COMPTIA SECURITY+ SY0-701 EXAM
AND PRACTICE EXAM NEWEST 2026/
2027 | SY0-701 BY COMPTIA EXAM PREP
WITH COMPLETE 200 REAL EXAM
QUESTIONS AND CORRECT DETAILED
ANSWERS (VERIFIED ANSWERS)
ALREADY GRADED A+ (MOST RECENT!!)
Domain 1: General Security Concepts (12%) — Questions 1-
35
1. A systems administrator wants to make it impossible to deny that someone has
performed an action. What is this called?
A. Non-repudiation
B. Adaptive identity
C. Security zones
D. Deception and disruption
Answer: A. Non-repudiation — Provides proof of origin or delivery of data to prevent
the sender from denying the action.
2. Which type of control decreases the likelihood of a cybersecurity breach
occurring?
,A. Corrective
B. Transfer
C. Detective
D. Preventive
Answer: D. Preventive — These controls stop security incidents before they happen.
3. What is the principle of least privilege?
A. Giving users all permissions they request
B. Granting users only the minimum access rights needed to perform their job
C. Requiring two forms of authentication
D. Limiting the number of users in an organization
Answer: B — Least privilege is a fundamental security principle that minimizes access to
reduce risk.
4. Which of the following is an example of a detective control?
A. Firewall rules
B. Encryption
C. Security audit log review
D. Biometric authentication
Answer: C — Detective controls identify and log events after they occur; logs are
detective in nature.
,5. What is a compensating control?
A. A control that completely prevents an attack
B. An alternative control used when the primary control is not feasible
C. A control that detects attacks after they happen
D. A control that transfers risk to a third party
Answer: B — Compensating controls provide an alternative when the preferred control
cannot be implemented.
6. Which security principle ensures data is accessible when needed by authorized
users?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: C — Availability ensures authorized users can access systems and data when
needed.
7. A company implements multi-factor authentication (MFA). This is an example of
which type of control?
A. Administrative
B. Technical
C. Physical
D. Deterrent
, Answer: B — MFA is a technical (logical) control implemented through
software/hardware.
8. A security guard checking employee IDs at the entrance is an example of which
control category?
A. Technical
B. Administrative
C. Physical
D. Detective
Answer: C — Physical controls include guards, fences, locks, and other tangible security
measures.
9. Which type of security control is an acceptable use policy (AUP)?
A. Technical
B. Administrative
C. Physical
D. Corrective
Answer: B — Administrative controls are policies, procedures, and guidelines that
govern behavior.
10. What is defense in depth?
AND PRACTICE EXAM NEWEST 2026/
2027 | SY0-701 BY COMPTIA EXAM PREP
WITH COMPLETE 200 REAL EXAM
QUESTIONS AND CORRECT DETAILED
ANSWERS (VERIFIED ANSWERS)
ALREADY GRADED A+ (MOST RECENT!!)
Domain 1: General Security Concepts (12%) — Questions 1-
35
1. A systems administrator wants to make it impossible to deny that someone has
performed an action. What is this called?
A. Non-repudiation
B. Adaptive identity
C. Security zones
D. Deception and disruption
Answer: A. Non-repudiation — Provides proof of origin or delivery of data to prevent
the sender from denying the action.
2. Which type of control decreases the likelihood of a cybersecurity breach
occurring?
,A. Corrective
B. Transfer
C. Detective
D. Preventive
Answer: D. Preventive — These controls stop security incidents before they happen.
3. What is the principle of least privilege?
A. Giving users all permissions they request
B. Granting users only the minimum access rights needed to perform their job
C. Requiring two forms of authentication
D. Limiting the number of users in an organization
Answer: B — Least privilege is a fundamental security principle that minimizes access to
reduce risk.
4. Which of the following is an example of a detective control?
A. Firewall rules
B. Encryption
C. Security audit log review
D. Biometric authentication
Answer: C — Detective controls identify and log events after they occur; logs are
detective in nature.
,5. What is a compensating control?
A. A control that completely prevents an attack
B. An alternative control used when the primary control is not feasible
C. A control that detects attacks after they happen
D. A control that transfers risk to a third party
Answer: B — Compensating controls provide an alternative when the preferred control
cannot be implemented.
6. Which security principle ensures data is accessible when needed by authorized
users?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: C — Availability ensures authorized users can access systems and data when
needed.
7. A company implements multi-factor authentication (MFA). This is an example of
which type of control?
A. Administrative
B. Technical
C. Physical
D. Deterrent
, Answer: B — MFA is a technical (logical) control implemented through
software/hardware.
8. A security guard checking employee IDs at the entrance is an example of which
control category?
A. Technical
B. Administrative
C. Physical
D. Detective
Answer: C — Physical controls include guards, fences, locks, and other tangible security
measures.
9. Which type of security control is an acceptable use policy (AUP)?
A. Technical
B. Administrative
C. Physical
D. Corrective
Answer: B — Administrative controls are policies, procedures, and guidelines that
govern behavior.
10. What is defense in depth?