Comptia

SY0-701 Practice Test: 10 Original Questions

Ten questions across the five Security+ SY0-701 domains: general security concepts; threats, vulnerabilities and mitigations; security architecture; security operations; and security program management. Each answer links to a NIST, OWASP, CISA, IETF or PCI SSC source that defines the concept.

These questions were written for CertBlaze from the official Security+ exam guide, with AI assistance. They are not taken from the real exam, an exam dump or any other question bank. Each answer names the official page it is based on; if you spot a mistake, please tell us.

What this set covers

  • General Security Concepts: 2 questions
  • Threats, Vulnerabilities, and Mitigations: 3 questions
  • Security Architecture: 2 questions
  • Security Operations: 2 questions
  • Security Program Management and Oversight: 1 question

Question 1

General Security Concepts

A software vendor digitally signs every update so customers can confirm the file was not changed and that it really came from the vendor. Which two security goals does the signature provide?

A. Confidentiality and availability
B. Confidentiality and integrity
C. Availability and authorization
D. Integrity and non-repudiation
Show Answer
Correct Answer: D
Explanation:
A digital signature lets the recipient detect any change to the file (integrity) and ties the file to the holder of the private key, who cannot credibly deny signing it (non-repudiation, which includes origin authentication). A signature does not encrypt the file, so it adds no confidentiality, and it does nothing for availability.
Source: Digital signature (NIST CSRC Glossary)

Question 2

General Security Concepts

A company puts up signs at its entrances stating that the premises are monitored by video surveillance. Which type of control are the signs primarily?

A. Detective
B. Compensating
C. Corrective
D. Deterrent
Show Answer
Correct Answer: D
Explanation:
A deterrent control discourages someone from attempting a violation; a warning sign works by changing the would-be intruder's mind. The cameras themselves are detective (A) because they record what happens. Corrective controls (C) fix a problem after it occurs, and compensating controls (B) stand in for a control that cannot be implemented.
Source: Security control (NIST CSRC Glossary)

Question 3

Threats, Vulnerabilities, and Mitigations

Employees receive text messages that appear to come from the company's bank and ask them to confirm a payment by tapping a link. What is this attack called?

A. Vishing
B. Smishing
C. Whaling
D. Pharming
Show Answer
Correct Answer: B
Explanation:
Smishing is phishing over SMS text messages. Vishing (A) uses voice calls, whaling (C) targets senior executives, and pharming (D) redirects users to a fake site by tampering with DNS or host settings rather than sending them a message.
Source: Avoiding social engineering and phishing attacks (CISA)

Question 4

Threats, Vulnerabilities, and Mitigations

A web server log shows the string ' OR '1'='1 submitted in a login form's username field. Which control most directly prevents this attack from succeeding?

A. Enforcing TLS 1.3 on the login page
B. Using parameterized queries (prepared statements) in the application code
C. Limiting the username field to 64 characters
D. Requiring complex passwords
Show Answer
Correct Answer: B
Explanation:
The input is a SQL injection attempt. Parameterized queries send the SQL statement and the user input separately, so the input can never change the structure of the query. TLS (A) protects data in transit, a length limit (C) does not stop a short payload, and password complexity (D) is unrelated to how the query is built.
Source: SQL Injection Prevention Cheat Sheet (OWASP)

Question 5

Threats, Vulnerabilities, and Mitigations

A user installs a free PDF converter from a download site. The tool converts files as promised, but it also opens a hidden backdoor that lets an attacker run commands on the laptop. Which type of malware is this?

A. Worm
B. Logic bomb
C. Trojan
D. Ransomware
Show Answer
Correct Answer: C
Explanation:
A Trojan looks like legitimate, useful software and hides a malicious function. A worm (A) spreads by itself between systems, a logic bomb (B) waits for a trigger condition before acting, and ransomware (D) encrypts or locks data and demands payment.
Source: Trojan horse (NIST CSRC Glossary)

Question 6

Security Architecture

A hospital's smart thermostats and badge readers sit on the same flat network as its billing servers. The security team wants to limit how far an attacker could move if one of these IoT devices is compromised. What should it do first?

A. Place the IoT devices in their own network segment and allow only the traffic they need through firewall rules
B. Install full-disk encryption on the IoT devices
C. Increase the password length policy for all users
D. Deploy a honeypot on the billing network
Show Answer
Correct Answer: A
Explanation:
Segmentation puts the IoT devices in a separate zone and lets a firewall or access control list permit only required flows, so a compromised device cannot reach the billing servers directly. Disk encryption (B) protects stored data, password policy (C) does not apply to device-to-server traffic, and a honeypot (D) detects attackers rather than containing them.
Source: Zero Trust Architecture, NIST SP 800-207 (NIST)

Question 7

Security Architecture

An online store replaces each card number in its order database with a random value and keeps the mapping between the two in a separate, tightly controlled vault. What is this technique?

A. Hashing
B. Salting
C. Data masking
D. Tokenization
Show Answer
Correct Answer: D
Explanation:
Tokenization swaps sensitive data for a surrogate value with no mathematical relationship to the original, and only the token vault can map it back. Hashing (A) is a one-way function with no lookup back to the card number. Masking (C) hides part of a value when it is displayed, and salting (B) adds random data to inputs before hashing.
Source: PCI DSS Tokenization Guidelines (PCI Security Standards Council)

Question 8

Security Operations

A SOC analyst confirms that a workstation is infected and disconnects it from the network so the malware cannot spread, before removing the malware. Which incident response activity is the analyst performing?

A. Eradication
B. Recovery
C. Containment
D. Lessons learned
Show Answer
Correct Answer: C
Explanation:
Isolating an affected system to stop the damage from spreading is containment. Eradication (A) removes the malware and its persistence, recovery (B) returns the system to normal operation, and lessons learned (D) happens after the incident to improve the process.
Source: Incident Response Recommendations, NIST SP 800-61 Rev. 3 (NIST)

Question 9

Security Operations

Attackers keep sending emails that show the company's own domain in the From address. The company already publishes SPF and signs mail with DKIM. Which record lets it tell receiving servers to reject messages that fail those checks, and send it reports about them?

A. An MX record
B. A DMARC record
C. A PTR record
D. An S/MIME certificate
Show Answer
Correct Answer: B
Explanation:
DMARC builds on SPF and DKIM: it checks that the visible From domain aligns with them, publishes a policy (none, quarantine or reject) for messages that fail, and requests aggregate reports. MX records (A) route inbound mail, PTR records (C) map IP addresses to names, and S/MIME (D) signs or encrypts individual messages.
Source: RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (IETF)

Question 10

Security Program Management and Oversight

After a risk assessment, a company buys a cyber insurance policy that would cover its financial losses from a ransomware attack. Which risk response is this?

A. Risk transference
B. Risk acceptance
C. Risk avoidance
D. Risk mitigation
Show Answer
Correct Answer: A
Explanation:
Buying insurance moves the financial impact of the risk to a third party, which is transference (also called sharing). Acceptance (B) means taking the risk as is, avoidance (C) means stopping the risky activity, and mitigation (D) means adding controls that lower likelihood or impact.
Source: Risk response (NIST CSRC Glossary)