CompTIA Security + SY0-701 (V7) Exam Practice Test 2

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 29, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. An organization deliberately uses server hardware, operating systems, or cloud providers from more than one vendor, so that a single vendor's vulnerability or outage does not affect every system simultaneously. What resilience concept does this reflect?

Explanation

Platform diversity deliberately uses more than one vendor's hardware, operating system, or cloud provider, so that a single vendor's vulnerability or outage does not simultaneously affect every system in the environment, providing resilience against vendor-specific failure modes. Geographic dispersion instead addresses resilience against a localized physical disaster by spreading systems across different physical locations, which is a related but distinct resilience strategy from vendor diversity. Combining platform diversity with geographic dispersion provides resilience against a broader range of potential failure scenarios than relying on either strategy alone.

Submit
Please wait...
About This Quiz
CompTIA Security + Sy0-701 (V7) Exam Practice Test 2 - Quiz

This practice assessment focuses on the CompTIA Security + SY0-701 (V7) certification, evaluating essential skills in security concepts, risk management, and network protection. It's designed for learners preparing for the exam, helping to reinforce knowledge and identify areas for improvement. Engage with this resource to boost your confidence and readiness... see morefor the certification. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Before an authorized penetration test begins its active phase, the tester gathers publicly available information about the target without directly interacting with or scanning the target's systems. What type of reconnaissance is this?

Explanation

Passive reconnaissance gathers publicly available information about a target without directly interacting with or scanning its systems, such as reviewing public records, social media, or DNS registration information, which carries essentially no risk of alerting the target to the upcoming assessment. Active reconnaissance instead directly interacts with the target's systems, such as through port scanning, which can potentially be detected by the target's own monitoring, unlike passive methods. Beginning with passive reconnaissance before moving to active techniques reflects a standard, methodical approach to penetration testing that maximizes information gathering while minimizing early detection risk.

Submit

3. A data privacy regulation grants individuals the ability to request that an organization delete their personal data under certain circumstances. What privacy concept does this represent?

Explanation

The right to be forgotten grants individuals the ability to request deletion of their personal data under certain circumstances, reflecting a privacy principle found in regulations like GDPR that gives data subjects meaningful control over their own information even after it has already been collected. Data sovereignty instead addresses which country's laws govern data based on where it is physically stored or processed, which is a related but distinct privacy and compliance concept from an individual's right to request deletion. Organizations operating in jurisdictions recognizing this right must have actual technical and process capability to locate and delete an individual's data upon a valid request, not just a policy stating they will.

Submit

4. Two organizations sign a document expressing mutual intent to collaborate without necessarily being a legally binding contract, and separately sign a formal agreement specifying exact deliverables, timeline, and payment terms for a specific project. Which two agreement types, respectively, does this describe?

Explanation

A memorandum of understanding expresses mutual intent to collaborate between parties, often without the same level of binding legal obligation as a full contract, serving more as a documented statement of shared understanding. A statement of work instead is a formal agreement specifying exact deliverables, timeline, and payment terms for a specific project, providing the detailed, enforceable structure needed to actually execute and be held accountable for a defined scope of work. Recognizing which type of agreement a given business relationship actually requires helps ensure the right level of formality and enforceability is applied to each specific arrangement.

Submit

5. A single security incident is expected to cause $50,000 in damage, and this type of incident is expected to occur twice per year on average. What is the annualized loss expectancy?

Explanation

Annualized loss expectancy is calculated by multiplying the single loss expectancy by the annualized rate of occurrence, which here is $50,000 multiplied by 2, equaling $100,000. This calculation combines the severity of a single occurrence with how frequently that type of incident is expected to happen, producing a single annualized figure that supports comparing the cost-effectiveness of different risk mitigation investments against the risk they address. Understanding this calculation is fundamental to quantitative risk analysis, since it translates an abstract risk into a concrete annual dollar figure that can be directly compared against the cost of a proposed control.

Submit

6. One document broadly states that all data must be encrypted, a second document specifies the exact encryption algorithm and minimum key length required, and a third document lists the exact step-by-step commands to configure that encryption. Which three governance document types, in order, does this describe?

Explanation

A policy broadly states a requirement, such as all data must be encrypted, without specifying exact technical parameters. A standard then specifies the exact technical parameters needed to satisfy that policy, such as the specific encryption algorithm and minimum key length required. A procedure finally lists the exact step-by-step commands or actions needed to actually implement that standard, providing the most granular, actionable level of the governance document hierarchy, from broad intent down to specific execution.

Submit

7. During a forensic investigation, every person who handles a piece of evidence, and exactly when and how they handled it, is meticulously documented to ensure the evidence remains legally admissible. This documented tracking process is called ____ of custody.

Explanation

Chain of custody documents every person who handles evidence, along with exactly when and how they handled it, ensuring the evidence remains legally admissible and its integrity cannot be credibly questioned later in any legal or disciplinary proceeding. Breaking the chain of custody, even through a simple documentation gap, can undermine confidence in evidence that might otherwise have been perfectly valid, which is why this process is treated with such strict procedural rigor throughout digital forensics. Maintaining proper chain of custody from the moment evidence is first acquired through its final analysis and storage is a foundational requirement for any forensic investigation that might eventually face legal scrutiny.

Submit

8. A user logs into a partner organization's application using credentials from their own home organization's identity provider, without needing a separate account at the partner organization. What identity concept does this represent?

Explanation

Federation allows a user to authenticate using credentials from their own home organization's identity provider to access a partner organization's application, without needing a separate account specifically created at that partner organization. This differs from simple single sign-on within one organization's own applications, since federation specifically spans trust relationships between separate organizations. Federation relies on standards like SAML or OAuth to establish the trust and communication needed between the home identity provider and the partner application accepting that identity assertion.

Submit

9. A firewall inspects traffic not just by port and protocol but also by application identity and user context, integrating intrusion prevention capability within the same device. What type of firewall is this?

Explanation

A next-generation firewall inspects traffic by application identity and user context, not just traditional port and protocol information, while also integrating intrusion prevention capability within the same device, providing much richer visibility and control than a traditional firewall. A traditional Layer 4 packet-filtering firewall instead only inspects traffic based on basic header information like source, destination, port, and protocol, without the deeper application-aware inspection an NGFW provides. Deploying an NGFW rather than a traditional firewall reflects the reality that modern threats often cannot be adequately identified or blocked using port and protocol information alone.

Submit

10. A security team notices a specific detection rule generates far too many alerts for benign, routine activity, so they adjust the rule's thresholds to reduce this noise while still catching genuinely suspicious activity. What activity does this represent?

Explanation

Alert tuning adjusts detection rule thresholds to reduce noise from benign, routine activity while still catching genuinely suspicious activity, which is an ongoing operational necessity since poorly tuned alerts can bury genuinely important signals under excessive low-value noise. Log aggregation instead centralizes log collection from many sources, which is a related but distinct activity from adjusting the specific thresholds that determine when an alert actually fires. Regularly revisiting and tuning alert rules, rather than leaving them static indefinitely, helps a security operations team maintain confidence that alerts genuinely warrant attention when they do fire.

Submit

11. A vulnerability is assigned a numerical score reflecting factors like how easily it can be exploited and how severe the impact would be, following a standardized industry scoring methodology. What is this scoring system called?

Explanation

CVSS assigns a standardized numerical score to a vulnerability reflecting factors like exploitability and severity of impact, providing a consistent, industry-standard basis for comparing and prioritizing vulnerabilities across different systems and sources. CVE instead is simply a standardized naming and identification system for publicly known vulnerabilities, without itself providing a severity score the way CVSS does. Using CVSS scores as one input into a broader prioritization process, alongside factors like exposure and environmental variables, produces a more realistic risk-based remediation priority than relying on the raw score alone.

Submit

12. Before purchasing new laptops, an organization follows a formal procurement process with defined approval steps, and separately maintains an ongoing inventory tracking exactly which employee each device is currently assigned to. Which two asset management activities, respectively, does this describe?

Explanation

Acquisition and procurement follows a formal process with defined approval steps before a purchase is made, ensuring new assets enter the organization through a controlled, accountable process rather than ad hoc purchasing. Monitoring and asset tracking instead maintains an ongoing inventory of exactly which employee or location each device is currently assigned to, providing continuous visibility long after the initial purchase. Both activities span different points in an asset's lifecycle, one controlling how assets enter the organization and the other tracking them throughout their operational life.

Submit

13. A company allows employees to use their own personal smartphones for work but requires a management profile to be installed to separate and secure corporate data. Which deployment model does this describe?

Explanation

Bring your own device allows employees to use their own personal smartphones for work, typically requiring a management profile to separate and secure corporate data without the organization owning the physical device itself. COPE instead provides company-owned devices that employees may also use personally, and CYOD lets employees choose from an approved list of company-owned devices, both of which differ from BYOD in that the organization owns the physical hardware. Each deployment model carries different tradeoffs between employee convenience, cost, and the organization's level of control over the device.

Submit

14. A company writes a policy requiring quarterly access reviews, and separately configures a firewall rule blocking a specific port. Which two control categories, respectively, do these represent?

Explanation

A managerial control involves administrative policy and oversight decisions, such as requiring quarterly access reviews, which governs process rather than directly implementing a technical mechanism. A technical control instead directly implements a technical mechanism, such as a firewall rule blocking a specific port, enforcing the security requirement through technology itself rather than through policy alone. Recognizing this distinction helps ensure a security program includes both the administrative oversight and the technical enforcement needed for genuinely effective control coverage.

Submit

15. An organization labels one dataset as available to the general public with no restrictions, and labels a separate dataset as accessible only to a small, specifically named group of individuals. Which two data classifications, respectively, does this describe?

Explanation

Public data classification indicates the data is available to the general public with no restrictions, representing the lowest sensitivity level in a typical data classification scheme. Restricted classification instead indicates access is limited to a small, specifically named group of individuals, representing a much higher sensitivity level requiring more stringent access controls. Applying a consistent data classification scheme across an organization ensures appropriate protections are applied based on actual sensitivity, rather than either over-protecting low-sensitivity data or under-protecting genuinely restricted information.

Submit

16. A security appliance is configured so that if it experiences a failure, all traffic is blocked by default rather than allowed to pass through unchecked. What failure mode does this represent?

Explanation

Fail-closed configures a security appliance to block all traffic by default if it experiences a failure, prioritizing security over availability, since no traffic is permitted to pass through unchecked even during a device malfunction. Fail-open instead does the opposite, allowing traffic to pass through unchecked if the device fails, prioritizing availability over security, which might be appropriate for a less critical monitoring device but is generally undesirable for an actively protective control. Choosing between fail-open and fail-closed for a given security appliance depends on which risk, an availability outage or an unprotected traffic window, the organization considers more acceptable for that specific device's role.

Submit

17. An application is broken into many small, independently deployable services that each handle a specific function and communicate over well-defined APIs, rather than existing as one large monolithic codebase. What architecture pattern is this?

Explanation

Microservices break an application into many small, independently deployable services that each handle a specific function, communicating over well-defined APIs, which differs from a monolithic architecture where all functionality exists within a single large, tightly coupled codebase. Serverless architecture instead specifically means the underlying compute infrastructure is fully abstracted away and managed by the provider, which is a related but distinct architectural concept from how an application's functionality is decomposed into services. Microservices architectures can offer security benefits like smaller individual attack surfaces per service, but also introduce new considerations like securing the many inter-service API calls that a monolithic application would not have needed.

Submit

18. An attacker sends small requests to a third-party server using a spoofed source address, causing that server to send much larger responses to the actual target, and separately exploits a protocol where responses are naturally much larger than requests. Which two DDoS attack characteristics does this combination describe?

Explanation

A reflected attack sends requests with a spoofed source address, causing the third-party server's responses to be sent to the actual target rather than back to the attacker, hiding the attacker's true origin while directing traffic at the victim. An amplified attack additionally exploits a protocol where responses are naturally much larger than the requests that triggered them, multiplying the volume of traffic that ultimately reaches the target relative to what the attacker had to send. Combining both techniques, as many real-world DDoS attacks do, allows a relatively small amount of attacker-originated traffic to generate an overwhelming flood directed at the victim.

Submit

19. A database service account is granted only read access to the specific tables its application needs, rather than broader administrative access across the entire database. What mitigation technique does this reflect?

Explanation

Least privilege grants an account only the minimum access necessary to perform its required function, which matches granting a service account read-only access to specific tables rather than broader administrative access it does not actually need. Segmentation instead isolates network zones from each other, and isolation more broadly separates systems or processes, both of which address a different scope of protection than restricting what a single account is specifically permitted to do. Applying least privilege consistently significantly limits the potential damage if that specific account's credentials are ever compromised, since an attacker using them would be constrained to the same limited access.

Submit

20. A server that normally only generates log entries during business hours suddenly shows a burst of log activity at 3 AM, well outside its typical pattern. What indicator does this represent?

Explanation

Out-of-cycle logging flags log activity occurring at unusual times relative to a system's established normal pattern, such as a burst of activity at 3 AM on a server that typically only logs during business hours, which can indicate unauthorized activity happening outside normal operational windows. Missing logs instead indicates an absence of expected log entries, which is the opposite indicator, potentially suggesting an attacker has tampered with or disabled logging to cover their tracks. Recognizing out-of-cycle logging as a distinct indicator, separate from the log content itself, adds a valuable timing-based signal that content analysis alone might miss.

Submit

21. An attacker sends more data to a program's input buffer than it was designed to hold, overwriting adjacent memory, and separately injects malicious code directly into a running process's memory space. Which two vulnerability types, respectively, does this describe?

Explanation

A buffer overflow occurs when a program receives more data than its input buffer was designed to hold, causing the excess data to overwrite adjacent memory, potentially corrupting program execution or enabling malicious code execution. Memory injection instead directly injects malicious code into a running process's memory space, which is a related but distinct technique from overflowing an existing buffer's capacity. Both vulnerability types can ultimately lead to arbitrary code execution, but they exploit different underlying mechanisms, which is why defenses like input validation and memory protection features each address a different piece of this broader vulnerability category.

Submit

22. An attacker compromises a website that employees of a specific target organization are known to frequently visit, planting malware that infects visitors from that organization. What threat vector does this describe?

Explanation

A watering hole attack compromises a website that the target's employees are known to frequently visit, planting malware there to infect visitors, which is an indirect approach compared to directly targeting the organization's own systems or sending phishing emails. Typosquatting instead registers domains with common misspellings of a legitimate site, hoping users mistype a URL, which is a different mechanism from compromising a genuinely legitimate, frequently visited site. Watering hole attacks can be especially effective against well-defended organizations, since they exploit trust in a third-party site rather than needing to breach the target's own defenses directly.

Submit

23. A frustrated employee with legitimate system access deliberately deletes critical files before resigning from the company. What threat actor category does this represent?

Explanation

An insider threat comes from someone who already has legitimate authorized access, such as an employee, and misuses that access for harmful purposes, which matches a frustrated employee deliberately deleting files using access they were already granted. This differs from external threat actors like nation-states or hacktivists, who must first gain unauthorized access before they can cause harm, unlike an insider who already possesses it. Insider threats can be particularly damaging precisely because existing access controls are often designed to keep unauthorized parties out, rather than to detect misuse by someone who already legitimately holds valid credentials.

Submit

24. Before implementing a significant change, the team documents the specific steps needed to reverse the change and restore the previous state if something goes wrong. This documented reversal procedure is called a ____ plan.

Explanation

A backout plan documents the specific steps needed to reverse a change and restore the previous working state if something goes wrong during implementation, providing a safety net that is explicitly part of sound change management practice. Without a backout plan prepared in advance, a team facing an unexpected problem during a change would need to improvise a recovery under pressure, which is both slower and riskier than following a pre-tested procedure. Requiring a documented backout plan as part of the change approval process helps ensure this safety net actually exists before a change is allowed to proceed.

Submit

25. A security team plants a fake credential in a location only an attacker exploring the network would find, configured to trigger an alert the moment it is used anywhere. What deception technology is this?

Explanation

A honeytoken is a fake piece of data, such as a credential, planted specifically to trigger an alert when used, providing an early warning specifically because no legitimate user would ever have a reason to use that particular fake credential. A honeypot instead is an entire decoy system designed to attract and study attacker behavior, and a honeyfile is a decoy file rather than a credential, both of which are related but distinct deception technologies from a honeytoken's specific credential-based tripwire approach. Honeytokens are particularly effective precisely because their use is such an unambiguous signal of unauthorized activity, unlike more generic anomaly-based detection that can produce false positives.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
An organization deliberately uses server hardware, operating systems,...
Before an authorized penetration test begins its active phase, the...
A data privacy regulation grants individuals the ability to request...
Two organizations sign a document expressing mutual intent to...
A single security incident is expected to cause $50,000 in damage, and...
One document broadly states that all data must be encrypted, a second...
During a forensic investigation, every person who handles a piece of...
A user logs into a partner organization's application using...
A firewall inspects traffic not just by port and protocol but also by...
A security team notices a specific detection rule generates far too...
A vulnerability is assigned a numerical score reflecting factors like...
Before purchasing new laptops, an organization follows a formal...
A company allows employees to use their own personal smartphones for...
A company writes a policy requiring quarterly access reviews, and...
An organization labels one dataset as available to the general public...
A security appliance is configured so that if it experiences a...
An application is broken into many small, independently deployable...
An attacker sends small requests to a third-party server using a...
A database service account is granted only read access to the specific...
A server that normally only generates log entries during business...
An attacker sends more data to a program's input buffer than it was...
An attacker compromises a website that employees of a specific target...
A frustrated employee with legitimate system access deliberately...
Before implementing a significant change, the team documents the...
A security team plants a fake credential in a location only an...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!