wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Security+ Certification Exam SY0-701 Practice Test 1

Total questions: 25

Worksheet time: 25mins

Name
Class
Date
1.

Which of the following answers can be used to describe technical security controls? (Select 3 answers)

a)

Focused on protecting material assets

b)

Implemented with technology

c)

Executed by computer systems (instead of people)

d)

Also known as administrative controls

e)

Sometimes called logical security controls

2.

Which of the answers listed below refer to examples of technical security controls? (Select 3 answers)

a)

Encryption

b)

Security audits

c)

IDSs

d)

Organizational security policy

e)

Firewalls

3.

Which of the following answers refer to the characteristic features of managerial security controls? (Select 3 answers)

a)

Also known as administrative controls

b)

Focused on reducing the risk of security incidents

c)

Executed by computer systems (instead of people)

d)

Documented in written policies

e)

Sometimes referred to as logical security controls

4.

Examples of managerial security controls include: (Select 3 answers)

a)

Configuration management

b)

Data backups

c)

Organizational security policy

d)

Risk assessments

e)

Security awareness training

5.

Which of the answers listed below can be used to describe operational security controls (Select 3 answers)

a)

Executed by computer systems (instead of people)

b)

Also known as administrative controls

c)

Primarily implemented and executed by people (as opposed to computer systems)

d)

Used to ensure that the equipment continues to work as specified

e)

Focused on the day-to-day procedures of an organization

6.

Which of the following examples fall into the category of operational security controls? (Select 3 answers)

a)

Risk assessments

b)

Configuration management

c)

System backups

d)

Authentication protocols

e)

Patch management

7.

Which of the answers listed below refers to security controls designed to deter, detect, and prevent unauthorized access, theft, damage, or destruction of material assets?

a)

Managerial security controls

b)

Physical security controls

c)

Technical security controls

d)

Operational security controls

8.

Which of the following examples do not fall into the category of physical security controls? (Select 3 answers)

a)

Access control vestibules

b)

Asset management

c)

Firewalls

d)

Lighting

e)

Data backups

9.

What are the examples of preventive security controls? (Select 3 answers)

a)

Encryption

b)

IDS

c)

Sensors

d)

Firewalls

e)

Warning signs

10.

Examples of deterrent security controls include: (Select 3 answers)

a)

Warning signs

b)

Fencing/Bollards

c)

Lighting

d)

Sensors

e)

Video surveillance

11.

Which of the answers listed below refer(s) to detective security control(s)? (Select all that apply)

a)

Vulnerability scanning

b)

IDS

c)

CCTV

d)

Lighting

e)

Log monitoring

12.

Which of the following answers refer(s) to corrective security control(s)? (Select all that apply)

a)

Recovering data from backup copies

b)

Applying software updates and patches to fix vulnerabilities

c)

Developing and implementing IRPs to respond to and recover from security incidents

d)

Regularly reviewing logs for anomalies or patterns indicative of attacks

e)

Activating and executing DRPs to restore operations after a major incident

13.

Which of the answers listed below refer(s) to compensating security control(s)? (Select all that apply)

a)

Backup power systems

b)

Video surveillance

c)

MFA

d)

Application sandboxing

e)

Network segmentation

14.

The term "Directive security controls" refers to the category of security controls that are implemented through policies and procedures.

a)

True

b)

False

15.

Which of the following terms fall into the category of directive security controls? (Select 2 answers)

a)

IRP

b)

AUP

c)

IDS

d)

MFA

e)

IPS

16.

Which of the terms listed below can be used to describe the basic principles of information security?

a)

PKI

b)

AAA

c)

GDPR

d)

CIA

17.

The term "Non-repudiation" describes the inability to deny responsibility for performing a specific action. In the context of data security, non-repudiation ensures data confidentiality, provides proof of data integrity, and proof of data origin.

a)

True

b)

False

18.

Which of the following best applies to the concept of non-repudiation?

a)

Digital certificate

b)

MFA

c)

Hashing

d)

Encryption

19.

Which type of user account violates the concept of non-repudiation?

a)

Standard user account

b)

Shared account

c)

Guest user account

d)

Service account

20.

Which part of the AAA security architecture deals with the verification of the identity of a person or process?

a)

Authentication

b)

Authorization

c)

Accounting

21.

In the AAA security architecture, the process of granting or denying access to resources is known as:

a)

Authentication

b)

Authorization

c)

Accounting

22.

In the AAA security architecture, the process of tracking accessed services as well as the amount of consumed resources is called:

a)

Authentication

b)

Authorization

c)

Accounting

23.

Which of the following solutions provide(s) the AAA functionality? (Select all that apply)

a)

CHAP

b)

TACACS+

c)

PAP

d)

RADIUS

e)

MS-CHAP

24.

In the context of the AAA framework, common methods for authenticating people include: (Select 3 answers)

a)

IP addresses

b)

Usernames and passwords

c)

MAC addresses

d)

Biometrics

e)

MFA

25.

Which of the answers listed below refer to common methods of device authentication used within the AAA framework? (Select 3 answers)

a)

MFA

b)

Usernames and passwords

c)

MAC addresses

d)

IP addresses

e)

Digital certificates