Font size
WorksheetsCompTIA Security+ Certification Exam SY0-701 Practice Test 24
Total questions: 25
Worksheet time: 13mins
What is a detailed agreement outlining work to be performed on a project?
MSA
SLA
WO
SOW
Which contract restricts a person from sharing confidential information?
ISA
NDA
BPA
SLA
What formal contract outlines the rights and obligations of business partners?
MSA
SLA
BPA
MOA
What is the term for assessing risks and facts before making decisions?
Fiduciary duty
Due care
Standard of care
Due diligence
Which term describes actions taken to mitigate known risks?
Due diligence
Standard of care
Due care
Fiduciary duty
What is the term for the person whose data is collected and processed?
Data holder
Data owner
Data user
Data subject
Who determines the purpose and means of processing personal data?
Data processor
Data owner
Data controller
Data subject
Who processes data on behalf of the controller?
Data steward
Data processor
Data subject
Data custodian
Which principle allows people to request deletion of personal data?
De-identification
Right to be forgotten
Anonymization
Consent management
What is a formal auditor declaration of compliance with standards?
Assertion
Certification
Validation
Attestation
Who typically provides attestation during audits?
Regulatory body
External auditor
Audit committee
Internal audit team
In cybersecurity, the red team role is:
An attacker
A defender
Both attacker and defender
An overseer
In cybersecurity exercises, who defends against attacks?
Red team
Blue team
White team
Purple team
Which team oversees and monitors cybersecurity exercises?
Red team
Blue team
White team
Purple team
The purple team performs all red, blue, and white team roles.
True
False
What type of test is done with full system knowledge?
Black-hat hacking
White-box testing
Black-box testing
White-hat hacking
Which test involves limited knowledge of internal systems?
Black-box testing
Fuzz testing
Gray-box testing
White-box testing
A black-box penetration test involves no system knowledge beforehand.
True
False
Active reconnaissance in pen testing uses only public info.
True
False
Passive reconnaissance includes pinging and port scanning.
True
False
Which of the following can indicate a phishing email?
Bad grammar
Request for personal info
Urgency
Suspicious attachments
All of the above
What are appropriate user actions in response to phishing? (Select all that apply)
Not reply or give info
Report to IT/security
Forward to sender for verification
Delete the message
Avoid clicking links or downloading attachments
What best describes a disgruntled employee misusing access?
APT
Insider threat
Gray hat
Threat actor
What could a malicious USB cable potentially do?
GPS tracking
Capture keystrokes
Send/receive commands
Deliver malware
All of the above
What is the best defense against social engineering?
Situational awareness
Implicit deny policy
User education
Strong security controls
