CompTIAAssociate levelSY0-701

SY0-701 exam dumps: 490 free CompTIA Security+ practice questions

Free SY0-701 practice questions for the Security+ exam, with the correct answer and a full explanation for every option. Read the first 10 below, browse all 490 by number, or take a timed practice exam.

Question bank last updated June 2026

Free SY0-701 practice questions

Questions 1 to 10 of 490

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

SY0-701 Question 1

Select 21.1 Compare and contrast various types of security controls.

A healthcare company experienced a phishing incident that led to unauthorized access to an employee's email account. During the post-incident review, management decides to reduce the likelihood of similar compromises and to improve the ability to detect them quickly if they occur again. Which TWO security controls best meet these goals?

  1. A

    Implement mandatory annual security awareness training focused on phishing recognition

  2. B

    Deploy multifactor authentication (MFA) for employee email access

  3. C

    Install bollards outside the main office entrance

  4. D

    Enable security information and event management (SIEM) alerting for suspicious sign-in activity

  5. E

    Purchase cyber liability insurance

Show answer and explanation

Correct answers: B, D

Explanation

This question tests the ability to compare and apply different types of security controls in a real-world scenario. The best answers are MFA and SIEM alerting because they align directly with the two stated goals: prevention and detection. MFA is a preventive technical control that reduces the chance of successful account compromise after credential theft. SIEM alerting is a detective technical control that improves visibility into suspicious authentication events so responders can act quickly. Security awareness training is also valuable and is commonly recommended in security programs, but in this scenario it addresses only part of the requirement and does not provide direct technical detection. Physical controls like bollards and risk-transfer measures like insurance are valid security-related measures, but they do not address the email account compromise scenario. This mapping of controls is consistent with common Security+ classifications such as preventive, detective, corrective, deterrent, compensating, physical, technical, and administrative controls, and aligns with widely accepted guidance such as NIST security control families and general best practices for identity and access management and security monitoring.

  • A. Incorrect.

    This is a plausible choice because security awareness training is an administrative control and can help reduce phishing success. However, the scenario asks for controls that both reduce the likelihood of account compromise and improve rapid detection if compromise occurs. Training helps prevention but does not directly improve technical detection of suspicious account use. It is beneficial, but it does not best satisfy both goals together compared with MFA and SIEM alerting.

  • B. Correct.

    This is correct. MFA is a preventive technical control that reduces the likelihood that stolen credentials alone will result in unauthorized access. In real environments, phishing often captures passwords, and MFA adds an additional factor that significantly limits account takeover risk.

  • C. Incorrect.

    This is incorrect. Bollards are a physical preventive control designed to protect people and facilities from vehicle-based threats. They do not address phishing-related email compromise or account misuse, so they are not relevant to the stated goals.

  • D. Correct.

    This is correct. SIEM alerting for suspicious sign-in activity is a detective technical control. It helps security teams identify anomalous behavior such as impossible travel, repeated failed logins, unusual geolocation, or atypical login times, improving the organization's ability to detect compromised accounts quickly.

  • E. Incorrect.

    This is incorrect. Cyber liability insurance is a compensating or risk-transfer measure that can help offset financial impact after an incident, but it does not prevent phishing-based compromise or improve operational detection of malicious sign-in activity.

SY0-701 Question 2

Single answer1.1 Compare and contrast various types of security controls.

A healthcare company is preparing for an audit after several employees were tricked by phishing emails that led to credential theft. Management wants to reduce the likelihood of similar incidents by changing employee behavior, while also demonstrating to auditors that the organization has implemented a formal security control specifically intended to influence user actions. Which of the following is the BEST choice?

  1. A

    Deploy an email sandbox to detonate attachments before delivery

  2. B

    Require annual security awareness and phishing simulation training for all staff

  3. C

    Implement account lockout thresholds after repeated failed logon attempts

  4. D

    Enable full-disk encryption on all company laptops

Show answer and explanation

Correct answer: B

Explanation

This question tests the ability to compare security controls by category and purpose rather than simply identifying a technology. In Security+, candidates should distinguish administrative, technical, and physical controls, as well as functional types such as preventive, detective, corrective, deterrent, compensating, and directive. In this scenario, the organization wants a control that specifically influences employee actions after phishing incidents. Security awareness training is an administrative control and is commonly used as a directive or deterrent measure to shape user behavior. It is also frequently reviewed during audits as part of an organization's security program. By contrast, email sandboxing and account lockout are technical controls, and full-disk encryption protects data at rest rather than addressing user susceptibility to phishing. This aligns with common best practices reflected in security awareness guidance from NIST, including training and awareness concepts in NIST SP 800-50, and broader control frameworks that separate administrative and technical safeguards.

  • A. Incorrect.

    Deploying an email sandbox is a technical preventive/detective control that helps identify and block malicious attachments or links before they reach users. While it reduces phishing risk, it does not primarily function as a formal control intended to influence employee behavior. A candidate might choose this because it directly addresses phishing, but the question specifically asks for a control designed to change user actions.

  • B. Correct.

    Annual security awareness and phishing simulation training is the best answer because it is an administrative control and, more specifically, a deterrent/directive style of control used to influence user behavior and reduce the chance that employees will fall for phishing attempts. It also provides clear evidence to auditors that the organization has implemented a formal program to guide employee actions.

  • C. Incorrect.

    Account lockout thresholds are technical preventive controls that can reduce brute-force password attacks or limit repeated login attempts. However, they do not directly address the root issue in the scenario: employees being socially engineered through phishing. This option is plausible because compromised credentials are involved, but it does not primarily change user behavior.

  • D. Incorrect.

    Full-disk encryption is a corrective/compensating safeguard for protecting data at rest if a device is lost or stolen. It is an important control in many environments, especially healthcare, but it does not reduce phishing susceptibility or serve as a control intended to direct user behavior. Someone might choose it because healthcare data is sensitive, but it does not fit the scenario.

SY0-701 Question 3

Single answerCategories: Technical , Managerial , Operational , Physical

A company is opening a small satellite office that will not have dedicated on-site security staff. The security manager must recommend a set of controls that addresses risks across administrative/managerial, technical, operational, and physical categories before employees move in. Which of the following combinations BEST meets this requirement?

  1. A

    Deploy badge-controlled door locks, require a clean desk policy and visitor sign-in procedures, enforce MFA for remote access, and perform a site risk assessment

  2. B

    Install antivirus on employee laptops, purchase cyber insurance, and place a privacy screen on the receptionist's monitor

  3. C

    Require employees to change passwords every 30 days, encrypt all email, and add a fence around the parking lot

  4. D

    Hire a guard for business hours, disable unused switch ports, and create an incident response contact list

Show answer and explanation

Correct answer: A

Explanation

The best answer is the one that demonstrates defense in depth while also mapping controls to the requested categories. In Security+ terminology, managerial/administrative controls include activities such as risk assessments, policy development, governance, and planning. Technical controls include mechanisms such as MFA, firewalls, and endpoint protection. Operational controls are people-driven and process-oriented, such as visitor procedures, awareness activities, and clean desk practices. Physical controls include locks, cameras, guards, fences, and badge access systems. A site risk assessment is especially important before occupancy because it helps identify local threats, likelihood, impact, and compensating control needs. This aligns with common best practices reflected in NIST guidance such as NIST SP 800-53 control families and NIST risk management concepts, where organizations select a mix of administrative, technical, and physical safeguards based on assessed risk.

  • A. Correct.

    Correct. This option includes a physical control (badge-controlled door locks), operational controls (clean desk policy and visitor sign-in procedures), a technical control (MFA for remote access), and a managerial/administrative control (site risk assessment). Security+ commonly expects candidates to distinguish among these control categories and choose a layered approach that addresses multiple domains. The scenario specifically asks for coverage across managerial, technical, operational, and physical categories, and this is the only option that clearly includes all four.

  • B. Incorrect.

    Incorrect. Antivirus is a technical control, cyber insurance is generally a risk-transfer measure associated with managerial risk treatment, and a privacy screen is a physical safeguard. However, this option does not clearly include an operational control such as procedures, day-to-day processes, or staff-led security practices. It is partially useful but does not satisfy the requirement to address all categories.

  • C. Incorrect.

    Incorrect. Password changes and email encryption are technical or policy-driven measures, and a fence is a physical control. However, this choice lacks a clear operational control and does not provide a strong managerial element such as governance, risk assessment, or formal security planning. Also, frequent password expiration by itself is no longer broadly considered a best-practice default unless driven by specific risk or compromise indicators, making this option less aligned with modern guidance.

  • D. Incorrect.

    Incorrect. A guard is a physical/deterrent control, disabling unused switch ports is a technical control, and an incident response contact list can support operations. However, this option does not clearly include a managerial/administrative control such as a risk assessment, policy approval, or governance activity. It is a plausible set of controls, which makes it a good distractor, but it does not fully satisfy the category coverage required by the scenario.

SY0-701 Question 4

Single answerCategories: Technical , Managerial , Operational , Physical

A company is preparing for an external audit after several security weaknesses were identified at its headquarters. Investigators found that server room doors were often propped open by contractors, employees had not completed annual security awareness training, privileged access reviews had not been performed in over a year, and several workstations were still missing endpoint protection updates. The security manager wants to categorize each issue correctly so the right control owners can be assigned. Which option lists the issues in the correct order of control categories: endpoint protection updates, access review process, security awareness training, and server room door controls?

  1. A

    Technical, Managerial, Operational, Physical

  2. B

    Operational, Technical, Managerial, Physical

  3. C

    Technical, Operational, Managerial, Physical

  4. D

    Physical, Managerial, Operational, Technical

Show answer and explanation

Correct answer: A

Explanation

Security+ expects candidates to distinguish among common control categories and apply them in real scenarios. Technical controls are enforced by systems or devices, such as endpoint protection, encryption, and firewalls. Managerial controls focus on governance, risk management, policies, and oversight activities, such as account reviews, risk assessments, and policy approval. Operational controls are people-driven and process-oriented, including training, incident response procedures, and change management execution. Physical controls protect facilities and assets through mechanisms such as locks, guards, badges, fences, and mantraps. This mapping aligns with widely used security frameworks and guidance, including NIST control families and standard Security+ domain treatment of administrative/managerial, operational, technical, and physical safeguards.

  • A. Correct.

    Correct. Endpoint protection updates are a technical control because they are implemented through technology such as EDR/antivirus platforms and patching mechanisms on systems. The access review process is a managerial control because it is part of governance, oversight, and administrative decision-making about who should retain privileges. Security awareness training is an operational control because it is carried out through people and day-to-day security procedures. Server room door controls are physical controls because they protect facilities and hardware through barriers, locks, and access restrictions.

  • B. Incorrect.

    Incorrect. This option reverses the first two categories. Endpoint protection updates are not primarily operational controls; while staff may perform them, the control itself is technical because it relies on security software and system configurations. Likewise, access reviews are not technical controls; they are managerial/administrative because they involve policy enforcement, approval, and governance.

  • C. Incorrect.

    Incorrect. The first category is correct, but the second and third are swapped. Access reviews are generally categorized as managerial controls because they support oversight, compliance, and risk management. Security awareness training is typically operational because it is executed as part of ongoing security operations and user-facing processes.

  • D. Incorrect.

    Incorrect. This option misclassifies nearly every item. Endpoint protection updates are not physical controls, and server room door controls are not technical in this context. While some doors may use technical components such as badge readers, the control category for protecting the room itself is physical.

SY0-701 Question 5

Single answerControl types: Preventive , Deterrent , Detective , Corrective , Compensating , Directive

A healthcare organization stores patient records in a legacy application that cannot support modern multifactor authentication. The security team must reduce the risk of unauthorized access while the application is being replaced next year. Management wants a control that provides equivalent risk reduction when the preferred control cannot be implemented because of a technical limitation. Which control type best fits this requirement?

  1. A

    Compensating control

  2. B

    Corrective control

  3. C

    Detective control

  4. D

    Directive control

  5. E

    Deterrent control

Show answer and explanation

Correct answer: A

Explanation

The best answer is compensating control. In Security+ and common security governance practice, compensating controls are implemented when a recommended or required control cannot be used as intended, often because of legacy technology, cost, or operational constraints. The key distinction is that the substitute control should provide comparable risk reduction. This aligns with real-world security frameworks and audit practices, where organizations document why the primary control is not feasible and what alternative safeguards are used instead. By contrast, preventive controls stop incidents before they happen, detective controls identify incidents, corrective controls restore systems after incidents, deterrent controls discourage violations, and directive controls instruct users and administrators on expected behavior.

  • A. Correct.

    Correct. A compensating control is used when the ideal or primary control cannot be implemented due to technical, operational, or business constraints, but another control is put in place to reduce risk to an acceptable level. In this scenario, the legacy application cannot support MFA, so the organization would use alternative measures, such as restricting access through a jump box, enforcing stronger network segmentation, or increasing monitoring, as compensating controls.

  • B. Incorrect.

    Incorrect. Corrective controls are intended to fix or remediate an issue after an event occurs. Examples include restoring from backup, reimaging a system, or applying a patch after a vulnerability is identified. The scenario is focused on reducing risk before unauthorized access occurs, not recovering afterward.

  • C. Incorrect.

    Incorrect. Detective controls identify or alert on events that have already happened or are in progress, such as log reviews, SIEM alerts, or intrusion detection systems. While detective controls might be part of the overall solution, the question specifically asks for the control type used when the preferred control cannot be implemented and an alternative is needed to provide similar risk reduction.

  • D. Incorrect.

    Incorrect. Directive controls guide behavior through policies, procedures, standards, and training. For example, an access control policy may require MFA for remote access. However, a directive control does not itself provide the substitute technical or operational protection described in the scenario.

  • E. Incorrect.

    Incorrect. Deterrent controls are designed to discourage undesirable actions, such as warning banners, visible cameras, or security lighting. These can reduce opportunistic misuse, but they do not specifically address the need for an alternative safeguard that compensates for a missing primary control in a legacy system.

SY0-701 Question 6

Single answerControl types: Preventive , Deterrent , Detective , Corrective , Compensating , Directive

A healthcare company operates a legacy radiology system that cannot support modern endpoint protection software without causing system instability. The security team still needs to reduce the risk of malware spreading from that system while the vendor works on an upgrade. Which control type best describes placing the radiology system on a restricted VLAN with tightly limited firewall rules and additional monitoring to reduce the risk created by the unsupported security capability?

  1. A

    Preventive control

  2. B

    Detective control

  3. C

    Compensating control

  4. D

    Directive control

  5. E

    Deterrent control

Show answer and explanation

Correct answer: C

Explanation

The key to this question is distinguishing between the functional effect of a control and the reason it is being used. Network segmentation and firewall rules can absolutely be preventive controls in many contexts because they block or limit unwanted access. However, in this scenario they are specifically being used as an alternate safeguard because the preferred control, endpoint protection on the legacy system, cannot be implemented. That is the classic definition of a compensating control.

This distinction appears in common security practice and governance models: when a required or preferred control is not feasible, organizations document an exception and implement other measures that provide comparable risk reduction. Examples include isolating unsupported systems, limiting administrative access, increasing logging, and applying stricter network filtering. This approach aligns with best practices described in control frameworks and guidance such as NIST SP 800-53, which discusses control selection and tailoring, and PCI DSS, which explicitly uses the term compensating controls for alternate measures that meet the intent and rigor of the original requirement.

In exam scenarios, watch for wording such as 'cannot support,' 'not feasible,' 'legacy system,' 'business constraint,' or 'temporary alternative.' Those clues often indicate compensating controls rather than simply preventive, detective, or corrective controls.

  • A. Incorrect.

    A preventive control is designed to stop an event from occurring in the first place, such as application allowlisting, MFA, or network segmentation. While the restricted VLAN and firewall rules do have preventive elements, the key detail in the scenario is that they are being implemented because the primary control, endpoint protection on the host, cannot be used. That makes this a compensating control rather than simply classifying it at the higher level as preventive.

  • B. Incorrect.

    A detective control identifies or records events after or as they occur, such as log monitoring, SIEM alerts, IDS, or CCTV review. The scenario does mention additional monitoring, which is detective in nature, but the overall question asks for the control type that best describes the alternative security measure used to address the missing host-based protection. That is not primarily detective.

  • C. Correct.

    A compensating control is the best answer because it is an alternative safeguard used when the preferred or standard control cannot be implemented due to technical, operational, or business constraints. In this case, the legacy radiology system cannot run endpoint protection, so the organization uses segmentation, restrictive firewall rules, and monitoring to reduce risk in another way. This matches the definition of a compensating control commonly used in frameworks and real-world exception handling.

  • D. Incorrect.

    A directive control tells people what they are supposed to do through policies, standards, procedures, or training. Examples include an acceptable use policy or incident response procedures. The scenario is focused on a technical risk-reduction measure implemented because of a system limitation, not on guidance or instruction to personnel.

  • E. Incorrect.

    A deterrent control is intended to discourage malicious activity, such as warning banners, visible guards, or prominent camera signage. Although deterrent controls may influence behavior, the restricted VLAN and firewall rules in the scenario are not primarily there to discourage action; they are there to offset the inability to deploy the normal host protection.

SY0-701 Question 7

Single answer1.2 Summarize fundamental security concepts.

A healthcare company is deploying a new patient records application to a shared virtualization cluster. The security architect wants to reduce the risk that a compromise of the web front end could expose the database containing protected health information (PHI). The design must limit lateral movement, keep systems with different sensitivity levels separated, and follow a core security design principle rather than relying only on patching or monitoring. Which of the following is the BEST recommendation?

  1. A

    Place the web server and database on the same virtual network so traffic stays internal to the cluster

  2. B

    Implement network segmentation and isolate the database in a separate security zone with tightly restricted access from the web tier

  3. C

    Increase log collection on both servers and review alerts daily for suspicious activity

  4. D

    Deploy the application on the fastest available hosts to reduce the time attackers have to exploit the systems

Show answer and explanation

Correct answer: B

Explanation

The best answer is to implement network segmentation and isolate the database in a separate security zone with tightly controlled access. This applies fundamental security concepts covered in Security+, especially segmentation, isolation, and defense in depth. In a real-world architecture, the web tier and database tier should not share the same trust boundary when the database stores sensitive information such as PHI. Restricting communication to only necessary ports, protocols, and source systems reduces the attack surface and helps contain breaches. This aligns with widely accepted best practices from sources such as NIST guidance on network security architecture and system protection, including the use of segmentation, least privilege, and layered controls. Logging remains important as a detective control, but preventive architectural controls are the best primary recommendation in this scenario.

  • A. Incorrect.

    This is incorrect because keeping the web server and database on the same virtual network reduces separation between systems with different trust levels. If the web server is compromised, an attacker may have easier access to the database. Internal traffic is not automatically secure simply because it remains within a cluster; segmentation and access control are still necessary.

  • B. Correct.

    This is correct because segmentation and isolation enforce separation between components with different sensitivity levels and limit lateral movement. Placing the database in a separate security zone and allowing only specific required connections from the web tier reflects fundamental concepts such as segmentation, isolation, and minimizing attack surface. This is a strong preventive control that helps protect PHI if the web tier is compromised.

  • C. Incorrect.

    This is incorrect because logging and alerting are important detective controls, but they do not by themselves prevent unauthorized access or lateral movement. An organization should collect and review logs, but the scenario specifically asks for the best recommendation based on a core security design principle to separate sensitive assets.

  • D. Incorrect.

    This is incorrect because performance does not meaningfully address the security objective in the scenario. Faster hosts may improve application responsiveness, but they do not provide isolation, segmentation, or protection of sensitive data from a compromised web front end.

SY0-701 Question 8

Single answer1.2 Summarize fundamental security concepts.

A healthcare company is deploying a new patient scheduling portal. The security architect wants to reduce the risk that a compromise of the web server will expose the internal database or other critical systems. The architect proposes placing the web server in a segmented network, allowing only required traffic to the database server, and preventing direct access from the internet to internal application servers. Which security concept is the architect primarily applying?

  1. A

    Isolation and segmentation

  2. B

    Non-repudiation

  3. C

    Hashing

  4. D

    Obfuscation

Show answer and explanation

Correct answer: A

Explanation

The best answer is isolation and segmentation because the scenario describes separating a public-facing service from sensitive internal resources and allowing only necessary communications. This aligns with fundamental security architecture principles such as reducing attack surface, limiting lateral movement, and enforcing least functionality and least privilege at the network level. In real environments, organizations often implement this through a DMZ, internal firewalls, ACLs, security groups, or microsegmentation. These practices are consistent with common guidance from NIST, including concepts in NIST SP 800-41 for firewalls and NIST SP 800-125/207 for segmentation and zero trust-related design principles. The other options are valid security concepts, but they do not directly address the primary architectural control being used in this scenario.

  • A. Correct.

    Correct. Isolation and segmentation are being applied by placing the public-facing web server in a separate network zone and tightly controlling communications to internal systems. This limits lateral movement, reduces attack surface, and supports containment if the web server is compromised. In practice, this is commonly implemented through DMZs, VLANs, firewalls, ACLs, and microsegmentation.

  • B. Incorrect.

    Incorrect. Non-repudiation is the assurance that a person or system cannot deny performing an action, typically supported by mechanisms such as digital signatures, strong authentication, and logging. The scenario is focused on limiting network exposure and controlling system-to-system access, not proving who performed an action.

  • C. Incorrect.

    Incorrect. Hashing is used to verify integrity or securely store password verifiers, depending on implementation. While hashing is an important security control, it does not address the architectural goal described in the scenario, which is to separate systems and restrict network paths between them.

  • D. Incorrect.

    Incorrect. Obfuscation makes code, data, or logic more difficult to understand, often to slow reverse engineering or hide implementation details. It does not primarily prevent a compromised web server from reaching internal systems or reduce exposure through network design.

SY0-701 Question 9

Single answerConfidentiality, Integrity, and Availability (CIA)

A regional healthcare provider stores patient records in an internal application used by clinics around the clock. After a recent ransomware incident at another hospital, the security manager is asked to recommend the single BEST control improvement to ensure doctors can still access patient records during a similar attack, while also preserving the trustworthiness of restored data. Which of the following should the manager implement first?

  1. A

    Deploy immutable, offline backups and routinely test restoration procedures

  2. B

    Enable full-disk encryption on all database servers

  3. C

    Require multifactor authentication for all staff who access the application

  4. D

    Implement file integrity monitoring on the patient records database

Show answer and explanation

Correct answer: A

Explanation

This question maps directly to the CIA triad. The scenario prioritizes availability first, because clinicians must continue accessing patient records, and integrity second, because restored data must be trustworthy. Backups that are offline or otherwise isolated from production are a widely accepted best practice against ransomware, since attackers often try to encrypt or delete reachable backups. Immutability further reduces the chance that backup data can be altered. Routine restoration testing is equally important because many organizations discover backup failures only during an incident. Guidance from sources such as NIST's contingency planning and ransomware-focused recommendations consistently emphasizes tested backups and recovery procedures as foundational resilience measures. The other options are valid security controls, but they align more closely to confidentiality, preventive access control, or detective integrity monitoring rather than the primary recovery and continuity need described in the scenario.

  • A. Correct.

    Correct. Immutable, offline backups directly support availability by allowing recovery if ransomware encrypts production systems, and they also support integrity because clean backup copies can be restored and validated. Regular restoration testing is critical; backups that cannot be restored do not meaningfully improve resilience. This is the best first control because the scenario emphasizes continued access to records during a ransomware event and confidence in restored data.

  • B. Incorrect.

    Incorrect. Full-disk encryption primarily protects confidentiality of data at rest if a server or drive is lost or stolen. It does not meaningfully ensure that patient records remain available during ransomware, because ransomware can encrypt data after the system is running and the disk is already unlocked. It also does not provide a recovery path for restoring trusted data.

  • C. Incorrect.

    Incorrect. Multifactor authentication is a strong preventive control that helps reduce the risk of unauthorized access and some forms of account compromise. However, it does not by itself ensure availability of patient records during a ransomware attack, nor does it provide a trusted source for recovery. Candidates may choose this because MFA is broadly recommended, but it is not the best answer for the stated objective.

  • D. Incorrect.

    Incorrect. File integrity monitoring helps detect unauthorized changes and can support integrity objectives by alerting administrators to tampering. However, it is primarily detective, not restorative. It does not ensure continued access to records during a ransomware incident and does not replace a tested backup and recovery capability.

SY0-701 Question 10

Single answerConfidentiality, Integrity, and Availability (CIA)

A healthcare organization stores patient records in a central database used by clinics in multiple states. During a recent incident review, the security team found three issues: database administrators can read all patient data in plaintext, a misconfigured application server was able to alter billing records without detection, and several clinics lost access to records for hours after a storage failure. Management wants to prioritize a control that most directly addresses the integrity issue identified in the review without primarily focusing on confidentiality or availability. Which control should the organization implement first?

  1. A

    Enable database activity monitoring and enforce least-privilege administrative roles

  2. B

    Implement digital signatures or hashing with file integrity monitoring on billing records

  3. C

    Deploy full-disk encryption on the database servers

  4. D

    Add database replication and redundant storage across multiple sites

Show answer and explanation

Correct answer: B

Explanation

The CIA triad separates security objectives into confidentiality, integrity, and availability. In this scenario, plaintext access by administrators is a confidentiality concern, unauthorized alteration of billing records without detection is an integrity concern, and clinic outages after a storage failure are an availability concern. Because the question asks for the control that most directly addresses integrity, the best answer is to implement digital signatures or hashing with file integrity monitoring on billing records. These controls help verify that data has not been altered improperly and support detection of tampering. This aligns with common security best practices and guidance such as NIST principles for protecting data integrity through checksums, hashes, and monitoring of unauthorized changes. The other options are valuable controls, but they primarily map to confidentiality or availability rather than the specific integrity gap described.

  • A. Incorrect.

    This would help reduce unnecessary access and improve confidentiality by limiting who can view sensitive records. Database activity monitoring can also support detection, but it does not most directly ensure that unauthorized changes to billing records are detectable or prevented from going unnoticed. A candidate might choose this because least privilege is an important security control, but in this scenario the question specifically asks for the control that most directly addresses integrity.

  • B. Correct.

    This is correct because integrity focuses on ensuring data is not altered in an unauthorized or undetected manner. Digital signatures, cryptographic hashes, and file integrity monitoring provide mechanisms to verify that billing records have not been tampered with and to detect unauthorized modifications. In the scenario, the core integrity problem is that records were altered without detection, so implementing integrity validation and monitoring is the most direct response.

  • C. Incorrect.

    Full-disk encryption protects data at rest and is primarily a confidentiality control. It helps if drives are stolen or improperly disposed of, but it does not address the problem of an authorized system or misconfigured server changing data in the database. This is a common misconception because encryption is often viewed as a general security fix, but it does not by itself ensure integrity of application data changes.

  • D. Incorrect.

    Replication and redundant storage are availability controls. They help maintain access to systems during outages or storage failures, which matches the clinics' inability to access records for hours. However, they do not directly solve the issue of billing records being modified without detection. Someone might pick this option because the scenario mentions outages, but the question explicitly asks for the control that best addresses integrity.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

What the SY0-701 exam covers

Official Security+ exam domains and weightings.

  • General Security Concepts

    12% of exam

  • Threats, Vulnerabilities, and Mitigations

    22% of exam

  • Security Architecture

    18% of exam

  • Security Operations

    28% of exam

  • Security Program Management and Oversight

    20% of exam

All 490 SY0-701 practice questions

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them.

  1. 1.A healthcare company experienced a phishing incident that led to unauthorized access to an employee's email...
  2. 2.A healthcare company is preparing for an audit after several employees were tricked by phishing emails that...
  3. 3.A company is opening a small satellite office that will not have dedicated on-site security staff. The...
  4. 4.A company is preparing for an external audit after several security weaknesses were identified at its...
  5. 5.A healthcare organization stores patient records in a legacy application that cannot support modern...
  6. 6.A healthcare company operates a legacy radiology system that cannot support modern endpoint protection...
  7. 7.A healthcare company is deploying a new patient records application to a shared virtualization cluster. The...
  8. 8.A healthcare company is deploying a new patient scheduling portal. The security architect wants to reduce the...
  9. 9.A regional healthcare provider stores patient records in an internal application used by clinics around the...
  10. 10.A healthcare organization stores patient records in a central database used by clinics in multiple states....
  11. 11.A financial services company is moving its contract approval process from paper to a web-based workflow....
  12. 12.A procurement manager approves high-value purchase orders through a web portal. After a disputed transaction,...
  13. 13.A company is replacing shared local administrator passwords on 200 Windows servers with a more secure access...
  14. 14.A company is replacing shared local administrator accounts on Linux servers with a centralized AAA solution....
  15. 15.A healthcare company is preparing for an external security assessment after expanding into a new cloud-hosted...
  16. 16.A healthcare company is preparing for an external assessment against its internal security baseline and...
  17. 17.A company is replacing its traditional VPN with a Zero Trust architecture for access to internal...
  18. 18.A company is replacing its flat internal network with a Zero Trust architecture after an attacker used a...
  19. 19.A financial services company is renovating the entrance to its data center after a recent incident in which...
  20. 20.A company is upgrading security at a small data center after two incidents: an unauthorized person followed...
  21. 21.A security analyst wants early warning if an attacker gains access to the internal file share that stores...
  22. 22.A security team suspects an attacker has limited access to an internal file share and may be browsing...
  23. 23.A company experienced a two-hour outage after a network engineer changed firewall rules during business hours...
  24. 24.A security administrator needs to deploy a critical update to the company's internet-facing VPN gateways...
  25. 25.A security administrator needs to deploy an emergency change to a production web application after a critical...
  26. 26.A security team needs to deploy an emergency configuration change to a customer-facing web application after...
  27. 27.A security administrator is preparing to deploy application allow listing on several Windows servers that...
  28. 28.A security administrator must quickly reduce the risk of malware on a hospital's Windows-based medication...
  29. 29.A company recently moved several internal applications from an on-premises server network to a segmented...
  30. 30.A company recently segmented its network after a ransomware incident. The security administrator moved the...
  31. 31.A software company stores infrastructure-as-code templates and application source code in a shared Git...
  32. 32.A security team maintains infrastructure-as-code templates and firewall configuration files in a shared...
  33. 33.A healthcare company is deploying a new patient portal that allows patients to view lab results, message...
  34. 34.A healthcare company is deploying thousands of IoT medical sensors that send patient telemetry to a cloud...
  35. 35.A financial services company is deploying a new internal web application that handles sensitive customer...
  36. 36.A company is rolling out mutual TLS for a customer-facing payment API. During a security review, the team...
  37. 37.A healthcare company stores patient records in a central SQL database. Administrators need to protect highly...
  38. 38.A healthcare company is moving a legacy patient records application to a new environment. The security team...
  39. 39.A healthcare company is modernizing its patient billing platform. Developers need to let customer service...
  40. 40.A retail company is moving payment processing to a third-party cloud application. Developers need realistic...
  41. 41.A security administrator is reviewing a recently deployed customer portal after an internal audit found that...
  42. 42.A company discovers that an attacker copied its customer authentication database. During the incident review,...
  43. 43.A software company distributes internal update packages to thousands of managed laptops. After a recent...
  44. 44.A software company distributes monthly updates to customers through its public download portal. After a...
  45. 45.A SaaS company discovers that a copy of its authentication database was exposed through a misconfigured...
  46. 46.A security administrator is reviewing an internally developed web application's password storage design after...
  47. 47.A security architect is evaluating whether to use a public blockchain to store evidence that software updates...
  48. 48.A security architect is evaluating whether to store software supply-chain attestations on a blockchain so...
  49. 49.A company is deploying HTTPS for dozens of internally managed web applications hosted on subdomains of...
  50. 50.A company is deploying a new public-facing web platform with servers named app1.example.com,...
  51. 51.A regional power utility discovers that several engineering workstations in its operational technology (OT)...
  52. 52.A regional electric utility discovers that several engineering workstations in its operational technology...
  53. 53.A security analyst discovers that several employees have been uploading customer records to a public...
  54. 54.A financial services company discovers that several employees have been using an unsanctioned file-sharing...
  55. 55.A financial services company discovers unusual outbound traffic from a database server that contains...
  56. 56.A security analyst is reviewing a recent breach at a manufacturing company. The attacker used valid VPN...
  57. 57.A defense contractor discovers that an engineer who recently resigned copied proprietary drone design files...
  58. 58.A defense contractor discovers that an engineer who recently resigned copied proprietary aircraft design...
  59. 59.A company recently rolled out a web-based customer portal that integrates with a third-party payment...
  60. 60.A company recently moved several internal applications behind a reverse proxy and enabled remote access for...
  61. 61.A company's security team notices an increase in successful account takeovers. In several cases, users...
  62. 62.A company's security team is investigating a rise in account takeovers. Several employees reported receiving...
  63. 63.A security analyst is investigating suspicious activity on a Linux web server that hosts customer records....
  64. 64.A security analyst is reviewing alerts from several Linux servers and notices repeated detections of files...
  65. 65.An accounts payable clerk receives a voice call from someone claiming to be the company's CFO, who says they...
  66. 66.A company's help desk receives a voice call from someone claiming to be the CFO, who says they are traveling...
  67. 67.A security administrator discovers that several employees have been copying sensitive project files to...
  68. 68.A security administrator discovers that several employees have been copying sensitive engineering files to...
  69. 69.A security administrator is choosing a vulnerability assessment approach for a mixed environment that...
  70. 70.A security administrator is deploying a vulnerability management program across a hybrid environment that...
  71. 71.A hospital's radiology department relies on a legacy imaging workstation that runs an operating system and...
  72. 72.A manufacturing company relies on a legacy quality-control application that only runs on Windows 7. The...
  73. 73.A security administrator is reviewing a small branch office after a report that an unknown person was seen...
  74. 74.A security administrator is reviewing a small branch office after a recent penetration test. The report shows...
  75. 75.A healthcare company uses a managed service provider (MSP) to administer firewalls, endpoint protection, and...
  76. 76.A company uses a managed service provider (MSP) to administer endpoints and patch servers. During a security...
  77. 77.A company's accounting department receives an email that appears to come from the CEO, who is traveling...
  78. 78.A company's finance clerk receives an email that appears to come from the CEO, who is traveling overseas. The...
  79. 79.A security analyst is reviewing a web application after users report that they can change the URL from...
  80. 80.A security analyst is reviewing a new customer support web application after a penetration test. The tester...
  81. 81.A development team maintains a Linux-based billing application that runs a scheduled script every minute as...
  82. 82.A development team releases a Linux-based finance application that runs with elevated privileges to write...
  83. 83.A security administrator is hardening a fleet of corporate laptops used by remote employees. The company...
  84. 84.A security administrator needs to harden a fleet of company-issued Windows 11 laptops used by remote...
  85. 85.A company launches a customer portal that includes a search field and a comment section. During testing, a...
  86. 86.A company launches a customer support portal that allows users to search tickets and post comments. During...
  87. 87.A security administrator is deploying 50 laptops to employees who frequently travel with sensitive customer...
  88. 88.A security administrator is deploying new laptops to executives who frequently travel internationally. The...
  89. 89.A security administrator is responding to a report that several laptops in a finance department are loading...
  90. 90.A hospital's security team discovers that a critical radiology workstation is still running an operating...
  91. 91.A security administrator discovers that a business-critical file server is running an operating system...
  92. 92.A manufacturing company is connecting a 15-year-old HVAC control system to its corporate network so engineers...
  93. 93.A manufacturing company still relies on a legacy industrial control server that runs an unsupported operating...
  94. 94.A company runs a multi-tenant private cloud for several internal business units. After a penetration test,...
  95. 95.A cloud operations team hosts multiple customers on the same virtualization cluster. After a security review,...
  96. 96.A company is migrating a customer-facing application to a public cloud provider. The security team must...
  97. 97.A company is migrating a customer-facing web application to a public cloud provider. The security team must...
  98. 98.A company is preparing to deploy 500 point-of-sale terminals across multiple retail locations. The devices...
  99. 99.A company is preparing to deploy a new customer relationship management platform that will rely on a...
  100. 100.A security administrator is deploying full-disk encryption on a fleet of company laptops used by traveling...
  101. 101.A company is deploying thousands of IoT sensors to remote facilities. The security team needs a cryptographic...
  102. 102.A company migrated several internal web applications to a new reverse proxy in its DMZ. Two weeks later, the...
  103. 103.A company migrates an internal web application to a newly provisioned Linux server in its DMZ. Shortly after...
  104. 104.A company allows employees to use smartphones to access email, file-sharing, and an internal CRM app through...
  105. 105.A security administrator is investigating why a company-owned smartphone was able to install a file-sharing...
  106. 106.A security team detects suspicious outbound connections from several employee workstations to an unfamiliar...
  107. 107.A security analyst notices several engineering workstations making unusual outbound connections to random...
  108. 108.A security analyst notices that a file server is generating a much higher volume of outbound SMB traffic than...
  109. 109.A security analyst is reviewing alerts from a file server after several users reported that shared documents...
  110. 110.A security analyst is investigating several Windows workstations after users reported slow performance and...
  111. 111.A security administrator is investigating a workstation that began performing poorly after a user installed a...
  112. 112.A company stores backup tapes and network equipment in a small branch office server room. Over one weekend,...
  113. 113.A company experiences two physical security incidents in the same month. First, an attacker was seen...
  114. 114.A company hosts a public web application in its data center. During several outages, the security team...
  115. 115.A public-facing web application becomes intermittently unavailable shortly after a marketing campaign begins....
  116. 116.A company discovers that an internally developed web application allows authenticated users to download...
  117. 117.A company deploys a web application that lets authenticated users download invoices by requesting a file path...
  118. 118.A company signs software update packages with a legacy certificate that uses SHA-1. During a security review,...
  119. 119.A company is migrating legacy web applications behind a reverse proxy that terminates TLS. During testing, a...
  120. 120.A company uses Microsoft 365 and receives repeated user complaints that accounts are being locked out at the...
  121. 121.A security analyst notices a sharp increase in failed VPN logon attempts across hundreds of employee accounts...
  122. 122.A security analyst is reviewing alerts from the company's identity provider and SIEM after several employees...
  123. 123.A security analyst is reviewing alerts from the company SIEM after several users report intermittent access...
  124. 124.A company is rolling out a new customer support platform. The application must be reachable from the...
  125. 125.A company is expanding its remote workforce and has discovered that several employees' home computers were...
  126. 126.A company is expanding its manufacturing network and has added several industrial control system (ICS)...
  127. 127.A hospital is preparing for a security audit after a ransomware incident on its corporate user network. The...
  128. 128.A systems administrator is reviewing access to a shared finance folder on a Windows file server after an...
  129. 129.A systems administrator is reviewing access to a shared finance folder on a Windows file server after an...
  130. 130.A hospital's security team is responding to several malware incidents caused by users downloading...
  131. 131.A hospital's security team is responding to several malware incidents caused by users downloading...
  132. 132.A security administrator discovers that a developer's workstation is communicating with a known malicious...
  133. 133.A security administrator detects ransomware-like behavior on an employee workstation in the accounting...
  134. 134.A security administrator must deploy a critical operating system patch that fixes an actively exploited...
  135. 135.A security administrator learns that a critical remote code execution vulnerability is being actively...
  136. 136.A company is deploying full-disk encryption on employee laptops that store sensitive customer data. During...
  137. 137.A security administrator is deploying encryption for a web-based payroll application that is accessed by...
  138. 138.A security analyst is tuning the organization's monitoring strategy after a recent incident in which malware...
  139. 139.A security analyst is reviewing alerts from the company's monitoring platform after several users reported...
  140. 140.A company is preparing for an external audit after a ransomware incident. The security team discovers that...
  141. 141.A company discovers that several help desk technicians have been using a shared domain administrator account...
  142. 142.A security administrator discovers that several Windows laptops used by remote employees have disabled...
  143. 143.A healthcare company is decommissioning several storage arrays that previously held patient records and...
  144. 144.A company is retiring several virtual and physical servers that previously stored customer records and API...
  145. 145.A company is preparing 200 newly imaged Windows laptops for remote employees. During a pilot, a security...
  146. 146.A company is preparing 50 newly imaged laptops for remote employees. During a security review, the...
  147. 147.A healthcare company is redesigning its patient portal and supporting APIs. The security team must allow...
  148. 148.A company is redesigning its customer-facing application after a recent audit found that a compromise of a...
  149. 149.A company is modernizing a customer-facing application by moving the web tier to containers running in a...
  150. 150.A company is moving a customer-facing application from an on-premises data center to a hybrid architecture....
  151. 151.A regional healthcare provider is redesigning a patient scheduling application after several outages caused...
  152. 152.A regional healthcare provider is redesigning its patient appointment portal after several outages during...
  153. 153.A healthcare company is onboarding a third-party billing vendor that will remotely access systems containing...
  154. 154.A healthcare company is onboarding a third-party billing vendor that will process insurance claims and store...
  155. 155.A company uses infrastructure as code (IaC) templates to deploy web applications into its cloud environment....
  156. 156.A company uses Infrastructure as Code (IaC) templates in a shared Git repository to deploy cloud web servers,...
  157. 157.A company uses a serverless architecture to process customer-uploaded images. When a file is placed in cloud...
  158. 158.A company has migrated part of its customer support application to a serverless architecture. An API gateway...
  159. 159.A company is modernizing its customer portal by breaking a monolithic application into microservices. Each...
  160. 160.A company is modernizing its customer portal by breaking a monolithic application into microservices deployed...
  161. 161.A company is expanding its office and needs to connect a third-party HVAC management system to the corporate...
  162. 162.A company is replacing several unmanaged switches with managed switches in a shared office building....
  163. 163.A defense contractor maintains a workstation used to process highly sensitive design files. The system is...
  164. 164.A defense contractor maintains an engineering workstation that stores classified design data. The workstation...
  165. 165.A company is preparing for a security audit after discovering that employee workstations can directly...
  166. 166.A company is preparing for a PCI DSS assessment. The cardholder data environment (CDE) currently shares the...
  167. 167.A security operations center (SOC) receives an alert that a public-facing web application is intermittently...
  168. 168.A company's security operations center detects unusual outbound traffic from a finance workstation at 2:00...
  169. 169.A company hosts several internet-facing applications on a virtualization cluster. During a security review,...
  170. 170.A company hosts several internal applications on virtual machines in a shared VMware environment. A security...
  171. 171.A company is migrating its customer portal to a cloud-hosted environment. During seasonal sales, the portal...
  172. 172.A company is deploying a new customer portal that must support rapid growth during seasonal traffic spikes....
  173. 173.A hospital is deploying internet-connected infusion pumps so biomedical staff can remotely monitor device...
  174. 174.A healthcare clinic is deploying internet-connected infusion pumps and patient monitoring devices on its...
  175. 175.A security administrator must quickly deploy full-disk encryption to 500 company laptops used by remote...
  176. 176.A security administrator at a growing company must roll out full-disk encryption to 600 Windows laptops...
  177. 177.A power generation company is connecting a legacy SCADA environment to the corporate network so engineers can...
  178. 178.A power generation company is modernizing a legacy SCADA environment that manages turbine controllers and...
  179. 179.A regional healthcare provider is moving a patient scheduling application to a third-party cloud platform....
  180. 180.A healthcare software company is preparing to launch a new patient portal that will store limited protected...
  181. 181.A company is redesigning its backup strategy after a ransomware incident. During the last recovery effort,...
  182. 182.A company is redesigning its backup strategy after a ransomware incident. During the last recovery effort,...
  183. 183.A security administrator is reviewing vulnerability scan results for a public-facing application server that...
  184. 184.A security administrator learns that a critical remote code execution vulnerability affects the company's...
  185. 185.A manufacturing company deploys robotic arms controlled by embedded devices running a real-time operating...
  186. 186.A manufacturer deploys internet-connected infusion pumps in a hospital. The pumps run a real-time operating...
  187. 187.A hospital uses a legacy imaging system that controls MRI equipment. The vendor has not validated the latest...
  188. 188.A hospital is deploying internet-connected infusion pumps across several patient care units. The pumps run a...
  189. 189.A hospital is deploying new network-connected infusion pumps that run a stripped-down embedded operating...
  190. 190.A security administrator is hardening a small branch office that contains a firewall, a PoE switch powering...
  191. 191.A security administrator is reviewing the physical security posture of a small data center after several...
  192. 192.A company hosts its customer-facing web application in a single on-premises data center. During a recent...
  193. 193.A security administrator is redesigning a company’s remote-access environment after a recent outage prevented...
  194. 194.A company is migrating a customer-facing application to a public cloud provider and will run it on virtual...
  195. 195.A company is moving a customer-facing web application from on-premises virtual machines to a public cloud...
  196. 196.A company is redesigning its enterprise network after a ransomware incident spread from a compromised user...
  197. 197.A company is redesigning its enterprise network after a ransomware incident spread from a compromised user...
  198. 198.A healthcare company is redesigning its network after a recent outage exposed both security and availability...
  199. 199.A hospital is redesigning its network to support internet-facing patient appointment portals, internal...
  200. 200.A company hosts a customer-facing online ordering portal. After a recent code deployment, the security team...
  201. 201.A retail company hosts an Internet-facing e-commerce application that recently experienced several attempts...
  202. 202.A security administrator needs to add a new network security device in front of a public web application that...
  203. 203.A security administrator must deploy a new monitoring solution on a critical link between the core switch and...
  204. 204.A company hosts a customer-facing web application behind a load balancer in its DMZ. Security analysts...
  205. 205.A company hosts a customer-facing web application in a DMZ behind a load balancer. After a recent update, the...
  206. 206.A company is deploying 802.1X port-based access control on access switches to prevent unauthorized devices...
  207. 207.A company is deploying 802.1X on access switch ports to prevent unauthorized devices from connecting to the...
  208. 208.A company is replacing its legacy remote-access VPN concentrator. The security team wants remote employees to...
  209. 209.A company is replacing a legacy remote-access VPN concentrator used by traveling employees. The security team...
  210. 210.A company has moved most of its workforce to remote and hybrid work. Employees now access SaaS applications,...
  211. 211.A company has moved most of its workforce to remote and hybrid work. Employees now access SaaS applications...
  212. 212.A healthcare company stores patient records in a cloud-based application that is accessed by employees,...
  213. 213.A healthcare company allows employees to use their own smartphones to access email and a patient scheduling...
  214. 214.A healthcare company is moving archived patient records from an on-premises file server to a cloud object...
  215. 215.A healthcare company is moving patient billing records from an on-premises file server to a cloud storage...
  216. 216.A software company is preparing a litigation hold and data protection plan after discovering that an engineer...
  217. 217.A security administrator is helping a company classify data before migrating several repositories to a cloud...
  218. 218.A healthcare company is revising its data handling standard after an employee accidentally emailed an...
  219. 219.A healthcare organization is updating its data handling standard after several employees shared files through...
  220. 220.A healthcare company is preparing to move several datasets into a cloud analytics platform so data scientists...
  221. 221.A healthcare organization is preparing to move several business processes to a third-party SaaS platform. The...
  222. 222.A healthcare organization stores patient records in a cloud-hosted database, allows clinicians to access the...
  223. 223.A healthcare organization is updating its security controls after an audit found gaps in how patient records...
  224. 224.A multinational company based in Germany is moving its customer records to a cloud-based SaaS platform....
  225. 225.A U.S.-based software company is migrating its customer records platform to a public cloud provider. The...
  226. 226.A company allows employees to access its cloud-based HR system remotely. The security team notices repeated...
  227. 227.A company has moved its payroll application to a cloud-hosted web portal. The security team notices repeated...
  228. 228.A healthcare company is migrating a customer support application to the cloud. Support agents need to look up...
  229. 229.A retail company is modernizing its e-commerce environment after an internal audit found that customer...
  230. 230.A healthcare provider was hit by ransomware that encrypted several virtual servers, including the primary...
  231. 231.A healthcare organization recently suffered a ransomware attack that encrypted several on-premises file...
  232. 232.An e-commerce company is redesigning its public web environment after a recent outage. The security team...
  233. 233.A company hosts a customer-facing web application that must remain available during peak shopping periods....
  234. 234.A regional healthcare provider is updating its disaster recovery plan after a ransomware incident caused a...
  235. 235.A regional healthcare provider is updating its disaster recovery plan after a ransomware incident caused a...
  236. 236.A healthcare organization wants to validate its disaster recovery plan for the electronic medical records...
  237. 237.A healthcare organization is preparing to test its disaster recovery capabilities for an electronic medical...
  238. 238.A financial services company is updating its business continuity plan after a regional power failure took its...
  239. 239.A financial services company is redesigning its disaster recovery strategy after a regional power outage took...
  240. 240.A company hosts its customer portal across two cloud providers to reduce the risk of a single-provider...
  241. 241.A company runs customer-facing applications in two different public cloud providers to improve resilience and...
  242. 242.A regional healthcare provider is hit by ransomware that encrypts several on-premises application servers in...
  243. 243.A regional healthcare provider is updating its continuity of operations plan after a ransomware incident made...
  244. 244.A healthcare company is expanding from one clinic to eight regional sites and must maintain 24/7 security...
  245. 245.A healthcare company is expanding from one clinic to eight regional locations over the next six months. The...
  246. 246.A company runs a customer order database on a virtualized server. After a recent ransomware incident,...
  247. 247.A company is hit by ransomware at 3:00 p.m. on Wednesday. The security administrator confirms the malware...
  248. 248.A regional office hosts security appliances, badge access controllers, and a small virtualization cluster in...
  249. 249.A company hosts its authentication servers and security monitoring systems in a small on-premises server...
  250. 250.A company is migrating several customer-facing applications to a public cloud provider. During a security...
  251. 251.A systems administrator is hardening a group of Linux-based web servers that host an internal business...
  252. 252.A security administrator is standardizing 500 newly issued Windows laptops for a hybrid workforce. The...
  253. 253.A security administrator is tasked with standardizing 600 newly deployed Windows laptops for a hybrid...
  254. 254.A manufacturing company is connecting a legacy ICS/SCADA segment to a new analytics platform hosted in the...
  255. 255.A manufacturing company is connecting new IoT environmental sensors to an existing ICS/SCADA network to...
  256. 256.A security administrator is hardening a company’s wireless network after discovering that employees can still...
  257. 257.A security administrator is investigating reports that employees' wireless headsets are intermittently...
  258. 258.A security administrator is deploying new wireless access points in a healthcare clinic that handles...
  259. 259.A security administrator is deploying a new WPA3-Enterprise wireless network in a multitenant office...
  260. 260.A company allows employees to use personal smartphones to access corporate email and documents. After several...
  261. 261.A company allows employees to use personal smartphones to access corporate email, calendars, and internally...
  262. 262.A healthcare company must provide mobile access to email, scheduling, and an internal clinical messaging app...
  263. 263.A healthcare company must allow clinicians to access email, messaging, and scheduling apps from mobile...
  264. 264.A security administrator is deploying tablets for field technicians who work in customer buildings and remote...
  265. 265.A healthcare organization issues tablets to nurses for bedside charting. The tablets normally use the...
  266. 266.A company is replacing its shared Wi-Fi password with a more secure solution for employee laptops and phones....
  267. 267.A security administrator is upgrading a corporate wireless network used by employee laptops and tablets. The...
  268. 268.A company is preparing to release an updated customer portal after a penetration test found two issues:...
  269. 269.A company is releasing a customer portal update after a security review found several issues. Testers...
  270. 270.A security analyst receives a suspicious spreadsheet attachment from a vendor email account that may have...
  271. 271.A security analyst receives a suspicious email attachment that appears to be an invoice PDF. The company...
  272. 272.A security analyst is tuning the company's monitoring program after several ransomware attempts were missed...
  273. 273.A security analyst is tuning the company’s monitoring strategy after a recent incident in which an attacker...
  274. 274.A healthcare company is preparing for an external audit after discovering that several retired laptops...
  275. 275.A healthcare company is preparing for an external audit after discovering that several laptops issued to...
  276. 276.A healthcare company is acquiring a cloud-based document management platform to store contracts, HR files,...
  277. 277.A company is procuring a cloud-based document management platform to store contracts, customer records, and...
  278. 278.A security administrator is reviewing remote-access controls for a company that uses a centralized AAA server...
  279. 279.A security administrator is reviewing remote-access controls for a company VPN that uses a AAA framework with...
  280. 280.A company is updating its information security program after a failed audit found that several critical...
  281. 281.A company is preparing for a compliance audit after several incidents in which critical customer records were...
  282. 282.A healthcare company is rolling out a data handling policy after discovering that employees store patient...
  283. 283.A healthcare organization is implementing a new data handling standard after discovering that staff have been...
  284. 284.A security administrator is responding to an incident involving a contractor's laptop that accessed sensitive...
  285. 285.A security administrator discovers that several company laptops are appearing on the wireless network after...
  286. 286.A security administrator is responding to a ransomware incident and discovers several engineering...
  287. 287.A security administrator is preparing for a vulnerability management initiative after several unmanaged...
  288. 288.A security analyst is reviewing the results of an internal assessment on a Windows-based network. The tester...
  289. 289.A security analyst is validating the scope of an internal penetration test and wants to identify exposed...
  290. 290.A healthcare organization is retiring several storage systems from a claims-processing environment. The...
  291. 291.A healthcare organization is retiring several storage systems after a data center refresh. The environment...
  292. 292.A healthcare company is reviewing its security logging strategy after an incident investigation failed...
  293. 293.A healthcare company is reviewing its log management process after an incident response exercise revealed...
  294. 294.A security analyst runs a credentialed vulnerability scan against a group of internet-facing Linux web...
  295. 295.A security analyst runs a credentialed vulnerability scan against a group of internet-facing Linux web...
  296. 296.A software company is preparing to release a new customer portal built with several open-source libraries....
  297. 297.A software company is preparing to release a new customer portal within two weeks. During final testing, the...
  298. 298.A security analyst at a healthcare company reviews the weekly vulnerability scan results. The scanner reports...
  299. 299.A security analyst at a healthcare company reviews the latest vulnerability scan results. The scanner reports...
  300. 300.A hospital's security team identifies a critical remote code execution vulnerability on a legacy radiology...
  301. 301.A hospital's security team identifies a critical remote-code-execution vulnerability on a legacy radiology...
  302. 302.A security administrator deployed patches to address a critical web server vulnerability identified during...
  303. 303.After applying emergency patches to several internet-facing Linux web servers to remediate a critical...
  304. 304.A security analyst has completed the initial investigation of a ransomware incident affecting several file...
  305. 305.A security analyst is preparing a monthly report for executive leadership after several phishing attempts and...
  306. 306.A security analyst is overwhelmed by thousands of daily alerts from multiple tools, including the firewall,...
  307. 307.A security analyst is reviewing overnight alerts and sees that a domain controller generated hundreds of...
  308. 308.A security administrator is tuning monitoring controls after a recent incident in which a compromised web...
  309. 309.A security administrator is investigating an intermittent outage affecting a public web application hosted on...
  310. 310.A security analyst at a healthcare company is investigating a suspected phishing campaign that may have led...
  311. 311.A security administrator is improving the company’s monitoring program after an incident in which suspicious...
  312. 312.A security analyst notices that the EDR platform is repeatedly generating high-severity alerts for a finance...
  313. 313.A security analyst is investigating repeated endpoint detection and response (EDR) alerts for a finance...
  314. 314.A security administrator must improve visibility into suspicious outbound traffic from several remote office...
  315. 315.A security team must quickly improve visibility across a hybrid environment that includes on-premises...
  316. 316.A company recently adopted a hybrid work model and allows employees to access internal web applications from...
  317. 317.A company recently acquired a smaller business and needs to give the new employees access to several internal...
  318. 318.A company hosts a public web application in a screened subnet (DMZ). The web server must be reachable from...
  319. 319.A company hosts a public web application in a screened subnet (DMZ). The web server must be reachable from...
  320. 320.A security analyst notices that an organization’s network IPS is generating repeated alerts for outbound...
  321. 321.A security administrator deployed a network IPS at the internet edge and enabled a vendor-provided signature...
  322. 322.A company has moved to a hybrid work model, and many users now work from home without a VPN connection. The...
  323. 323.A company has moved to a hybrid work model, and many employees now work from home or travel frequently. The...
  324. 324.A company manages Windows 11 workstations through Active Directory and hosts a public-facing web application...
  325. 325.A company manages Windows workstations through Active Directory and runs a public-facing web application on a...
  326. 326.A company is deploying a new remote administration solution for Linux servers in a segmented data center. The...
  327. 327.A security administrator is replacing several legacy remote administration services used by network...
  328. 328.A company recently had several users click links in phishing emails that led to newly registered domains...
  329. 329.A company recently had several users click links in phishing emails that attempted to send them to newly...
  330. 330.A company recently moved its outbound marketing emails to a third-party cloud service. Soon after, customers...
  331. 331.A company uses a cloud email gateway to filter inbound and outbound mail for the domain example.com. The...
  332. 332.A security administrator enables file integrity monitoring (FIM) on a Linux-based public web server after a...
  333. 333.A security administrator is deploying file integrity monitoring (FIM) on a public-facing Linux web server...
  334. 334.A company recently allowed employees to use personal email and cloud storage sites from corporate laptops....
  335. 335.A healthcare organization allows employees to use a cloud-based email service and web browser access from...
  336. 336.A company is rolling out a network access control (NAC) solution to reduce the risk of unmanaged devices...
  337. 337.A company is rolling out network access control (NAC) for all wired and wireless connections. The security...
  338. 338.A security analyst is investigating a phishing incident in which a user opened a malicious attachment on a...
  339. 339.A security analyst is investigating a suspected phishing incident. An employee clicked a malicious link, and...
  340. 340.A company uses a SIEM with user behavior analytics (UBA) to detect insider threats. Over the past week, the...
  341. 341.A security analyst is tuning a newly deployed user behavior analytics (UBA) capability in the company SIEM....
  342. 342.A company recently integrated its HR system with its identity provider so that employee status changes...
  343. 343.A company is onboarding 150 temporary contractors for a six-week project. The contractors need access to a...
  344. 344.A company discovers that a recently terminated employee was still able to sign in to a cloud-based...
  345. 345.A company discovered that a recently terminated payroll administrator was still able to sign in to a cloud HR...
  346. 346.A security administrator is reviewing access to a shared finance folder on a Windows file server after an...
  347. 347.A systems administrator is reviewing access to a shared finance folder after an internal audit found that...
  348. 348.A healthcare company is rolling out a self-service process for issuing credentials to newly hired remote...
  349. 349.A healthcare organization is onboarding remote contractors who need access to systems containing regulated...
  350. 350.A company is integrating with a cloud-based partner portal so employees can use their existing corporate...
  351. 351.A company is acquiring a smaller business and needs users from both organizations to access a shared SaaS...
  352. 352.A company is integrating a new cloud-based human resources application with its existing on-premises identity...
  353. 353.A company uses an on-premises Active Directory environment as its central identity source and wants employees...
  354. 354.A healthcare company is integrating a cloud-based identity provider with several on-premises and SaaS...
  355. 355.A company is integrating a cloud-based identity provider with several third-party SaaS applications. The...
  356. 356.A company is rolling out remote access for administrators to manage critical servers from company-issued...
  357. 357.A company allows remote administrators to connect to a critical virtualization cluster only from approved...
  358. 358.A hospital is deploying a new electronic health record (EHR) system. Nurses must be able to view and update...
  359. 359.A hospital is deploying a new electronic health record (EHR) system. Nurses should be able to view and update...
  360. 360.A financial services company is rolling out multifactor authentication for employees who access cloud-based...
  361. 361.A healthcare organization is rolling out MFA for employees who access its cloud-based patient records system....
  362. 362.A financial services company is tightening access to its wire-transfer system after a phishing incident...
  363. 363.A financial services company allows employees to access its trading platform remotely. After several account...
  364. 364.A security administrator is updating the company’s password policy after several help desk tickets revealed...
  365. 365.A company is revising its password policy after a phishing campaign led to several account compromises. The...
  366. 366.A security administrator is revising the company password policy after several user accounts were compromised...
  367. 367.A security administrator is updating the password policy for a company after an internal audit found that...
  368. 368.A security administrator is rolling out a password manager to a hybrid workforce. The company wants to reduce...
  369. 369.A security administrator is deploying a password manager for a hybrid workforce. Employees currently reuse...
  370. 370.A company wants to reduce phishing-related account compromises for employees who access email, HR, and...
  371. 371.A healthcare company is replacing passwords for access to its patient records application because users...
  372. 372.A company is tightening controls over administrator access after an internal audit found that server...
  373. 373.A security administrator at a healthcare company needs to reduce the risk of privileged account misuse on...
  374. 374.A company is moving its administrative access model from shared service-account passwords to a more secure...
  375. 375.A company is moving its administrative access model to reduce the risk of stolen credentials being reused....
  376. 376.A security operations center (SOC) is overwhelmed by repeated phishing emails that deliver the same malicious...
  377. 377.A security operations center (SOC) is overwhelmed by repeated phishing alerts from the email gateway....
  378. 378.A company is moving to an automated joiner/mover/leaver process for cloud and SaaS accounts. The security...
  379. 379.A company is moving its employee onboarding and offboarding process to an automated workflow that integrates...
  380. 380.A company is expanding rapidly and now deploys new cloud-based application servers every week. The security...
  381. 381.A security manager at a rapidly growing company needs to reduce the time required to deploy new cloud servers...
  382. 382.A mid-sized company is replacing its aging VPN solution. The security team proposes a highly customized...
  383. 383.A mid-sized company is replacing its legacy remote access solution. The security team proposes a highly...
  384. 384.A security analyst discovers that a finance department workstation is communicating with a known...
  385. 385.A security analyst receives multiple alerts indicating that a finance department workstation is communicating...
  386. 386.A company’s security team detects ransomware activity on a file server after several users report that shared...
  387. 387.A security analyst discovers that several employee workstations are communicating with a known malicious...
  388. 388.A healthcare company wants to evaluate its incident response plan for a ransomware attack without disrupting...
  389. 389.A security manager wants to validate the company incident response plan for a ransomware attack without...
  390. 390.A security analyst is investigating why several internal file servers became unreachable for 20 minutes...
  391. 391.A security analyst is conducting a threat-hunting exercise after a recent industry alert about attackers...
  392. 392.A security analyst is conducting a threat hunt after receiving industry intelligence that a ransomware group...
  393. 393.A company discovers that a departing employee may have exfiltrated proprietary design files before leaving....
  394. 394.A company discovers that an employee may have exfiltrated sensitive design documents before resigning. Legal...
  395. 395.A security analyst is investigating a suspected compromise of a file server after several users reported...
  396. 396.A security analyst is investigating a suspected account compromise involving a finance employee. At 2:13...
  397. 397.A security analyst is investigating a suspected data exfiltration incident from a finance department...
  398. 398.A security analyst is investigating a suspected data exfiltration incident from a finance application server....
  399. 399.A security analyst is investigating reports that several internal web servers are intermittently failing...
  400. 400.A security analyst sees a spike in failed logon attempts on the SOC dashboard for a public-facing web...
  401. 401.A healthcare company recently expanded through acquisition and now has multiple business units handling...
  402. 402.A healthcare company is expanding into two new states and must align its security program with stricter...
  403. 403.A security manager is updating the organization's policy framework after an internal audit found that several...
  404. 404.A healthcare organization is updating its security documentation after an internal audit found that different...
  405. 405.A company is preparing to roll out a security patch to the web application that handles customer orders. The...
  406. 406.A software company discovers that a recently deployed web application update is exposing customer data...
  407. 407.A healthcare company is updating security controls for a records room that stores paper files and a...
  408. 408.A healthcare clinic is renovating a satellite office that will handle patient check-ins and insurance...
  409. 409.A company recently had a terminated employee use a still-active VPN account to access internal systems after...
  410. 410.A company recently terminated a systems administrator and, two days later, discovered that the former...
  411. 411.A U.S.-based e-commerce company is expanding into the European Union and Brazil. The company processes online...
  412. 412.A U.S.-based e-commerce company is expanding into the European Union and Brazil. The company collects...
  413. 413.A company completed a major cloud migration six months ago and enabled continuous monitoring through its...
  414. 414.A company recently completed a security audit after discovering that several critical Windows servers had...
  415. 415.A multinational company has grown through acquisitions and now operates several autonomous business units....
  416. 416.A multinational company recently acquired three regional businesses. Each region currently manages its own...
  417. 417.A healthcare company uses a third-party SaaS platform to store and analyze patient appointment data. The...
  418. 418.A healthcare company stores patient billing records in a SaaS platform. The finance director decides which...
  419. 419.A healthcare company is preparing to roll out a new cloud-based patient scheduling platform. During a risk...
  420. 420.A healthcare company is preparing to launch a new patient portal that will store protected health information...
  421. 421.A healthcare company is preparing to deploy a new internet-facing patient scheduling portal. During a...
  422. 422.A company is preparing to launch a new customer portal that will process payment data and store customer...
  423. 423.A healthcare company is migrating several patient-facing applications from an on-premises data center to a...
  424. 424.A healthcare company is migrating several patient-facing applications to a new cloud platform over the next...
  425. 425.A healthcare company is evaluating the financial risk of a ransomware attack against its patient scheduling...
  426. 426.A healthcare company is evaluating the financial risk of ransomware affecting a file server that stores...
  427. 427.A healthcare company tracks third-party vendor risks in a risk register. One entry covers a cloud billing...
  428. 428.A healthcare company maintains a risk register for its patient billing platform. One entry lists the risk of...
  429. 429.A regional retail company is reviewing cybersecurity spending after several quarters of lower-than-expected...
  430. 430.A healthcare company is preparing to launch a new patient scheduling portal. The security team identifies...
  431. 431.A company is launching a new customer analytics platform in a highly competitive market. During a governance...
  432. 432.A retail company is expanding into online sales and plans to launch a new mobile checkout feature before the...
  433. 433.A healthcare company uses a legacy imaging system that controls MRI machines. The vendor no longer provides...
  434. 434.A healthcare company wants to launch a patient outreach web portal before the end of the quarter. During the...
  435. 435.A security analyst has completed a quarterly risk assessment and must present the results to executive...
  436. 436.A security analyst has completed a quarterly risk assessment and identified a legacy public-facing...
  437. 437.A healthcare provider is updating its business impact analysis for a patient scheduling application. During...
  438. 438.A healthcare provider is updating its business impact analysis for a patient records application. The...
  439. 439.A healthcare company is evaluating a cloud-based billing vendor that will store and process protected health...
  440. 440.A healthcare company is evaluating a cloud-based billing vendor that will process protected health...
  441. 441.A healthcare company is evaluating a cloud-based claims-processing vendor that will store protected health...
  442. 442.A healthcare company is evaluating a cloud-based billing vendor that will process protected health...
  443. 443.A company is selecting a managed security service provider (MSSP) to monitor its SIEM and incident response...
  444. 444.A company is selecting a managed security service provider (MSSP) to monitor its cloud environment. During...
  445. 445.A company is outsourcing the deployment of a new security monitoring platform to a managed security services...
  446. 446.A company is hiring a third-party security firm to perform a six-week penetration test and vulnerability...
  447. 447.A healthcare company uses a third-party billing vendor that connects to internal systems through a...
  448. 448.A company uses a third-party payroll provider that stores employee tax records and bank account information....
  449. 449.A security analyst is helping the procurement team evaluate a cloud-based payroll vendor before signing a...
  450. 450.A healthcare organization is onboarding a cloud-based billing vendor that will process patient account data...
  451. 451.A company hires a third-party security firm to perform a penetration test against its production environment....
  452. 452.A company hires a third-party security firm to perform a penetration test against its public-facing web...
  453. 453.A healthcare provider is preparing for an external compliance assessment after expanding its telemedicine...
  454. 454.A healthcare company is preparing for an external audit after expanding into online patient scheduling and...
  455. 455.A healthcare company is preparing two different compliance reports after a quarterly security review. Senior...
  456. 456.A healthcare company recently completed a quarterly review of its access controls, log retention, and...
  457. 457.A payment-processing company that handles credit card transactions failed a PCI DSS assessment after auditors...
  458. 458.A regional healthcare billing company that processes protected health information (PHI) for several hospitals...
  459. 459.A healthcare company is preparing for an external HIPAA assessment after a recent internal review found...
  460. 460.A healthcare company must demonstrate ongoing compliance with internal security policies and external...
  461. 461.A U.S.-based e-commerce company sells directly to customers in Germany, California, and Brazil. It uses a...
  462. 462.A U.S.-based e-commerce company sells directly to customers in Germany, Brazil, and California. It uses a...
  463. 463.A healthcare organization is preparing to sign a contract with a cloud-based billing provider that will...
  464. 464.A healthcare company is preparing to sign a contract with a cloud-based billing vendor that will process...
  465. 465.A company is deploying laptops to remote employees and wants to allow VPN access only from devices that can...
  466. 466.A company is deploying a remote access solution for third-party contractors who will connect from unmanaged...
  467. 467.A financial services company is preparing for its annual governance review after several minor policy...
  468. 468.A company's audit committee has asked the security manager to improve oversight of internal compliance with...
  469. 469.A regional healthcare provider is preparing for an external review after a recent expansion into a new state....
  470. 470.A regional healthcare provider is preparing for an unannounced review by a government regulator after...
  471. 471.A financial services company hires a third-party firm to evaluate how well its security team can detect and...
  472. 472.A healthcare organization is hiring a third-party firm to evaluate how well its security team can detect and...
  473. 473.A security analyst is gathering information about a third-party company's internet-facing environment before...
  474. 474.A security analyst is gathering information about a newly acquired subsidiary before a formal penetration...
  475. 475.A healthcare startup is preparing to sign a contract with a large enterprise customer that requires proof the...
  476. 476.A healthcare company is preparing to sign contracts with several new business partners that will require...
  477. 477.A company has seen an increase in successful phishing attacks after several employees clicked links in emails...
  478. 478.A company recently had several employees disclose their usernames and MFA approval codes after receiving...
  479. 479.A company's security awareness program encourages employees to report suspicious emails by using a...
  480. 480.A company's help desk receives several reports about an email titled "Updated MFA Policy - Immediate Action...
  481. 481.A security analyst is reviewing alerts from a user and entity behavior analytics (UEBA) platform. One...
  482. 482.A security analyst is reviewing activity in a company's SaaS environment after a data loss prevention alert....
  483. 483.A company has shifted to a hybrid work model. Several recent incidents have occurred: employees have plugged...
  484. 484.A company has shifted to a hybrid work model. Several recent incidents have occurred: an employee plugged an...
  485. 485.A security manager is formalizing reporting for a newly deployed SIEM. Executives want an initial report that...
  486. 486.A security analyst has completed the first round of vulnerability scans after a new reporting and monitoring...
  487. 487.A software development team is preparing to release a new customer-facing web application. During a...
  488. 488.A software development team is building a customer-facing web application. During a security review, the team...
  489. 489.A security analyst is reviewing alerts from several Windows endpoints after a user opened a malicious email...
  490. 490.A security analyst is reviewing alerts from an endpoint detection and response (EDR) platform after a user...

SY0-701 exam dumps FAQ

Are these SY0-701 dumps real exam questions?

No. These are original practice questions written to the Security+ exam objectives, not questions copied from a live exam. Memorising leaked questions violates CompTIA's candidate agreement and stops working the moment the question pool rotates. Use this bank to check your understanding of each domain and to find the topics you still need to study.

How many SY0-701 practice questions are there?

490 questions, each with the correct answer, an explanation of the answer, and a note on why every other option is wrong. The first 10 are on this page and every question has its own page linked below.

Are the SY0-701 exam dumps free?

Yes. Every question, answer and explanation on this page and the linked question pages is free to read without an account. A free HydraNode account adds timed practice exams, scoring and progress tracking across attempts.

How do I take a timed SY0-701 practice test?

Sign in and start the Security+ exam on HydraNode. A session gives you 90 questions drawn from this bank in 90 minutes, then a score report with a per-question review.

What topics does the SY0-701 exam cover?

The official exam domains are: General Security Concepts; Threats, Vulnerabilities, and Mitigations; Security Architecture; Security Operations; Security Program Management and Oversight.