SY0-701 Exam Details

  • Exam Code
    :SY0-701
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :983 Q&As
  • Last Updated
    :May 26, 2026

CompTIA SY0-701 Online Questions & Answers

  • Question 691:

    A network security analyst monitors the network's IDS, which has flagged unusual activity. The IDS has detected multiple login attempts to a database server within a short period. These attempts come from various IP addresses that are not normally recognized by the network's usual traffic patterns. Each attempt uses the same username and password. Based on the following log output (corrected formatting for readability):

    2025-04-10 14:22:01.4532 - Source IP: 192.168.15.101 - Status: Failed - User: JDoe - Action: Login Attempt

    2025-04-10 14:22:02.1122 - Source IP: 192.168.15.102 - Status: Failed - User: JDoe - Action: Login Attempt

    2025-04-10 14:22:02.7835 - Source IP: 192.168.15.103 - Status: Failed - User: JDoe - Action: Login Attempt

    2025-04-10 14:22:03.5637 - Source IP: 192.168.15.104 - Status: Failed - User: JDoe - Action: Login Attempt

    2025-04-10 14:22:04.9474 - Source IP: 192.168.15.105 - Status: Failed - User: JDoe - Action: Login Attempt

    2025-04-10 14:22:05.5673 - Source IP: 192.168.15.106 - Status: Failed - User: JDoe - Action: Login Attempt

    2025-04-10 14:22:06.1573 - Source IP: 192.168.15.107 - Status: Failed - User: JDoe - Action: Login Attempt

    2025-04-10 14:22:07.7462 - Source IP: 192.168.15.108 - Status: Failed - User: JDoe - Action: Login Attempt

    Which of the following types of network attacks is most likely occurring?

    A. Cross-site scripting
    B. Credential replay
    C. Distributed denial of service
    D. SQL injection

  • Question 692:

    While updating the security awareness training, a security analyst wants to address issues created if vendors' email accounts are compromised.

    Which of the following recommendations should the security analyst include in the training?

    A. Refrain from clicking on images included in emails from new vendors
    B. Delete emails from unknown service provider partners.
    C. Require that invoices be sent as attachments
    D. Be alert to unexpected requests from familiar email addresses

  • Question 693:

    A nation-state attacker gains access to the email accounts of several journalists by compromising a website that the journalists frequently use.

    Which of the following types of attacks describes this example?

    A. On-path
    B. Watering-hole
    C. Typosquatting
    D. Brand impersonation

  • Question 694:

    A company wants to add an MFA solution for all employees who access the corporate network remotely. Log-in requirements include something you know, are, and have. The company wants a solution that does not require purchasing third-party applications or specialized hardware.

    Which of the following MFA solutions would best meet the company's requirements?

    A. Smart card with PIN and password
    B. Security questions and a one-time passcode sent via email
    C. Voice and ngerprint verification with an SMS one-time passcode
    D. Mobile application-generated, one-time passcode with facial recognition

  • Question 695:

    A network team segmented a critical, end-of-life server to a VLAN that can only be reached by specific devices but cannot be reached by the perimeter network.

    Which of the following best describe the controls the team implemented? (Choose two.)

    A. Managerial
    B. Physical
    C. Corrective
    D. Detective
    E. Compensating
    F. Technical
    G. Deterrent

  • Question 696:

    An organization is required to maintain financial data records for three years and customer data for five years.

    Which of the following data management policies should the organization implement?

    A. Retention
    B. Destruction
    C. Inventory
    D. Certification

  • Question 697:

    Which of the following is the act of proving to a customer that software developers are trained on secure coding?

    A. Assurance
    B. Contract
    C. Due diligence
    D. Attestation

  • Question 698:

    Which of the following is the most likely reason a security analyst would review SIEM logs?

    A. To check for recent password reset attempts
    B. To monitor for potential DDoS attacks
    C. To assess the scope of a privacy breach
    D. To see correlations across multiple hosts

  • Question 699:

    A client asked a security company to provide a document outlining the project, the cost, and the completion time frame.

    Which of the following documents should the company provide to the client?

    A. MSA
    B. SLA
    C. BPA
    D. SOW

  • Question 700:

    Which of the following security measures is required when using a cloud-based platform for IoT management?

    A. Encrypted connection
    B. Federated identity
    C. Firewall
    D. Single sign-on

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-701 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.