wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Security+ Certification Exam SY0-701 Practice Test 24

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

What is a detailed agreement outlining work to be performed on a project?

a)

MSA

b)

SLA

c)

WO

d)

SOW

2.

Which contract restricts a person from sharing confidential information?

a)

ISA

b)

NDA

c)

BPA

d)

SLA

3.

What formal contract outlines the rights and obligations of business partners?

a)

MSA

b)

SLA

c)

BPA

d)

MOA

4.

What is the term for assessing risks and facts before making decisions?

a)

Fiduciary duty

b)

Due care

c)

Standard of care

d)

Due diligence

5.

Which term describes actions taken to mitigate known risks?

a)

Due diligence

b)

Standard of care

c)

Due care

d)

Fiduciary duty

6.

What is the term for the person whose data is collected and processed?

a)

Data holder

b)

Data owner

c)

Data user

d)

Data subject

7.

Who determines the purpose and means of processing personal data?

a)

Data processor

b)

Data owner

c)

Data controller

d)

Data subject

8.

Who processes data on behalf of the controller?

a)

Data steward

b)

Data processor

c)

Data subject

d)

Data custodian

9.

Which principle allows people to request deletion of personal data?

a)

De-identification

b)

Right to be forgotten

c)

Anonymization

d)

Consent management

10.

What is a formal auditor declaration of compliance with standards?

a)

Assertion

b)

Certification

c)

Validation

d)

Attestation

11.

Who typically provides attestation during audits?

a)

Regulatory body

b)

External auditor

c)

Audit committee

d)

Internal audit team

12.

In cybersecurity, the red team role is:

a)

An attacker

b)

A defender

c)

Both attacker and defender

d)

An overseer

13.

In cybersecurity exercises, who defends against attacks?

a)

Red team

b)

Blue team

c)

White team

d)

Purple team

14.

Which team oversees and monitors cybersecurity exercises?

a)

Red team

b)

Blue team

c)

White team

d)

Purple team

15.

The purple team performs all red, blue, and white team roles.

a)

True

b)

False

16.

What type of test is done with full system knowledge?

a)

Black-hat hacking

b)

White-box testing

c)

Black-box testing

d)

White-hat hacking

17.

Which test involves limited knowledge of internal systems?

a)

Black-box testing

b)

Fuzz testing

c)

Gray-box testing

d)

White-box testing

18.

A black-box penetration test involves no system knowledge beforehand.

a)

True

b)

False

19.

Active reconnaissance in pen testing uses only public info.

a)

True

b)

False

20.

Passive reconnaissance includes pinging and port scanning.

a)

True

b)

False

21.

Which of the following can indicate a phishing email?

a)

Bad grammar

b)

Request for personal info

c)

Urgency

d)

Suspicious attachments

e)

All of the above

22.

What are appropriate user actions in response to phishing? (Select all that apply)

a)

Not reply or give info

b)

Report to IT/security

c)

Forward to sender for verification

d)

Delete the message

e)

Avoid clicking links or downloading attachments

23.

What best describes a disgruntled employee misusing access?

a)

APT

b)

Insider threat

c)

Gray hat

d)

Threat actor

24.

What could a malicious USB cable potentially do?

a)

GPS tracking

b)

Capture keystrokes

c)

Send/receive commands

d)

Deliver malware

e)

All of the above

25.

What is the best defense against social engineering?

a)

Situational awareness

b)

Implicit deny policy

c)

User education

d)

Strong security controls