Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 111 páginas
Examen

CompTIA Security+ SY0-701: Exam Prep with 200+ Questions & Rationales

Document preview thumbnail
Vista previa 4 fuera de 111 páginas

Ace the CompTIA Security+ SY0-701 certification exam with this comprehensive practice guide featuring over 200 questions mirroring the actual exam format. Covering all domains including threats and vulnerabilities, architecture and design, implementation, operations and incident response, and governance/risk/compliance—this resource is updated for the exam objectives. Each question includes expert rationales explaining correct answers and why incorrect options are wrong, helping you understand the reasoning behind every answer. Perfect for IT professionals, security analysts, and anyone pursuing cybersecurity certification. Features questions on network security, identity management, cryptography, PKI, risk management, and the latest threat intelligence. Get certified with confidence!

Vista previa del contenido

1|Page




CompTIA Security+ (SY0-701) – CompTIA – 2026–2027
Edition Exam Preparation With Complete Questions And
Correct Answers With Rationales Already Graded
A+Brand New Version!!



1. A security analyst is implementing a new wireless network and must
ensure that data transmitted over the air is protected with the highest
level of encryption available for enterprise environments. Which of the
following protocols should the analyst deploy?
A) WEP
B) WPA
C) WPA2 with TKIP
D) WPA3 with SAE
Answer: D
Explanation: WPA3 with Simultaneous Authentication of Equals (SAE)
provides the most robust encryption and authentication for wireless
networks. It replaces the Pre-Shared Key (PSK) method of WPA2 with a
more secure key exchange resistant to offline dictionary attacks. WEP is
obsolete, WPA is outdated, and WPA2 with TKIP is less secure than the
AES-based encryption of WPA3.

,2|Page


2. A company wants to ensure that a single compromised employee
credential does not allow an attacker to access all sensitive internal
systems. Which access control principle is specifically designed to
mitigate this risk?
A) Principle of least privilege
B) Separation of duties
C) Mandatory Access Control
D) Role-Based Access Control
Answer: A
Explanation: The principle of least privilege ensures that users are
granted only the minimum necessary permissions to perform their job
functions. By limiting access, a compromised account cannot be used to
access systems or data beyond the user's legitimate scope, thereby
containing the potential damage.


3. An organization is required to maintain detailed logs of all user
authentication attempts, including successful and failed logins, for a
period of five years. Which of the following best describes this
requirement?
A) Data retention policy
B) Data classification policy
C) Acceptable use policy
D) Password policy
Answer: A

,3|Page


Explanation: A data retention policy dictates how long an organization
must keep certain types of data, often for regulatory, legal, or
operational reasons. The requirement to keep authentication logs for
five years falls directly under such a policy, specifying the retention
period for these specific records.


4. A security administrator is configuring a firewall to prevent external
attackers from discovering which internal services are running. Which
of the following techniques is most effective at hiding the presence of
open ports?
A) Stateful inspection
B) Packet filtering
C) Port address translation (PAT)
D) Implicit deny
Answer: C
Explanation: Port Address Translation (PAT), a form of Network Address
Translation (NAT), hides internal port numbers by mapping them to a
single public IP address with different source ports. This obscures the
internal service structure from external scans. While packet filtering and
stateful inspection control traffic, PAT actively conceals port details.


5. An employee accidentally emails a file containing customers'
personally identifiable information (PII) to an unauthorized external
recipient. The security team is notified and must determine the scope
of the data exposure. What is the FIRST step in the incident response
process in this scenario?

, 4|Page


A) Eradication
B) Containment
C) Detection and analysis
D) Recovery
Answer: C
Explanation: The incident response process begins with detection and
analysis. The security team must first confirm that an incident has
occurred and gather initial details about the event, such as what data
was exposed, who the unauthorized recipient is, and how the exposure
happened, before moving to containment or eradication.


6. A developer needs to securely store API keys and database
passwords used by a cloud application. Which of the following is the
MOST secure method for managing these secrets?
A) Hardcoding them in the application source code
B) Storing them in a configuration file with restricted file permissions
C) Using a dedicated secrets management service (e.g., HashiCorp
Vault, AWS Secrets Manager)
D) Encrypting them with a symmetric key stored in the same source
code repository
Answer: C
Explanation: Secrets management services are designed specifically to
store, access, and rotate secrets securely. They offer centralized
management, auditing, encryption at rest and in transit, and fine-
grained access control, eliminating the risks associated with hardcoding

Información del documento

Subido en
16 de agosto de 2026
Número de páginas
111
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$25.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Vendido
2
Seguidores
2
Artículos
1446
Última venta
1 mes hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes