to authorized users when needed
, C. Users are authenticated via MFA
D. Logs are retained for 1 year
Answer: B
Rationale: Availability ensures timely and reliable access to systems and data.
5. A security control that deters an attacker from attempting an attack is best described as a:
A. Preventive control
B. Detective control
C. Deterrent control
D. Corrective control
Answer: C
Rationale: Deterrent controls discourage potential attackers (e.g., warning signs,
policies).
6. Which of the following is an example of a preventive control?
A. Firewall blocking unauthorized traffic
B. IDS alerting on suspicious traffic
C. Backup restoration after ransomware
D. Log review
Answer: A
Rationale: Firewalls prevent unauthorized access; they are preventive.
7. An intrusion detection system (IDS) that alerts on suspicious activity is primarily a:
A. Preventive control
B. Detective control
C. Deterrent control
D. Corrective control
Answer: B
Rationale: IDS detects and alerts; it does not block traffic by itself.
8. Restoring systems from backups after a ransomware attack is an example of a:
A. Preventive control
B. Detective control
C. Corrective control
D. Deterrent control
Answer: C
Rationale: Corrective controls restore normal operations after an incident.
9. Which of the following best describes “defense in depth”?
A. Relying on a single strong control
B. Layering multiple security controls across people, processes, and technology
, C. Using only encryption
D. Outsourcing all security
Answer: B
Rationale: Defense in depth uses multiple layers of controls.
10. A policy that requires employees to lock their workstations when away is primarily a:
A. Technical control
B. Physical control
C. Administrative control
D. Detective control
Answer: C
Rationale: Policies and procedures are administrative controls.
11. Which of the following is a technical control?
A. Security awareness training
B. Firewall rules
C. Guard at the entrance
D. Background checks
Answer: B
Rationale: Firewalls are technical (logical) controls.
12. A guard at a data center entrance is primarily a:
A. Technical control
B. Physical control
C. Administrative control
D. Detective control
Answer: B
Rationale: Guards are physical security controls.
13. Which of the following best describes “zero trust”?
A. Trust all internal users by default
B. Never trust, always verify; enforce least privilege and micro-segmentation
C. Trust external partners completely
D. Use only perimeter firewalls
Answer: B
Rationale: Zero trust assumes no implicit trust and verifies every access request.
14. In a zero trust architecture, access decisions are primarily based on:
A. Network location only
B. Identity, device posture, and context
C. Physical location only
D. Time of day only
, Answer: B
Rationale: Zero trust uses identity, device health, and context for access decisions.
15. Which of the following is a key principle of least privilege?
A. Users have maximum access by default
B. Users have only the access necessary to perform their job functions
C. All users share the same admin account
D. Access is never reviewed
Answer: B
Rationale: Least privilege limits access to what is required for the role.
16. A company implements MFA for all remote access. This primarily improves:
A. Confidentiality only
B. Integrity only
C. Authentication strength
D. Physical security
Answer: C
Rationale: MFA strengthens authentication by requiring multiple factors.
17. Which of the following is an example of “security through obscurity”?
A. Using strong encryption
B. Hiding a service on a non-standard port without other controls
C. Implementing MFA
D. Using role-based access control
Answer: B
Rationale: Relying on hiding details (e.g., non-standard ports) without real
controls is security through obscurity.
18. Which of the following best describes “risk appetite”?
A. The total amount of risk an organization is willing to accept
B. The cost of all security controls
C. The number of incidents per year
D. The number of employees
Answer: A
Rationale: Risk appetite is the level of risk an organization is willing to tolerate.
19. A company decides to purchase cyber insurance to cover potential losses from a data breach.
This is an example of:
A. Risk avoidance
B. Risk mitigation
C. Risk transfer
D. Risk acceptance