CompTIA SY0-701 Online Practice
Questions and Exam Preparation
SY0-701 Exam Details
Exam Code
:SY0-701
Exam Name
:CompTIA Security+
Certification
:CompTIA Certifications
Vendor
:CompTIA
Total Questions
:1016 Q&As
Last Updated
:Jul 14, 2026
CompTIA SY0-701 Online Questions &
Answers
Question 141:
An organization has hired a red team to simulate attacks on its security posture.
Which of the following will the blue team do after detecting an IoC?
A. Reimage the impacted workstations B. Activate runbooks for incident response C. Conduct forensics on the compromised system D. Conduct passive reconnaissance to gather information
B. Activate runbooks for incident response
Explanation
The blue team is responsible for detecting, responding to, and containing attacks. After identifying an IoC, the most appropriate next step is to activate incident response runbooks so the team can follow established response procedures.
Reimaging and forensics may happen later depending on the situation, while passive reconnaissance is typically associated with pre-attack information gathering, not blue team response.
Question 142:
Which of the following should be deployed on an externally facing web server in order to establish an encrypted connection?
A. Public key B. Private Key C. Asymmetric key D. Symmetric key
A. Public key
Question 143:
Which of the following is the best reason an organization should enforce a data classification policy to help protect its most sensitive information?
A. End users will be required to consider the classification of data that can be used in documents. B. The policy will result in the creation of access levels for each level of classification. C. The organization will have the ability to create security requirements based on classification levels. D. Security analysts will be able to see the classification of data within a document before opening it.
C. The organization will have the ability to create security requirements based on classification levels.
Question 144:
A company decides to purchase an insurance policy.
Which of the following risk management strategies is this company implementing?
A. Mitigate B. Accept C. Avoid D. Transfer
D. Transfer
Question 145:
Which of the following incident response activities ensures evidence is properly handied?
A. E-discovery B. Chain of custody C. Legal hold D. Preservation
B. Chain of custody
Explanation
Chain of custody is the process of documenting and preserving the integrity of evidence collected during an incident response. It involves recording the details of each person who handled the evidence, the time and date of each transfer, and the location where the evidence was stored. Chain of custody ensures that the evidence is admissible in legal proceedings and can be traced back to its source. E-discovery, legal hold, and preservation are related concepts, but they do not ensure evidence is properly handled.
References:
CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 487
NIST SP 800-61: 3.2. Evidence Gathering and Handling
Question 146:
HOTSPOT
Select the appropriate attack and remediation from each drop-down list to label the corresponding attack with its remediation.
INSTRUCTIONS
Not all attacks and remediation actions will be used.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Explanation
Web serverBotnet Enable DDoS protectionUser RAT Implement a host-based IPS Database server Worm Change the default application passwordExecutive KeyloggerDisable vulnerable servicesApplication Backdoor Implement 2FA
using push notification.
Question 147:
An organization has recently decided to implement SSO. The requirements are to leverage access tokens and focus on application authorization rather than user authentication.
Which of the following solutions would the engineering team most likely configure?
A. LDAP B. Federation C. SAML D. OAuth
D. OAuth
Explanation
OAuth is designed for authorization rather than authentication. It uses access tokens to grant applications permission to access resources on behalf of a user, focusing on what the application can do with the user's data rather than verifying the user's identity. This makes OAuth a suitable choice for Single Sign-On (SSO) when the focus is on application authorization.
Question 148:
Which of the following methods would most likely be used to identify legacy systems?
A. Bug bounty program B. Vulnerability scan C. Package monitoring D. Dynamic analysis
B. Vulnerability scan
Explanation
A vulnerability scan is the most likely method to identify legacy systems. These scans assess an organization's network and systems for known vulnerabilities, including outdated or unsupported software (i.e., legacy systems) that may pose a security risk. The scan results can highlight systems that are no longer receiving updates, helping IT teams address these risks. Bug bounty programs are used to incentivize external researchers to find security flaws, but they are less effective at identifying legacy systems. Package monitoring tracks installed software packages for updates or issues but is not as comprehensive for identifying legacy systems. Dynamic analysis is typically used for testing applications during runtime to find vulnerabilities, but not for identifying legacy systems.
Question 149:
After conducting a vulnerability scan, a systems administrator notices that one of the identified vulnerabilities is not present on the systems that were scanned.
Which of the following describes this example?
A. False positive B. False negative C. True positive D. True negative
A. False positive
Explanation
A false positive occurs when a vulnerability scan identifies a vulnerability that is not actually present on the systems that were scanned. This means that the scan has incorrectly flagged a system as vulnerable.
False positive: Incorrectly identifies a vulnerability that does not exist on the scanned systems.
False negative: Fails to identify an existing vulnerability on the system. True positive: Correctly identifies an existing vulnerability. True negative: Correctly identifies that there is no vulnerability.
References:
CompTIA Security+ SY0-701 Exam Objectives, Domain 4.3 - Explain various activities associated with vulnerability management (False positives and false negatives).
Question 150:
The author of a software package is concerned about bad actors repackaging and inserting malware into the software. The software download is hosted on a website, and the author exclusively controls the website's contents.
Which of the following techniques would best ensure the software's integrity?
A. Input validation B. Code signing C. Secure cookies D. Fuzzing
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only CompTIA exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your SY0-701 exam preparations
and CompTIA certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.