2026-2027: 200 Practice Questions with Correct
Answers and Clear Rationales for Exam Success
Pass A+
Introduction
The CompTIA Security+ SY0-701 certification remains one of the most sought-after credentials for
cybersecurity professionals in 2026. As the foundational certification for IT security roles, it validates
the core knowledge required to secure networks, detect threats, and implement appropriate security
controls across enterprise environments . With the current exam version running through May 2027,
2026 represents an ideal window to pursue certification without the disruption of a mid-study exam
update .
Domain 1: General Security Concepts (12%)
Questions 1-24
Question 1: Which of the following security concepts describes the process of verifying that a user's
session has not been hijacked by re-authenticating for sensitive transactions?
A. Session Management
B. Continuous Validation
C. Step-up Authentication
D. Single Sign-On
Rationale: Step-up authentication requires additional authentication factors when users attempt to
access sensitive resources or perform high-risk transactions. This reduces the risk of session hijacking
by ensuring the legitimate user is still in control before allowing sensitive operations .
Question 2: A company implements mandatory vacation policies for employees in financial roles. What
is the primary security purpose of this policy?
A. To ensure employees receive adequate rest
B. To detect fraud or irregularities that require ongoing access
C. To reduce labor costs during slow periods
D. To comply with labor laws
,Rationale: Mandatory vacation policies require employees to be away from their duties for a period,
during which another person performs their job. This can reveal fraudulent activities that depend on
the employee maintaining continuous control over processes without oversight .
Question 3: Which control type is designed to reduce the impact of an incident that has already
occurred?
A. Preventive
B. Detective
C. Corrective
D. Deterrent
Rationale: Corrective controls are implemented after an incident to restore systems and reduce
impact. Examples include backup restoration, system patching, and incident response procedures .
Question 4: A security analyst is explaining the DAD triad to new team members. What does DAD
represent in the context of security?
A. Disclosure, Alteration, and Denial
B. Detection, Analysis, and Defense
C. Data, Access, and Delivery
D. Defense, Assessment, and Documentation
Rationale: The DAD triad represents the opposite of the CIA triad—Disclosure (confidentiality breach),
Alteration (integrity breach), and Denial (availability breach). Understanding DAD helps security
professionals identify the negative outcomes that security controls aim to prevent.
Question 5: Which security control is classified as both physical and preventive?
A. Security awareness training
B. Data encryption
C. Intrusion detection system
D. Mantrap at a building entrance
Rationale: A mantrap is a physical control (a physical structure) that serves a preventive function by
preventing unauthorized individuals from entering a secured area after the first door closes before the
second opens .
Question 6: A software company wants to migrate to a single, integrated authentication solution that is
more secure and provides a smoother login experience. Which solution best satisfies this need?
A. Migrating to FIDO2 passkeys utilizing built-in device biometrics
B. Implementing SMS-based one-time passwords as the primary second factor
,C. Implementing SAML federation for SSO access
D. Deploying a PKI system requiring smart cards for login
Rationale: FIDO2 passkeys allow passwordless authentication using cryptographic credentials stored
on the user's device, often unlocked with biometrics or a local PIN. This improves both security
(phishing resistance) and usability (no password manager plus authenticator app required) .
Question 7: The principle that requires a user to be re-authenticated before performing highly sensitive
operations is known as:
A. Continuous authentication
B. Step-up authentication
C. Multi-factor authentication
D. Adaptive authentication
Rationale: Step-up authentication dynamically increases authentication requirements when users
access sensitive resources or perform high-risk actions. This reduces the window of opportunity for
session hijacking attacks.
Question 8: Which of the following is an example of a deterrent control?
A. Firewall rules blocking malicious traffic
B. Warning signs posted at building entrances
C. Security cameras recording activity
D. Intrusion prevention system blocking attacks
Rationale: Deterrent controls discourage potential attackers from attempting to breach security.
Warning signs serve as a deterrent by signaling the presence of security measures and legal
consequences for unauthorized access.
Question 9: A company is concerned that lost laptops could expose locally stored customer data. Which
control most directly protects the data if a device is stolen while powered off?
A. A longer desktop wallpaper message
B. Disabling screen lock timers
C. Using a faster Wi-Fi standard
D. Full-disk encryption with protected keys and enforced authentication
Rationale: Full-disk encryption protects data at rest when the device is lost or stolen, assuming keys
and authentication are managed correctly. Other options either do not protect stored data or weaken
endpoint protection .
, Question 10: Which concept ensures that no single individual has complete control over a critical
process without oversight?
A. Separation of duties
B. Least privilege
C. Defense in depth
D. Job rotation
Rationale: Separation of duties is implemented by splitting responsibilities among multiple individuals.
The administrator performs actions while the security team reviews them, ensuring no single person
has complete control without oversight .
Question 11: Which cryptographic solution provides non-repudiation for digital communications?
A. Symmetric encryption
B. Digital signatures
C. Hashing
D. Steganography
Rationale: Digital signatures provide non-repudiation by ensuring that a message or document was
signed by the claimed sender and has not been altered. They use asymmetric cryptography where the
sender's private key signs the content, and the recipient verifies with the public key.
Question 12: A security administrator implements a policy requiring that all changes to production
systems must be documented, approved, and tested before deployment. This is an example of:
A. Risk management
B. Change management
C. Configuration management
D. Incident management
Rationale: Change management processes ensure that modifications to systems are properly
evaluated, approved, and documented to prevent unintended security consequences. This includes
assessing the impact of changes and maintaining rollback procedures .
Question 13: Which of the following best describes a compensating control?
A. A control that prevents security incidents from occurring
B. A control that detects security violations after they occur
C. An alternative control that meets the same security objective when the primary control is not
feasible
D. A control that corrects the effects of a security incident