CompTIA Security+ SY0-701 Practice
Exam Most Tested Questions
Collection & Verified Detailed Answers
With Rationales| Tutor Verified
Success Exam) Graded A+
1. Which security principle ensures that users receive only the
permissions required to perform their assigned duties?
A. Separation of duties
B. Least privilege
C. Job rotation
D. Mandatory vacation
Answer: B. Least privilege
Rationale: Least privilege limits users, applications, and processes to
only the permissions necessary to perform their tasks, reducing the
potential impact of compromise.
2. Which security objective is primarily concerned with preventing
unauthorized modification of data?
A. Availability
B. Confidentiality
C. Integrity
D. Authentication
Answer: C. Integrity
Rationale: Integrity ensures that information remains accurate and
has not been improperly altered.
,3. An organization deploys redundant servers so that an application
remains accessible when one server fails. Which security objective
does this primarily support?
A. Confidentiality
B. Availability
C. Non-repudiation
D. Privacy
Answer: B. Availability
Rationale: Availability ensures that systems and information remain
accessible to authorized users when needed.
4. Which control is an example of a preventive control?
A. Security camera reviewing an incident
B. Audit log
C. Firewall blocking unauthorized traffic
D. Incident report
Answer: C. Firewall blocking unauthorized traffic
Rationale: Preventive controls attempt to stop unwanted events
before they occur.
5. Which control is primarily detective?
A. Intrusion detection system
B. Password policy
C. Firewall rule
D. Security awareness training
Answer: A. Intrusion detection system
,Rationale: An IDS monitors activity and identifies potentially
malicious behavior, making it primarily a detective control.
6. What is the primary purpose of a honeypot?
A. Encrypt production databases
B. Attract and monitor attackers
C. Replace a firewall
D. Increase bandwidth
Answer: B. Attract and monitor attackers
Rationale: Honeypots are deliberately exposed systems or services
designed to attract suspicious activity and provide intelligence about
attackers.
7. Which concept requires two or more independent individuals to
complete a sensitive operation?
A. Least privilege
B. Separation of duties
C. Federation
D. Single sign-on
Answer: B. Separation of duties
Rationale: Separation of duties reduces fraud and abuse by dividing
sensitive responsibilities among multiple people.
8. Which term describes confidence that a user, device, or system is
who or what it claims to be?
A. Authorization
B. Accounting
, C. Authentication
D. Availability
Answer: C. Authentication
Rationale: Authentication verifies identity. Authorization determines
what the authenticated entity is permitted to access.
9. A company requires managers to approve access requests before
users receive permissions. What security function is being
performed?
A. Authorization
B. Identification
C. Accounting
D. Encryption
Answer: A. Authorization
Rationale: Authorization determines whether an authenticated entity
should be permitted to access a resource.
10. Which technology is most directly associated with proving that
a message was created by a particular sender and was not altered?
A. Digital signature
B. RAID
C. NAT
D. VLAN
Answer: A. Digital signature
Rationale: Digital signatures provide integrity and authentication and
can support non-repudiation.
Exam Most Tested Questions
Collection & Verified Detailed Answers
With Rationales| Tutor Verified
Success Exam) Graded A+
1. Which security principle ensures that users receive only the
permissions required to perform their assigned duties?
A. Separation of duties
B. Least privilege
C. Job rotation
D. Mandatory vacation
Answer: B. Least privilege
Rationale: Least privilege limits users, applications, and processes to
only the permissions necessary to perform their tasks, reducing the
potential impact of compromise.
2. Which security objective is primarily concerned with preventing
unauthorized modification of data?
A. Availability
B. Confidentiality
C. Integrity
D. Authentication
Answer: C. Integrity
Rationale: Integrity ensures that information remains accurate and
has not been improperly altered.
,3. An organization deploys redundant servers so that an application
remains accessible when one server fails. Which security objective
does this primarily support?
A. Confidentiality
B. Availability
C. Non-repudiation
D. Privacy
Answer: B. Availability
Rationale: Availability ensures that systems and information remain
accessible to authorized users when needed.
4. Which control is an example of a preventive control?
A. Security camera reviewing an incident
B. Audit log
C. Firewall blocking unauthorized traffic
D. Incident report
Answer: C. Firewall blocking unauthorized traffic
Rationale: Preventive controls attempt to stop unwanted events
before they occur.
5. Which control is primarily detective?
A. Intrusion detection system
B. Password policy
C. Firewall rule
D. Security awareness training
Answer: A. Intrusion detection system
,Rationale: An IDS monitors activity and identifies potentially
malicious behavior, making it primarily a detective control.
6. What is the primary purpose of a honeypot?
A. Encrypt production databases
B. Attract and monitor attackers
C. Replace a firewall
D. Increase bandwidth
Answer: B. Attract and monitor attackers
Rationale: Honeypots are deliberately exposed systems or services
designed to attract suspicious activity and provide intelligence about
attackers.
7. Which concept requires two or more independent individuals to
complete a sensitive operation?
A. Least privilege
B. Separation of duties
C. Federation
D. Single sign-on
Answer: B. Separation of duties
Rationale: Separation of duties reduces fraud and abuse by dividing
sensitive responsibilities among multiple people.
8. Which term describes confidence that a user, device, or system is
who or what it claims to be?
A. Authorization
B. Accounting
, C. Authentication
D. Availability
Answer: C. Authentication
Rationale: Authentication verifies identity. Authorization determines
what the authenticated entity is permitted to access.
9. A company requires managers to approve access requests before
users receive permissions. What security function is being
performed?
A. Authorization
B. Identification
C. Accounting
D. Encryption
Answer: A. Authorization
Rationale: Authorization determines whether an authenticated entity
should be permitted to access a resource.
10. Which technology is most directly associated with proving that
a message was created by a particular sender and was not altered?
A. Digital signature
B. RAID
C. NAT
D. VLAN
Answer: A. Digital signature
Rationale: Digital signatures provide integrity and authentication and
can support non-repudiation.