CompTIA Security + SY0-701 (V7) Exam Practice Test 4

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 29, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. An organization's disaster recovery plan accounts for having enough trained personnel available to actually execute the recovery procedures during an emergency, not just having the right technology in place. What capacity planning dimension does this address?

Explanation

People capacity planning ensures enough trained personnel are actually available to execute recovery procedures during an emergency, recognizing that even perfectly designed technology and infrastructure recovery plans fail if there are not enough qualified people available to actually carry them out. Technology and infrastructure capacity instead address having sufficient compute resources and physical facilities respectively, which are necessary but not sufficient conditions without also having adequate people capacity. Overlooking people capacity planning, such as by relying on a single key individual with no backup, is a common and often costly gap in otherwise well-designed recovery plans.

Submit
Please wait...
About This Quiz
CompTIA Security + Sy0-701 (V7) Exam Practice Test 4 - Quiz

This practice resource focuses on the CompTIA Security + SY0-701 (V7) certification. It evaluates essential skills in network security, risk management, and compliance. By taking this assessment, learners can enhance their understanding of critical security concepts and prepare effectively for the certification exam.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. One penetration testing engagement focuses on actively attempting to breach systems and evade detection, while a separate engagement focuses on evaluating how well the organization's own defensive team detects and responds to a simulated attack. Which two penetration testing categories, respectively, does this describe?

Explanation

Offensive penetration testing actively attempts to breach systems and evade detection, focusing on demonstrating what an attacker could actually accomplish against the target environment. Defensive testing instead focuses on evaluating how well the organization's own defensive team, sometimes called the blue team, actually detects and responds to a simulated attack, which is a different evaluation goal from simply demonstrating successful breach techniques. Combining both offensive and defensive testing perspectives, sometimes through an integrated engagement involving both red and blue teams working together, provides a more complete picture of an organization's actual security readiness than either perspective alone.

Submit

3. A company's internal audit team reports compliance status to its own executive leadership, and separately the company submits a formal compliance report to an external government regulator. Which two compliance reporting audiences, respectively, does this describe?

Explanation

Internal compliance reporting communicates compliance status to the organization's own executive leadership, supporting internal decision-making and accountability without necessarily satisfying any external legal reporting requirement. External compliance reporting instead submits a formal report to an outside party, such as a government regulator, which typically carries its own specific format and legal requirements distinct from purely internal reporting. Maintaining both internal and external reporting processes ensures the organization's own leadership stays informed while also satisfying whatever formal external reporting obligations actually apply to that organization.

Submit

4. Before a vendor's security team conducts an authorized test against a client's systems, both parties agree on specific boundaries and procedures for the test, and separately the client sends the vendor a detailed written survey about its own security practices. Which two third-party risk activities, respectively, does this describe?

Explanation

Rules of engagement establish specific boundaries and procedures for an authorized test, such as a penetration test, ensuring both parties have a clear, agreed-upon understanding of what is and is not permitted during the engagement. A questionnaire instead is a detailed written survey sent to a vendor about its security practices, providing a structured way to gather self-reported information without requiring an active technical engagement like a penetration test. Both activities support third-party risk management, but they serve different purposes, one governing an active technical assessment and the other gathering structured self-reported information from the vendor.

Submit

5. After careful analysis, an organization decides to discontinue a specific risky business activity entirely, rather than trying to reduce, transfer, or simply accept the associated risk. What risk management strategy does this represent?

Explanation

Avoiding a risk means eliminating the underlying activity or exposure entirely, such as discontinuing a risky business activity altogether, which is often the most complete way to address a risk but can also mean forgoing whatever benefit that activity would have provided. Mitigating instead reduces a risk's probability or impact through additional controls while still continuing the underlying activity, which is a less drastic response than eliminating the activity entirely. Choosing avoidance over mitigation, transfer, or acceptance reflects a judgment that the risk associated with a specific activity outweighs any benefit that activity provides, at least given currently available options for managing it.

Submit

6. An organization periodically reviews its security policies to confirm they remain relevant given changes in technology, regulation, and business operations, updating them as needed. What governance element does this represent?

Explanation

Monitoring and revision periodically reviews security policies to confirm they remain relevant given changes in technology, regulation, and business operations, updating them as needed rather than treating a policy as a static, one-time document. Without this ongoing review process, policies can quietly become outdated and increasingly disconnected from actual current practices and requirements, undermining their practical value even if they technically remain in effect. Building a regular policy review cadence into governance processes helps ensure the organization's documented policies continue to reflect its actual current risk environment and obligations.

Submit

7. During an ongoing investigation, an analyst reviews a real-time visual summary consolidating key security metrics and alerts from multiple systems into a single consolidated view. This visual summary tool is called a ____.

Explanation

A dashboard consolidates key security metrics and alerts from multiple systems into a single real-time visual summary, giving an analyst quick situational awareness during an investigation without needing to separately query each individual underlying system. This differs from raw log data or packet captures, which provide much more granular detail but require more time and expertise to interpret directly compared to a dashboard's pre-summarized visual presentation. Well-designed security dashboards strike a balance between providing enough summarized insight to be immediately useful while still allowing an analyst to drill down into underlying detailed data when a specific alert warrants closer investigation.

Submit

8. A user logs into a system using a biometric fingerprint scan combined with a device-bound security key, with no traditional password involved at any point in the process. What authentication approach is this?

Explanation

Passwordless authentication eliminates traditional passwords entirely, relying instead on factors like biometrics combined with a device-bound security key, which removes the risk of password-related attacks like credential stuffing or phishing that specifically target traditional password-based logins. Password vaulting instead still involves managing actual passwords, just doing so securely within a centralized vault, which is a different approach from eliminating passwords from the authentication process altogether. Passwordless authentication is increasingly favored specifically because it removes an entire category of common attack vectors that depend on a password existing somewhere in the first place, whether it can be guessed, stolen, or reused.

Submit

9. A security platform not only monitors and responds to threats on individual endpoints but also correlates data across endpoints, network, and email to provide broader detection and response capability. What does this expanded capability represent?

Explanation

XDR extends beyond EDR's endpoint-focused monitoring and response, correlating data across multiple security domains such as network and email in addition to endpoints, providing broader visibility and more comprehensive detection than any single domain's tools could achieve alone. EDR by itself focuses specifically on endpoint-level monitoring and response, which is valuable but narrower in scope than XDR's cross-domain correlation capability. Adopting XDR reflects a recognition that sophisticated attacks often span multiple domains, such as an email-delivered payload that later exhibits network-level command-and-control activity, which siloed single-domain tools might correlate too slowly or miss entirely.

Submit

10. A network team analyzes summarized records of network traffic flows, including source, destination, and volume, without capturing the actual full packet contents. What monitoring tool is this?

Explanation

NetFlow captures summarized records of network traffic flows, including source, destination, and volume information, without capturing the actual full packet contents, providing a lightweight way to understand traffic patterns at scale compared to full packet capture. A vulnerability scanner instead identifies weaknesses in systems, which is a completely different monitoring purpose from summarizing network traffic flow patterns. NetFlow data is particularly useful for identifying unusual traffic volume patterns or unexpected communication between systems, even when the actual packet content itself is not available for deeper inspection.

Submit

11. A business unit requests permission to leave a known vulnerability unaddressed for a limited time due to a valid operational reason, and separately a different vulnerability is formally deemed not applicable to the organization's environment at all. Which two vulnerability response concepts, respectively, does this describe?

Explanation

An exception temporarily accepts a known, applicable vulnerability for a limited time due to a valid operational reason, typically with an expiration date and a plan to eventually address it. An exemption instead formally determines that a vulnerability does not actually apply to the specific environment at all, such as when the vulnerable component is not actually present or exploitable in that particular deployment. Both concepts provide a formal, documented way to handle a vulnerability without immediate remediation, but they reflect fundamentally different underlying justifications, temporary acceptance versus genuine inapplicability.

Submit

12. A decommissioned hard drive is securely wiped so its data cannot be recovered but the drive itself remains physically intact and reusable, while a different drive is physically shredded so it can never be used again. Which two disposal methods, respectively, does this describe?

Explanation

Sanitization securely wipes data from a drive while leaving the physical device intact and reusable, which is appropriate when the hardware itself still has value and the organization is confident the wiping process fully removes all recoverable data. Destruction instead physically shreds or otherwise permanently destroys the drive so it can never be used again, providing the strongest possible assurance against data recovery at the cost of losing any remaining hardware value. Choosing between sanitization and destruction often depends on the sensitivity of the data that was stored and the organization's risk tolerance for any residual chance of data recovery.

Submit

13. A web application sets a browser cookie with attributes ensuring it is only transmitted over encrypted HTTPS connections and cannot be accessed by client-side scripts. What application security practice does this represent?

Explanation

Secure cookies use attributes ensuring a cookie is only transmitted over encrypted HTTPS connections and cannot be accessed by client-side scripts, protecting session tokens and other sensitive cookie data from interception or theft through cross-site scripting attacks. Static code analysis instead examines application source code for vulnerabilities without executing it, which is a different application security practice from configuring how a specific cookie behaves at runtime. Properly configuring secure cookie attributes is a simple but often overlooked web application hardening step that directly mitigates several common cookie-based attack techniques.

Submit

14. A company issues a formal written policy requiring all employees to complete annual security awareness training, relying on the policy itself to instruct required behavior rather than a technical enforcement mechanism. What control type is this?

Explanation

A directive control instructs or mandates specific behavior through policy, such as requiring annual training, relying on the written directive itself rather than a technical mechanism to actually enforce compliance. A preventive control instead directly stops an incident through technical or physical means, which is a fundamentally different mechanism than simply issuing an instruction and expecting compliance. Directive controls often work best when paired with a verification mechanism, such as tracking training completion rates, since the directive alone provides no automatic enforcement of the required behavior.

Submit

15. A regulation requires that a specific category of citizen data must be physically stored on servers located within that country's own borders. What two related data protection concepts does this requirement reflect?

Explanation

Data sovereignty refers to the legal principle that data is subject to the laws of the country where it is physically located, and geolocation tracks exactly where that data actually resides, together explaining why a regulation might require certain citizen data to be physically stored within a specific country's borders. Tokenization, masking, encryption, and hashing instead address protecting data's content or format, which is a different concern from where the data is physically located and which country's laws apply to it. Organizations operating across multiple jurisdictions must carefully track data sovereignty requirements, since storing regulated data in the wrong physical location can create serious compliance violations regardless of how well that data is otherwise protected.

Submit

16. A network places its public-facing web server in a segment isolated from both the public internet and the fully trusted internal network, allowing controlled traffic between all three zones. What is this segment called?

Explanation

A screened subnet, sometimes still called a DMZ, isolates public-facing resources like a web server from both the public internet and the fully trusted internal network, allowing controlled traffic between all three zones through carefully defined firewall rules. This differs from a VLAN, which is a Layer 2 segmentation mechanism that could be used to implement a screened subnet but is not itself the broader security zone concept. Placing internet-facing resources in a screened subnet, rather than directly on the internal network, ensures that if the web server is ever compromised, the attacker still faces additional barriers before reaching fully trusted internal systems.

Submit

17. An organization runs some workloads on its own private infrastructure while running other workloads on a public cloud provider, with data and applications sometimes moving between the two. What cloud model is this?

Explanation

A hybrid cloud model runs some workloads on private infrastructure and others on a public cloud provider, with data and applications sometimes moving between the two environments, combining benefits of both approaches rather than committing exclusively to one. A purely public cloud model instead runs everything on a third-party provider's shared infrastructure, and a purely private cloud model runs everything on dedicated, organization-controlled infrastructure, both of which are simpler single-environment approaches compared to a hybrid model's combination. Hybrid cloud considerations specifically require attention to how the responsibility matrix and security boundaries shift as workloads move between the private and public portions of the environment.

Submit

18. An attacker sends a malicious link through a text message rather than email, and separately leaves an infected USB drive in a parking lot hoping an employee will plug it in out of curiosity. Which two threat vector categories, respectively, does this describe?

Explanation

Message-based threat vectors include SMS text messages as one specific channel alongside email and instant messaging, all of which can carry malicious links or content designed to trick a recipient into taking a harmful action. Removable device threat vectors instead exploit physical media, such as a deliberately left USB drive relying on human curiosity, which is a completely different delivery mechanism than any message-based channel. Both vectors ultimately rely on social engineering to succeed, since the attacker needs the target to actually click a link or plug in a device rather than exploiting a purely technical flaw.

Submit

19. A tool automatically checks systems against a defined secure configuration standard and automatically reverts any unauthorized configuration change back to the approved baseline. What mitigation technique does this represent?

Explanation

Configuration enforcement automatically checks systems against a defined secure configuration standard and automatically reverts any unauthorized deviation back to the approved baseline, providing continuous, automated protection against configuration drift rather than relying solely on periodic manual audits. Monitoring alone instead might detect and alert on a deviation without automatically correcting it, which is a less proactive response than configuration enforcement's automatic reversion. Automating configuration enforcement significantly reduces the window during which an unauthorized or accidental configuration change could leave a system exposed before being caught and corrected.

Submit

20. A server's CPU and memory usage spikes to abnormally high levels without any corresponding increase in legitimate user traffic, suggesting something unexpected is consuming resources. What indicator does this represent?

Explanation

Resource consumption flags abnormally high CPU or memory usage without a corresponding legitimate explanation, such as increased user traffic, suggesting something unexpected, potentially malicious, is consuming those resources. Resource inaccessibility instead describes a resource becoming unavailable entirely, which is a related but distinct indicator from elevated but still-functioning resource usage. Cryptomining malware is a common real-world cause of this specific indicator, since it deliberately consumes significant CPU resources for as long as it remains undetected on a compromised system.

Submit

21. An attacker inserts malicious database commands into a web form's input field to manipulate a backend database query, and separately injects malicious script code into a web page that then executes in other users' browsers. Which two web-based vulnerability types, respectively, does this describe?

Explanation

SQL injection inserts malicious database commands into an application's input, exploiting improperly sanitized or parameterized queries so the database executes unintended commands, potentially exposing or corrupting data. Cross-site scripting instead injects malicious script code into a web page that then executes in other users' browsers when they view the compromised page, targeting the victim's browser session rather than the backend database directly. Both vulnerability types stem from insufficient input validation and output encoding, but they target fundamentally different layers, one the database backend and the other the client-side browser experience.

Submit

22. A vulnerability scanner requires a dedicated software component installed directly on each target system to perform its assessment, as opposed to a different tool that assesses systems remotely without installing anything locally. Which two vulnerability scanning approaches, respectively, does this describe?

Explanation

A client-based approach requires a dedicated software component, often called an agent, installed directly on each target system to perform its assessment, which can provide deeper visibility but requires ongoing agent deployment and maintenance across the environment. An agentless approach instead assesses systems remotely without installing anything locally, which is simpler to deploy broadly but may provide less depth of visibility than a locally installed agent can achieve. Choosing between client-based and agentless approaches often involves weighing deployment overhead against the depth of visibility each approach can realistically provide for a given environment.

Submit

23. A group defaces a company's website specifically to protest the company's environmental practices, with no apparent financial motive involved. What threat actor category and motivation does this represent?

Explanation

A hacktivist is motivated by philosophical or political beliefs, which matches defacing a website specifically to protest environmental practices with no apparent financial motive, reflecting an ideologically driven rather than profit-driven attack. Organized crime instead is primarily motivated by financial gain, which does not match this scenario's clear absence of any apparent monetary objective. Recognizing hacktivist motivation helps predict likely targets, since hacktivists tend to select targets based on perceived ideological or political relevance rather than simply whichever target offers the highest financial payoff.

Submit

24. A hardware-based cryptographic foundation is inherently trusted by the system, since every other layer of security ultimately depends on and is verified against it. This foundational trust anchor is called the ____ of trust.

Explanation

A root of trust is a hardware-based cryptographic foundation that is inherently trusted by the system, since every other layer of security, such as Secure Boot verification, ultimately depends on and is verified against this foundational anchor. If the root of trust itself were ever compromised, every security guarantee built on top of it would become unreliable, which is why this component typically receives the strongest possible physical and cryptographic protection, often through a dedicated hardware component like a TPM. Understanding the root of trust concept helps explain why hardware-based security foundations are considered fundamentally stronger than purely software-based trust mechanisms that lack this same hardware anchor.

Submit

25. A security team compares its current control implementation against an industry framework's requirements, specifically identifying which required controls are missing or incomplete. What activity does this represent?

Explanation

A gap analysis compares current control implementation against a defined standard or framework's requirements, specifically identifying which required controls are missing or incomplete, providing a clear, prioritized roadmap for closing those identified gaps. This differs from simply reviewing authorization models, which addresses how access decisions are structured rather than comparing overall control coverage against an external framework. Conducting a gap analysis is a common and valuable first step when an organization is working toward a specific compliance framework or maturity target, since it clarifies exactly where effort needs to be focused.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
An organization's disaster recovery plan accounts for having enough...
One penetration testing engagement focuses on actively attempting to...
A company's internal audit team reports compliance status to its own...
Before a vendor's security team conducts an authorized test against a...
After careful analysis, an organization decides to discontinue a...
An organization periodically reviews its security policies to confirm...
During an ongoing investigation, an analyst reviews a real-time visual...
A user logs into a system using a biometric fingerprint scan combined...
A security platform not only monitors and responds to threats on...
A network team analyzes summarized records of network traffic flows,...
A business unit requests permission to leave a known vulnerability...
A decommissioned hard drive is securely wiped so its data cannot be...
A web application sets a browser cookie with attributes ensuring it is...
A company issues a formal written policy requiring all employees to...
A regulation requires that a specific category of citizen data must be...
A network places its public-facing web server in a segment isolated...
An organization runs some workloads on its own private infrastructure...
An attacker sends a malicious link through a text message rather than...
A tool automatically checks systems against a defined secure...
A server's CPU and memory usage spikes to abnormally high levels...
An attacker inserts malicious database commands into a web form's...
A vulnerability scanner requires a dedicated software component...
A group defaces a company's website specifically to protest the...
A hardware-based cryptographic foundation is inherently trusted by the...
A security team compares its current control implementation against an...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!