CompTIA SY0-701 Online Practice
Questions and Exam Preparation
SY0-701 Exam Details
Exam Code
:SY0-701
Exam Name
:CompTIA Security+
Certification
:CompTIA Certifications
Vendor
:CompTIA
Total Questions
:1016 Q&As
Last Updated
:Jul 14, 2026
CompTIA SY0-701 Online Questions &
Answers
Question 611:
A company is utilizing an offshore team to help support the finance department. The company wants to keep the data secure by keeping it on a company device but does not want to provide equipment to the offshore team.
Which of the following should the company implement to meet this requirement?
A. VDI B. MDM C. VPN D. VPC
A. VDI
Explanation
Virtual Desktop Infrastructure (VDI) allows a company to host desktop environments on a centralized server. Offshore teams can access these virtual desktops remotely, ensuring that sensitive data stays within the company's infrastructure without the need to provide physical devices to the team. This solution is ideal for maintaining data security while enabling remote work, as all data processing occurs on the company's secure servers.
References:
CompTIA Security+ SY0-701 Course Content: VDI is discussed as a method for securely managing remote access to company resources without compromising data security.
Question 612:
Which of the following describes an executive team that is meeting in a board room and testing the company's incident response plan?
A. Continuity of operations B. Capacity planning C. Tabletop exercise D. Parallel processing
C. Tabletop exercise
Explanation
A tabletop exercise involves the executive team or key stakeholders discussing and testing the company's incident response plan in a simulated environment. These exercises are low-stress, discussion-based, and help to validate the plan's effectiveness by walking through different scenarios without disrupting actual operations. It is an essential part of testing business continuity and incident response strategies. Continuity of operations refers to the ability of an organization to continue functioning during and after a disaster but doesn't specifically involve simulations like tabletop exercises.
Capacity planning is related to ensuring the infrastructure can handle growth, not incident response testing.
Parallel processing refers to running multiple processes simultaneously, which is unrelated to testing an incident response plan.
Question 613:
Which of the following is a compensating control for providing user access to a high-risk website?
A. Enabling threat prevention features on the firewall B. Configuring a SIEM tool to capture all web traffic C. Setting firewall rules to allow traffic from any port to that destination D. Blocking that website on the endpoint protection software
A. Enabling threat prevention features on the firewall
Explanation
Enabling threat prevention features on the firewall is a compensating control that adds a layer of security when accessing a high-risk website. This approach helps to detect and block malicious activities associated with the website by scanning for threats, malicious code, and suspicious traffic patterns, thereby mitigating potential risks without completely restricting access.
Question 614:
Which of the following would most likely be used by attackers to perform credential harvesting?
A. Social engineering B. Supply chain compromise C. Third-party software D. Rainbow table
A. Social engineering
Explanation
Social engineering tactics, such as phishing, are commonly used by attackers to trick individuals into revealing their login credentials. By posing as a trusted entity or creating a fake login page, attackers can harvest usernames and passwords directly from unsuspecting users. This method is highly effective and frequently used for credential harvesting.
Question 615:
A systems administrator would like to create a point-in-time backup of a virtual machine.
Which of the following should the administrator use?
A. Replication B. Simulation C. Snapshot D. Containerization
C. Snapshot
Question 616:
A security analyst recently read a report about a flaw in several of the organization's printer models that causes credentials to be sent over the network in cleartext, regardless of the encryption settings.
Which of the following would be best to use to validate this finding?
A. Wireshark B. netcat C. Nessus D. Nmap
A. Wireshark
Question 617:
A Chief Information Security Officer (CISO) wants to explicitly raise awareness about the increase of ransomware-as-a-service in a report to the management team.
Which of the following best describes the threat actor in the CISO's report?
A. Insider threat B. Hacktivist C. Nation-state D. Organized crime
D. Organized crime
Explanation
Ransomware-as-a-service is a type of cybercrime where hackers sell or rent ransomware tools or services to other criminals who use them to launch attacks and extort money from victims. This is a typical example of organized crime, which is a group of criminals who work together to conduct illegal activities for profit. Organized crime is different from other types of threat actors, such as insider threats, hacktivists, or nation-states, who may have different motives, methods, or targets.
References:
CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 17
Question 618:
A user would like to install software and features that are not available with a smartphone's default software.
Which of the following would allow the user to install unauthorized software and enable new features?
A. SOU B. Cross-site scripting C. Jailbreaking D. Side loading
C. Jailbreaking
Explanation
Jailbreaking is the process of removing restrictions imposed by the manufacturer on a smartphone, allowing the user to install unauthorized software and features not available through official app stores. This action typically voids the warranty and can introduce security risks by bypassing built-in protections. SOU (Statement of Understanding) is not related to modifying devices. Cross-site scripting is a web-based attack technique, unrelated to smartphone software. Side loading refers to installing apps from unofficial sources but without necessarily removing built-in restrictions like jailbreaking does.
Question 619:
Which of the following is used to validate a certificate when it is presented to a user?
A. OCSP B. CSR C. CA D. CRC
A. OCSP
Explanation
OCSP stands for Online Certificate Status Protocol. It is a protocol that allows applications to check the revocation status of a certificate in real-time. It works by sending a query to an OCSP responder, which is a server that maintains a database of revoked certificates. The OCSP responder returns a response that indicates whether the certificate is valid, revoked, or unknown. OCSP is faster and more efficient than downloading and parsing Certificate Revocation Lists (CRLs), which are large files that contain the serial numbers of all revoked certificates issued by a Certificate Authority (CA).
References:
CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 337
Question 620:
In an effort to reduce costs, a company is implementing a strategy that gives employees access to internal company resources, including email, from personal devices.
Which of the following strategies is the company implementing?
A. CYOD B. BYOD C. COPE D. MDM
B. BYOD
Explanation
BYOD, or Bring Your Own Device, is the correct answer because the company is allowing employees to use personally owned devices to access internal company resources such as email. In Security+ architecture and operations topics, mobile deployment models are important because each model shifts ownership, management, and risk differently. BYOD reduces hardware procurement costs, but it increases security concerns because the organization does not fully own or control the endpoint. Controls such as MDM, conditional access, encryption, remote wipe, acceptable use policies, and device compliance checks are commonly needed. CYOD means employees choose from approved corporate devices, while COPE means the company owns the device and permits personal use. MDM is a management control, not the deployment strategy itself.
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only CompTIA exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your SY0-701 exam preparations
and CompTIA certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.