This is the free Comptia SY0-701 practice question bank —
310 of 608 total questions, each with a full explanation, free to
read with no signup required. Updated 2026-08-04.
Every answer is verified against official Comptia documentation —
see our methodology.
Question 1
A security analyst is examining a penetration test report and notices that the tester pivoted to critical internal systems with the same local user ID and password. Which of the following would help prevent this in the future?
A. Implement centralized authentication with proper password policies
B. Add password complexity rules and increase password history limits
C. Connect the systems to an external authentication server
D. Limit the ability of user accounts to change passwords
Show Answer
Correct Answer: A
Explanation: Using the same local username and password across multiple systems enables credential reuse and lateral movement after compromise. Centralized authentication with enforced password policies reduces reliance on duplicated local accounts and allows consistent credential management. Password complexity alone does not address reuse across systems, connecting to an external authentication server is less complete than implementing centralized authentication and policy, and limiting password changes is counterproductive.
Question 2
A security professional discovers a folder that contains an employee's personal information located on the enterprise’s shared drive. Which of the following best describes the data type the security professional should use to identify organizational policies and standards concerning the storage of employees' personal information?
A. Legal
B. Financial
C. Privacy
D. Intellectual property
Show Answer
Correct Answer: C
Explanation: Employee personal information is classified as privacy data. Organizational policies and standards governing the collection, storage, handling, and protection of personally identifiable information (PII) fall under the privacy data classification, not legal, financial, or intellectual property.
Question 3
An administrator implements web-filtering products but still sees that users are visiting malicious links. Which of the following configuration items does the security administrator need to review?
A. Intrusion prevention system
B. Content categorization
C. Encryption
D. DNS service
Show Answer
Correct Answer: B
Explanation: Web-filtering products depend on content categorization to determine which sites should be allowed or blocked. If users can still access malicious links, the administrator should review the categorization policies and category database/configuration to ensure malicious categories are correctly identified and blocked. An IPS detects and blocks exploits rather than performing URL categorization, encryption is unrelated, and DNS services may support filtering but are not the core web-filter categorization configuration described.
Question 4
When used with an access control vestibule which of the following would provide the best prevention against tailgating?
A. PIN
B. Access card
C. Security guard
D. CCTV
Show Answer
Correct Answer: C
Explanation: An access control vestibule (mantrap) is designed to control entry, but preventing tailgating is most effective when someone can actively observe, challenge, and intervene. A security guard can verify that only authorized individuals enter and stop attempts to follow another person through the vestibule. PINs and access cards authenticate users but do not by themselves prevent someone from following closely behind. CCTV provides monitoring and evidence but does not actively prevent tailgating.
Question 5
Which of the following analysis methods allows an organization to measure the exposure factor associated with organizational assets?
A. Heuristic
B. Quantitative
C. User-driven
D. Trend-based
Show Answer
Correct Answer: B
Explanation: Quantitative risk analysis measures risk using numerical values. The exposure factor (EF) is a core quantitative metric representing the percentage of an asset's value lost in a specific incident, and it is used with asset value to calculate single loss expectancy (SLE).
Question 6
A security team receives reports about high latency and complete network unavailability throughout most of the office building. Flow logs from the campus switches show high traffic on TCP 445. Which of the following is most likely the root cause of this incident?
A. Buffer overflow
B. NTP amplification attack
C. Worm
D. DoS attack
Show Answer
Correct Answer: C
Explanation: TCP port 445 is used by SMB. A sudden surge of TCP 445 traffic across a campus network, accompanied by widespread latency and outages, is most consistent with a self-propagating SMB worm scanning and infecting hosts (for example, behavior similar to WannaCry). An NTP amplification attack uses UDP port 123, a generic DoS does not specifically explain the SMB-focused traffic, and a buffer overflow is an exploit type rather than the likely network-wide root cause.
Question 7
A security analyst notices an increase in port scans on the edge of the corporate network. Which of the following logs should the analyst check to obtain the attacker’s source IP address?
A. OS security
B. Firewall
C. Application
D. Endpoint
Show Answer
Correct Answer: B
Explanation: Firewall logs are the appropriate source because they record inbound and outbound network connection attempts at the network perimeter, including source IP addresses, destination ports, protocols, and allowed/blocked actions. These logs are the primary place to identify the external source IP responsible for port scans. OS security, application, and endpoint logs are not the primary source for edge network reconnaissance events.
Question 8
A security analyst is reviewing the following logs about a suspicious activity alert for a user's VPN log-ins:
Which of the following malicious activity indicators triggered the alert?
A. Impossible travel
B. Account lockout
C. Blocked content
D. Concurrent session usage
Show Answer
Correct Answer: A
Explanation: The alert is triggered by an impossible travel scenario: the same user appears to authenticate from geographically distant locations (e.g., Chicago and Rome) within a timeframe that is not physically plausible. This matches the definition of an impossible travel detection rather than an account lockout, blocked content event, or concurrent session usage.
Question 9
A retail company receives a request to remove a customer's data. Which of the following is the retail company considered under GDPR legislation?
A. Data processor
B. Data controller
C. Data subject
D. Data custodian
Show Answer
Correct Answer: B
Explanation: Under GDPR, a data controller determines the purposes and means of processing personal data. A retail company that collects and manages customer information for its own business decides why and how the data is processed and is responsible for responding to data subject rights requests such as erasure. A data processor acts on behalf of a controller, the data subject is the individual whose data is processed, and 'data custodian' is not the GDPR role in question.
Question 10
Which of the following should an organization use to ensure that it can review the controls and performance of a service provider or vendor?
A. Service-level agreement
B. Memorandum of agreement
C. Right-to-audit clause
D. Supply chain analysis
Show Answer
Correct Answer: C
Explanation: A right-to-audit clause contractually grants an organization the ability to inspect and assess a service provider's controls, processes, compliance, and performance. A service-level agreement defines expected service performance but does not itself guarantee audit rights. A memorandum of agreement outlines cooperation, and supply chain analysis is a risk assessment activity, not a contractual mechanism for audits.
$19
Get all 608 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.