ADVANCED PRACTICE EXAMINATION
90 Questions
Answers + Detailed Explanations
CompTIA Security+ SY0-701 Exam
,1. A security architect reviews the following simplified network:
Internet
|
[Edge Firewall]
|
[DMZ] ---- [Public Web Server]
|
[Internal Firewall]
|
[User Network] ---- [Database Network]
A web server is compromised through an internet-facing vulnerability. Which change
would BEST reduce the attacker's ability to reach the database?
A. A. Place the database on the same subnet as the web server
B. B. Permit all traffic from the DMZ to the database
C. C. Restrict traffic between the web tier and database tier with segmentation and least-
privilege firewall rules
D. D. Disable logging on the internal firewall
Correct Answer: C
Explanation: Segmentation creates a security boundary between tiers, while restrictive firewall
rules limit which systems and ports can communicate. This reduces lateral movement if the web
server is compromised.
2. An attacker sends an email that appears to come from the chief executive and asks the
finance department to urgently transfer money to a new account. Which attack is MOST
likely?
A. A. Business email compromise
B. B. Bluejacking
C. C. Tailgating
D. D. DNS tunneling
Correct Answer: A
Explanation: Business email compromise uses trusted business identities or compromised
accounts to manipulate employees into actions such as fraudulent payments.
3. A web application accepts user input that becomes part of a database query, allowing an
attacker to retrieve records from tables they should not access. Which vulnerability is
involved?
A. B. Cross-site scripting
B. A. SQL injection
CompTIA Security+ SY0-701 Exam
, C. C. Race condition
D. D. Directory traversal
Correct Answer: B
Explanation: SQL injection occurs when untrusted input is interpreted as database commands.
Parameterized queries and input validation are key defenses.
4. A security analyst discovers that a workstation is communicating with a known
malicious command-and-control server. Which action should generally occur FIRST?
A. B. Delete every suspicious file before collecting evidence
B. C. Rebuild every company server
C. A. Isolate or contain the affected endpoint
D. D. Announce a confirmed data breach publicly
Correct Answer: C
Explanation: Containment limits further communication and spread while preserving the
opportunity for investigation. Destructive actions can destroy useful evidence.
5. An organization wants cloud access decisions to consider user identity, device health,
location, and the sensitivity of the requested resource instead of automatically trusting
internal users. Which architecture BEST fits?
A. B. Flat network
B. C. Open access
C. D. Perimeter-only security
D. A. Zero Trust
Correct Answer: D
Explanation: Zero Trust removes implicit trust based on network location and uses contextual
access decisions with continuous verification.
6. A security operations center wants to collect and correlate authentication, firewall,
endpoint, and application events in one platform. Which technology is MOST appropriate?
A. A. SIEM
B. B. RAID
C. C. Hypervisor
D. D. VPN concentrator
Correct Answer: A
Explanation: A SIEM aggregates and correlates security events from multiple sources to support
centralized monitoring and investigation.
7. A company wants to compare a workstation's current configuration with an approved
secure configuration. What is being used?
CompTIA Security+ SY0-701 Exam