Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 54 páginas
Examen

CompTIA Security+ SY0-701: Complete Practice Question Bank with Rationales (2026/2027 Edition)

Document preview thumbnail
Vista previa 4 fuera de 54 páginas

CompTIA Security+ SY0-701: Complete Practice Question Bank with Rationales (2026/2027 Edition)

Vista previa del contenido

CompTIA Security+ SY0-701:
Complete Practice Question Bank
with Rationales (2026/2027 Edition)

Question 1
A business development team reports that files are missing from the
database system and the server login screens are showing a lock symbol
requiring users to contact an email address to access the system and data.
Which type of attack is the company facing?

A. Rootkit
B. Ransomware
C. Spyware
D. Bloatware

Answer : B. Ransomware

Rationale: Ransomware is malware that encrypts files and displays a ransom
note demanding payment for decryption. The lock symbol and contact email
are classic indicators of a ransomware infection .




Question 2
During a security incident, the security operations team identified sustained
network traffic from a malicious IP address: 10.1.4.9. A security analyst is
creating an inbound firewall rule to block this IP. Which ACL fulfills this
request?

,A. access-list inbound deny ip source 0.0.0.0/0 destination 10.1.4.9/32
B. access-list inbound deny ip source 10.1.4.9/32 destination 0.0.0.0/0
C. access-list inbound permit ip source 10.1.4.9/32 destination 0.0.0.0/0
D. access-list inbound permit ip source 0.0.0.0/0 destination 10.1.4.9/32

Answer : B. access-list inbound deny ip source 10.1.4.9/32 destination
0.0.0.0/0

Rationale: For an inbound rule, the source is the external malicious IP and the
destination is the internal network (0.0.0.0/0 represents any destination). The
rule must deny (block) traffic from the malicious source .




Question 3
Which threat actor is most likely to use common hacking tools found on
the internet to attempt to remotely compromise an organization's web
server?

A. Organized crime
B. Insider threat
C. Unskilled attacker
D. Nation-state

Answer : C. Unskilled attacker

Rationale: Unskilled attackers (script kiddies) typically use readily available
tools and exploits found on the internet without deep technical
understanding. They lack the sophisticated custom tools used by nation-
states or organized crime .

,Question 4
A systems administrator wants to set up a system that makes it difficult or
impossible to deny that someone has performed an action. What is the
administrator trying to accomplish?

A. Non-repudiation
B. Adaptive identity
C. Security zones
D. Deception and disruption

Answer : A. Non-repudiation

Rationale: Non-repudiation ensures that an individual cannot deny having
performed a specific action. This is typically achieved through digital
signatures, audit logs, and authentication systems .




Question 5
Which type of control decreases the likelihood of a cybersecurity breach
occurring?

A. Corrective
B. Transfer
C. Detective
D. Preventive

Answer : D. Preventive

Rationale: Preventive controls are designed to stop security incidents before
they occur. Examples include firewalls, access controls, and encryption.
Corrective controls fix issues after detection, detective controls identify
incidents, and transfer controls shift risk .

, Question 6
A company is expanding its threat surface program by allowing researchers
to security test the company's internet-facing application and
compensating them based on vulnerabilities discovered. What best
describes this program?

A. Open-source intelligence
B. Bug bounty
C. Red team
D. Penetration testing

Answer : B. Bug bounty

Rationale: A bug bounty program invites external security researchers to find
and report vulnerabilities in exchange for monetary rewards. This differs from
penetration testing, which is typically a contracted, time-bound engagement .




Question 7
What is the final step of the incident response process?

A. Containment
B. Lessons learned
C. Eradication
D. Detection

Answer : B. Lessons learned

Rationale: The incident response lifecycle (NIST SP 800-61) includes
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and

Información del documento

Subido en
7 de agosto de 2026
Número de páginas
54
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$20.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Vendido
3
Seguidores
0
Artículos
891
Última venta
2 días hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes