CompTIA Security + SY0-701 (V7) Exam Practice Test 1

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 29, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. An organization maintains a fully equipped, continuously running backup facility with real-time data replication, ready to take over operations almost immediately if the primary site fails. What type of site is this?

Explanation

A hot site is fully equipped and continuously running with real-time data replication, allowing it to take over operations almost immediately if the primary site fails, representing the fastest but also most expensive disaster recovery site option. A cold site instead provides only basic infrastructure with no active systems or current data, requiring significant time and effort to become operational, which is a much slower but less costly alternative. A warm site falls between these two extremes, offering partially configured systems and periodically updated data, providing a middle ground between recovery speed and ongoing cost.

Submit
Please wait...
About This Quiz
CompTIA Security + Sy0-701 (V7) Exam Practice Test 1 - Quiz

This practice assessment focuses on key concepts for the CompTIA Security + SY0-701 certification. It evaluates your understanding of essential cybersecurity principles, risk management, and network security. This resource is invaluable for those preparing for the certification exam, ensuring you grasp critical topics necessary for success in the field.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A penetration tester is given full access to network diagrams, source code, and system credentials before beginning the engagement, rather than starting with no prior information about the target. What type of testing environment does this represent?

Explanation

A known environment penetration test gives the tester full access to network diagrams, source code, and system credentials beforehand, which allows for a deeper, more thorough assessment since the tester does not need to spend time on reconnaissance to discover this information themselves. An unknown environment test instead gives the tester no prior information at all, more closely simulating a genuine external attacker's starting position, though it may not achieve the same depth of coverage within a limited testing timeframe. A partially known environment falls between these two extremes, providing some but not complete information, which is a common practical compromise balancing realism against thoroughness.

Submit

3. A regulatory violation results in the organization losing its license to operate in a specific market, and separately results in significant negative press coverage damaging public trust. Which two consequences of non-compliance, respectively, does this describe?

Explanation

Loss of license specifically results in the organization losing its legal ability to operate in a given market or industry, which is one of the most severe possible consequences of non-compliance, since it can halt business operations entirely. Reputational damage instead results from negative public perception, such as press coverage, which can persist and affect customer trust well beyond any immediate financial or regulatory penalty. Recognizing that non-compliance carries multiple distinct consequence categories, not just financial fines, helps build a more complete business case for genuinely prioritizing compliance rather than treating it as merely a checkbox exercise.

Submit

4. A contract with a vendor includes a provision allowing the organization to conduct its own independent security assessment of the vendor's environment at any time during the engagement. What contractual element is this?

Explanation

A right-to-audit clause specifically grants the organization the contractual ability to conduct its own independent security assessment of a vendor's environment, providing ongoing verification rather than relying solely on the vendor's own self-reported assurances. A non-disclosure agreement instead protects confidential information shared between the parties, which is a different contractual concern from the ability to independently verify a vendor's security posture. Including a right-to-audit clause in vendor contracts reflects a proactive approach to third-party risk management, rather than trusting vendor security claims without any means of independent verification.

Submit

5. A risk management document tracks each identified risk's assigned owner, a specific threshold that would trigger further action, and key indicators used to monitor the risk over time. What is this document called?

Explanation

A risk register tracks each identified risk along with its assigned owner, a defined risk threshold that would trigger further action, and key risk indicators used to monitor that specific risk over time, serving as the central living record for an organization's risk management program. A business impact analysis instead focuses specifically on understanding the operational impact of a disruption, including metrics like RTO and RPO, which is a related but distinct risk management artifact from the broader risk register. Maintaining an accurate, actively used risk register, rather than a document created once and then ignored, is central to genuinely managing risk rather than merely documenting it.

Submit

6. An organization designates a specific role responsible for the day-to-day handling and technical protection of data, distinct from the role that decides how and why that data may be used. Which role is being described?

Explanation

The data custodian, or steward, is responsible for the day-to-day handling and technical protection of data, such as applying appropriate access controls and backups, which is a distinct role from the data owner or controller who decides how and why the data may be used in the first place. This division of responsibility ensures that someone with genuine day-to-day technical expertise is accountable for a dataset's practical protection, separate from the higher-level strategic decisions about its use. Clearly defining these roles helps avoid a situation where everyone assumes someone else is responsible for a specific data protection task.

Submit

7. During an investigation, an analyst reviews a complete record of raw network traffic captured at a specific point in time, allowing detailed reconstruction of exactly what data was exchanged. This data source is called a packet ____.

Explanation

A packet capture records raw network traffic at a specific point, allowing an analyst to reconstruct in detail exactly what data was exchanged between systems, which provides far more granular insight than summary logs alone can offer. This level of detail makes packet captures especially valuable for investigating sophisticated attacks where summary logs might not reveal the full content or context of suspicious traffic. Because packet captures can be very large and may contain sensitive data, they are typically retained selectively and handled with appropriate access controls during an investigation.

Submit

8. After containing and eradicating a security incident, a team works to restore affected systems to normal operation before finally documenting what was learned. Which two phases, in order, does this describe?

Explanation

Recovery restores affected systems to normal operation after containment and eradication have already addressed the immediate threat, and lessons learned follows afterward to document what was learned from the incident for future improvement. This sequence reflects the standard incident response process order, where recovery must occur before a team can step back and reflect on lessons learned, since the incident is not yet actually resolved during recovery itself. Skipping or rushing the lessons learned phase, even after a technically successful recovery, forfeits valuable insight that could improve the organization's response to a similar future incident.

Submit

9. An organization implements a technology that tells receiving mail servers what to do with messages claiming to be from the organization's domain but that fail SPF and DKIM authentication checks. What technology is this?

Explanation

DMARC builds on top of SPF and DKIM by telling receiving mail servers exactly what to do with messages that claim to be from the organization's domain but fail those underlying authentication checks, such as rejecting or quarantining them. This provides a stronger, more actionable email security posture than SPF or DKIM alone, since without DMARC's explicit policy instruction, receiving servers might simply deliver an unauthenticated message anyway despite a failed check. Implementing DMARC alongside SPF and DKIM is a foundational email security practice specifically aimed at reducing domain spoofing and business email compromise attacks.

Submit

10. A security team centralizes log correlation and alerting from firewalls, servers, and applications into a single platform that can detect patterns spanning multiple sources at once. What tool is this?

Explanation

A SIEM centralizes log correlation and alerting across many sources, such as firewalls, servers, and applications, allowing it to detect patterns spanning multiple sources that would be invisible if each log source were reviewed in isolation. A vulnerability scanner instead identifies weaknesses in systems, and DLP focuses specifically on preventing sensitive data from leaving the organization, both of which serve different, more specialized purposes than a SIEM's broad log correlation and alerting function. A well-tuned SIEM is often considered the central nervous system of a security operations center, since it is where disparate signals from across the environment actually come together for correlated analysis.

Submit

11. A vulnerability scan flags a system as vulnerable, but manual verification confirms the system is actually already patched and not vulnerable, and separately a different vulnerable system was never flagged by the scan at all. Which two confirmation outcomes, respectively, does this describe?

Explanation

A false positive occurs when a scan incorrectly flags a system as vulnerable when it is not actually vulnerable, wasting remediation effort investigating a non-issue. A false negative instead occurs when a scan fails to flag a system that actually is vulnerable, which is generally considered the more dangerous outcome, since the organization remains unaware of a genuine risk. Regularly reviewing both false positive and false negative rates helps a security team assess and improve the actual reliability of its vulnerability scanning tools and processes over time.

Submit

12. Before disposing of old hard drives, an organization uses a certified process to ensure all data is irrecoverably destroyed, and retains documentation proving this was done correctly. What asset management activity does this represent?

Explanation

Disposal and decommissioning includes sanitization, ensuring data is irrecoverably destroyed before a device leaves the organization's control, and certification, retaining documentation proving this was done correctly, which is essential for both security and regulatory compliance purposes. This differs from acquisition or procurement, which instead addresses how assets enter the organization, occurring at the opposite end of the asset lifecycle from disposal. Maintaining proper certification documentation for sanitized devices provides an auditable record that can be critical evidence if a data breach is ever alleged to have originated from improperly disposed hardware.

Submit

13. A security team defines a standard, hardened configuration that every new server must be deployed with, then periodically checks existing servers against that same standard to catch configuration drift. What practice does this represent?

Explanation

Secure baselines establish a standard, hardened configuration that servers are deployed with, and then that same baseline is maintained over time by periodically checking existing servers for configuration drift away from the established standard. Sandboxing instead isolates a program's execution environment to contain potentially malicious behavior, which is a different security technique from defining and maintaining a configuration standard. Establishing secure baselines and then actively maintaining them, rather than only defining them once, is what actually prevents gradual configuration drift from silently eroding an organization's security posture over time.

Submit

14. A legacy application cannot be patched against a known vulnerability, so the security team instead adds extra network monitoring and restricts access to only two authorized administrators. What type of control does this represent?

Explanation

A compensating control addresses the risk posed by a vulnerability without directly fixing the underlying flaw itself, which is exactly what added monitoring and restricted access accomplish when the legacy application cannot actually be patched. A preventive control instead aims to stop an incident before it occurs through direct means, and a corrective control acts after an incident to restore normal operations, both of which are different control types from a compensating control's indirect risk-reduction approach. Recognizing when a compensating control is genuinely needed, rather than assuming every vulnerability can simply be patched away, reflects a practical understanding of real-world constraints in security operations.

Submit

15. A database encrypts records stored on disk, and separately encrypts the connection used to transmit query results to an application server. Which two data states, respectively, do these two protections address?

Explanation

Data at rest refers to data stored on a persistent medium, such as records stored on disk, which encryption at that layer directly protects against unauthorized access if the storage medium itself is ever compromised or stolen. Data in transit instead refers to data actively moving across a network connection, such as query results being transmitted to an application server, which requires a different protection mechanism like TLS to secure the connection itself. Recognizing that data requires different protection mechanisms depending on its current state is foundational to designing a comprehensive data protection strategy that does not leave any single state unprotected.

Submit

16. Administrators must connect through a single, tightly monitored intermediary server before reaching any production system, rather than connecting directly from their own workstations. What network appliance does this describe?

Explanation

A jump server serves as a single, tightly monitored intermediary that administrators must pass through before reaching production systems, rather than connecting directly from their own workstations, which centralizes logging and access control onto one well-secured chokepoint. A load balancer instead distributes incoming traffic across multiple servers for performance and availability, which is a different function entirely from providing a secure administrative access chokepoint. Requiring all administrative access to route through a jump server significantly reduces the direct exposure of production systems to potentially compromised administrator workstations.

Submit

17. A highly sensitive system is physically disconnected from any other network, with no wired or wireless connection whatsoever, to eliminate any possibility of remote network-based attack. What architecture concept does this represent?

Explanation

Physical isolation, specifically an air-gapped configuration, physically disconnects a system from any other network entirely, eliminating any possibility of a remote network-based attack reaching it, which is reserved for the most sensitive systems where this level of isolation is justified by the risk. Logical segmentation instead still maintains network connectivity but restricts traffic flow through rules like firewalls or VLANs, which is a weaker isolation guarantee than true physical air-gapping. Air-gapping is not without operational tradeoffs, since legitimate data transfer to and from an air-gapped system typically requires manual processes like removable media, which introduces its own distinct security considerations.

Submit

18. A well-funded nation-state group conducts a highly sophisticated, long-term campaign against a target, while an unskilled attacker uses a basic, publicly available tool with minimal technical understanding. Which two attributes distinguish these two threat actors?

Explanation

Resources and funding distinguish a well-funded nation-state group, which can sustain long-term, well-resourced campaigns, from an unskilled attacker with minimal financial or technical backing. Level of sophistication and capability similarly distinguishes the nation-state's advanced, long-term campaign from the unskilled attacker's basic, publicly available tooling and minimal technical understanding. Recognizing these attribute differences helps a security team calibrate its defenses appropriately, since the controls needed to deter an unskilled opportunistic attacker differ significantly from those needed to meaningfully slow a well-resourced, sophisticated nation-state campaign.

Submit

19. A security team configures endpoints to only permit a specific, pre-approved set of applications to run, blocking anything not explicitly included on that list. What mitigation technique does this represent?

Explanation

An application allow list only permits a specific, pre-approved set of applications to run, blocking anything not explicitly included, which is a strong preventive mitigation against unauthorized or malicious software since only known-good applications are permitted by default. This differs from segmentation, which instead isolates network zones from each other, addressing a different attack surface than controlling exactly which applications can execute on an endpoint. Allow listing requires more upfront maintenance than a simpler block list approach, since every legitimate application must be explicitly approved, but it provides significantly stronger protection against unknown or novel malicious software.

Submit

20. A user's account shows a successful login from New York, followed by another successful login from Singapore just twenty minutes later. What indicator of malicious activity does this represent?

Explanation

Impossible travel flags logins from geographically distant locations within a timeframe that would be physically impossible to travel between, such as New York and Singapore twenty minutes apart, strongly suggesting the account credentials are being used from two different locations simultaneously, likely indicating compromise. Concurrent session usage instead flags simultaneous active sessions without necessarily analyzing geographic feasibility, which is a related but distinct indicator. Many identity providers now automatically flag impossible travel patterns, since this specific indicator is both highly reliable and relatively easy to calculate from login timestamp and location data alone.

Submit

21. A vulnerability exists where a program checks whether a file is safe to use, but between that check and the actual use of the file, an attacker replaces it with a malicious version. Which two terms describe the two specific points in this race condition?

Explanation

Time-of-check refers to the moment a program verifies a condition, such as a file's safety, while time-of-use refers to the later moment the program actually acts on that condition, such as using the file. A race condition vulnerability exploits the gap between these two moments, allowing an attacker to swap in a malicious file after the check has already passed but before the file is actually used. Understanding this TOC/TOU gap is essential for recognizing why certain checks must be performed atomically, with no window for external interference, to be genuinely secure.

Submit

22. An attacker impersonates a company's CEO in an email to the finance department, urgently requesting an unusual wire transfer. What threat vector does this represent?

Explanation

Business email compromise involves an attacker impersonating a trusted figure, such as a CEO, typically through a spoofed or compromised email account, to manipulate an employee into taking a harmful action like an unauthorized wire transfer. A watering hole attack instead compromises a website the target is likely to visit, and typosquatting registers domains with common misspellings, both of which are different attack techniques from directly impersonating an executive in an email. Business email compromise attacks often succeed specifically because they exploit urgency and authority, making user awareness training around this specific tactic particularly valuable.

Submit

23. An employee sets up an unauthorized cloud storage account to share files with colleagues, entirely outside of any IT department approval or visibility. What does this represent?

Explanation

Shadow IT refers to technology, such as an unauthorized cloud storage account, that is used within an organization entirely outside official IT department approval or visibility, which creates security risk since the organization has no ability to monitor, secure, or ensure compliance for that unmanaged resource. This differs from a nation-state actor or organized crime group, both of which are external threat actors with malicious intent, rather than an internal employee's well-intentioned but unauthorized workaround. Shadow IT often emerges when official IT-approved tools are perceived as too slow or restrictive, which is why addressing the underlying friction, not just blocking the workaround, is often part of an effective long-term response.

Submit

24. A weak password is run through a deliberately slow, computationally expensive algorithm multiple times before being stored, making brute-force attacks against the stored value significantly more difficult. This technique is called key ____.

Explanation

Key stretching deliberately runs a password or key through a slow, computationally expensive algorithm multiple times, which significantly increases the time and resources required for a brute-force attack against the stored value, even if the original password itself was relatively weak. This differs from simple hashing alone, which by itself can still be attacked relatively quickly with modern hardware unless deliberately slowed down through stretching. Algorithms like PBKDF2 are specifically designed to implement key stretching for exactly this purpose, making them a standard choice for securely storing password-derived values.

Submit

25. In a Zero Trust architecture, a specific component sits directly in the path of a connection request and actually enforces the decision to allow or deny access made elsewhere. What is this component called?

Explanation

The policy enforcement point sits directly in the path of a connection request and actually enforces the access decision, acting as the gatekeeper that allows or denies traffic based on a decision made elsewhere in the architecture. The policy engine instead evaluates policy and makes the actual access decision, and the policy administrator communicates that decision to the enforcement point, both of which are logically separate components from the enforcement point itself. Understanding this separation of decision-making from enforcement is fundamental to how Zero Trust architecture is actually structured across its control plane and data plane.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
An organization maintains a fully equipped, continuously running...
A penetration tester is given full access to network diagrams, source...
A regulatory violation results in the organization losing its license...
A contract with a vendor includes a provision allowing the...
A risk management document tracks each identified risk's assigned...
An organization designates a specific role responsible for the...
During an investigation, an analyst reviews a complete record of raw...
After containing and eradicating a security incident, a team works to...
An organization implements a technology that tells receiving mail...
A security team centralizes log correlation and alerting from...
A vulnerability scan flags a system as vulnerable, but manual...
Before disposing of old hard drives, an organization uses a certified...
A security team defines a standard, hardened configuration that every...
A legacy application cannot be patched against a known vulnerability,...
A database encrypts records stored on disk, and separately encrypts...
Administrators must connect through a single, tightly monitored...
A highly sensitive system is physically disconnected from any other...
A well-funded nation-state group conducts a highly sophisticated,...
A security team configures endpoints to only permit a specific,...
A user's account shows a successful login from New York, followed by...
A vulnerability exists where a program checks whether a file is safe...
An attacker impersonates a company's CEO in an email to the finance...
An employee sets up an unauthorized cloud storage account to share...
A weak password is run through a deliberately slow, computationally...
In a Zero Trust architecture, a specific component sits directly in...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!