CompTIAAssociate levelSY0-701

SY0-701 exam dumps: 490 free CompTIA Security+ practice questions

Free SY0-701 practice questions for the Security+ exam, with the correct answer and a full explanation for every option. Read the first 10 below, browse all 490 by number, or take a timed practice exam.

Question bank last updated June 2026

Free SY0-701 practice questions

Questions 1 to 10 of 490

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

SY0-701 Question 1

Select 21.1 Compare and contrast various types of security controls.

A healthcare company experienced a phishing incident that led to unauthorized access to an employee's email account. During the post-incident review, management decides to reduce the likelihood of similar compromises and to improve the ability to detect them quickly if they occur again. Which TWO security controls best meet these goals?

  1. A

    Implement mandatory annual security awareness training focused on phishing recognition

  2. B

    Deploy multifactor authentication (MFA) for employee email access

  3. C

    Install bollards outside the main office entrance

  4. D

    Enable security information and event management (SIEM) alerting for suspicious sign-in activity

  5. E

    Purchase cyber liability insurance

Show answer and explanation

Correct answers: B, D

Explanation

This question tests the ability to compare and apply different types of security controls in a real-world scenario. The best answers are MFA and SIEM alerting because they align directly with the two stated goals: prevention and detection. MFA is a preventive technical control that reduces the chance of successful account compromise after credential theft. SIEM alerting is a detective technical control that improves visibility into suspicious authentication events so responders can act quickly. Security awareness training is also valuable and is commonly recommended in security programs, but in this scenario it addresses only part of the requirement and does not provide direct technical detection. Physical controls like bollards and risk-transfer measures like insurance are valid security-related measures, but they do not address the email account compromise scenario. This mapping of controls is consistent with common Security+ classifications such as preventive, detective, corrective, deterrent, compensating, physical, technical, and administrative controls, and aligns with widely accepted guidance such as NIST security control families and general best practices for identity and access management and security monitoring.

  • A. Incorrect.

    This is a plausible choice because security awareness training is an administrative control and can help reduce phishing success. However, the scenario asks for controls that both reduce the likelihood of account compromise and improve rapid detection if compromise occurs. Training helps prevention but does not directly improve technical detection of suspicious account use. It is beneficial, but it does not best satisfy both goals together compared with MFA and SIEM alerting.

  • B. Correct.

    This is correct. MFA is a preventive technical control that reduces the likelihood that stolen credentials alone will result in unauthorized access. In real environments, phishing often captures passwords, and MFA adds an additional factor that significantly limits account takeover risk.

  • C. Incorrect.

    This is incorrect. Bollards are a physical preventive control designed to protect people and facilities from vehicle-based threats. They do not address phishing-related email compromise or account misuse, so they are not relevant to the stated goals.

  • D. Correct.

    This is correct. SIEM alerting for suspicious sign-in activity is a detective technical control. It helps security teams identify anomalous behavior such as impossible travel, repeated failed logins, unusual geolocation, or atypical login times, improving the organization's ability to detect compromised accounts quickly.

  • E. Incorrect.

    This is incorrect. Cyber liability insurance is a compensating or risk-transfer measure that can help offset financial impact after an incident, but it does not prevent phishing-based compromise or improve operational detection of malicious sign-in activity.

SY0-701 Question 2

Single answer1.1 Compare and contrast various types of security controls.

A healthcare company is preparing for an audit after several employees were tricked by phishing emails that led to credential theft. Management wants to reduce the likelihood of similar incidents by changing employee behavior, while also demonstrating to auditors that the organization has implemented a formal security control specifically intended to influence user actions. Which of the following is the BEST choice?

  1. A

    Deploy an email sandbox to detonate attachments before delivery

  2. B

    Require annual security awareness and phishing simulation training for all staff

  3. C

    Implement account lockout thresholds after repeated failed logon attempts

  4. D

    Enable full-disk encryption on all company laptops

Show answer and explanation

Correct answer: B

Explanation

This question tests the ability to compare security controls by category and purpose rather than simply identifying a technology. In Security+, candidates should distinguish administrative, technical, and physical controls, as well as functional types such as preventive, detective, corrective, deterrent, compensating, and directive. In this scenario, the organization wants a control that specifically influences employee actions after phishing incidents. Security awareness training is an administrative control and is commonly used as a directive or deterrent measure to shape user behavior. It is also frequently reviewed during audits as part of an organization's security program. By contrast, email sandboxing and account lockout are technical controls, and full-disk encryption protects data at rest rather than addressing user susceptibility to phishing. This aligns with common best practices reflected in security awareness guidance from NIST, including training and awareness concepts in NIST SP 800-50, and broader control frameworks that separate administrative and technical safeguards.

  • A. Incorrect.

    Deploying an email sandbox is a technical preventive/detective control that helps identify and block malicious attachments or links before they reach users. While it reduces phishing risk, it does not primarily function as a formal control intended to influence employee behavior. A candidate might choose this because it directly addresses phishing, but the question specifically asks for a control designed to change user actions.

  • B. Correct.

    Annual security awareness and phishing simulation training is the best answer because it is an administrative control and, more specifically, a deterrent/directive style of control used to influence user behavior and reduce the chance that employees will fall for phishing attempts. It also provides clear evidence to auditors that the organization has implemented a formal program to guide employee actions.

  • C. Incorrect.

    Account lockout thresholds are technical preventive controls that can reduce brute-force password attacks or limit repeated login attempts. However, they do not directly address the root issue in the scenario: employees being socially engineered through phishing. This option is plausible because compromised credentials are involved, but it does not primarily change user behavior.

  • D. Incorrect.

    Full-disk encryption is a corrective/compensating safeguard for protecting data at rest if a device is lost or stolen. It is an important control in many environments, especially healthcare, but it does not reduce phishing susceptibility or serve as a control intended to direct user behavior. Someone might choose it because healthcare data is sensitive, but it does not fit the scenario.

SY0-701 Question 3

Single answerCategories: Technical , Managerial , Operational , Physical

A company is opening a small satellite office that will not have dedicated on-site security staff. The security manager must recommend a set of controls that addresses risks across administrative/managerial, technical, operational, and physical categories before employees move in. Which of the following combinations BEST meets this requirement?

  1. A

    Deploy badge-controlled door locks, require a clean desk policy and visitor sign-in procedures, enforce MFA for remote access, and perform a site risk assessment

  2. B

    Install antivirus on employee laptops, purchase cyber insurance, and place a privacy screen on the receptionist's monitor

  3. C

    Require employees to change passwords every 30 days, encrypt all email, and add a fence around the parking lot

  4. D

    Hire a guard for business hours, disable unused switch ports, and create an incident response contact list

Show answer and explanation

Correct answer: A

Explanation

The best answer is the one that demonstrates defense in depth while also mapping controls to the requested categories. In Security+ terminology, managerial/administrative controls include activities such as risk assessments, policy development, governance, and planning. Technical controls include mechanisms such as MFA, firewalls, and endpoint protection. Operational controls are people-driven and process-oriented, such as visitor procedures, awareness activities, and clean desk practices. Physical controls include locks, cameras, guards, fences, and badge access systems. A site risk assessment is especially important before occupancy because it helps identify local threats, likelihood, impact, and compensating control needs. This aligns with common best practices reflected in NIST guidance such as NIST SP 800-53 control families and NIST risk management concepts, where organizations select a mix of administrative, technical, and physical safeguards based on assessed risk.

  • A. Correct.

    Correct. This option includes a physical control (badge-controlled door locks), operational controls (clean desk policy and visitor sign-in procedures), a technical control (MFA for remote access), and a managerial/administrative control (site risk assessment). Security+ commonly expects candidates to distinguish among these control categories and choose a layered approach that addresses multiple domains. The scenario specifically asks for coverage across managerial, technical, operational, and physical categories, and this is the only option that clearly includes all four.

  • B. Incorrect.

    Incorrect. Antivirus is a technical control, cyber insurance is generally a risk-transfer measure associated with managerial risk treatment, and a privacy screen is a physical safeguard. However, this option does not clearly include an operational control such as procedures, day-to-day processes, or staff-led security practices. It is partially useful but does not satisfy the requirement to address all categories.

  • C. Incorrect.

    Incorrect. Password changes and email encryption are technical or policy-driven measures, and a fence is a physical control. However, this choice lacks a clear operational control and does not provide a strong managerial element such as governance, risk assessment, or formal security planning. Also, frequent password expiration by itself is no longer broadly considered a best-practice default unless driven by specific risk or compromise indicators, making this option less aligned with modern guidance.

  • D. Incorrect.

    Incorrect. A guard is a physical/deterrent control, disabling unused switch ports is a technical control, and an incident response contact list can support operations. However, this option does not clearly include a managerial/administrative control such as a risk assessment, policy approval, or governance activity. It is a plausible set of controls, which makes it a good distractor, but it does not fully satisfy the category coverage required by the scenario.

SY0-701 Question 4

Single answerCategories: Technical , Managerial , Operational , Physical

A company is preparing for an external audit after several security weaknesses were identified at its headquarters. Investigators found that server room doors were often propped open by contractors, employees had not completed annual security awareness training, privileged access reviews had not been performed in over a year, and several workstations were still missing endpoint protection updates. The security manager wants to categorize each issue correctly so the right control owners can be assigned. Which option lists the issues in the correct order of control categories: endpoint protection updates, access review process, security awareness training, and server room door controls?

  1. A

    Technical, Managerial, Operational, Physical

  2. B

    Operational, Technical, Managerial, Physical

  3. C

    Technical, Operational, Managerial, Physical

  4. D

    Physical, Managerial, Operational, Technical

Show answer and explanation

Correct answer: A

Explanation

Security+ expects candidates to distinguish among common control categories and apply them in real scenarios. Technical controls are enforced by systems or devices, such as endpoint protection, encryption, and firewalls. Managerial controls focus on governance, risk management, policies, and oversight activities, such as account reviews, risk assessments, and policy approval. Operational controls are people-driven and process-oriented, including training, incident response procedures, and change management execution. Physical controls protect facilities and assets through mechanisms such as locks, guards, badges, fences, and mantraps. This mapping aligns with widely used security frameworks and guidance, including NIST control families and standard Security+ domain treatment of administrative/managerial, operational, technical, and physical safeguards.

  • A. Correct.

    Correct. Endpoint protection updates are a technical control because they are implemented through technology such as EDR/antivirus platforms and patching mechanisms on systems. The access review process is a managerial control because it is part of governance, oversight, and administrative decision-making about who should retain privileges. Security awareness training is an operational control because it is carried out through people and day-to-day security procedures. Server room door controls are physical controls because they protect facilities and hardware through barriers, locks, and access restrictions.

  • B. Incorrect.

    Incorrect. This option reverses the first two categories. Endpoint protection updates are not primarily operational controls; while staff may perform them, the control itself is technical because it relies on security software and system configurations. Likewise, access reviews are not technical controls; they are managerial/administrative because they involve policy enforcement, approval, and governance.

  • C. Incorrect.

    Incorrect. The first category is correct, but the second and third are swapped. Access reviews are generally categorized as managerial controls because they support oversight, compliance, and risk management. Security awareness training is typically operational because it is executed as part of ongoing security operations and user-facing processes.

  • D. Incorrect.

    Incorrect. This option misclassifies nearly every item. Endpoint protection updates are not physical controls, and server room door controls are not technical in this context. While some doors may use technical components such as badge readers, the control category for protecting the room itself is physical.

SY0-701 Question 5

Single answerControl types: Preventive , Deterrent , Detective , Corrective , Compensating , Directive

A healthcare organization stores patient records in a legacy application that cannot support modern multifactor authentication. The security team must reduce the risk of unauthorized access while the application is being replaced next year. Management wants a control that provides equivalent risk reduction when the preferred control cannot be implemented because of a technical limitation. Which control type best fits this requirement?

  1. A

    Compensating control

  2. B

    Corrective control

  3. C

    Detective control

  4. D

    Directive control

  5. E

    Deterrent control

Show answer and explanation

Correct answer: A

Explanation

The best answer is compensating control. In Security+ and common security governance practice, compensating controls are implemented when a recommended or required control cannot be used as intended, often because of legacy technology, cost, or operational constraints. The key distinction is that the substitute control should provide comparable risk reduction. This aligns with real-world security frameworks and audit practices, where organizations document why the primary control is not feasible and what alternative safeguards are used instead. By contrast, preventive controls stop incidents before they happen, detective controls identify incidents, corrective controls restore systems after incidents, deterrent controls discourage violations, and directive controls instruct users and administrators on expected behavior.

  • A. Correct.

    Correct. A compensating control is used when the ideal or primary control cannot be implemented due to technical, operational, or business constraints, but another control is put in place to reduce risk to an acceptable level. In this scenario, the legacy application cannot support MFA, so the organization would use alternative measures, such as restricting access through a jump box, enforcing stronger network segmentation, or increasing monitoring, as compensating controls.

  • B. Incorrect.

    Incorrect. Corrective controls are intended to fix or remediate an issue after an event occurs. Examples include restoring from backup, reimaging a system, or applying a patch after a vulnerability is identified. The scenario is focused on reducing risk before unauthorized access occurs, not recovering afterward.

  • C. Incorrect.

    Incorrect. Detective controls identify or alert on events that have already happened or are in progress, such as log reviews, SIEM alerts, or intrusion detection systems. While detective controls might be part of the overall solution, the question specifically asks for the control type used when the preferred control cannot be implemented and an alternative is needed to provide similar risk reduction.

  • D. Incorrect.

    Incorrect. Directive controls guide behavior through policies, procedures, standards, and training. For example, an access control policy may require MFA for remote access. However, a directive control does not itself provide the substitute technical or operational protection described in the scenario.

  • E. Incorrect.

    Incorrect. Deterrent controls are designed to discourage undesirable actions, such as warning banners, visible cameras, or security lighting. These can reduce opportunistic misuse, but they do not specifically address the need for an alternative safeguard that compensates for a missing primary control in a legacy system.

SY0-701 Question 6

Single answerControl types: Preventive , Deterrent , Detective , Corrective , Compensating , Directive

A healthcare company operates a legacy radiology system that cannot support modern endpoint protection software without causing system instability. The security team still needs to reduce the risk of malware spreading from that system while the vendor works on an upgrade. Which control type best describes placing the radiology system on a restricted VLAN with tightly limited firewall rules and additional monitoring to reduce the risk created by the unsupported security capability?

  1. A

    Preventive control

  2. B

    Detective control

  3. C

    Compensating control

  4. D

    Directive control

  5. E

    Deterrent control

Show answer and explanation

Correct answer: C

Explanation

The key to this question is distinguishing between the functional effect of a control and the reason it is being used. Network segmentation and firewall rules can absolutely be preventive controls in many contexts because they block or limit unwanted access. However, in this scenario they are specifically being used as an alternate safeguard because the preferred control, endpoint protection on the legacy system, cannot be implemented. That is the classic definition of a compensating control.

This distinction appears in common security practice and governance models: when a required or preferred control is not feasible, organizations document an exception and implement other measures that provide comparable risk reduction. Examples include isolating unsupported systems, limiting administrative access, increasing logging, and applying stricter network filtering. This approach aligns with best practices described in control frameworks and guidance such as NIST SP 800-53, which discusses control selection and tailoring, and PCI DSS, which explicitly uses the term compensating controls for alternate measures that meet the intent and rigor of the original requirement.

In exam scenarios, watch for wording such as 'cannot support,' 'not feasible,' 'legacy system,' 'business constraint,' or 'temporary alternative.' Those clues often indicate compensating controls rather than simply preventive, detective, or corrective controls.

  • A. Incorrect.

    A preventive control is designed to stop an event from occurring in the first place, such as application allowlisting, MFA, or network segmentation. While the restricted VLAN and firewall rules do have preventive elements, the key detail in the scenario is that they are being implemented because the primary control, endpoint protection on the host, cannot be used. That makes this a compensating control rather than simply classifying it at the higher level as preventive.

  • B. Incorrect.

    A detective control identifies or records events after or as they occur, such as log monitoring, SIEM alerts, IDS, or CCTV review. The scenario does mention additional monitoring, which is detective in nature, but the overall question asks for the control type that best describes the alternative security measure used to address the missing host-based protection. That is not primarily detective.

  • C. Correct.

    A compensating control is the best answer because it is an alternative safeguard used when the preferred or standard control cannot be implemented due to technical, operational, or business constraints. In this case, the legacy radiology system cannot run endpoint protection, so the organization uses segmentation, restrictive firewall rules, and monitoring to reduce risk in another way. This matches the definition of a compensating control commonly used in frameworks and real-world exception handling.

  • D. Incorrect.

    A directive control tells people what they are supposed to do through policies, standards, procedures, or training. Examples include an acceptable use policy or incident response procedures. The scenario is focused on a technical risk-reduction measure implemented because of a system limitation, not on guidance or instruction to personnel.

  • E. Incorrect.

    A deterrent control is intended to discourage malicious activity, such as warning banners, visible guards, or prominent camera signage. Although deterrent controls may influence behavior, the restricted VLAN and firewall rules in the scenario are not primarily there to discourage action; they are there to offset the inability to deploy the normal host protection.

SY0-701 Question 7

Single answer1.2 Summarize fundamental security concepts.

A healthcare company is deploying a new patient records application to a shared virtualization cluster. The security architect wants to reduce the risk that a compromise of the web front end could expose the database containing protected health information (PHI). The design must limit lateral movement, keep systems with different sensitivity levels separated, and follow a core security design principle rather than relying only on patching or monitoring. Which of the following is the BEST recommendation?

  1. A

    Place the web server and database on the same virtual network so traffic stays internal to the cluster

  2. B

    Implement network segmentation and isolate the database in a separate security zone with tightly restricted access from the web tier

  3. C

    Increase log collection on both servers and review alerts daily for suspicious activity

  4. D

    Deploy the application on the fastest available hosts to reduce the time attackers have to exploit the systems

Show answer and explanation

Correct answer: B

Explanation

The best answer is to implement network segmentation and isolate the database in a separate security zone with tightly controlled access. This applies fundamental security concepts covered in Security+, especially segmentation, isolation, and defense in depth. In a real-world architecture, the web tier and database tier should not share the same trust boundary when the database stores sensitive information such as PHI. Restricting communication to only necessary ports, protocols, and source systems reduces the attack surface and helps contain breaches. This aligns with widely accepted best practices from sources such as NIST guidance on network security architecture and system protection, including the use of segmentation, least privilege, and layered controls. Logging remains important as a detective control, but preventive architectural controls are the best primary recommendation in this scenario.

  • A. Incorrect.

    This is incorrect because keeping the web server and database on the same virtual network reduces separation between systems with different trust levels. If the web server is compromised, an attacker may have easier access to the database. Internal traffic is not automatically secure simply because it remains within a cluster; segmentation and access control are still necessary.

  • B. Correct.

    This is correct because segmentation and isolation enforce separation between components with different sensitivity levels and limit lateral movement. Placing the database in a separate security zone and allowing only specific required connections from the web tier reflects fundamental concepts such as segmentation, isolation, and minimizing attack surface. This is a strong preventive control that helps protect PHI if the web tier is compromised.

  • C. Incorrect.

    This is incorrect because logging and alerting are important detective controls, but they do not by themselves prevent unauthorized access or lateral movement. An organization should collect and review logs, but the scenario specifically asks for the best recommendation based on a core security design principle to separate sensitive assets.

  • D. Incorrect.

    This is incorrect because performance does not meaningfully address the security objective in the scenario. Faster hosts may improve application responsiveness, but they do not provide isolation, segmentation, or protection of sensitive data from a compromised web front end.

SY0-701 Question 8

Single answer1.2 Summarize fundamental security concepts.

A healthcare company is deploying a new patient scheduling portal. The security architect wants to reduce the risk that a compromise of the web server will expose the internal database or other critical systems. The architect proposes placing the web server in a segmented network, allowing only required traffic to the database server, and preventing direct access from the internet to internal application servers. Which security concept is the architect primarily applying?

  1. A

    Isolation and segmentation

  2. B

    Non-repudiation

  3. C

    Hashing

  4. D

    Obfuscation

Show answer and explanation

Correct answer: A

Explanation

The best answer is isolation and segmentation because the scenario describes separating a public-facing service from sensitive internal resources and allowing only necessary communications. This aligns with fundamental security architecture principles such as reducing attack surface, limiting lateral movement, and enforcing least functionality and least privilege at the network level. In real environments, organizations often implement this through a DMZ, internal firewalls, ACLs, security groups, or microsegmentation. These practices are consistent with common guidance from NIST, including concepts in NIST SP 800-41 for firewalls and NIST SP 800-125/207 for segmentation and zero trust-related design principles. The other options are valid security concepts, but they do not directly address the primary architectural control being used in this scenario.

  • A. Correct.

    Correct. Isolation and segmentation are being applied by placing the public-facing web server in a separate network zone and tightly controlling communications to internal systems. This limits lateral movement, reduces attack surface, and supports containment if the web server is compromised. In practice, this is commonly implemented through DMZs, VLANs, firewalls, ACLs, and microsegmentation.

  • B. Incorrect.

    Incorrect. Non-repudiation is the assurance that a person or system cannot deny performing an action, typically supported by mechanisms such as digital signatures, strong authentication, and logging. The scenario is focused on limiting network exposure and controlling system-to-system access, not proving who performed an action.

  • C. Incorrect.

    Incorrect. Hashing is used to verify integrity or securely store password verifiers, depending on implementation. While hashing is an important security control, it does not address the architectural goal described in the scenario, which is to separate systems and restrict network paths between them.

  • D. Incorrect.

    Incorrect. Obfuscation makes code, data, or logic more difficult to understand, often to slow reverse engineering or hide implementation details. It does not primarily prevent a compromised web server from reaching internal systems or reduce exposure through network design.

SY0-701 Question 9

Single answerConfidentiality, Integrity, and Availability (CIA)

A regional healthcare provider stores patient records in an internal application used by clinics around the clock. After a recent ransomware incident at another hospital, the security manager is asked to recommend the single BEST control improvement to ensure doctors can still access patient records during a similar attack, while also preserving the trustworthiness of restored data. Which of the following should the manager implement first?

  1. A

    Deploy immutable, offline backups and routinely test restoration procedures

  2. B

    Enable full-disk encryption on all database servers

  3. C

    Require multifactor authentication for all staff who access the application

  4. D

    Implement file integrity monitoring on the patient records database

Show answer and explanation

Correct answer: A

Explanation

This question maps directly to the CIA triad. The scenario prioritizes availability first, because clinicians must continue accessing patient records, and integrity second, because restored data must be trustworthy. Backups that are offline or otherwise isolated from production are a widely accepted best practice against ransomware, since attackers often try to encrypt or delete reachable backups. Immutability further reduces the chance that backup data can be altered. Routine restoration testing is equally important because many organizations discover backup failures only during an incident. Guidance from sources such as NIST's contingency planning and ransomware-focused recommendations consistently emphasizes tested backups and recovery procedures as foundational resilience measures. The other options are valid security controls, but they align more closely to confidentiality, preventive access control, or detective integrity monitoring rather than the primary recovery and continuity need described in the scenario.

  • A. Correct.

    Correct. Immutable, offline backups directly support availability by allowing recovery if ransomware encrypts production systems, and they also support integrity because clean backup copies can be restored and validated. Regular restoration testing is critical; backups that cannot be restored do not meaningfully improve resilience. This is the best first control because the scenario emphasizes continued access to records during a ransomware event and confidence in restored data.

  • B. Incorrect.

    Incorrect. Full-disk encryption primarily protects confidentiality of data at rest if a server or drive is lost or stolen. It does not meaningfully ensure that patient records remain available during ransomware, because ransomware can encrypt data after the system is running and the disk is already unlocked. It also does not provide a recovery path for restoring trusted data.

  • C. Incorrect.

    Incorrect. Multifactor authentication is a strong preventive control that helps reduce the risk of unauthorized access and some forms of account compromise. However, it does not by itself ensure availability of patient records during a ransomware attack, nor does it provide a trusted source for recovery. Candidates may choose this because MFA is broadly recommended, but it is not the best answer for the stated objective.

  • D. Incorrect.

    Incorrect. File integrity monitoring helps detect unauthorized changes and can support integrity objectives by alerting administrators to tampering. However, it is primarily detective, not restorative. It does not ensure continued access to records during a ransomware incident and does not replace a tested backup and recovery capability.

SY0-701 Question 10

Single answerConfidentiality, Integrity, and Availability (CIA)

A healthcare organization stores patient records in a central database used by clinics in multiple states. During a recent incident review, the security team found three issues: database administrators can read all patient data in plaintext, a misconfigured application server was able to alter billing records without detection, and several clinics lost access to records for hours after a storage failure. Management wants to prioritize a control that most directly addresses the integrity issue identified in the review without primarily focusing on confidentiality or availability. Which control should the organization implement first?

  1. A

    Enable database activity monitoring and enforce least-privilege administrative roles

  2. B

    Implement digital signatures or hashing with file integrity monitoring on billing records

  3. C

    Deploy full-disk encryption on the database servers

  4. D

    Add database replication and redundant storage across multiple sites

Show answer and explanation

Correct answer: B

Explanation

The CIA triad separates security objectives into confidentiality, integrity, and availability. In this scenario, plaintext access by administrators is a confidentiality concern, unauthorized alteration of billing records without detection is an integrity concern, and clinic outages after a storage failure are an availability concern. Because the question asks for the control that most directly addresses integrity, the best answer is to implement digital signatures or hashing with file integrity monitoring on billing records. These controls help verify that data has not been altered improperly and support detection of tampering. This aligns with common security best practices and guidance such as NIST principles for protecting data integrity through checksums, hashes, and monitoring of unauthorized changes. The other options are valuable controls, but they primarily map to confidentiality or availability rather than the specific integrity gap described.

  • A. Incorrect.

    This would help reduce unnecessary access and improve confidentiality by limiting who can view sensitive records. Database activity monitoring can also support detection, but it does not most directly ensure that unauthorized changes to billing records are detectable or prevented from going unnoticed. A candidate might choose this because least privilege is an important security control, but in this scenario the question specifically asks for the control that most directly addresses integrity.

  • B. Correct.

    This is correct because integrity focuses on ensuring data is not altered in an unauthorized or undetected manner. Digital signatures, cryptographic hashes, and file integrity monitoring provide mechanisms to verify that billing records have not been tampered with and to detect unauthorized modifications. In the scenario, the core integrity problem is that records were altered without detection, so implementing integrity validation and monitoring is the most direct response.

  • C. Incorrect.

    Full-disk encryption protects data at rest and is primarily a confidentiality control. It helps if drives are stolen or improperly disposed of, but it does not address the problem of an authorized system or misconfigured server changing data in the database. This is a common misconception because encryption is often viewed as a general security fix, but it does not by itself ensure integrity of application data changes.

  • D. Incorrect.

    Replication and redundant storage are availability controls. They help maintain access to systems during outages or storage failures, which matches the clinics' inability to access records for hours. However, they do not directly solve the issue of billing records being modified without detection. Someone might pick this option because the scenario mentions outages, but the question explicitly asks for the control that best addresses integrity.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

What the SY0-701 exam covers

Official Security+ exam domains and weightings.

  • General Security Concepts

    12% of exam

  • Threats, Vulnerabilities, and Mitigations

    22% of exam

  • Security Architecture

    18% of exam

  • Security Operations

    28% of exam

  • Security Program Management and Oversight

    20% of exam

SY0-701 practice questions 1 to 100 of 490

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them. The bank is split into 5 pages of up to 100 questions.

  1. 1.A healthcare company experienced a phishing incident that led to unauthorized access to an employee's email...
  2. 2.A healthcare company is preparing for an audit after several employees were tricked by phishing emails that...
  3. 3.A company is opening a small satellite office that will not have dedicated on-site security staff. The...
  4. 4.A company is preparing for an external audit after several security weaknesses were identified at its...
  5. 5.A healthcare organization stores patient records in a legacy application that cannot support modern...
  6. 6.A healthcare company operates a legacy radiology system that cannot support modern endpoint protection...
  7. 7.A healthcare company is deploying a new patient records application to a shared virtualization cluster. The...
  8. 8.A healthcare company is deploying a new patient scheduling portal. The security architect wants to reduce the...
  9. 9.A regional healthcare provider stores patient records in an internal application used by clinics around the...
  10. 10.A healthcare organization stores patient records in a central database used by clinics in multiple states....
  11. 11.A financial services company is moving its contract approval process from paper to a web-based workflow....
  12. 12.A procurement manager approves high-value purchase orders through a web portal. After a disputed transaction,...
  13. 13.A company is replacing shared local administrator passwords on 200 Windows servers with a more secure access...
  14. 14.A company is replacing shared local administrator accounts on Linux servers with a centralized AAA solution....
  15. 15.A healthcare company is preparing for an external security assessment after expanding into a new cloud-hosted...
  16. 16.A healthcare company is preparing for an external assessment against its internal security baseline and...
  17. 17.A company is replacing its traditional VPN with a Zero Trust architecture for access to internal...
  18. 18.A company is replacing its flat internal network with a Zero Trust architecture after an attacker used a...
  19. 19.A financial services company is renovating the entrance to its data center after a recent incident in which...
  20. 20.A company is upgrading security at a small data center after two incidents: an unauthorized person followed...
  21. 21.A security analyst wants early warning if an attacker gains access to the internal file share that stores...
  22. 22.A security team suspects an attacker has limited access to an internal file share and may be browsing...
  23. 23.A company experienced a two-hour outage after a network engineer changed firewall rules during business hours...
  24. 24.A security administrator needs to deploy a critical update to the company's internet-facing VPN gateways...
  25. 25.A security administrator needs to deploy an emergency change to a production web application after a critical...
  26. 26.A security team needs to deploy an emergency configuration change to a customer-facing web application after...
  27. 27.A security administrator is preparing to deploy application allow listing on several Windows servers that...
  28. 28.A security administrator must quickly reduce the risk of malware on a hospital's Windows-based medication...
  29. 29.A company recently moved several internal applications from an on-premises server network to a segmented...
  30. 30.A company recently segmented its network after a ransomware incident. The security administrator moved the...
  31. 31.A software company stores infrastructure-as-code templates and application source code in a shared Git...
  32. 32.A security team maintains infrastructure-as-code templates and firewall configuration files in a shared...
  33. 33.A healthcare company is deploying a new patient portal that allows patients to view lab results, message...
  34. 34.A healthcare company is deploying thousands of IoT medical sensors that send patient telemetry to a cloud...
  35. 35.A financial services company is deploying a new internal web application that handles sensitive customer...
  36. 36.A company is rolling out mutual TLS for a customer-facing payment API. During a security review, the team...
  37. 37.A healthcare company stores patient records in a central SQL database. Administrators need to protect highly...
  38. 38.A healthcare company is moving a legacy patient records application to a new environment. The security team...
  39. 39.A healthcare company is modernizing its patient billing platform. Developers need to let customer service...
  40. 40.A retail company is moving payment processing to a third-party cloud application. Developers need realistic...
  41. 41.A security administrator is reviewing a recently deployed customer portal after an internal audit found that...
  42. 42.A company discovers that an attacker copied its customer authentication database. During the incident review,...
  43. 43.A software company distributes internal update packages to thousands of managed laptops. After a recent...
  44. 44.A software company distributes monthly updates to customers through its public download portal. After a...
  45. 45.A SaaS company discovers that a copy of its authentication database was exposed through a misconfigured...
  46. 46.A security administrator is reviewing an internally developed web application's password storage design after...
  47. 47.A security architect is evaluating whether to use a public blockchain to store evidence that software updates...
  48. 48.A security architect is evaluating whether to store software supply-chain attestations on a blockchain so...
  49. 49.A company is deploying HTTPS for dozens of internally managed web applications hosted on subdomains of...
  50. 50.A company is deploying a new public-facing web platform with servers named app1.example.com,...
  51. 51.A regional power utility discovers that several engineering workstations in its operational technology (OT)...
  52. 52.A regional electric utility discovers that several engineering workstations in its operational technology...
  53. 53.A security analyst discovers that several employees have been uploading customer records to a public...
  54. 54.A financial services company discovers that several employees have been using an unsanctioned file-sharing...
  55. 55.A financial services company discovers unusual outbound traffic from a database server that contains...
  56. 56.A security analyst is reviewing a recent breach at a manufacturing company. The attacker used valid VPN...
  57. 57.A defense contractor discovers that an engineer who recently resigned copied proprietary drone design files...
  58. 58.A defense contractor discovers that an engineer who recently resigned copied proprietary aircraft design...
  59. 59.A company recently rolled out a web-based customer portal that integrates with a third-party payment...
  60. 60.A company recently moved several internal applications behind a reverse proxy and enabled remote access for...
  61. 61.A company's security team notices an increase in successful account takeovers. In several cases, users...
  62. 62.A company's security team is investigating a rise in account takeovers. Several employees reported receiving...
  63. 63.A security analyst is investigating suspicious activity on a Linux web server that hosts customer records....
  64. 64.A security analyst is reviewing alerts from several Linux servers and notices repeated detections of files...
  65. 65.An accounts payable clerk receives a voice call from someone claiming to be the company's CFO, who says they...
  66. 66.A company's help desk receives a voice call from someone claiming to be the CFO, who says they are traveling...
  67. 67.A security administrator discovers that several employees have been copying sensitive project files to...
  68. 68.A security administrator discovers that several employees have been copying sensitive engineering files to...
  69. 69.A security administrator is choosing a vulnerability assessment approach for a mixed environment that...
  70. 70.A security administrator is deploying a vulnerability management program across a hybrid environment that...
  71. 71.A hospital's radiology department relies on a legacy imaging workstation that runs an operating system and...
  72. 72.A manufacturing company relies on a legacy quality-control application that only runs on Windows 7. The...
  73. 73.A security administrator is reviewing a small branch office after a report that an unknown person was seen...
  74. 74.A security administrator is reviewing a small branch office after a recent penetration test. The report shows...
  75. 75.A healthcare company uses a managed service provider (MSP) to administer firewalls, endpoint protection, and...
  76. 76.A company uses a managed service provider (MSP) to administer endpoints and patch servers. During a security...
  77. 77.A company's accounting department receives an email that appears to come from the CEO, who is traveling...
  78. 78.A company's finance clerk receives an email that appears to come from the CEO, who is traveling overseas. The...
  79. 79.A security analyst is reviewing a web application after users report that they can change the URL from...
  80. 80.A security analyst is reviewing a new customer support web application after a penetration test. The tester...
  81. 81.A development team maintains a Linux-based billing application that runs a scheduled script every minute as...
  82. 82.A development team releases a Linux-based finance application that runs with elevated privileges to write...
  83. 83.A security administrator is hardening a fleet of corporate laptops used by remote employees. The company...
  84. 84.A security administrator needs to harden a fleet of company-issued Windows 11 laptops used by remote...
  85. 85.A company launches a customer portal that includes a search field and a comment section. During testing, a...
  86. 86.A company launches a customer support portal that allows users to search tickets and post comments. During...
  87. 87.A security administrator is deploying 50 laptops to employees who frequently travel with sensitive customer...
  88. 88.A security administrator is deploying new laptops to executives who frequently travel internationally. The...
  89. 89.A security administrator is responding to a report that several laptops in a finance department are loading...
  90. 90.A hospital's security team discovers that a critical radiology workstation is still running an operating...
  91. 91.A security administrator discovers that a business-critical file server is running an operating system...
  92. 92.A manufacturing company is connecting a 15-year-old HVAC control system to its corporate network so engineers...
  93. 93.A manufacturing company still relies on a legacy industrial control server that runs an unsupported operating...
  94. 94.A company runs a multi-tenant private cloud for several internal business units. After a penetration test,...
  95. 95.A cloud operations team hosts multiple customers on the same virtualization cluster. After a security review,...
  96. 96.A company is migrating a customer-facing application to a public cloud provider. The security team must...
  97. 97.A company is migrating a customer-facing web application to a public cloud provider. The security team must...
  98. 98.A company is preparing to deploy 500 point-of-sale terminals across multiple retail locations. The devices...
  99. 99.A company is preparing to deploy a new customer relationship management platform that will rely on a...
  100. 100.A security administrator is deploying full-disk encryption on a fleet of company laptops used by traveling...

SY0-701 exam dumps FAQ

Are these SY0-701 dumps real exam questions?

No. These are original practice questions written to the Security+ exam objectives, not questions copied from a live exam. Memorising leaked questions violates CompTIA's candidate agreement and stops working the moment the question pool rotates. Use this bank to check your understanding of each domain and to find the topics you still need to study.

How many SY0-701 practice questions are there?

490 questions, each with the correct answer, an explanation of the answer, and a note on why every other option is wrong. The first 10 are on this page and every question has its own page linked below.

Are the SY0-701 exam dumps free?

Yes. Every question, answer and explanation on this page and the linked question pages is free to read without an account. A free HydraNode account adds timed practice exams, scoring and progress tracking across attempts.

How do I take a timed SY0-701 practice test?

Sign in and start the Security+ exam on HydraNode. A session gives you 90 questions drawn from this bank in 90 minutes, then a score report with a per-question review.

What topics does the SY0-701 exam cover?

The official exam domains are: General Security Concepts; Threats, Vulnerabilities, and Mitigations; Security Architecture; Security Operations; Security Program Management and Oversight.