SY0-701 Exam Details

  • Exam Code
    :SY0-701
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1016 Q&As
  • Last Updated
    :Jul 14, 2026

CompTIA SY0-701 Online Questions & Answers

  • Question 571:

    While updating the security awareness training, a security analyst wants to address issues created if vendors' email accounts are compromised.

    Which of the following recommendations should the security analyst include in the training?

    A. Refrain from clicking on images included in emails from new vendors
    B. Delete emails from unknown service provider partners.
    C. Require that invoices be sent as attachments
    D. Be alert to unexpected requests from familiar email addresses

  • Question 572:

    An organization conducts a self-evaluation with a phishing campaign that requests login credentials. The organization receives the following results:

    1. None of the staff were fooled by the attempt due to proper security awareness.

    2. Staff deleted the email without performing any additional actions.

    Which of the following security practices would add the most value to the organization?

    A. Implement a strict password reset policy for all senior managers after a security event.
    B. Update user guidance to include suspicious incident reporting.
    C. Conduct end-user training regarding spear-phishing attempts to raise awareness.
    D. Require remote workers to use a VPN when connecting to the organization ' s networks.

  • Question 573:

    Which of the following control types describes an alert from a SIEM tool?

    A. Preventive
    B. Corrective
    C. Compensating
    D. Detective

  • Question 574:

    An organization is building a new backup data center with cost-benefit as the primary requirement and RTO and RPO values around two days.

    Which of the following types of sites is the best for this scenario?

    A. Real-time recovery
    B. Hot
    C. Cold
    D. Warm

  • Question 575:

    Which of the following control types involves restricting IP connectivity to a router's web management interface to protect it from being exploited by a vulnerability?

    A. Corrective
    B. Physical
    C. Preventive
    D. Managerial

  • Question 576:

    A systems administrator just purchased multiple network devices.

    Which of the following should the systems administrator perform to prevent attackers from accessing the devices by using publicly available information?

    A. Install endpoint protection.
    B. Disable ports/protocols.
    C. Change default passwords.
    D. Remove unnecessary software.

  • Question 577:

    A security analyst is reviewing the following logs about a suspicious activity alert for a user's VPN log-ins:

    Which of the following malicious activity indicators triggered the alert?

    A. Impossible travel
    B. Account lockout
    C. Blocked content
    D. Concurrent session usage

  • Question 578:

    After a company was compromised, customers initiated a lawsuit. The company's attorneys have requested that the security team initiate a legal hold in response to the lawsuit.

    Which of the following describes the action the security team will most likely be required to take?

    A. Retain the emails between the security team and affected customers for 30 days.
    B. Retain any communications related to the security breach until further notice.
    C. Retain any communications between security members during the breach response.
    D. Retain all emails from the company to affected customers for an indefinite period of time.

  • Question 579:

    A company's accounts payable clerk receives a message from a vendor asking to change their bank account before paying an invoice. The clerk makes the change and sends the payment to the new account. Days later, the clerk receives another message from the same vendor with a request for a missing payment to the original bank account.

    Which of the following has most likely occurred?

    A. Phishing campaign
    B. Data exfiltration
    C. Pretext calling
    D. Business email compromise

  • Question 580:

    Which of the following are the most important considerations when encrypting data? (Select two).

    A. Obfuscation
    B. Algorithms
    C. Data masking
    D. Key length
    E. Tokenization
    F. Salting

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-701 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.