Comptia

SY0-701 Free Practice Questions

This is the free Comptia SY0-701 practice question bank — 310 of 609 total questions, each with a full explanation, free to read with no signup required. Updated 2026-04-24.

Every answer is verified against official Comptia documentation — see our methodology.

Question 1

A security analyst is examining a penetration test report and notices that the tester pivoted to critical internal systems with the same local user ID and password. Which of the following would help prevent this in the future?

A. Implement centralized authentication with proper password policies
B. Add password complexity rules and increase password history limits
C. Connect the systems to an external authentication server
D. Limit the ability of user accounts to change passwords
Show Answer
Correct Answer: A
Explanation:
The issue described is lateral movement using identical local credentials across multiple systems. Implementing centralized authentication (e.g., Active Directory, LDAP) with proper password policies eliminates reliance on shared local accounts and enforces unique credentials and centralized control, significantly reducing the risk of pivoting. The other options still allow local accounts to exist or do not address credential reuse across systems.

Question 2

A security professional discovers a folder that contains an employee's personal information located on the enterprise’s shared drive. Which of the following best describes the data type the security professional should use to identify organizational policies and standards concerning the storage of employees' personal information?

A. Legal
B. Financial
C. Privacy
D. Intellectual property
Show Answer
Correct Answer: C
Explanation:
Employee personal information is classified as privacy data. Organizational policies and standards governing how such data is stored, accessed, and protected fall under privacy requirements rather than legal, financial, or intellectual property categories.

Question 3

An administrator implements web-filtering products but still sees that users are visiting malicious links. Which of the following configuration items does the security administrator need to review?

A. Intrusion prevention system
B. Content categorization
C. Encryption
D. DNS service
Show Answer
Correct Answer: B
Explanation:
Web-filtering solutions depend on content categorization databases to classify sites (e.g., malicious, phishing, gambling). If users can still access malicious links, the administrator should review whether categories are up to date, correctly assigned, and properly enforced in policy. Misclassification or overly permissive category rules commonly allow malicious sites through.

Question 4

When used with an access control vestibule which of the following would provide the best prevention against tailgating?

A. PIN
B. Access card
C. Security guard
D. CCTV
Show Answer
Correct Answer: C
Explanation:
An access control vestibule (mantrap) is most effective against tailgating when combined with active human enforcement. A security guard can observe behavior in real time, challenge unauthorized individuals, and physically prevent multiple people from entering on a single authorization. PINs and access cards only authenticate users but do not stop someone from following closely, and CCTV is primarily a deterrent or investigative tool rather than an active prevention measure.

Question 5

Which of the following analysis methods allows an organization to measure the exposure factor associated with organizational assets?

A. Heuristic
B. Quantitative
C. User-driven
D. Trend-based
Show Answer
Correct Answer: B
Explanation:
Quantitative risk analysis assigns numerical values to risk components, including exposure factor (EF), which represents the percentage of asset value lost from a threat. EF is a core element of quantitative methods alongside AV, SLE, and ALE.

Question 6

A security team receives reports about high latency and complete network unavailability throughout most of the office building. Flow logs from the campus switches show high traffic on TCP 445. Which of the following is most likely the root cause of this incident?

A. Buffer overflow
B. NTP amplification attack
C. Worm
D. DoS attack
Show Answer
Correct Answer: C
Explanation:
TCP port 445 is used by SMB, which has historically been exploited by self-propagating worms (e.g., WannaCry, NotPetya). A worm spreading via SMB would generate excessive east-west traffic on port 445, causing widespread latency and network unavailability across the campus. The symptoms and protocol specificity align with a worm rather than a generic DoS, buffer overflow, or NTP amplification attack.

Question 7

A security analyst notices an increase in port scans on the edge of the corporate network. Which of the following logs should the analyst check to obtain the attacker’s source IP address?

A. OS security
B. Firewall
C. Application
D. Endpoint
Show Answer
Correct Answer: B
Explanation:
Port scans target multiple ports across the network perimeter. Firewall logs sit at the network edge and record inbound connection attempts, including source IP addresses, destination ports, protocols, and allow/deny actions. This makes firewall logs the most reliable source for identifying the attacker’s source IP. OS security, application, and endpoint logs focus on local system or application events rather than perimeter-wide scanning activity.

Question 8

A security analyst is reviewing the following logs about a suspicious activity alert for a user's VPN log-ins: Which of the following malicious activity indicators triggered the alert?

A. Impossible travel
B. Account lockout
C. Blocked content
D. Concurrent session usage
Show Answer
Correct Answer: A
Explanation:
The logs show successful VPN logins from geographically distant locations (e.g., Chicago and Rome) within a very short time window. Such rapid location changes are not physically possible, which matches the impossible travel indicator rather than account lockout, blocked content, or concurrent session usage.

Question 9

A recent power outage halted operations at a company's only data center. Which of the following solutions would best prevent an event like this one in the future?

A. Platform diversity
B. Generator
C. Snapshots
D. Load balancing
Show Answer
Correct Answer: B
Explanation:
A backup generator directly addresses the root cause of the outage by providing power when the primary electrical supply fails. This allows the data center to continue operating during power interruptions, which is the most effective prevention for this specific scenario. Other options do not prevent power loss.

Question 10

A retail company receives a request to remove a customer's data. Which of the following is the retail company considered under GDPR legislation?

A. Data processor
B. Data controller
C. Data subject
D. Data custodian
Show Answer
Correct Answer: B
Explanation:
Under GDPR, the data controller is the entity that determines the purposes and means of processing personal data. A retail company deciding how and why it collects, stores, and uses customer data—and handling deletion requests—acts as the data controller.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.