SY0-701 Exam Details

  • Exam Code
    :SY0-701
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1016 Q&As
  • Last Updated
    :Jul 14, 2026

CompTIA SY0-701 Online Questions & Answers

  • Question 251:

    Which of the following is the first step to secure a newly deployed server?

    A. Close unnecessary service ports.
    B. Update the current version of the software.
    C. Add the device to the ACL.
    D. Upgrade the OS version.

  • Question 252:

    A company wants to use new Wi-Fi-enabled environmental sensors in order to automatically collect metrics.

    Which of the following will the security team most likely do?

    A. Add the sensor software to the risk register.
    B. Create a VLAN for the sensors.
    C. Physically air gap the sensors.
    D. Configure TLS 1.2 on all sensors.

  • Question 253:

    Which of the following is an example of a data protection strategy that uses tokenization?

    A. Encrypting databases containing sensitive data
    B. Replacing sensitive data with surrogate values
    C. Removing sensitive data from production systems
    D. Hashing sensitive data in critical systems

  • Question 254:

    An application developer accidentally uploaded a company's code-signing certificate private key to a public web server. The company is concerned about malicious use of its certificate.

    Which of the following should the company do FIRST?

    A. Delete the private key from the repository.
    B. Verify the public key is not exposed as well.
    C. Update the DLP solution to check for private keys.
    D. Revoke the code-signing certificate.

  • Question 255:

    Which of the following is a risk of conducting a vulnerability assessment?

    A. A disruption of business operations
    B. Unauthorized access to the system
    C. Reports of false positives
    D. Finding security gaps in the system

  • Question 256:

    A security analyst discovers that a large number of employee credentials had been stolen and were being sold on the dark web. The analyst investigates and discovers that some hourly employee credentials were compromised, but salaried employee credentials were not affected.

    Most employees clocked in and out while they were inside the building using one of the kiosks connected to the network. However, some clocked out and recorded their time after leaving to go home. Only those who clocked in and out while inside the building had credentials stolen. Each of the kiosks are on different floors, and there are multiple routers, since the business segments environments for certain business functions.

    Hourly employees are required to use a website called acmetimekeeping.com to clock in and out. This website is accessible from the internet.

    Which of the following is the most likely reason for this compromise?

    A. A brute-force attack was used against the time-keeping website to scan for common passwords.
    B. A malicious actor compromised the time-keeping website with malicious code using an unpatched vulnerability on the site, stealing the credentials.
    C. The internal DNS servers were poisoned and were redirecting acmetimekeeping.com to a malicious domain that intercepted the credentials and then passed them through to the real site.
    D. ARP poisoning affected the machines in the building and caused the kiosks to send a copy of all the submitted credentials to a malicious machine.

  • Question 257:

    Which of the following actors attacking an organization is the most likely to be motivated by personal beliefs?

    A. Nation-state
    B. Organized crime
    C. Hacktivist
    D. Insider threat

  • Question 258:

    The CIRT is reviewing an incident that involved a human resources recruiter exfiltrating sensitive company data. The CIRT found that the recruiter was able to use HTTP over port 53 to upload documents to a web server.

    Which of the following security infrastructure devices could have identified and blocked this activity?

    A. WAF utilizing SSL decryption
    B. NGFW utilizing application inspection
    C. UTM utilizing a threat feed
    D. SD-WAN utilizing IPSec

  • Question 259:

    An organization experiences a compromise in a cloud-hosted solution that contains customer information.

    Which of the following strategies will help determine the sensitivity level of the breach?

    A. Permission restrictions
    B. Tabletop exercise
    C. Data classification
    D. Asset inventory

  • Question 260:

    Which of the following organizational documents is most often used to establish and communicate expectations associated with integrity and ethical behavior within an organization?

    A. AUP
    B. SLA
    C. EULA
    D. MOA

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-701 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.