Free SY0-701 Practice Test Questions 2026

909 Questions


Last Updated On : 27-Jul-2026


After a security incident, a systems administrator asks the company to buy a NAC platform. Which of the following attack surfaces is the systems administrator trying to protect?


A. Bluetooth


B. Wired


C. NFC


D. SCADA





B.
  Wired

Explanation:
A NAC (Network Access Control) platform is primarily designed to secure wired and wireless network access by enforcing security policies on devices before they are allowed to connect to the network. It ensures that only compliant and authorized devices can access network resources. In the context of a security incident, the administrator is likely addressing vulnerabilities related to unauthorized or non-compliant devices connecting via wired ports (e.g., Ethernet), which could lead to threats like rogue devices, malware propagation, or lateral movement.

Why the others are incorrect:

A. Bluetooth:
This is a short-range wireless technology for personal area networks (PANs). NAC focuses on broader network access (LAN/WLAN) and does not typically govern Bluetooth connections.

C. NFC (Near Field Communication):
This is a very short-range wireless technology used for contactless payments/data exchange. NAC is not designed to protect NFC, as it operates at a different network layer and scale.

D. SCADA (Supervisory Control and Data Acquisition):
These are industrial control systems (ICS) used in critical infrastructure. While NAC can be part of securing SCADA networks, it is not specific to SCADA. The question asks for the attack surface NAC is most directly associated with, which is general wired (and wireless) network access.

Reference:
This aligns with SY0-701 Objective 3.4 ("Given a scenario, implement secure network designs"). NAC is a core technology for enforcing access control on wired and wireless networks, as outlined in frameworks like NIST SP 800-181 ("Guide to LTE Security") and best practices for network segmentation and endpoint compliance.

Client files can only be accessed by employees who need to know the information and have specified roles in the company. Which of the following best describes this security concept?


A. Availability


B. Confidentiality


C. Integrity


D. Non-repudiation





B.
  Confidentiality

Explanation:
Confidentiality is the security principle that ensures information is not disclosed or accessed by unauthorized individuals, devices, or processes. The scenario describes restricting access to client files only to employees with a specific "need to know" and designated roles. This is a classic example of enforcing confidentiality through access controls.

Why the other options are incorrect:

A. Availability:
This principle ensures that information and systems are accessible and operational when needed by authorized users. The scenario is focused on restricting access, not ensuring it is available.

C. Integrity:
This principle guards against improper modification or destruction of information, ensuring its accuracy and trustworthiness. The scenario is about who can see the files, not about protecting them from being altered.

D. Non-repudiation:
This is a concept that prevents an individual from denying having taken a specific action, such as sending a message or approving a transaction. It is typically achieved through digital signatures and auditing. The scenario does not involve proving an action was taken; it is solely about controlling read-access to information.

Reference:
This question tests the fundamental understanding of the CIA triad (Confidentiality, Integrity, Availability), which is the core of information security.

This is a key concept in Domain 2.1: Explain the importance of security concepts in an enterprise environment of the CompTIA Security+ SY0-701 exam objectives.

The "need-to-know" principle and role-based access are primary mechanisms for enforcing confidentiality, as outlined in various security frameworks like those from NIST.

Which of the following most impacts an administrator's ability to address CVEs discovered on a server?


A. Rescanning requirements


B. Patch availability


C. Organizational impact


D. Risk tolerance





B.
  Patch availability

Explanation: Patch availability most impacts an administrator's ability to address Common Vulnerabilities and Exposures (CVEs) discovered on a server. If a patch is not available for a discovered vulnerability, the administrator cannot remediate the issue directly through patching, which leaves the system exposed until a patch is released.
Patch availability: Directly determines whether a discovered vulnerability can be fixed promptly. Without available patches, administrators must look for other mitigation strategies. Rescanning requirements: Important for verifying the effectiveness of patches but secondary to the availability of the patches themselves.
Organizational impact: Considers the potential consequences of vulnerabilities but does not directly impact the ability to apply patches. Risk tolerance: Influences how the organization prioritizes addressing vulnerabilities but does not affect the actual availability of patches.

Which of the following is the phase in the incident response process when a security analyst reviews roles and responsibilities?


A. Preparation


B. Recovery


C. Lessons learned


D. Analysis





A.
  Preparation

Explanation: Preparation is the phase in the incident response process when a security analyst reviews roles and responsibilities, as well as the policies and procedures for handling incidents. Preparation also involves gathering and maintaining the necessary tools, resources, and contacts for responding to incidents. Preparation can help a security analyst to be ready and proactive when an incident occurs, as well as to reduce the impact and duration of the incident. Some of the activities that a security analyst performs during the preparation phase are: Defining the roles and responsibilities of the incident response team members, such as the incident manager, the incident coordinator, the technical lead, the communications lead, and the legal advisor. Establishing the incident response plan, which outlines the objectives, scope, authority, and procedures for responding to incidents, as well as the escalation and reporting mechanisms. Developing the incident response policy, which defines the types and categories of incidents, the severity levels, the notification and reporting requirements, and the roles and responsibilities of the stakeholders. Creating the incident response playbook, which provides the step-by-step guidance and checklists for handling specific types of incidents, such as denial-of- service, ransomware, phishing, or data breach. Acquiring and testing the incident response tools, such as network and host-based scanners, malware analysis tools, forensic tools, backup and recovery tools, and communication and collaboration tools. Identifying and securing the incident response resources, such as the incident response team, the incident response location, the evidence storage, and the external support. Building and maintaining the incident response contacts, such as the internal and external stakeholders, the law enforcement agencies, the regulatory bodies, and the media.

department is not using the company VPN when accessing various company-related services and systems. Which of the following scenarios describes this activity?


A. Espionage


B. Data exfiltration


C. Nation-state attack


D. Shadow IT





D.
  Shadow IT

Explanation: The activity described, where a department is not using the company VPN when accessing various company-related services and systems, is an example of Shadow IT. Shadow IT refers to the use of IT systems, devices, software, applications, and services without explicit IT department approval. Espionage: Involves spying to gather confidential information, not simply bypassing the VPN.
Data exfiltration: Refers to unauthorized transfer of data, which might involve not using a VPN but is more specific to the act of transferring data out of the organization.
Nation-state attack: Involves attacks sponsored by nation-states, which is not indicated in the scenario.
Shadow IT: Use of unauthorized systems and services, which aligns with bypassing the company VPN.
Reference: CompTIA Security+ SY0-701 Exam Objectives, Domain 2.1 - Compare and contrast common threat actors and motivations (Shadow IT).

After a company was compromised, customers initiated a lawsuit. The company's attorneys have requested that the security team initiate a legal hold in response to the lawsuit. Which of the following describes the action the security team will most likely be required to take?


A. Retain the emails between the security team and affected customers for 30 days.


B. Retain any communications related to the security breach until further notice.


C. Retain any communications between security members during the breach response.


D. Retain all emails from the company to affected customers for an indefinite period of time.





B.
  Retain any communications related to the security breach until further notice.

Explanation:
A legal hold (also known as a litigation hold) is a directive issued by an organization's legal counsel to preserve all forms of relevant information when litigation is reasonably anticipated or has already been initiated. This is a critical process to prevent the spoliation (destruction or alteration) of evidence.

The key characteristic of a legal hold is that it is broad and indefinite. It applies to all data—including emails, documents, logs, system images, and communications—that could be potentially relevant to the case. The hold remains in effect "until further notice," meaning until legal counsel determines the litigation or threat of litigation has concluded and formally releases the hold.

In this scenario, the lawsuit is related to the security compromise. Therefore, the security team would be required to retain any and all communications, data, and evidence related to the security breach to ensure it is available for the discovery process in the lawsuit.

Why the Other Options are Incorrect:

A. Retain the emails... for 30 days:
A legal hold is not for a fixed, short-term period. It remains in effect for the duration of the legal process, which could last months or years. A 30-day retention policy would directly conflict with the requirements of a legal hold.

C. Retain any communications between security members...:
While this is part of the hold, the scope is too narrow. A legal hold applies to all relevant information, not just internal team communications. It includes communications with third parties, system logs, data backups, and more.

D. Retain all emails from the company to affected customers...:
This is also too narrow. The legal hold would require preserving not just outbound customer emails, but also inbound communications, internal discussions about those customers, and any other data related to the breach and its impact.

Reference:
This question falls under CompTIA SY0-701 Objective 4.3: "Explain the importance of policies to organizational security." Specifically, it covers data governance concepts like legal hold and e-discovery, which are critical components of an organization's incident response and data retention policies, especially in the context of compliance and litigation.

Which of the following best describes the practice of researching laws and regulations related to information security operations within a specific industry?


A. Compliance reporting


B. GDPR


C. Due diligence


D. Attestation





C.
  Due diligence

Explanation:
Due diligence is the proactive, ongoing process of researching, understanding, and complying with laws, regulations, and standards that apply to an organization's operations. In the context of information security, this involves continuously identifying and analyzing legal and regulatory requirements (such as GDPR, HIPAA, PCI DSS, etc.) that are relevant to the organization's specific industry and ensuring that security practices are aligned to meet those obligations.

Why not A?
Compliance reporting: This is the act of demonstrating adherence to laws and regulations through reports, audits, or certifications. It is an output or result of performing due diligence, not the research process itself.

Why not B?
GDPR: The General Data Protection Regulation (GDPR) is a specific regulation governing data privacy in the European Union. It is an example of a law that might be researched as part of due diligence, but it is not the term that describes the overall practice of researching all applicable laws and regulations.

Why not D?
Attestation: This is a formal declaration or verification (often by a third party) that certain controls or processes are in place and effective. Like reporting, it is a method for proving compliance, not the research process behind it.

Reference:
Domain 5.5: "Explain the importance of compliance." The SY0-701 objectives emphasize the need for organizations to understand their legal and regulatory requirements. Due diligence is the foundational practice that ensures an organization is aware of these obligations and can build its security program accordingly.

A security analyst reviews domain activity logs and notices the following:



Which of the following is the best explanation for what the security analyst has discovered?


A. The user jsmith's account has been locked out.


B. A keylogger is installed on [smith's workstation


C. An attacker is attempting to brute force ismith's account.


D. Ransomware has been deployed in the domain.





C.
  An attacker is attempting to brute force ismith's account.

Explanation:
The log entries show a pattern highly indicative of a brute force attack:

Multiple repeated login attempts using the same username (jsmith) and password (password).

Each attempt results in successful authentication (likely because the password is correct, suggesting the attacker has compromised the password).

However, each attempt fails at the MFA (Multi-Factor Authentication) stage due to an "invalid code."

This pattern suggests that an attacker has obtained jsmith's password (e.g., via phishing, a data breach, or credential stuffing) but is now trying to bypass the MFA protection by repeatedly guessing or submitting invalid MFA codes. The goal is to eventually guess a valid MFA code or exploit a weakness in the MFA implementation.

Why not A?
The account does not appear locked out, as authentication continues to succeed (password is accepted). Lockouts typically prevent further authentication attempts entirely.

Why not B?
A keylogger might explain how the password was stolen initially, but the logs show active ongoing attacks from an external source (repeated MFA failures), not local keylogging activity.

Why not D?
There is no evidence of ransomware in these logs (e.g., file encryption, ransom notes). The activity is focused on authentication attempts.

Reference:
Domain 1.3: "Given a scenario, analyze potential indicators associated with application attacks." Brute force attacks (including MFA bypass attempts) are a common attack vector. The pattern of successful password authentication followed by MFA failures is a classic sign of an attacker trying to compromise an account protected by MFA.

Which of the following is the primary purpose of a service that tracks log-ins and time spent using the service?


A. Availability


B. Accounting


C. Authentication


D. Authorization





B.
  Accounting

Explanation:
The question describes a service that tracks user activity, specifically log-ins and time spent. This is a classic function of monitoring and recording user actions for the purposes of auditing, billing, and accountability.

B. Accounting is correct.
In the context of AAA (Authentication, Authorization, and Accounting) security services, accounting is the process of tracking and logging user activities and resource usage. This includes recording when users log in, how long they are connected, what commands they execute, and the data they access. The primary purpose is to create an audit trail for security reviews, compliance, billing (e.g., for paid services), and monitoring for suspicious behavior.

A. Availability is incorrect.
Availability ensures that systems and data are accessible to authorized users when needed. It is a core security objective (part of the CIA triad: Confidentiality, Integrity, Availability) but is not related to tracking user log-ins or usage time.

C. Authentication is incorrect.
Authentication is the process of verifying a user's identity (e.g., with a password or biometric scan). It answers the question, "Who are you?" While authentication is necessary for a user to gain access, it does not involve tracking their activity after they are logged in.

D. Authorization is incorrect.
Authorization determines what an authenticated user is allowed to do or access (e.g., read a file, run a program). It answers the question, "What are you allowed to do?" Like authentication, it is a prerequisite for access but does not involve logging or tracking the user's actions during their session.

Reference:
CompTIA Security+ SY0-701 Objective 3.8: "Explain authentication and authorization concepts." The AAA framework (Authentication, Authorization, Accounting) is a key concept. Accounting is explicitly defined as the process that audits and logs what users do and how long they use resources, which aligns perfectly with the service described in the question.

A company needs to provide administrative access to internal resources while minimizing the traffic allowed through the security boundary. Which of the following methods is most secure?


A. Implementing a bastion host


B. Deploying a perimeter network


C. Installing a WAF


D. Utilizing single sign-on





A.
  Implementing a bastion host

Explanation:
A bastion host is a specialized server designed to withstand attacks and provide a secure gateway for administrative access to internal resources from external networks (e.g., the internet). It is heavily hardened (minimized attack surface, strict access controls, extensive logging) and serves as a single point of entry for administrative traffic. By funneling all administrative access through this dedicated host, the company can:

Minimize traffic through the security boundary: Only traffic directed to the bastion host is allowed, reducing the exposure of internal resources.

Enforce strict security policies:
The bastion host can be configured with rigorous authentication (e.g., multi-factor authentication) and monitoring.

Isolate internal systems:
Direct access to internal resources is blocked; administrators must first access the bastion host, which then proxies or relays connections to internal systems under controlled conditions.

This approach is more secure than opening multiple administrative pathways into the network.

Analysis of Incorrect Options:

B. Deploying a perimeter network (DMZ):
A DMZ is a segmented network that hosts publicly accessible services (e.g., web servers, email servers). While it isolates these services from the internal network, it does not specifically secure administrative access to internal resources. Administrative access should not be provided from the DMZ; it should be further controlled via a bastion host or similar secure method.

C. Installing a WAF (Web Application Firewall):
A WAF protects web applications from attacks (e.g., SQL injection, XSS). It is irrelevant to securing general administrative access (e.g., SSH, RDP, database admin tools) unless the administrative interface is web-based. Even then, a WAF alone does not minimize traffic or provide the centralized control of a bastion host.

D. Utilizing single sign-on (SSO):
SSO improves usability and security by allowing users to authenticate once to access multiple applications. However, it does not restrict or minimize traffic through the security boundary; it only simplifies authentication. SSO could be used in conjunction with a bastion host for stronger access control but is not a substitute for it.

Reference:
This question falls under Domain 3.0: Security Architecture, specifically network design and secure access methodologies. Bastion hosts are a best practice for providing secure remote administrative access, aligning with principles of defense-in-depth and network segmentation. They are often part of a zero-trust architecture, where access is tightly controlled and monitored.

An organization is required to maintain financial data records for three years and customer data for five years. Which of the following data management policies should the organization implement?


A. Retention


B. Destruction


C. Inventory


D. Certification





A.
  Retention

Explanation: The organization should implement a retention policy to ensure that financial data records are kept for three years and customer data for five years. A retention policy specifies how long different types of data should be maintained and when they should be deleted. Retention: Ensures that data is kept for a specific period to comply with legal, regulatory, or business requirements. Destruction: Involves securely deleting data that is no longer needed, which is part of the retention lifecycle but not the primary focus here. Inventory: Involves keeping track of data assets, not specifically about how long to retain data. Certification: Ensures that processes and systems meet certain standards, not directly related to data retention periods.

A company is expanding its threat surface program and allowing individuals to security test the company’s internet-facing application. The company will compensate researchers based on the vulnerabilities discovered. Which of the following best describes the program the company is setting up?


A. Open-source intelligence


B. Bug bounty


C. Red team


D. Penetration testing





B.
  Bug bounty

Explanation: A bug bounty is a program that rewards security researchers for finding and reporting vulnerabilities in an application or system. Bug bounties are often used by companies to improve their security posture and incentivize ethical hacking. A bug bounty program typically defines the scope, rules, and compensation for the researchers. References = CompTIA Security+ Study Guide with over 500 Practice Test Questions: Exam SY0-701, 9th Edition, Chapter 1, page 10. CompTIA Security+ (SY0-701) Certification Exam Objectives, Domain 1.1, page 2.


Page 16 out of 76 Pages
PreviousNext
56789101112131415161718192021222324252627
SY0-701 Practice Test Home

What Makes Our CompTIA Security+ Exam 2026 Practice Test So Effective?

Real-World Scenario Mastery: Our SY0-701 practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.

Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before CompTIA Security+ Exam 2026 exam day arrives.

Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive SY0-701 practice exam questions pool covering all topics, the real exam feels like just another practice session.