CompTIAAssociate levelSY0-701Page 2 of 5

SY0-701 exam dumps: questions 101 to 200 of 490

Page 2 of the free SY0-701 question bank for the Security+ exam. Questions 101 to 200 are listed below, the first 5 in full with answers and explanations. Back to page 1 for the exam overview and FAQ.

Question bank last updated June 2026

Free SY0-701 practice questions

Questions 101 to 105 of 490

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

SY0-701 Question 101

Single answerCryptographic

A company is deploying thousands of IoT sensors to remote facilities. The security team needs a cryptographic solution that allows each device to authenticate to the company's management platform over TLS while minimizing CPU usage and battery consumption on the sensors. The solution must also support strong security and practical certificate-based identity management. Which of the following is the BEST choice?

  1. A

    Use RSA 4096-bit certificates for all devices because larger key sizes provide the best performance-to-security balance on constrained hardware

  2. B

    Use elliptic curve cryptography (ECC) certificates because ECC provides strong security with smaller key sizes and lower computational overhead than RSA

  3. C

    Use a pre-shared key (PSK) for all devices because symmetric cryptography is stronger than public key cryptography for device identity

  4. D

    Use SHA-256 hashing instead of certificates because hashing provides device authentication without requiring asymmetric cryptography

Show answer and explanation

Correct answer: B

Explanation

The best answer is to use ECC certificates. In real-world Security+ contexts, candidates are expected to understand not just what cryptographic algorithms do, but where they are most appropriate. For constrained devices such as IoT sensors, ECC is often preferred because it achieves strong security with smaller key sizes than RSA, which reduces CPU usage, memory consumption, storage requirements, and handshake overhead during TLS operations. This directly supports the scenario's goals of efficiency, strong security, and certificate-based identity management. By contrast, RSA 4096-bit increases computational cost, a shared PSK does not provide robust scalable per-device identity, and SHA-256 alone cannot replace certificates or asymmetric authentication. This aligns with common industry guidance and best practices reflected in NIST cryptographic recommendations and standard TLS deployment considerations for resource-constrained systems.

  • A. Incorrect.

    Incorrect. RSA 4096-bit keys provide strong security, but they are computationally heavier than ECC and are generally a poor fit for constrained IoT devices where CPU, memory, and battery life matter. In this scenario, the requirement is to minimize resource usage while still supporting certificate-based identity management over TLS. Larger RSA keys work against that goal.

  • B. Correct.

    Correct. ECC is commonly preferred for constrained environments because it provides comparable security to RSA with much smaller key sizes, reducing processing, storage, and bandwidth requirements. This makes ECC well suited for IoT devices that must use certificate-based authentication over TLS while conserving CPU and battery resources.

  • C. Incorrect.

    Incorrect. A PSK can reduce overhead in some environments, but using one shared key for all devices does not provide strong per-device identity or scalable certificate-based management. If one device is compromised, the shared secret may be exposed, affecting the entire fleet. The scenario specifically calls for practical certificate-based identity management, which PSKs do not satisfy in the same way as unique device certificates.

  • D. Incorrect.

    Incorrect. SHA-256 is a hashing algorithm used for integrity-related functions, not a standalone mechanism for certificate-based device authentication. Hashing by itself does not establish identity over TLS. Certificates and asymmetric cryptography are used to bind a device identity to a public key, which is what the scenario requires.

SY0-701 Question 102

Single answerMisconfiguration

A company migrated several internal web applications to a new reverse proxy in its DMZ. Two weeks later, the security team discovers that one of the applications is accessible from the internet without requiring authentication, even though the application itself was intended for internal HR staff only. Log review shows no exploit attempts or malware activity; instead, external users were simply able to browse directly to the application URL. The proxy configuration was recently changed to speed up deployment of new apps. Which of the following is the MOST likely cause of this exposure?

  1. A

    The reverse proxy was misconfigured with an overly permissive access control rule that allowed unauthenticated external requests to the HR application

  2. B

    The HR application was compromised through a buffer overflow that disabled authentication checks for internet users

  3. C

    The DNS server was poisoned, causing external users to be redirected to the internal HR application

  4. D

    The web server certificate expired, causing the reverse proxy to bypass authentication for availability

Show answer and explanation

Correct answer: A

Explanation

This question tests recognition of misconfiguration as a root cause of security exposure. When a service becomes accessible externally immediately after an infrastructure change, and there is no evidence of exploitation, the most likely cause is a configuration error. In this case, a reverse proxy or application gateway may have been configured with overly broad access rules, incorrect path publishing, or missing authentication requirements. Security best practices emphasize least privilege, change control, secure baseline configurations, and validation after deployment. Guidance from sources such as NIST SP 800-41 on boundary protection and NIST SP 800-123 on secure configuration management supports reviewing access control rules, published services, and authentication enforcement after changes. A key lesson is that misconfiguration can create significant exposure even when no attacker has exploited a software vulnerability.

  • A. Correct.

    Correct. This is the most likely explanation because the scenario specifically points to a recent configuration change on the reverse proxy and notes that there were no signs of exploitation. In real environments, exposing an internal application often results from permissive routing, access control lists, missing authentication enforcement, or publishing the wrong backend path. This is a classic misconfiguration issue rather than an attack.

  • B. Incorrect.

    Incorrect. A buffer overflow is a software vulnerability exploitation scenario, but the question explicitly states there is no evidence of exploit attempts or malware activity. The facts better support accidental exposure through configuration error rather than memory corruption leading to disabled authentication.

  • C. Incorrect.

    Incorrect. DNS poisoning can redirect users to malicious or unintended destinations, but it would not typically make an internal HR application broadly reachable from the internet by itself. The issue described is that the application was directly accessible through the newly deployed reverse proxy, which points to a publishing or access-rule misconfiguration rather than name resolution manipulation.

  • D. Incorrect.

    Incorrect. An expired certificate can cause trust warnings, service interruptions, or TLS negotiation problems, but it does not normally cause a reverse proxy to disable authentication. Choosing this option reflects a misconception that certificate problems automatically change authorization behavior. Authentication and certificate validity are separate controls in most architectures.

SY0-701 Question 103

Single answerMisconfiguration

A company migrates an internal web application to a newly provisioned Linux server in its DMZ. Shortly after go-live, a security analyst discovers that the application is reachable from the internet over both HTTPS and SSH. The operations team confirms that administrators only need SSH access from the internal management subnet, and the web application should be publicly accessible only over HTTPS. A review of the server shows that the SSH service is installed and running, and the host-based firewall is enabled. Which action would BEST address the security issue caused by misconfiguration while preserving required administrative access?

  1. A

    Disable the host-based firewall so it does not interfere with application traffic

  2. B

    Restrict inbound SSH on the host-based firewall to the internal management subnet and leave HTTPS open to the internet

  3. C

    Uninstall the SSH service entirely because any remote administration service in a DMZ is insecure

  4. D

    Move the web server from the DMZ to the internal network so administrators can access it safely

Show answer and explanation

Correct answer: B

Explanation

The best answer is to restrict SSH access using the host-based firewall so only the internal management subnet can connect, while keeping HTTPS available publicly for the web application. This is a classic misconfiguration scenario: a service that should be limited to administrative networks is exposed to the internet. Security best practices emphasize least privilege, secure management plane separation, and system hardening by restricting administrative access paths. Guidance from organizations such as NIST supports limiting management access to authorized networks, reducing exposed services, and using layered controls such as host-based and network firewalls. In a real environment, this would often be implemented with host firewall rules, security groups, ACLs, or access through a bastion host, depending on the architecture.

  • A. Incorrect.

    This is incorrect. Disabling the host-based firewall would increase exposure and does not solve the underlying misconfiguration. Best practice is to use layered defenses, including host-based firewalls, to restrict management services. Removing the firewall would make the server less secure and could expose additional services unintentionally.

  • B. Correct.

    This is correct. The issue is a misconfiguration of access controls, not the mere presence of SSH. SSH can be appropriate for secure administration when access is limited to authorized sources such as a management subnet or jump host. Restricting inbound SSH to the internal management subnet while allowing HTTPS from the internet enforces least privilege and aligns the server configuration with business requirements.

  • C. Incorrect.

    This is incorrect. While removing unnecessary services is good hardening practice, the scenario states administrators require SSH access. Uninstalling SSH would break a valid operational need rather than correct the misconfiguration. The better solution is to limit SSH exposure to approved sources.

  • D. Incorrect.

    This is incorrect. Moving the web server to the internal network would undermine the purpose of the DMZ, which is to isolate public-facing services from the internal network. The problem is not server placement but improper access control on a management service. Re-architecting the network in this way would likely increase risk instead of reducing it.

SY0-701 Question 104

Select 2Mobile device: Side loading , Jailbreaking

A company allows employees to use smartphones to access email, file-sharing, and an internal CRM app through a mobile device management (MDM) platform. During an investigation, the security team discovers that one employee installed a third-party app store to load an unofficial VPN app that is not available in the device's approved app marketplace. The same device is also found to have operating system protections removed so the user could install unsigned apps. Which TWO issues best describe what occurred on this device?

  1. A

    The device was rooted or jailbroken to bypass built-in operating system restrictions

  2. B

    The device used side loading to install an app outside the approved app store

  3. C

    The device was SIM cloned to duplicate the carrier identity for network access

  4. D

    The device used NFC pairing, which automatically disables application signature checks

  5. E

    The device was carrier unlocked, which allows installation of any unsigned application

Show answer and explanation

Correct answers: A, B

Explanation

The scenario describes two separate but related mobile device risks commonly covered in Security+: side loading and rooting/jailbreaking. Installing an unofficial VPN app from a third-party app store is side loading because the app came from outside the organization's approved marketplace. Removing operating system protections so unsigned apps can be installed indicates the device was rooted or jailbroken. In enterprise security practice, both conditions are high risk because they undermine the trusted software model, weaken platform security controls, and can violate MDM compliance policies. Best practices from major mobile platform vendors and enterprise mobility guidance recommend blocking or detecting rooted/jailbroken devices, restricting app installation sources, enforcing approved app stores, and using MDM or UEM compliance policies to quarantine noncompliant devices from corporate resources.

  • A. Correct.

    Correct. Rooting on Android or jailbreaking on iOS refers to removing or bypassing manufacturer and operating system security restrictions to gain elevated control over the device. This commonly enables installation of unapproved or unsigned software, weakens sandboxing and platform protections, and increases the risk of malware and data compromise in enterprise environments.

  • B. Correct.

    Correct. Side loading is the installation of applications from outside the official or approved app marketplace, such as directly from a website, third-party store, or manual package file. In a corporate environment, this bypasses normal vetting and increases the chance of installing malicious or tampered applications.

  • C. Incorrect.

    Incorrect. SIM cloning involves copying subscriber identity information to another SIM for fraudulent carrier access or impersonation. That issue is unrelated to installing apps from an unofficial source or removing OS protections to allow unsigned software.

  • D. Incorrect.

    Incorrect. NFC pairing is a short-range wireless method used to simplify device pairing or data exchange. It does not disable application signature verification or operating system security controls. This option is a plausible distractor because it involves mobile functionality, but it is not related to app installation trust controls.

  • E. Incorrect.

    Incorrect. Carrier unlocking removes restrictions that tie a device to a specific mobile carrier, allowing use with other compatible carriers. It does not inherently permit installation of unsigned applications or bypass operating system application security controls. Candidates may confuse carrier restrictions with OS security restrictions, but they are different concepts.

SY0-701 Question 105

Single answerMobile device: Side loading , Jailbreaking

A security administrator is investigating why a company-owned smartphone was able to install a file-sharing app that is not in the approved enterprise app catalog. The device also stopped reporting compliance status to the organization's mobile device management (MDM) platform shortly afterward. The user admits to following online instructions to gain access to additional apps and then manually installing the application package. Which action BEST explains what happened?

  1. A

    The user jailbroke or rooted the device and then sideloaded an unapproved app, bypassing normal app-store and MDM controls

  2. B

    The device automatically installed the app through near-field communication (NFC) pairing with another phone

  3. C

    The user enrolled the device in a different Wi-Fi network, which disabled the built-in application allowlist

  4. D

    The app was installed through a standard operating system update process that temporarily hides it from the MDM console

Show answer and explanation

Correct answer: A

Explanation

This question tests the practical difference and relationship between jailbreaking/rooting and sideloading. Jailbreaking (commonly associated with iOS) or rooting (commonly associated with Android) removes manufacturer or OS restrictions, often allowing elevated access and disabling security protections that enterprises rely on. Sideloading is the installation of apps from outside an official app store or approved enterprise app source. In real environments, these behaviors increase the risk of malware, policy bypass, data leakage, and loss of management visibility.

From a Security+ perspective, the best answer is the one that connects both actions in sequence: the device was modified to bypass restrictions, and then an unapproved app was manually installed. Enterprise best practices typically include using MDM/UEM solutions to detect rooted or jailbroken devices, block noncompliant devices from accessing corporate resources, restrict app installation sources, and enforce approved app catalogs. These practices align with vendor and industry guidance from major mobile platform providers and enterprise mobility management documentation, which warn that rooted/jailbroken devices undermine platform trust and that sideloading increases exposure to unvetted software.

  • A. Correct.

    Correct. The scenario describes two related issues: the user 'followed online instructions to gain access to additional apps' and then manually installed an application package. That strongly indicates jailbreaking on iOS or rooting on Android, followed by sideloading. Jailbreaking/rooting removes or weakens vendor security restrictions, and sideloading installs apps from outside the official store or managed enterprise catalog. These actions can also interfere with MDM compliance checks or trigger the device to fall out of a trusted state.

  • B. Incorrect.

    Incorrect. NFC can be used for limited data exchange or pairing, but it does not normally result in silent installation of a full mobile application package in a managed enterprise scenario. This option is plausible because users may associate wireless proximity features with file transfer, but it does not fit the details about intentionally gaining access to additional apps and manually installing a package.

  • C. Incorrect.

    Incorrect. Changing Wi-Fi networks does not disable mobile OS application allowlisting or remove MDM enforcement by itself. Network changes can affect connectivity to management systems, but they do not explain the user's admission that they used online instructions to gain access to unapproved apps and manually installed an app package.

  • D. Incorrect.

    Incorrect. Standard operating system updates come from the device vendor or carrier and are not a method for installing a random unapproved file-sharing app outside the enterprise catalog. Also, an OS update would not typically 'hide' an app from MDM; instead, the MDM should continue reporting device state unless the device has been altered, disconnected, or rendered noncompliant.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

SY0-701 practice questions 101 to 200 of 490

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them. The bank is split into 5 pages of up to 100 questions.

  1. 101.A company is deploying thousands of IoT sensors to remote facilities. The security team needs a cryptographic...
  2. 102.A company migrated several internal web applications to a new reverse proxy in its DMZ. Two weeks later, the...
  3. 103.A company migrates an internal web application to a newly provisioned Linux server in its DMZ. Shortly after...
  4. 104.A company allows employees to use smartphones to access email, file-sharing, and an internal CRM app through...
  5. 105.A security administrator is investigating why a company-owned smartphone was able to install a file-sharing...
  6. 106.A security team detects suspicious outbound connections from several employee workstations to an unfamiliar...
  7. 107.A security analyst notices several engineering workstations making unusual outbound connections to random...
  8. 108.A security analyst notices that a file server is generating a much higher volume of outbound SMB traffic than...
  9. 109.A security analyst is reviewing alerts from a file server after several users reported that shared documents...
  10. 110.A security analyst is investigating several Windows workstations after users reported slow performance and...
  11. 111.A security administrator is investigating a workstation that began performing poorly after a user installed a...
  12. 112.A company stores backup tapes and network equipment in a small branch office server room. Over one weekend,...
  13. 113.A company experiences two physical security incidents in the same month. First, an attacker was seen...
  14. 114.A company hosts a public web application in its data center. During several outages, the security team...
  15. 115.A public-facing web application becomes intermittently unavailable shortly after a marketing campaign begins....
  16. 116.A company discovers that an internally developed web application allows authenticated users to download...
  17. 117.A company deploys a web application that lets authenticated users download invoices by requesting a file path...
  18. 118.A company signs software update packages with a legacy certificate that uses SHA-1. During a security review,...
  19. 119.A company is migrating legacy web applications behind a reverse proxy that terminates TLS. During testing, a...
  20. 120.A company uses Microsoft 365 and receives repeated user complaints that accounts are being locked out at the...
  21. 121.A security analyst notices a sharp increase in failed VPN logon attempts across hundreds of employee accounts...
  22. 122.A security analyst is reviewing alerts from the company's identity provider and SIEM after several employees...
  23. 123.A security analyst is reviewing alerts from the company SIEM after several users report intermittent access...
  24. 124.A company is rolling out a new customer support platform. The application must be reachable from the...
  25. 125.A company is expanding its remote workforce and has discovered that several employees' home computers were...
  26. 126.A company is expanding its manufacturing network and has added several industrial control system (ICS)...
  27. 127.A hospital is preparing for a security audit after a ransomware incident on its corporate user network. The...
  28. 128.A systems administrator is reviewing access to a shared finance folder on a Windows file server after an...
  29. 129.A systems administrator is reviewing access to a shared finance folder on a Windows file server after an...
  30. 130.A hospital's security team is responding to several malware incidents caused by users downloading...
  31. 131.A hospital's security team is responding to several malware incidents caused by users downloading...
  32. 132.A security administrator discovers that a developer's workstation is communicating with a known malicious...
  33. 133.A security administrator detects ransomware-like behavior on an employee workstation in the accounting...
  34. 134.A security administrator must deploy a critical operating system patch that fixes an actively exploited...
  35. 135.A security administrator learns that a critical remote code execution vulnerability is being actively...
  36. 136.A company is deploying full-disk encryption on employee laptops that store sensitive customer data. During...
  37. 137.A security administrator is deploying encryption for a web-based payroll application that is accessed by...
  38. 138.A security analyst is tuning the organization's monitoring strategy after a recent incident in which malware...
  39. 139.A security analyst is reviewing alerts from the company's monitoring platform after several users reported...
  40. 140.A company is preparing for an external audit after a ransomware incident. The security team discovers that...
  41. 141.A company discovers that several help desk technicians have been using a shared domain administrator account...
  42. 142.A security administrator discovers that several Windows laptops used by remote employees have disabled...
  43. 143.A healthcare company is decommissioning several storage arrays that previously held patient records and...
  44. 144.A company is retiring several virtual and physical servers that previously stored customer records and API...
  45. 145.A company is preparing 200 newly imaged Windows laptops for remote employees. During a pilot, a security...
  46. 146.A company is preparing 50 newly imaged laptops for remote employees. During a security review, the...
  47. 147.A healthcare company is redesigning its patient portal and supporting APIs. The security team must allow...
  48. 148.A company is redesigning its customer-facing application after a recent audit found that a compromise of a...
  49. 149.A company is modernizing a customer-facing application by moving the web tier to containers running in a...
  50. 150.A company is moving a customer-facing application from an on-premises data center to a hybrid architecture....
  51. 151.A regional healthcare provider is redesigning a patient scheduling application after several outages caused...
  52. 152.A regional healthcare provider is redesigning its patient appointment portal after several outages during...
  53. 153.A healthcare company is onboarding a third-party billing vendor that will remotely access systems containing...
  54. 154.A healthcare company is onboarding a third-party billing vendor that will process insurance claims and store...
  55. 155.A company uses infrastructure as code (IaC) templates to deploy web applications into its cloud environment....
  56. 156.A company uses Infrastructure as Code (IaC) templates in a shared Git repository to deploy cloud web servers,...
  57. 157.A company uses a serverless architecture to process customer-uploaded images. When a file is placed in cloud...
  58. 158.A company has migrated part of its customer support application to a serverless architecture. An API gateway...
  59. 159.A company is modernizing its customer portal by breaking a monolithic application into microservices. Each...
  60. 160.A company is modernizing its customer portal by breaking a monolithic application into microservices deployed...
  61. 161.A company is expanding its office and needs to connect a third-party HVAC management system to the corporate...
  62. 162.A company is replacing several unmanaged switches with managed switches in a shared office building....
  63. 163.A defense contractor maintains a workstation used to process highly sensitive design files. The system is...
  64. 164.A defense contractor maintains an engineering workstation that stores classified design data. The workstation...
  65. 165.A company is preparing for a security audit after discovering that employee workstations can directly...
  66. 166.A company is preparing for a PCI DSS assessment. The cardholder data environment (CDE) currently shares the...
  67. 167.A security operations center (SOC) receives an alert that a public-facing web application is intermittently...
  68. 168.A company's security operations center detects unusual outbound traffic from a finance workstation at 2:00...
  69. 169.A company hosts several internet-facing applications on a virtualization cluster. During a security review,...
  70. 170.A company hosts several internal applications on virtual machines in a shared VMware environment. A security...
  71. 171.A company is migrating its customer portal to a cloud-hosted environment. During seasonal sales, the portal...
  72. 172.A company is deploying a new customer portal that must support rapid growth during seasonal traffic spikes....
  73. 173.A hospital is deploying internet-connected infusion pumps so biomedical staff can remotely monitor device...
  74. 174.A healthcare clinic is deploying internet-connected infusion pumps and patient monitoring devices on its...
  75. 175.A security administrator must quickly deploy full-disk encryption to 500 company laptops used by remote...
  76. 176.A security administrator at a growing company must roll out full-disk encryption to 600 Windows laptops...
  77. 177.A power generation company is connecting a legacy SCADA environment to the corporate network so engineers can...
  78. 178.A power generation company is modernizing a legacy SCADA environment that manages turbine controllers and...
  79. 179.A regional healthcare provider is moving a patient scheduling application to a third-party cloud platform....
  80. 180.A healthcare software company is preparing to launch a new patient portal that will store limited protected...
  81. 181.A company is redesigning its backup strategy after a ransomware incident. During the last recovery effort,...
  82. 182.A company is redesigning its backup strategy after a ransomware incident. During the last recovery effort,...
  83. 183.A security administrator is reviewing vulnerability scan results for a public-facing application server that...
  84. 184.A security administrator learns that a critical remote code execution vulnerability affects the company's...
  85. 185.A manufacturing company deploys robotic arms controlled by embedded devices running a real-time operating...
  86. 186.A manufacturer deploys internet-connected infusion pumps in a hospital. The pumps run a real-time operating...
  87. 187.A hospital uses a legacy imaging system that controls MRI equipment. The vendor has not validated the latest...
  88. 188.A hospital is deploying internet-connected infusion pumps across several patient care units. The pumps run a...
  89. 189.A hospital is deploying new network-connected infusion pumps that run a stripped-down embedded operating...
  90. 190.A security administrator is hardening a small branch office that contains a firewall, a PoE switch powering...
  91. 191.A security administrator is reviewing the physical security posture of a small data center after several...
  92. 192.A company hosts its customer-facing web application in a single on-premises data center. During a recent...
  93. 193.A security administrator is redesigning a company’s remote-access environment after a recent outage prevented...
  94. 194.A company is migrating a customer-facing application to a public cloud provider and will run it on virtual...
  95. 195.A company is moving a customer-facing web application from on-premises virtual machines to a public cloud...
  96. 196.A company is redesigning its enterprise network after a ransomware incident spread from a compromised user...
  97. 197.A company is redesigning its enterprise network after a ransomware incident spread from a compromised user...
  98. 198.A healthcare company is redesigning its network after a recent outage exposed both security and availability...
  99. 199.A hospital is redesigning its network to support internet-facing patient appointment portals, internal...
  100. 200.A company hosts a customer-facing online ordering portal. After a recent code deployment, the security team...