NEW
Font size
WorksheetsCompTIA Security+ SY0-701 Exam Practice
Total questions: 70
Worksheet time: 35mins
In a corporate office, Kgomotso is responsible for overseeing the information system. Which statement best describes a managerial control in information security that Kgomotso should implement?
Oversight of the information system, such as risk identification or selecting security controls
Physical barriers like locks and lighting placed to protect hardware
A mechanism that ensures a user is who they claim to be
Two interlocking doors that permit only one individual to pass at a time
Physical control is best illustrated by which example?
A policy describing how access restrictions are enforced based on user context
Security measure regulating entry to a secure area using two interlocking doors
A log that records attempted intrusions
Stakeholder meetings to approve changes before implementation
Aya and LJ are security officers at a large corporate office. They are discussing the various types of security controls in place. Aya asks, "What is the primary purpose of a detective control?"
Psychologically discourage an attacker from attempting an intrusion
Identify and record an attempted or successful intrusion
Grant access on a need-to-know basis
Define how to enforce access restrictions
In a school, a deterrent control is best characterized as a control that:
May not physically or logically prevent access but discourages attempts
Gives oversight of the information system for selecting controls
Ensures consensus and authorization before changes
Regulates entry using an access control vestibule
During a school event, Phenyo is responsible for ensuring that all attendees are legitimate. Identification control primarily aims to:
Ensure that customers are legitimate
Detect and record intrusions after they occur
Deter and detect access using physical devices
Complicate changes across dependent services
In a corporate office, Aya is responsible for managing access to sensitive information. She implements policy-driven access control to ensure that employees can only access data on a need-to-know basis. This approach is most closely associated with which idea?
Access on a need-to-know, task-limited basis
Describing how to enforce restrictions by identity, device posture, and context
Involving relevant stakeholders to ensure consensus and authorization before change
Using alarms and cameras to deter intruders
In a busy office, Nkay and Chloe are discussing how to improve security. They consider implementing a system where two doors interlock to allow only one individual through at a time. Which description best matches this approach to threat scope reduction?
Two doors that interlock to allow only one individual through at a time
Complicated change effects because a service restart in one area may significantly impact another
Granting network access only to resources needed for a specific task
Maintaining records of attempted intrusions
In a high-security building, Aya and Justice are trying to enter a restricted area. They encounter an access control vestibule that has two interlocking doors, allowing only one of them to enter at a time. What is this access control vestibule?
A process requiring management sign-off before changes
A security measure with two interlocking doors permitting one individual at a time
A document specifying how access is enforced by identity and context
A log that identifies and records intrusions
In a corporate office, Chloe and Alejandra are discussing the approval process for accessing sensitive data. Which statement best represents this approval process in security governance?
Access granted on a need-to-know basis for a specific task
Involving stakeholders like management and IT to ensure consensus and authorization before changes
A psychological barrier that discourages intrusions
A set of physical controls such as locks and lighting
In the context of access control, dependencies primarily:
Describe how access restrictions are enforced based on user identity and context
Provide oversight of the information system through risk evaluation
Complicate changes because a restart in one area can significantly affect another
Grant access only to the minimum resources needed
In a recent news article, Aya read about a group of individuals who launched a campaign to expose government corruption through online protests and website defacements. Which statement best describes these individuals in the context of threat actors?
They are internal threat actors operating from within an organization.
They are motivated by social or political causes and are typically external.
They are exclusively nation-state actors sponsored by governments.
They are only interested in financial gain and ransomware.
Chloe and Kgomotso are discussing different types of cryptography in their computer science class. Kgomotso mentions that public key encryption is a method used for secure communication. Chloe asks, 'Public key encryption is classified as which type of cryptography?'
Symmetric
Asymmetric
Hash-based
Quantum-only
During a high-security event, Sagrys needs to access a restricted area. To gain entry, he must use a password, his fingerprint, and a smart card. Together, these elements represent which authentication category?
Single-factor authentication
Two-factor authentication
Three-factor authentication
Biometric-only authentication
In a network setup at Phenyo's school, they are considering implementing a transparent firewall. Which is true of a transparent firewall in terms of network addressing?
It always requires readdressing IPs.
It never inspects traffic at Layer 2.
It does not require readdressing IPs.
It must use NAT on all interfaces.
During a recent class project, Phenyo and Nkay were discussing the best practices for backup media connectivity. Phenyo suggested that they should always keep backup media connected for faster restores, while Nkay argued that it is better to keep backup media offline or disconnected except during backup/restore. What is the recommended practice for backup media connectivity?
Always keep backup media connected for faster restores.
Keep backup media offline or disconnected except during backup/restore.
Connect backup media only to internet-facing servers.
Encrypting backups removes the need to disconnect media.
Justice is a cybersecurity analyst who is assessing the severity of vulnerabilities in a software application. He learns about the Common Vulnerability Scoring System (CVSS) and needs to determine the valid score range for CVSS vulnerabilities. What is the valid score range for CVSS vulnerabilities?
0 to 10
0 to 100
1 to 5
1 to 10, with decimals not allowed
While traveling, LJ and Chloe come across a public charging station. They wonder about the safety of using the chargers available there. Which statement about malicious USB chargers and mobile devices is correct?
They cannot compromise a device because charging ports block data.
They can compromise a device via malicious components or data lines.
They only affect laptops, not smartphones or tablets.
They are safe if the device uses a PIN.
Chloe and LJ are discussing internet security protocols. Chloe asks, 'TLS is related to SSL in which way?' What do you think she means?
TLS is an older protocol that SSL replaced.
TLS is the successor to SSL and provides encrypted communications.
TLS is unrelated to SSL and used only for email.
TLS removes the need for certificates.
During a cybersecurity training session, Phenyo asks, "What is a primary function of SIEM systems?"
Configure network devices automatically
Collect and analyse security event logs
Encrypt all traffic at the perimeter
Replace endpoint antivirus software
During a team meeting at a tech company, Phenyo raised a concern about the importance of security awareness training. He asked, when should this training occur?
Only during onboarding for new hires
Only after a security incident occurs
Continuously and not just during onboarding
Only for administrators and security staff
During a group project, Alejandra and her team members, including Kgomotso and Chloe, are using a shared online document to collaborate. How does accounting (audit logging) support non-repudiation in their project?
By encrypting all files by default
By recording user activities such as logins and file access, making actions traceable
By blocking all failed login attempts
By rotating passwords every week
During a cybersecurity workshop, Kgomotso and Chloe learned about different types of online scams. Kgomotso asked, 'What distinguishes phishing from spear phishing?'
Phishing targets executives only; spear phishing targets interns.
Phishing targets large groups randomly; spear phishing targets specific individuals with personalised messages.
Phishing uses phone calls; spear phishing uses emails only.
Phishing is legal; spear phishing is illegal.
In a company, Aya and Alejandra are assigned different roles. In Role-Based Access Control (RBAC), permissions are primarily assigned based on which factor?
The user's seniority
The user's role within the organisation
The device used to log in
Time since the last password change
In a company, Aya is tasked with setting up a network security system. She decides to create a DMZ to enhance security. What best describes a DMZ in network security?
A secure VPN tunnel for administrators only
A network segment that hosts publicly accessible servers while isolating them from internal systems
An encrypted storage area for backups
A wireless guest network with no authentication
During a class project, Aya was working on a virtual machine to develop a software application. She decided to take a snapshot of her VM before making significant changes. What is a snapshot in the context of virtual machines?
A text log of VM events
A saved state of a VM at a specific point in time, used for backup or rollback
A screenshot of the VM desktop
A performance benchmark file
During a school project, Sagrys discovered that sensitive student data was being shared without proper authorization. What is the function of a Data Loss Prevention (DLP) system in this scenario?
Detects malware at the endpoint only
Detects and blocks sensitive data from being leaked or transferred inappropriately
Optimises database queries
Manages user roles and permissions
Justice and Naledi are tasked with ensuring the security of their school's computer network. They need to establish a secure configuration baseline. What is this baseline used for?
Defining standard secure settings to ensure consistent security across endpoints
Allowing users to choose any settings they prefer
Disabling patches to increase stability
Testing performance under load
In a tech-savvy company, LJ and Justice are discussing mobile deployment models. They wonder which models allow employees to choose their own devices for work. What do you think they should consider?
COPE and COBO
BYOD and CYOD
CYOD only
BYOD only works for laptops
During a recent cybersecurity training session, Alejandra and her classmates learned about the importance of configuration management tools in maintaining system security. How do these tools assist vulnerability remediation?
They disable firewalls to speed up updates.
They ensure approved security settings are maintained across systems and allow quick rollback if unauthorised changes are made.
They replace patch management entirely.
They only inventory hardware models.
During a team project, Kgomotso and Aya are discussing the implications of allowing USB tethering on their mobile devices while working in the corporate office. What is a risk they should consider?
It reduces data usage costs.
It can bypass network security controls and enable unmonitored internet access.
It improves battery life of the device.
It forces all traffic through the corporate proxy automatically.
Choose the correct answer. During a recent compliance audit at their company, Naledi and Aya were tasked with identifying gaps in their adherence to the security framework. Which tool would they use to help with this task?
Risk register
SIEM
Gap analysis
Whitelist
Choose the correct answer. One day, Sagrys received an email that looked like it was from his bank, asking him to click a link to verify his account. However, when he clicked the link, he was redirected to a fake website that looked identical to his bank's site. Which type of attack does this scenario illustrate?
Whaling
Pharming
Spear phishing
Tailgating
Choose the correct answer. During a secure online meeting, Sagrys and Chloe are discussing the importance of encryption. Sagrys mentions that there is a protocol that uses asymmetric encryption during the handshake to ensure their conversation is secure. What protocol is he referring to?
TLS
SSH
HTTP
FTP
In a company where Sagrys and Chloe work, they are implementing a new security model called Zero Trust. Choose the correct answer. Zero Trust assumes which of the following?
External threats only
All internal traffic is secure
No inherent trust
VPNs are unnecessary
Choose the correct answer. In a recent project, Justice and Nkay were tasked with identifying critical assets and functions for their company's cybersecurity strategy. Which method should they use?
Business impact analysis
Penetration testing
Threat modelling
Risk register
Choose the correct answer. During a cybersecurity workshop, Aya and Justice were discussing the functionalities of a SIEM system. Aya mentioned that it is primarily used for a specific purpose. What does a SIEM system primarily do?
Host antivirus
Analyse event logs
Filter web content
Conduct backups
Choose the correct answer. During a team meeting, Chloe mentioned that the production line had been experiencing delays. To understand the underlying issues, Justice suggested using the Five Whys method. What is the Five Whys method used for?
Mitigation
Testing
Root cause analysis
Reporting
Choose the correct answer. Alejandra works at a financial services company that accepts a certain level of cyber risk in exchange for expected growth. Which term best describes the level of risk the company is willing to accept?
Risk tolerance
Risk threshold
Residual risk
Risk appetite
Choose the correct answer. During a cybersecurity workshop, LJ, Naledi, and Justice were discussing various compliance standards. Which of the following did they identify as a compliance standard?
Nmap
NIST
PCI-DSS
MD5
Choose the correct answer. Aya runs an e-commerce site that must be back online within 4 hours to avoid major revenue loss. Which term refers to the maximum amount of time the system can be unavailable before it significantly impacts the business?
MTTF
RTO
RPO
SLA
Naledi is working on a cybersecurity project and needs to ensure that the information she is protecting is secure. Which option correctly expands CIA in cybersecurity and captures its core purpose?
Confidentiality, Integrity, Availability — foundational principles guiding protection of information
Control, Inspection, Authorization — steps for approving user requests
Confidentiality, Integrity, Anonymity — privacy goals for masking identities
Compliance, Identification, Assurance — policy audit objectives
During a cybersecurity workshop, Kgomotso learned about various security tools. One of the tools discussed was FIM, which is primarily used to perform which security function?
Monitor file changes on critical system files to detect tampering
Encrypt entire disks to prevent data theft if a device is stolen
Manage digital certificates for web servers
Segment networks to isolate sensitive subnets
In enterprise security, Chloe is tasked with implementing a system to manage user identities and control access to sensitive information. Which description best aligns with the system she is implementing?
Centralized system for managing user identities and controlling access
Network protocol for encrypting traffic between routers
Tool for detecting malware by scanning memory
Method for hashing passwords before storage
In a corporate environment, Justice is tasked with ensuring that all communications over the network are secure. He decides to implement a technology that will secure IP communications through encryption and related protections. What is the primary purpose of this technology in the organization’s network stack?
Secure IP communications through encryption and related protections
Provide directory services for user accounts and groups
Aggregate event logs for correlation and alerting
Analyze user behavior to detect anomalies
In a company, Nkay is trying to understand how to access and modify the directory services for user accounts. He learns that LDAP is best described as which of the following?
Lightweight Directory Access Protocol used for accessing and modifying directory services
Logging framework for consolidating security events across hosts
Key exchange protocol used by public-key cryptography
Virtual tunneling method for remote connectivity
Chloe is trying to access her online banking account. To enhance security, the bank requires what?
Two or more verification factors to confirm identity
A password that changes every 90 days
A hardware token only, without passwords
Biometric verification as the sole login method
During a cybersecurity workshop, Sagrys and Alejandra were discussing the importance of securing online communications. Alejandra mentioned a system that helps manage digital certificates and supports public key encryption. Which option correctly defines this system?
Public Key Infrastructure that manages digital certificates and supports public key encryption
Packet Key Interchange used to rotate symmetric keys on routers
Private Kernel Interface that isolates system processes
Public Knowledge Index for cataloging security advisories
Chloe's organization is looking to enhance its security measures. They are considering implementing a SIEM platform. What primary function will this platform serve for them?
Aggregating and analyzing logs to provide security insight and alerts
Encrypting endpoint drives to protect data at rest
Hosting user directories and group policies
Providing VPN tunnels for remote workers
Justice is using UEBA tools in his organization. These tools focus on which capability?
Detecting anomalies by analyzing behavioral baselines of users and entities
Blocking malicious domains at the network edge
Issuing and revoking digital certificates
Enforcing multi-factor prompts during login
While working remotely, Nkay wants to ensure that his internet connection is secure when accessing sensitive company data. What is a VPN primarily used for in secure connectivity?
Creating an encrypted connection over public networks
Providing centralized identity management for enterprises
Monitoring file integrity on critical systems
Analyzing logs for threat correlation
In the DevSecure scenario, which security control category directly restricts who can access proprietary code and when, thereby preventing after-hours misuse?
Detective controls such as log reviews to find suspicious access
Preventive controls like RBAC and MFA to enforce least privilege
Corrective controls that restore systems after incidents
Operational controls like awareness campaigns and coaching
A developer at DevSecure stole code due to personal grievances and sold it for money. Which combination best classifies the threat actor and motivation?
External activist; ideological belief
Insider with high capability; financial gain
Third-party contractor; accidental error
Script kiddie; curiosity
How does role-based access control (RBAC) reduce the risk posed by insider threats in the DevSecure case?
By encrypting all files with public keys to prevent reading them
By limiting developer permissions to only the repositories needed for their role
By anonymizing user identities in logs to protect privacy
By replacing passwords with biometric-only access
Which auditing and logging practice would most effectively surface the after-hours unauthorized access seen at DevSecure?
Only retaining daily summaries to reduce storage
Logging file access and downloads from sensitive repositories with alerts for late-night activity
Disabling logs on source code servers to improve performance
Relying on manual weekly reviews without automated triggers
In the DevSecure scenario, which statement best explains how encryption could have protected the stolen proprietary code?
Encrypting the code would make it unreadable without decryption keys that are tightly controlled and monitored
Encryption primarily protects against malware and would not affect code readability
Encrypting only network traffic would fully prevent insider exfiltration
Encryption replaces the need for access controls by itself
Which combination of technologies and processes would have improved DevSecure’s speed of detection and response to the insider activity?
CSIRT with a defined incident response plan, SIEM alerts for unauthorized behavior, and UBA for anomaly detection
Daily team stand-ups and retrospective meetings without monitoring tools
Quarterly manual audits and passive logging with no alerting
Firewall rule changes only, without internal monitoring
Which training initiative most directly addresses preventing insider threats at DevSecure?
Generic office safety training
Insider threat awareness, acceptable use policy education, secure coding, and regular simulations including phishing tests
Advanced cryptography math workshops for non-technical staff
Time management seminars for developers
Refer to the incident response process diagram. Which phase typically comes first when establishing readiness before any security event occurs?
Detection
Preparation
Containment
Recovery
In the incident response lifecycle, which phase focuses on stopping the spread of an active threat to limit damage?
Eradication
Containment
Lessons Learned
Analysis
According to the incident response phases shown, which step occurs after containment and before recovery?
Analysis
Eradication
Preparation
Lessons Learned
In the cyber kill chain diagram, which stage involves pairing a delivered exploit with a payload prior to sending it to the target?
Reconnaissance
Weaponization
Installation
Command & Control
Within the kill chain, which stage is responsible for establishing a persistent channel so the attacker can issue instructions to compromised systems?
Exploitation
Delivery
Command & Control (C2)
Actions on Objectives
Look at the kill chain stages. After delivery succeeds, which stage most directly represents the exploit actually running to take advantage of a vulnerability?
Exploitation
Installation
Reconnaissance
Lessons Learned
Consider both diagrams. Which pairing correctly matches an incident response phase to the kill chain stage it is most likely to counter first?
Recovery countering Reconnaissance
Preparation countering Delivery
Analysis countering Actions on Objectives
Lessons Learned countering Weaponization
DoK 1 — Which option lists an industry standard specifically associated with payment card data security?
ISO/IEC 27002
PCI DSS
FIPS 199
ISO/IEC 27018
DoK 2 — An organization is updating its internal rules to govern how employees access systems, respond to incidents, and handle changes to production. Which combination of policies best addresses these needs?
Acceptable Use Policy (AUP), Incident Response, Change Management
Recruitment, Termination, Operations
ISO/IEC 27001, NIST SP 800-63, PCI DSS
Business Continuity only
DoK 3 — A company moving to cloud services wants to formalize privacy controls for personal data while aligning its overall information security management system. Which pair of standards provides the most appropriate match?
ISO/IEC 27018 and ISO/IEC 27001
PCI DSS and FIPS 140-3
NIST SP 800-63 and ISO/IEC 27002
COOP and SDLC
What is the primary purpose of a firewall in network security?
To manage user access permissions
To monitor and control incoming and outgoing network traffic
To perform regular backups of data
To encrypt data in transit
Which of the following best describes a DDoS attack?
An attempt to make a service unavailable by overwhelming it with traffic
A targeted attack on a specific user
A technique to steal sensitive information through phishing
A method to gain unauthorized access to a system
What does the principle of least privilege entail in access control?
Access should be granted based on seniority within the organization
All users should have the same level of access
Users should only have access to the resources necessary for their specific tasks
Users should have access to all resources to perform their jobs
