SY0-701 Exam Details

  • Exam Code
    :SY0-701
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1016 Q&As
  • Last Updated
    :Jul 14, 2026

CompTIA SY0-701 Online Questions & Answers

  • Question 351:

    Which of the following has been implemented when a host-based firewall on a legacy Linux system allows connections from only specific internal IP addresses?

    A. Compensating control
    B. Network segmentation
    C. Transfer of risk
    D. SNMP traps

  • Question 352:

    Which of the following is the most likely reason a security analyst would review SIEM logs?

    A. To check for recent password reset attempts
    B. To monitor for potential DDoS attacks
    C. To assess the scope of a privacy breach
    D. To see correlations across multiple hosts

  • Question 353:

    Which of the following is the stage in an investigation when forensic images are obtained?

    A. Acquisition
    B. Preservation
    C. Reporting
    D. E-discovery

  • Question 354:

    While considering the organization's cloud-adoption strategy, the Chief Information Security Officer sets a goal to outsource patching of firmware, operating systems, and applications to the chosen cloud vendor.

    Which of the following best meets this goal?

    A. Community cloud
    B. PaaS
    C. Containerization
    D. Private cloud
    E. SaaS
    F. laaS

  • Question 355:

    Which of the following is most likely to be deployed to obtain and analyze attacker activity and techniques?

    A. Firewall
    B. IDS
    C. Honeypot
    D. Layer 3 switch

  • Question 356:

    Which of the following would be the best way to block unknown programs from executing?

    A. Access control list
    B. Application allow list.
    C. Host-based firewall
    D. DLP solution

  • Question 357:

    A forensic engineer determines that the root cause of a compromise is a SQL injection attack.

    Which of the following should the engineer review to identify the command used by the threat actor?

    A. Metadata
    B. Application log
    C. System log
    D. Netflow log

  • Question 358:

    Which of the following techniques would identify whether data has been modified in transit?

    A. Hashing
    B. Tokenization
    C. Masking
    D. Encryption

  • Question 359:

    Which of the following strategies most effectively protects sensitive data at rest in a database?

    A. Hashing
    B. Masking
    C. Tokenization
    D. Obfuscation

  • Question 360:

    At the start of a penetration test, the tester checks OSINT resources for information about the client environment.

    Which of the following types of reconnaissance is the tester performing?

    A. Active
    B. Passive
    C. Offensive
    D. Defensive

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-701 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.