wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CompTIA Security+ SY0-701 Exam Practice

Total questions: 70

Worksheet time: 35mins

Name
Class
Date
1.

In a corporate office, Kgomotso is responsible for overseeing the information system. Which statement best describes a managerial control in information security that Kgomotso should implement?

a)

Oversight of the information system, such as risk identification or selecting security controls

b)

Physical barriers like locks and lighting placed to protect hardware

c)

A mechanism that ensures a user is who they claim to be

d)

Two interlocking doors that permit only one individual to pass at a time

2.

Physical control is best illustrated by which example?

a)

A policy describing how access restrictions are enforced based on user context

b)

Security measure regulating entry to a secure area using two interlocking doors

c)

A log that records attempted intrusions

d)

Stakeholder meetings to approve changes before implementation

3.

Aya and LJ are security officers at a large corporate office. They are discussing the various types of security controls in place. Aya asks, "What is the primary purpose of a detective control?"

a)

Psychologically discourage an attacker from attempting an intrusion

b)

Identify and record an attempted or successful intrusion

c)

Grant access on a need-to-know basis

d)

Define how to enforce access restrictions

4.

In a school, a deterrent control is best characterized as a control that:

a)

May not physically or logically prevent access but discourages attempts

b)

Gives oversight of the information system for selecting controls

c)

Ensures consensus and authorization before changes

d)

Regulates entry using an access control vestibule

5.

During a school event, Phenyo is responsible for ensuring that all attendees are legitimate. Identification control primarily aims to:

a)

Ensure that customers are legitimate

b)

Detect and record intrusions after they occur

c)

Deter and detect access using physical devices

d)

Complicate changes across dependent services

6.

In a corporate office, Aya is responsible for managing access to sensitive information. She implements policy-driven access control to ensure that employees can only access data on a need-to-know basis. This approach is most closely associated with which idea?

a)

Access on a need-to-know, task-limited basis

b)

Describing how to enforce restrictions by identity, device posture, and context

c)

Involving relevant stakeholders to ensure consensus and authorization before change

d)

Using alarms and cameras to deter intruders

7.

In a busy office, Nkay and Chloe are discussing how to improve security. They consider implementing a system where two doors interlock to allow only one individual through at a time. Which description best matches this approach to threat scope reduction?

a)

Two doors that interlock to allow only one individual through at a time

b)

Complicated change effects because a service restart in one area may significantly impact another

c)

Granting network access only to resources needed for a specific task

d)

Maintaining records of attempted intrusions

8.

In a high-security building, Aya and Justice are trying to enter a restricted area. They encounter an access control vestibule that has two interlocking doors, allowing only one of them to enter at a time. What is this access control vestibule?

a)

A process requiring management sign-off before changes

b)

A security measure with two interlocking doors permitting one individual at a time

c)

A document specifying how access is enforced by identity and context

d)

A log that identifies and records intrusions

9.

In a corporate office, Chloe and Alejandra are discussing the approval process for accessing sensitive data. Which statement best represents this approval process in security governance?

a)

Access granted on a need-to-know basis for a specific task

b)

Involving stakeholders like management and IT to ensure consensus and authorization before changes

c)

A psychological barrier that discourages intrusions

d)

A set of physical controls such as locks and lighting

10.

In the context of access control, dependencies primarily:

a)

Describe how access restrictions are enforced based on user identity and context

b)

Provide oversight of the information system through risk evaluation

c)

Complicate changes because a restart in one area can significantly affect another

d)

Grant access only to the minimum resources needed

11.

In a recent news article, Aya read about a group of individuals who launched a campaign to expose government corruption through online protests and website defacements. Which statement best describes these individuals in the context of threat actors?

a)

They are internal threat actors operating from within an organization.

b)

They are motivated by social or political causes and are typically external.

c)

They are exclusively nation-state actors sponsored by governments.

d)

They are only interested in financial gain and ransomware.

12.

Chloe and Kgomotso are discussing different types of cryptography in their computer science class. Kgomotso mentions that public key encryption is a method used for secure communication. Chloe asks, 'Public key encryption is classified as which type of cryptography?'

a)

Symmetric

b)

Asymmetric

c)

Hash-based

d)

Quantum-only

13.

During a high-security event, Sagrys needs to access a restricted area. To gain entry, he must use a password, his fingerprint, and a smart card. Together, these elements represent which authentication category?

a)

Single-factor authentication

b)

Two-factor authentication

c)

Three-factor authentication

d)

Biometric-only authentication

14.

In a network setup at Phenyo's school, they are considering implementing a transparent firewall. Which is true of a transparent firewall in terms of network addressing?

a)

It always requires readdressing IPs.

b)

It never inspects traffic at Layer 2.

c)

It does not require readdressing IPs.

d)

It must use NAT on all interfaces.

15.

During a recent class project, Phenyo and Nkay were discussing the best practices for backup media connectivity. Phenyo suggested that they should always keep backup media connected for faster restores, while Nkay argued that it is better to keep backup media offline or disconnected except during backup/restore. What is the recommended practice for backup media connectivity?

a)

Always keep backup media connected for faster restores.

b)

Keep backup media offline or disconnected except during backup/restore.

c)

Connect backup media only to internet-facing servers.

d)

Encrypting backups removes the need to disconnect media.

16.

Justice is a cybersecurity analyst who is assessing the severity of vulnerabilities in a software application. He learns about the Common Vulnerability Scoring System (CVSS) and needs to determine the valid score range for CVSS vulnerabilities. What is the valid score range for CVSS vulnerabilities?

a)

0 to 10

b)

0 to 100

c)

1 to 5

d)

1 to 10, with decimals not allowed

17.

While traveling, LJ and Chloe come across a public charging station. They wonder about the safety of using the chargers available there. Which statement about malicious USB chargers and mobile devices is correct?

a)

They cannot compromise a device because charging ports block data.

b)

They can compromise a device via malicious components or data lines.

c)

They only affect laptops, not smartphones or tablets.

d)

They are safe if the device uses a PIN.

18.

Chloe and LJ are discussing internet security protocols. Chloe asks, 'TLS is related to SSL in which way?' What do you think she means?

a)

TLS is an older protocol that SSL replaced.

b)

TLS is the successor to SSL and provides encrypted communications.

c)

TLS is unrelated to SSL and used only for email.

d)

TLS removes the need for certificates.

19.

During a cybersecurity training session, Phenyo asks, "What is a primary function of SIEM systems?"

a)

Configure network devices automatically

b)

Collect and analyse security event logs

c)

Encrypt all traffic at the perimeter

d)

Replace endpoint antivirus software

20.

During a team meeting at a tech company, Phenyo raised a concern about the importance of security awareness training. He asked, when should this training occur?

a)

Only during onboarding for new hires

b)

Only after a security incident occurs

c)

Continuously and not just during onboarding

d)

Only for administrators and security staff

21.

During a group project, Alejandra and her team members, including Kgomotso and Chloe, are using a shared online document to collaborate. How does accounting (audit logging) support non-repudiation in their project?

a)

By encrypting all files by default

b)

By recording user activities such as logins and file access, making actions traceable

c)

By blocking all failed login attempts

d)

By rotating passwords every week

22.

During a cybersecurity workshop, Kgomotso and Chloe learned about different types of online scams. Kgomotso asked, 'What distinguishes phishing from spear phishing?'

a)

Phishing targets executives only; spear phishing targets interns.

b)

Phishing targets large groups randomly; spear phishing targets specific individuals with personalised messages.

c)

Phishing uses phone calls; spear phishing uses emails only.

d)

Phishing is legal; spear phishing is illegal.

23.

In a company, Aya and Alejandra are assigned different roles. In Role-Based Access Control (RBAC), permissions are primarily assigned based on which factor?

a)

The user's seniority

b)

The user's role within the organisation

c)

The device used to log in

d)

Time since the last password change

24.

In a company, Aya is tasked with setting up a network security system. She decides to create a DMZ to enhance security. What best describes a DMZ in network security?

a)

A secure VPN tunnel for administrators only

b)

A network segment that hosts publicly accessible servers while isolating them from internal systems

c)

An encrypted storage area for backups

d)

A wireless guest network with no authentication

25.

During a class project, Aya was working on a virtual machine to develop a software application. She decided to take a snapshot of her VM before making significant changes. What is a snapshot in the context of virtual machines?

a)

A text log of VM events

b)

A saved state of a VM at a specific point in time, used for backup or rollback

c)

A screenshot of the VM desktop

d)

A performance benchmark file

26.

During a school project, Sagrys discovered that sensitive student data was being shared without proper authorization. What is the function of a Data Loss Prevention (DLP) system in this scenario?

a)

Detects malware at the endpoint only

b)

Detects and blocks sensitive data from being leaked or transferred inappropriately

c)

Optimises database queries

d)

Manages user roles and permissions

27.

Justice and Naledi are tasked with ensuring the security of their school's computer network. They need to establish a secure configuration baseline. What is this baseline used for?

a)

Defining standard secure settings to ensure consistent security across endpoints

b)

Allowing users to choose any settings they prefer

c)

Disabling patches to increase stability

d)

Testing performance under load

28.

In a tech-savvy company, LJ and Justice are discussing mobile deployment models. They wonder which models allow employees to choose their own devices for work. What do you think they should consider?

a)

COPE and COBO

b)

BYOD and CYOD

c)

CYOD only

d)

BYOD only works for laptops

29.

During a recent cybersecurity training session, Alejandra and her classmates learned about the importance of configuration management tools in maintaining system security. How do these tools assist vulnerability remediation?

a)

They disable firewalls to speed up updates.

b)

They ensure approved security settings are maintained across systems and allow quick rollback if unauthorised changes are made.

c)

They replace patch management entirely.

d)

They only inventory hardware models.

30.

During a team project, Kgomotso and Aya are discussing the implications of allowing USB tethering on their mobile devices while working in the corporate office. What is a risk they should consider?

a)

It reduces data usage costs.

b)

It can bypass network security controls and enable unmonitored internet access.

c)

It improves battery life of the device.

d)

It forces all traffic through the corporate proxy automatically.

31.

Choose the correct answer. During a recent compliance audit at their company, Naledi and Aya were tasked with identifying gaps in their adherence to the security framework. Which tool would they use to help with this task?

a)

Risk register

b)

SIEM

c)

Gap analysis

d)

Whitelist

32.

Choose the correct answer. One day, Sagrys received an email that looked like it was from his bank, asking him to click a link to verify his account. However, when he clicked the link, he was redirected to a fake website that looked identical to his bank's site. Which type of attack does this scenario illustrate?

a)

Whaling

b)

Pharming

c)

Spear phishing

d)

Tailgating

33.

Choose the correct answer. During a secure online meeting, Sagrys and Chloe are discussing the importance of encryption. Sagrys mentions that there is a protocol that uses asymmetric encryption during the handshake to ensure their conversation is secure. What protocol is he referring to?

a)

TLS

b)

SSH

c)

HTTP

d)

FTP

34.

In a company where Sagrys and Chloe work, they are implementing a new security model called Zero Trust. Choose the correct answer. Zero Trust assumes which of the following?

a)

External threats only

b)

All internal traffic is secure

c)

No inherent trust

d)

VPNs are unnecessary

35.

Choose the correct answer. In a recent project, Justice and Nkay were tasked with identifying critical assets and functions for their company's cybersecurity strategy. Which method should they use?

a)

Business impact analysis

b)

Penetration testing

c)

Threat modelling

d)

Risk register

36.

Choose the correct answer. During a cybersecurity workshop, Aya and Justice were discussing the functionalities of a SIEM system. Aya mentioned that it is primarily used for a specific purpose. What does a SIEM system primarily do?

a)

Host antivirus

b)

Analyse event logs

c)

Filter web content

d)

Conduct backups

37.

Choose the correct answer. During a team meeting, Chloe mentioned that the production line had been experiencing delays. To understand the underlying issues, Justice suggested using the Five Whys method. What is the Five Whys method used for?

a)

Mitigation

b)

Testing

c)

Root cause analysis

d)

Reporting

38.

Choose the correct answer. Alejandra works at a financial services company that accepts a certain level of cyber risk in exchange for expected growth. Which term best describes the level of risk the company is willing to accept?

a)

Risk tolerance

b)

Risk threshold

c)

Residual risk

d)

Risk appetite

39.

Choose the correct answer. During a cybersecurity workshop, LJ, Naledi, and Justice were discussing various compliance standards. Which of the following did they identify as a compliance standard?

a)

Nmap

b)

NIST

c)

PCI-DSS

d)

MD5

40.

Choose the correct answer. Aya runs an e-commerce site that must be back online within 4 hours to avoid major revenue loss. Which term refers to the maximum amount of time the system can be unavailable before it significantly impacts the business?

a)

MTTF

b)

RTO

c)

RPO

d)

SLA

41.

Naledi is working on a cybersecurity project and needs to ensure that the information she is protecting is secure. Which option correctly expands CIA in cybersecurity and captures its core purpose?

a)

Confidentiality, Integrity, Availability — foundational principles guiding protection of information

b)

Control, Inspection, Authorization — steps for approving user requests

c)

Confidentiality, Integrity, Anonymity — privacy goals for masking identities

d)

Compliance, Identification, Assurance — policy audit objectives

42.

During a cybersecurity workshop, Kgomotso learned about various security tools. One of the tools discussed was FIM, which is primarily used to perform which security function?

a)

Monitor file changes on critical system files to detect tampering

b)

Encrypt entire disks to prevent data theft if a device is stolen

c)

Manage digital certificates for web servers

d)

Segment networks to isolate sensitive subnets

43.

In enterprise security, Chloe is tasked with implementing a system to manage user identities and control access to sensitive information. Which description best aligns with the system she is implementing?

a)

Centralized system for managing user identities and controlling access

b)

Network protocol for encrypting traffic between routers

c)

Tool for detecting malware by scanning memory

d)

Method for hashing passwords before storage

44.

In a corporate environment, Justice is tasked with ensuring that all communications over the network are secure. He decides to implement a technology that will secure IP communications through encryption and related protections. What is the primary purpose of this technology in the organization’s network stack?

a)

Secure IP communications through encryption and related protections

b)

Provide directory services for user accounts and groups

c)

Aggregate event logs for correlation and alerting

d)

Analyze user behavior to detect anomalies

45.

In a company, Nkay is trying to understand how to access and modify the directory services for user accounts. He learns that LDAP is best described as which of the following?

a)

Lightweight Directory Access Protocol used for accessing and modifying directory services

b)

Logging framework for consolidating security events across hosts

c)

Key exchange protocol used by public-key cryptography

d)

Virtual tunneling method for remote connectivity

46.

Chloe is trying to access her online banking account. To enhance security, the bank requires what?

a)

Two or more verification factors to confirm identity

b)

A password that changes every 90 days

c)

A hardware token only, without passwords

d)

Biometric verification as the sole login method

47.

During a cybersecurity workshop, Sagrys and Alejandra were discussing the importance of securing online communications. Alejandra mentioned a system that helps manage digital certificates and supports public key encryption. Which option correctly defines this system?

a)

Public Key Infrastructure that manages digital certificates and supports public key encryption

b)

Packet Key Interchange used to rotate symmetric keys on routers

c)

Private Kernel Interface that isolates system processes

d)

Public Knowledge Index for cataloging security advisories

48.

Chloe's organization is looking to enhance its security measures. They are considering implementing a SIEM platform. What primary function will this platform serve for them?

a)

Aggregating and analyzing logs to provide security insight and alerts

b)

Encrypting endpoint drives to protect data at rest

c)

Hosting user directories and group policies

d)

Providing VPN tunnels for remote workers

49.

Justice is using UEBA tools in his organization. These tools focus on which capability?

a)

Detecting anomalies by analyzing behavioral baselines of users and entities

b)

Blocking malicious domains at the network edge

c)

Issuing and revoking digital certificates

d)

Enforcing multi-factor prompts during login

50.

While working remotely, Nkay wants to ensure that his internet connection is secure when accessing sensitive company data. What is a VPN primarily used for in secure connectivity?

a)

Creating an encrypted connection over public networks

b)

Providing centralized identity management for enterprises

c)

Monitoring file integrity on critical systems

d)

Analyzing logs for threat correlation

51.

In the DevSecure scenario, which security control category directly restricts who can access proprietary code and when, thereby preventing after-hours misuse?

a)

Detective controls such as log reviews to find suspicious access

b)

Preventive controls like RBAC and MFA to enforce least privilege

c)

Corrective controls that restore systems after incidents

d)

Operational controls like awareness campaigns and coaching

52.

A developer at DevSecure stole code due to personal grievances and sold it for money. Which combination best classifies the threat actor and motivation?

a)

External activist; ideological belief

b)

Insider with high capability; financial gain

c)

Third-party contractor; accidental error

d)

Script kiddie; curiosity

53.

How does role-based access control (RBAC) reduce the risk posed by insider threats in the DevSecure case?

a)

By encrypting all files with public keys to prevent reading them

b)

By limiting developer permissions to only the repositories needed for their role

c)

By anonymizing user identities in logs to protect privacy

d)

By replacing passwords with biometric-only access

54.

Which auditing and logging practice would most effectively surface the after-hours unauthorized access seen at DevSecure?

a)

Only retaining daily summaries to reduce storage

b)

Logging file access and downloads from sensitive repositories with alerts for late-night activity

c)

Disabling logs on source code servers to improve performance

d)

Relying on manual weekly reviews without automated triggers

55.

In the DevSecure scenario, which statement best explains how encryption could have protected the stolen proprietary code?

a)

Encrypting the code would make it unreadable without decryption keys that are tightly controlled and monitored

b)

Encryption primarily protects against malware and would not affect code readability

c)

Encrypting only network traffic would fully prevent insider exfiltration

d)

Encryption replaces the need for access controls by itself

56.

Which combination of technologies and processes would have improved DevSecure’s speed of detection and response to the insider activity?

a)

CSIRT with a defined incident response plan, SIEM alerts for unauthorized behavior, and UBA for anomaly detection

b)

Daily team stand-ups and retrospective meetings without monitoring tools

c)

Quarterly manual audits and passive logging with no alerting

d)

Firewall rule changes only, without internal monitoring

57.

Which training initiative most directly addresses preventing insider threats at DevSecure?

a)

Generic office safety training

b)

Insider threat awareness, acceptable use policy education, secure coding, and regular simulations including phishing tests

c)

Advanced cryptography math workshops for non-technical staff

d)

Time management seminars for developers

58.

Refer to the incident response process diagram. Which phase typically comes first when establishing readiness before any security event occurs?

a)

Detection

b)

Preparation

c)

Containment

d)

Recovery

59.

In the incident response lifecycle, which phase focuses on stopping the spread of an active threat to limit damage?

a)

Eradication

b)

Containment

c)

Lessons Learned

d)

Analysis

60.

According to the incident response phases shown, which step occurs after containment and before recovery?

a)

Analysis

b)

Eradication

c)

Preparation

d)

Lessons Learned

61.

In the cyber kill chain diagram, which stage involves pairing a delivered exploit with a payload prior to sending it to the target?

a)

Reconnaissance

b)

Weaponization

c)

Installation

d)

Command & Control

62.

Within the kill chain, which stage is responsible for establishing a persistent channel so the attacker can issue instructions to compromised systems?

a)

Exploitation

b)

Delivery

c)

Command & Control (C2)

d)

Actions on Objectives

63.

Look at the kill chain stages. After delivery succeeds, which stage most directly represents the exploit actually running to take advantage of a vulnerability?

a)

Exploitation

b)

Installation

c)

Reconnaissance

d)

Lessons Learned

64.

Consider both diagrams. Which pairing correctly matches an incident response phase to the kill chain stage it is most likely to counter first?

a)

Recovery countering Reconnaissance

b)

Preparation countering Delivery

c)

Analysis countering Actions on Objectives

d)

Lessons Learned countering Weaponization

65.

DoK 1 — Which option lists an industry standard specifically associated with payment card data security?

a)

ISO/IEC 27002

b)

PCI DSS

c)

FIPS 199

d)

ISO/IEC 27018

66.

DoK 2 — An organization is updating its internal rules to govern how employees access systems, respond to incidents, and handle changes to production. Which combination of policies best addresses these needs?

a)

Acceptable Use Policy (AUP), Incident Response, Change Management

b)

Recruitment, Termination, Operations

c)

ISO/IEC 27001, NIST SP 800-63, PCI DSS

d)

Business Continuity only

67.

DoK 3 — A company moving to cloud services wants to formalize privacy controls for personal data while aligning its overall information security management system. Which pair of standards provides the most appropriate match?

a)

ISO/IEC 27018 and ISO/IEC 27001

b)

PCI DSS and FIPS 140-3

c)

NIST SP 800-63 and ISO/IEC 27002

d)

COOP and SDLC

68.

What is the primary purpose of a firewall in network security?

a)

To manage user access permissions

b)

To monitor and control incoming and outgoing network traffic

c)

To perform regular backups of data

d)

To encrypt data in transit

69.

Which of the following best describes a DDoS attack?

a)

An attempt to make a service unavailable by overwhelming it with traffic

b)

A targeted attack on a specific user

c)

A technique to steal sensitive information through phishing

d)

A method to gain unauthorized access to a system

70.

What does the principle of least privilege entail in access control?

a)

Access should be granted based on seniority within the organization

b)

All users should have the same level of access

c)

Users should only have access to the resources necessary for their specific tasks

d)

Users should have access to all resources to perform their jobs