CompTIA SY0-701 Online Practice
Questions and Exam Preparation
SY0-701 Exam Details
Exam Code
:SY0-701
Exam Name
:CompTIA Security+
Certification
:CompTIA Certifications
Vendor
:CompTIA
Total Questions
:1016 Q&As
Last Updated
:Jul 14, 2026
CompTIA SY0-701 Online Questions &
Answers
Question 391:
While a user reviews their email, a host gets infected by malware from an external hard drive plugged into the host. The malware steals all the user's credentials stored in the browser.
Which of the following training topics should the user review to prevent this situation from reoccurring?
A. Operational security B. Removable media and cables C. Password management D. Social engineering
B. Removable media and cables
Explanation
This scenario highlights the need for training on the secure use of removable media. Users should learn to avoid using untrusted external storage devices to prevent malware infections.
References:
CompTIA Security+ SY0-701 Study Guide, Domain 4: Security Operations, Section: "Removable Media Controls and User Awareness Training".
Question 392:
Which of the following is a reason environmental variables are a concern when reviewing potential system vulnerabilities?
A. The contents of environmental variables could affect the scope and impact of an exploited vulnerability. B. In-memory environmental variable values can be overwritten and used by attackers to insert malicious code. C. Environmental variables de ne cryptographic standards for the system and could create vulnerabilities if deprecated algorithms are used. D. Environmental variables will determine when updates are run and could mitigate the likelihood of vulnerability exploitation.
A. The contents of environmental variables could affect the scope and impact of an exploited vulnerability.
Question 393:
Which of the following is a vulnerability concern for end-of-life hardware?
A. Failure to follow hardware disposal procedures could result in unintended data release. B. The supply chain may not have replacement hardware. C. Newly released software may require computing resources not available on legacy hardware. D. The vendor may stop providing patches and updates.
D. The vendor may stop providing patches and updates.
Explanation
The most significant vulnerability concern for end-of-life (EOL) hardware is that vendors stop providing patches and updates. CompTIA Security+ SY0-701 highlights that unsupported hardware and software no longer receive security fixes, leaving known vulnerabilities permanently unpatched. This creates an expanding attack surface that adversaries can easily exploit.
Once hardware reaches EOL status, newly discovered vulnerabilities will remain unaddressed, increasing the likelihood of compromise. This is especially dangerous for systems exposed to networks or handling sensitive data, where exploitation can lead to data breaches, lateral movement, or service disruption.
Option A relates to disposal risks, not active vulnerabilities.
Option B is a logistical issue, not a security vulnerability.
Option C is a compatibility concern, not a direct vulnerability.
Because unpatched systems are inherently vulnerable and cannot be secured through updates, the correct answer is D: The vendor may stop providing patches and updates.
Question 394:
An unexpected and out-of-character email message from a Chief Executive Officer's corporate account asked an employee to provide financial information and to change the recipient's contact number.
Which of the following attack vectors is most likely being used?
A. Business email compromise B. Phishing C. Brand impersonation D. Pretexting
A. Business email compromise
Explanation
Business Email Compromise (BEC) is a targeted phishing attack in which attackers impersonate executives or high-ranking officials (such as a CEO) to manipulate employees into transferring money or providing sensitive data. Since the request is coming from the CEO's corporate email (possibly spoofed or compromised), this is a classic example of BEC.
Phishing (B) is a broader term but typically involves mass fraudulent emails rather than targeted executive impersonation.
Pretexting (D) involves social engineering tactics but does not necessarily involve email compromise.
References:
CompTIA Security+ SY0-701 Official Study Guide, Threats, Vulnerabilities, and Mitigations domain.
Question 395:
An engineer has ensured that the switches are using the latest OS, the servers have the latest patches, and the endpoints' definitions are up to date.
Which of the following will these actions most effectively prevent?
A. Zero-day attacks B. Insider threats C. End-of-life support D. Known exploits
D. Known exploits
Question 396:
A network security analyst monitors the network's IDS, which has flagged unusual activity. The IDS has detected multiple login attempts to a database server within a short period. These attempts come from various IP addresses that are not normally recognized by the network's usual traffic patterns. Each attempt uses the same username and password. Based on the following log output (corrected formatting for readability):
Which of the following types of network attacks is most likely occurring?
A. Cross-site scripting B. Credential replay C. Distributed denial of service D. SQL injection
B. Credential replay
Explanation
The logs show multiple login attempts to the same account (JDoe) using the same username and password within a very short period. These attempts originate from different IP addresses, indicating that the same credentials are being reused repeatedly from multiple sources.
This behavior is characteristic of a credential replay attack. In a credential replay attack, previously obtained credentials are reused to attempt authentication across systems or services.
Cross-site scripting (A) involves injecting malicious scripts into web pages viewed by other users. Distributed denial of service (C) focuses on overwhelming a system with traffic to disrupt service availability. SQL injection (D) involves injecting malicious SQL statements into input fields to manipulate a database.
Therefore, the most likely attack is B: Credential replay.
Question 397:
An administrator must implement a solution that provides security and network connectivity between two companies.
Which of the following infrastructure solutions is the best for this purpose?
A. UTM B. VPN C. NAC D. NGFW
B. VPN
Explanation
The best answer is B. VPN.
A VPN (Virtual Private Network) is the standard solution for securely connecting two separate organizations or networks across an untrusted network, such as the internet. A site-to-site VPN provides: secure connectivity between both companies encrypted traffic in transit protection of data confidentiality and integrity a practical way to interconnect business networks.
Why the other options are incorrect:
A. UTMA unified threat management device offers multiple security features, but it is not specifically the best answer for secure connectivity between two companies.
C. NACNetwork Access Control regulates which devices can connect to a network, but it does not provide intercompany network connectivity.
D. NGFWA next-generation firewall improves traffic inspection and filtering, but it is not by itself the main solution for secure network connectivity between two companies. From the SY0-701 perspective, when secure communication between separate organizations is required, VPN is the most appropriate infrastructure solution.
Question 398:
Which of the following addresses individual rights such as the right to be informed, the right of access, and the right to be forgotten?
A. GDPR B. PCI DSS C. NIST D. ISO
A. GDPR
Question 399:
A systems administrator is redesigning how devices will perform network authentication. The following requirements need to be met:
1. An existing internal certificate must be used.
2. Wired and wireless networks must be supported.
3. Any unapproved device should be isolated in a quarantine subnet.
4. Approved devices should be updated before accessing resources.
Which of the following would best meet the requirements?
A. 802.IX B. EAP C. RADIUS D. WPA2
A. 802.IX
Explanation
802.1X is a network access control protocol that provides an authentication mechanism to devices trying to connect to a LAN or WLAN. It supports the use of certificates for authentication, can quarantine unapproved devices, and ensures that only approved and updated devices can access network resources. This protocol best meets the requirements of securing both wired and wireless networks with internal certificates.
References:
CompTIA Security+ SY0-701 study materials, particularly in the domain of network security and authentication protocols.
Question 400:
A company performs risk analysis on its equipment and estimates it will experience about ten incidents over a five-year period.
Which of the following is the correct ARO for the equipment?
A. 2 B. 5 C. 10 D. 50
A. 2
Explanation
The best answer is A. 2. ARO (Annualized Rate of Occurrence) measures how many times an incident is expected to occur per year. The company expects: 10 incidents over 5 years So the calculation is: ARO = 10 / 5 = 2 This means the expected annual rate of occurrence is 2 incidents per year. Why the other options are incorrect:
B. 5This would not represent the yearly average based on the numbers given.
C. 10This is the total number of incidents over five years, not the annualized value.
D. 50This is not supported by the information in the question. From a Security+ risk calculation standpoint, when a total event count is spread across multiple years, the ARO is found by dividing the total incidents by the number of years. Therefore, A is correct.
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only CompTIA exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your SY0-701 exam preparations
and CompTIA certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.