CompTIA Security + SY0-701 (V7) Exam Practice Test 3

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 29, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A team conducts a live failover test, actually shifting production traffic to a backup system to confirm the failover process genuinely works under real conditions, rather than only discussing the plan verbally. What testing method does this represent?

Explanation

A fail over test actually shifts production traffic to a backup system, confirming the failover process genuinely works under real conditions, which provides much stronger assurance than a tabletop exercise that only discusses the plan verbally without any live technical action. A tabletop exercise instead is discussion-based, walking through a scenario conversationally without actually executing any technical failover, making it a valuable but lower-fidelity complement to periodically conducting an actual live fail over test. Regularly conducting genuine fail over tests, rather than relying solely on tabletop discussions, is what actually validates that a disaster recovery plan will work as intended during a real event.

Submit
Please wait...
About This Quiz
CompTIA Security + Sy0-701 (V7) Exam Practice Test 3 - Quiz

This assessment focuses on the CompTIA Security + SY0-701 (V7) certification. It evaluates your understanding of key security concepts, risk management, and incident response strategies. Completing this assessment is essential for anyone preparing for the certification exam, as it reinforces critical knowledge and identifies areas for improvement.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. An external auditor issues a formal statement confirming that an organization's controls meet a specific required standard as of a given date. What compliance activity does this represent?

Explanation

An attestation is a formal statement, typically from an external auditor or authority, confirming that an organization's controls meet a specific required standard as of a given date, providing independent, documented assurance to stakeholders like customers or regulators. A self-assessment instead is conducted internally by the organization itself, which carries less independent credibility than an external attestation, since the organization is essentially grading its own work. Obtaining a formal attestation is often specifically required to satisfy customer contractual requirements or regulatory obligations that a purely internal self-assessment would not adequately satisfy.

Submit

3. Before entering a business relationship, an organization researches a partner's security practices and reputation, and separately, after the relationship begins, takes ongoing reasonable steps to maintain adequate security. Which two compliance concepts, respectively, does this describe?

Explanation

Due diligence involves researching a partner's practices and reputation before entering into a business relationship, representing the upfront investigative step taken prior to commitment. Due care instead involves the ongoing reasonable steps taken to maintain adequate security after the relationship has already begun, representing continuous responsible behavior rather than a one-time upfront check. Both concepts together support a defensible compliance posture, since demonstrating only upfront due diligence without ongoing due care, or vice versa, would leave a meaningful gap in an organization's overall risk management story.

Submit

4. Before engaging a new vendor, an organization reviews the vendor's own recent internal audit results, and separately commissions its own independent penetration test against the vendor's systems. Which two vendor assessment methods, respectively, does this describe?

Explanation

Reviewing evidence of internal audits relies on the vendor's own previously conducted internal audit results, which provides useful insight but ultimately depends on trusting the vendor's own self-reported assessment process. Commissioning an independent assessment, such as a penetration test conducted specifically for this evaluation, instead provides an objective, third-party-verified view of the vendor's actual security posture, rather than relying solely on the vendor's own internal reporting. Combining both methods provides a more complete picture of vendor risk than relying on either the vendor's self-reported audits or an independent assessment alone.

Submit

5. An organization explicitly states it is willing to accept significant risk in pursuit of aggressive growth opportunities, favoring bold moves over caution. Which risk appetite category does this reflect?

Explanation

An expansionary risk appetite explicitly favors accepting significant risk in pursuit of aggressive growth opportunities, reflecting an organizational culture that prioritizes bold moves over caution when weighing potential reward against potential downside. A conservative risk appetite instead favors minimizing risk exposure even at the cost of slower growth, representing essentially the opposite end of the risk appetite spectrum from expansionary. Explicitly documenting an organization's risk appetite category, rather than leaving it as an unstated assumption, helps ensure security and business decisions are made consistently with leadership's actual stated risk tolerance.

Submit

6. A multinational company must account for differing data protection laws depending on which country its customers reside in, adjusting its practices accordingly for each jurisdiction. What external governance consideration does this reflect?

Explanation

Legal and regional or national considerations reflect the reality that differing laws across jurisdictions require an organization to adjust its practices depending on where its customers or operations are located, rather than applying a single uniform policy worldwide regardless of local legal requirements. Internal committee structure instead addresses how governance decisions are made within the organization itself, which is a different concern from external legal variation across jurisdictions. Explicitly accounting for these external legal and regional considerations, rather than assuming one jurisdiction's rules apply everywhere, is essential governance awareness for any organization operating across multiple countries.

Submit

7. During an investigation, an analyst examines information about a file, such as its creation date, author, and modification history, rather than the file's actual content itself. This information about the data is called ____.

Explanation

Metadata provides information about data itself, such as a file's creation date, author, and modification history, rather than the file's actual content, which can reveal valuable investigative context even when the file's content alone would not. Metadata is often overlooked compared to more obvious data sources like log content, but it can reveal details like exactly when a document was actually created or last modified, which might contradict a suspect's claimed timeline. Properly preserving metadata during evidence collection, rather than allowing it to be inadvertently altered through improper handling, is an important consideration during digital forensic investigations.

Submit

8. A manager periodically reviews and formally confirms that each team member's current system access remains appropriate for their role, signing off on this review. What identity and access management activity does this represent?

Explanation

Attestation periodically reviews and formally confirms that existing access assignments remain appropriate, with a manager or other accountable party explicitly signing off on that review, which helps catch access that should have been revoked but was overlooked during normal offboarding or role-change processes. Provisioning instead refers to the initial process of creating and granting access accounts, which is a different point in the identity lifecycle from periodically re-confirming that already-granted access remains appropriate. Regular attestation cycles are often specifically required by regulatory or audit frameworks precisely because access tends to silently accumulate over time without this kind of periodic, deliberate re-review.

Submit

9. A security tool monitors outbound email and file transfers, automatically blocking any message containing what appears to be an unencrypted credit card number pattern. What enterprise capability is this?

Explanation

Data loss prevention monitors outbound channels like email and file transfers, automatically detecting and blocking sensitive data patterns like credit card numbers before they leave the organization, providing an automated safeguard against both accidental and deliberate data exfiltration. Network access control instead governs which devices are permitted to connect to the network in the first place, which is a different security function from inspecting the content of outbound data leaving an already-connected device. Effective DLP implementation typically requires careful tuning of what patterns to detect, balancing catching genuine sensitive data against generating excessive false positives on benign content that merely resembles a sensitive pattern.

Submit

10. Upon detecting malware on an endpoint, an automated response immediately isolates that specific device from the rest of the network to prevent further spread, without waiting for manual analyst intervention. What alert response action is this?

Explanation

Quarantine immediately isolates a detected malicious device from the rest of the network to prevent further spread, providing an automated first line of containment that does not require waiting for manual analyst intervention, which can be critical for limiting damage during a fast-moving incident. Alert tuning instead adjusts detection thresholds over time, which is a different, longer-term activity from taking immediate containment action on a specific detected threat. Automating quarantine response for high-confidence detections allows a security team to contain a spreading threat within seconds, well before a human analyst could manually review and act on the same alert.

Submit

11. A team runs an automated tool that checks systems against a database of known vulnerability signatures, and separately monitors dark web forums for mentions of the organization's leaked credentials or planned attacks. Which two vulnerability identification methods, respectively, does this describe?

Explanation

A vulnerability scan runs automated checks against systems using a database of known vulnerability signatures, systematically identifying known weaknesses across the environment at scale. A threat feed instead, including dark web monitoring as one specific source, provides external intelligence about emerging threats, leaked credentials, or planned attacks that a purely internal vulnerability scan would never surface on its own. Combining both identification methods provides broader coverage than either alone, since a vulnerability scan reveals known weaknesses in your own systems while threat feeds reveal external context and emerging risks that scanning alone would miss.

Submit

12. A specific laptop is formally recorded as assigned to a named employee, who is then accountable for its proper use and physical security. What asset management concept does this represent?

Explanation

Assignment and accounting formally records which specific employee a device is assigned to, establishing clear ownership and accountability for that device's proper use and physical security. This differs from monitoring and asset tracking, which instead focuses on maintaining an ongoing inventory count and location awareness, rather than specifically establishing who is personally accountable for a given device. Clear assignment and ownership records also directly support later disposal and decommissioning, since knowing exactly who currently holds a device is necessary before it can be properly collected and sanitized at end of life.

Submit

13. A web application checks that a form field expecting a numeric age value actually contains only digits within a reasonable range, rejecting anything else before processing. What application security practice does this represent?

Explanation

Input validation checks that submitted data actually matches expected format and range constraints, such as confirming an age field contains only reasonable numeric digits, rejecting anything that does not conform before the application processes it further. This is a foundational application security practice that directly prevents many injection-style attacks, since malicious input often relies on the application accepting and processing data it should have rejected outright. Consistently validating input on the server side, rather than relying only on client-side checks a user could bypass, is essential for input validation to actually provide meaningful security benefit.

Submit

14. A facility posts visible warning signs stating that all activity is monitored and violators will be prosecuted, discouraging potential intruders before they attempt anything. What type of control is this?

Explanation

A deterrent control discourages a potential attacker before they attempt anything, such as a visible warning sign, relying on psychological discouragement rather than directly preventing or detecting an actual attempt. A detective control instead identifies an incident after it has already begun or occurred, which is a fundamentally different point in the security timeline than deterring an attempt before it starts. Deterrent controls are often inexpensive to implement but rely on an attacker actually being rational enough to be discouraged, which limits their effectiveness against a sufficiently determined or irrational adversary.

Submit

15. A payment system replaces a customer's actual credit card number with a random, non-sensitive placeholder value that has no mathematical relationship to the original number, and separately displays only the last four digits of a different sensitive field while hiding the rest. Which two data protection methods, respectively, does this describe?

Explanation

Tokenization replaces sensitive data with a random, non-sensitive placeholder value, called a token, that has no mathematical relationship to the original data, meaning the token cannot be reverse-engineered back to the original value without access to a separate secure mapping table. Masking instead displays only a portion of a sensitive field, such as the last four digits of a credit card number, while hiding the rest, which is a different technique that still reveals some limited, generally low-risk information about the original value. Choosing between tokenization and masking depends on whether the underlying use case needs the original data recoverable through a secure lookup, as tokenization allows, or simply needs to safely display a partial value, as masking provides.

Submit

16. A network requires a device to authenticate before it is granted any network access on a specific switch port, rather than allowing any connected device to communicate freely. What port security standard does this represent?

Explanation

802.1X requires a device to authenticate before it is granted any network access on a specific switch port, providing port-based network access control that prevents unauthorized devices from communicating freely simply by physically connecting a cable. This differs from a screened subnet, which instead controls traffic between network zones at a higher level rather than authenticating individual devices at the physical port. Implementing 802.1X is a foundational network access control practice for preventing unauthorized device connections in environments where physical port access cannot always be perfectly restricted.

Submit

17. A developer deploys code that automatically runs in response to specific events, with the cloud provider fully managing all underlying servers, scaling, and infrastructure. What architecture model is this?

Explanation

Serverless architecture runs code automatically in response to specific events, with the cloud provider fully managing all underlying servers, scaling, and infrastructure, so the developer never directly provisions or manages any server instance at all. A traditional on-premises deployment instead requires the organization to fully own and manage its own physical infrastructure, which is the opposite end of the infrastructure management spectrum from serverless. Serverless architecture can offer security benefits like a reduced infrastructure management burden, but it also shifts certain security responsibilities to the provider, which requires clearly understanding the specific shared responsibility boundary for that service.

Submit

18. A disgruntled employee misuses their own legitimate access, while separately an unaffiliated criminal group attempts to breach the network from outside. Which two threat actor attributes, respectively, does this describe?

Explanation

An internal threat actor already possesses legitimate access from within the organization, such as a disgruntled employee misusing access they were properly granted for their job. An external threat actor instead has no legitimate access and must attempt to breach the network from outside, such as an unaffiliated criminal group with no prior relationship to the organization. This internal versus external distinction is one of the foundational attributes used to classify threat actors, since the defensive posture needed to address an already-trusted internal actor differs meaningfully from defenses aimed at keeping external actors out entirely.

Submit

19. A security team applies vendor-released software updates specifically designed to close known vulnerabilities identified in the previous month's disclosures. What mitigation technique does this represent?

Explanation

Patching applies vendor-released software updates specifically designed to close known vulnerabilities, directly addressing the underlying flaw rather than working around it through other means like segmentation or isolation. This is generally the most direct and complete mitigation available when a patch actually exists and can be safely applied, though real-world constraints like compatibility testing and required downtime often mean patching cannot happen instantly upon a vulnerability's disclosure. Maintaining a disciplined, regular patching cadence, rather than patching only reactively after an incident, is one of the most fundamentally important ongoing security mitigation practices any organization can maintain.

Submit

20. A monitoring system flags that the same user account currently has active sessions open on three different devices in three different countries simultaneously. What indicator does this represent?

Explanation

Concurrent session usage flags simultaneous active sessions for the same account, such as three different devices in three different countries at once, which is a strong signal that the account's credentials may be compromised and in use by more than one party simultaneously. This differs from impossible travel, which specifically analyzes whether the time between logins would make physical travel between locations feasible, though both indicators often appear together in genuinely suspicious scenarios. Monitoring for concurrent sessions is a relatively straightforward technical control to implement, since most identity systems already track active session state and can flag or block unusual concurrency patterns.

Submit

21. An attacker forces a connection to use an older, weaker encryption protocol version that is easier to break, and separately finds two different inputs that produce the identical hash output. Which two cryptographic attack types, respectively, does this describe?

Explanation

A downgrade attack forces a connection to use an older, weaker encryption protocol version that is easier to break, exploiting backward compatibility that was intended for legitimate interoperability rather than to weaken security. A collision attack instead finds two different inputs that produce the identical hash output, which undermines a hash function's fundamental assumption that different inputs should reliably produce different outputs. Both attack types exploit different underlying cryptographic weaknesses, which is why defenses like disabling legacy protocol support and using collision-resistant hash algorithms each address a different specific vulnerability.

Submit

22. An attacker gains access to a newly deployed IoT device simply by trying the manufacturer's factory-set username and password, which the customer never changed. What threat vector does this represent?

Explanation

Default credentials represent a threat vector where a device's factory-set username and password, widely known or easily discoverable, are never changed by the customer, allowing an attacker to gain access simply by trying these well-known values. This is a remarkably common and preventable threat vector, especially for IoT devices, since changing default credentials during initial setup is a simple, low-cost action that eliminates this specific risk entirely. Enforcing default password changes as part of a hardening checklist directly addresses this threat vector before a device is ever exposed to potential attackers.

Submit

23. A criminal group deploys ransomware against multiple hospitals specifically to extort payment, with financial gain as the clear and primary motivation. What threat actor category best fits this description?

Explanation

Organized crime groups are typically motivated primarily by financial gain, which matches deploying ransomware specifically to extort payment from victims like hospitals, representing a purely profit-driven criminal enterprise rather than an ideological or espionage-driven motive. A hacktivist instead is primarily motivated by philosophical or political beliefs, and a nation-state conducting espionage is motivated by intelligence gathering, both of which are different primary motivations from straightforward financial extortion. Recognizing organized crime's financial motivation helps predict likely targets and tactics, since these groups tend to pursue whatever targets offer the highest expected financial return relative to effort and risk.

Submit

24. When a certificate is compromised or no longer trusted before its natural expiration date, it is added to a published list that clients can check to confirm the certificate should no longer be trusted. This list is commonly abbreviated ____.

Explanation

A certificate revocation list, or CRL, is a published list of certificates that have been revoked before their natural expiration date, which clients can check to confirm a certificate should no longer be trusted even though it has not yet technically expired. The Online Certificate Status Protocol, OCSP, provides a related but distinct real-time alternative to checking a full CRL, querying the status of a single specific certificate directly rather than downloading an entire list. Understanding both revocation checking mechanisms is important since a client that never checks revocation status at all could continue trusting a certificate that has already been compromised and formally revoked.

Submit

25. A digitally signed document provides cryptographic proof of exactly who signed it, preventing that person from later credibly denying they did so. What security concept does this represent?

Explanation

Non-repudiation provides proof of an action's origin, such as a digital signature proving exactly who signed a document, specifically preventing that person from later credibly denying they performed the action. Confidentiality instead protects information from unauthorized disclosure, and availability ensures systems and data remain accessible when needed, both of which are different security properties from proving who performed a specific action. Non-repudiation is particularly important for legally or financially significant transactions, where being able to prove after the fact exactly who authorized an action carries real consequence.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A team conducts a live failover test, actually shifting production...
An external auditor issues a formal statement confirming that an...
Before entering a business relationship, an organization researches a...
Before engaging a new vendor, an organization reviews the vendor's own...
An organization explicitly states it is willing to accept significant...
A multinational company must account for differing data protection...
During an investigation, an analyst examines information about a file,...
A manager periodically reviews and formally confirms that each team...
A security tool monitors outbound email and file transfers,...
Upon detecting malware on an endpoint, an automated response...
A team runs an automated tool that checks systems against a database...
A specific laptop is formally recorded as assigned to a named...
A web application checks that a form field expecting a numeric age...
A facility posts visible warning signs stating that all activity is...
A payment system replaces a customer's actual credit card number with...
A network requires a device to authenticate before it is granted any...
A developer deploys code that automatically runs in response to...
A disgruntled employee misuses their own legitimate access, while...
A security team applies vendor-released software updates specifically...
A monitoring system flags that the same user account currently has...
An attacker forces a connection to use an older, weaker encryption...
An attacker gains access to a newly deployed IoT device simply by...
A criminal group deploys ransomware against multiple hospitals...
When a certificate is compromised or no longer trusted before its...
A digitally signed document provides cryptographic proof of exactly...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!