CompTIA Security + SY0-701 (V7) Exam Practice Test 5

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 29, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A file system continuously records pending changes to a separate log before actually committing them to the main data structure, allowing recovery to a consistent state if the system crashes mid-write. What backup and recovery concept is this?

Explanation

Journaling continuously records pending changes to a separate log before actually committing them to the main data structure, which allows a system to recover to a consistent state by replaying or discarding incomplete journal entries if it crashes mid-write. Snapshots instead capture a complete point-in-time copy of data, which is a different backup mechanism from continuously logging incremental pending changes as they occur. Journaling is particularly valuable for maintaining data consistency during unexpected crashes, since without it, a crash occurring mid-write could leave the underlying data structure in a corrupted, inconsistent state that a simple snapshot taken before the crash would not have captured.

Submit
Please wait...
About This Quiz
CompTIA Security + Sy0-701 (V7) Exam Practice Test 5 - Quiz

This resource focuses on the CompTIA Security + SY0-701 certification, evaluating your understanding of key security concepts and practices. It covers essential topics such as network security, risk management, and threat mitigation, making it a valuable tool for anyone preparing for the exam. Engaging with this content will enhance you... see moreknowledge and boost your confidence for the certification process. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A penetration tester is given limited information, such as general network architecture but no source code or credentials, before beginning an engagement. What type of testing environment does this represent?

Explanation

A partially known environment penetration test gives the tester limited information, such as general network architecture but not full details like source code or credentials, falling between a fully known environment test's complete access and an unknown environment test's complete lack of prior information. This approach can balance realism with efficiency, since the tester still needs to conduct some reconnaissance but is not starting completely from scratch the way an unknown environment test would require. Choosing a partially known environment test often reflects a practical compromise when a fully unknown environment test would take too long to reach meaningful depth within the engagement's available timeframe.

Submit

3. One organization decides how and why personal data will be used, while a separate organization processes that data strictly on behalf of and according to the instructions of the first organization. Which two privacy roles, respectively, does this describe?

Explanation

The controller decides how and why personal data will be used, bearing primary responsibility for ensuring that use complies with applicable privacy regulations. The processor instead processes data strictly on behalf of and according to the instructions of the controller, without independently deciding the purposes or means of that processing, which is a distinct and generally more limited role than the controller's decision-making authority. Regulations like GDPR place specific, sometimes differing obligations on controllers and processors respectively, which is why correctly identifying which role an organization occupies for a given data processing activity matters for compliance purposes.

Submit

4. Before selecting a vendor, an organization thoroughly researches the vendor's financial stability and reputation, and separately confirms that none of its own employees have an undisclosed personal financial stake in that specific vendor. Which two vendor selection considerations, respectively, does this describe?

Explanation

Due diligence thoroughly researches a vendor's financial stability and reputation before selection, providing confidence the vendor is a legitimate, capable, and stable business partner. Conflict of interest checks instead confirm that no employee involved in the selection process has an undisclosed personal financial stake in a specific vendor, protecting the integrity and objectivity of the selection decision itself. Both considerations address different risks in vendor selection, one evaluating the vendor's own qualifications and the other protecting against a compromised, self-interested selection process regardless of how qualified the vendor might actually be.

Submit

5. A risk team calculates a specific dollar-value annualized loss expectancy for a given risk, using precise numerical inputs, rather than simply rating the risk as low, medium, or high based on team judgment. What type of risk analysis does this represent?

Explanation

Quantitative risk analysis calculates precise numerical figures, such as an annualized loss expectancy in dollars, using specific measurable inputs rather than relying on relative categorical ratings like low, medium, or high the way qualitative analysis does. Qualitative risk analysis instead uses team judgment and relative categories, which can be produced more quickly and with less data but provides less precise prioritization than genuine quantitative figures. Choosing quantitative analysis when reliable numerical data is actually available provides a more precise basis for comparing the cost-effectiveness of different risk treatment options against each other.

Submit

6. A company establishes a dedicated group of senior leaders who meet regularly specifically to review and approve major security policy decisions. What type of governance structure is this?

Explanation

A committee is a dedicated group of leaders who meet regularly specifically to review and approve decisions within their defined scope, such as major security policy decisions, providing a structured internal governance mechanism distinct from external bodies like a government entity or industry standards organization. A government entity instead refers to an external regulatory body, which is a fundamentally different type of governance structure from an organization's own internal committee. Establishing a dedicated security governance committee, rather than leaving major policy decisions to ad hoc individual judgment, provides more consistent, accountable oversight over time.

Submit

7. A security tool automatically generates a scheduled summary of key findings and metrics on a recurring basis, without requiring an analyst to manually compile the information each time. This kind of automatically generated summary is called an automated ____.

Explanation

An automated report is a scheduled summary of key findings and metrics generated automatically on a recurring basis, freeing an analyst from manually compiling the same information repeatedly and ensuring consistent, timely reporting even during busy periods. This differs from an ad hoc manual investigation, which instead requires an analyst to actively dig through raw data sources like logs or packet captures for a specific, one-time question. Relying on automated reports for routine, recurring reporting needs allows analysts to focus their manual investigative effort on genuinely novel or complex questions that automation cannot adequately address on its own.

Submit

8. An access control system automatically grants or denies access based on a predefined set of if-then conditions, such as blocking all login attempts outside normal business hours regardless of the user's specific role. What access control model is this?

Explanation

Rule-based access control automatically grants or denies access based on a predefined set of if-then conditions, such as blocking logins outside business hours, applying uniformly regardless of a user's specific assigned role. Role-based access control instead grants access based specifically on a user's assigned role, which is a different organizing principle from applying uniform conditional rules across all users regardless of role. Rule-based and role-based access control can be combined within a single system, such as applying a time-of-day rule on top of otherwise role-based permissions, providing layered access logic rather than relying on only one model exclusively.

Submit

9. A security tool establishes a baseline of each user's typical login times, locations, and data access patterns, then flags an account when its behavior suddenly deviates significantly from that established baseline. What capability is this?

Explanation

User behavior analytics establishes a behavioral baseline for each user over time and flags significant deviations from that baseline, which can catch a compromised account or insider threat even when the credentials used are entirely valid and correctly authenticated. This adds a detection layer beyond simple authentication success or failure, since a stolen but valid credential would otherwise appear completely legitimate to traditional access controls that only check whether a login succeeded. Network access control instead governs which devices are permitted to connect to the network in the first place, which is a different security function from analyzing ongoing behavioral patterns after access has already been granted.

Submit

10. A security team uses a standardized protocol to automate checking system configurations against published industry hardening benchmarks, rather than manually verifying each setting one at a time. What does this represent?

Explanation

SCAP provides a standardized protocol for automating the process of checking system configurations against published industry hardening benchmarks, replacing slow, error-prone manual verification of each individual setting with consistent, repeatable automated checks. Benchmarks themselves define the specific target configuration values, such as those published by the Center for Internet Security, that SCAP-based tools then automatically check systems against. Using SCAP-based automation rather than manual configuration review allows a security team to consistently verify hardening compliance across a much larger number of systems than manual review could realistically cover.

Submit

11. After applying a patch to address a known vulnerability, a team re-runs the vulnerability scanner specifically against the patched system, and separately has an independent auditor confirm the remediation was properly implemented. Which two validation activities, respectively, does this describe?

Explanation

Rescanning re-runs the vulnerability scanner specifically against the patched system, providing a direct technical check confirming the scanner no longer detects the previously identified vulnerability. An audit instead involves an independent party confirming the remediation was properly implemented, which can catch process or documentation gaps that a purely technical rescan alone might not reveal. Combining both rescanning and audit validation provides stronger assurance that a remediation was both technically effective and properly documented than relying on either validation method alone.

Submit

12. An organization defines exactly how long different categories of data must be kept before they are eligible for deletion, balancing legal requirements against storage costs. What asset management concept does this represent?

Explanation

Data retention defines exactly how long different categories of data must be kept before becoming eligible for deletion, balancing legal and regulatory requirements to retain certain data against the ongoing cost and risk of retaining data longer than necessary. Certification instead refers to documenting proof that a disposal process, such as sanitization, was actually completed correctly, which is a related but distinct asset management concept from defining how long data should be kept in the first place. Establishing clear data retention schedules by data category, rather than an ad hoc or indefinite retention approach, supports both compliance and more efficient storage management.

Submit

13. Before deploying wireless access points across an office, a team walks the facility measuring signal strength at various points to create a visual map showing coverage strength throughout the space. What wireless installation practice does this represent?

Explanation

A site survey walks the facility measuring signal strength at various points, and a heat map visually represents that data, showing coverage strength throughout the space, which together inform optimal access point placement before a wireless network is actually deployed. This differs from application security practices like sandboxing or code signing, which address entirely different security concerns from physical wireless coverage planning. Conducting a proper site survey before deployment helps avoid both coverage gaps that frustrate users and unnecessary signal bleed beyond the facility's boundaries that could expose the wireless network to nearby unauthorized parties.

Submit

14. An organization installs a fence around its data center perimeter and posts a security guard at the entrance, physically restricting who can approach the building. What control category is this?

Explanation

Physical controls restrict physical access to a location or asset, such as a fence and a security guard restricting who can approach a data center, addressing the physical layer of security rather than technology configuration or administrative policy. Technical controls instead directly implement a technical mechanism, such as a firewall rule, which operates in a fundamentally different domain than physically restricting building access. Physical controls remain an essential category even in an increasingly digital security landscape, since no amount of technical or administrative control matters if an attacker can simply walk into a facility and access hardware directly.

Submit

15. A developer hides a secret message within the pixel data of an ordinary-looking image file, and separately replaces sensitive production data with realistic but fake values for use in a testing environment. Which two obfuscation techniques, respectively, does this describe?

Explanation

Steganography hides a secret message within an otherwise ordinary-looking carrier, such as an image file's pixel data, concealing not just the message's content but the very fact that a hidden message exists at all. Data masking instead replaces sensitive production data with realistic but fake values, which is useful for testing environments where realistic-looking data is needed but the actual sensitive values must not be exposed. Both techniques obscure data in different ways, but they serve different purposes, one concealing a secret communication entirely and the other providing safely usable substitute data for a legitimate business purpose like testing.

Submit

16. An organization adopts a converged, cloud-delivered service combining networking and security functions, including secure web gateway and Zero Trust network access, into a single unified offering. What is this converged approach called?

Explanation

SASE converges networking and security capabilities, such as secure web gateway and Zero Trust network access, into a single cloud-delivered service, which can enforce policy closer to users regardless of their location rather than requiring traffic to be backhauled to a central data center. SD-WAN alone instead focuses specifically on the networking and path-selection side, representing one component that SASE builds upon rather than the full converged security and networking offering SASE represents. Adopting SASE reflects a broader industry shift toward delivering security capabilities as a cloud service closer to distributed users, rather than routing all traffic back through a traditional centralized security stack.

Submit

17. An application and all of its dependencies are packaged together into a lightweight, portable unit that shares the host operating system's kernel rather than requiring a full separate guest operating system. What technology is this?

Explanation

Containerization packages an application and its dependencies into a lightweight, portable unit that shares the host operating system's kernel, avoiding the overhead of a full separate guest operating system that traditional virtual machines require. Full virtualization with a hypervisor instead does require each virtual machine to run its own complete guest operating system, which is more resource-intensive but also provides stronger isolation between workloads than sharing a single kernel across containers. This difference in isolation strength is an important security consideration, since a kernel-level vulnerability could potentially affect every container sharing that kernel, unlike a compromise contained within a single fully virtualized guest OS.

Submit

18. One attacker's primary goal is to covertly gather sensitive government intelligence over an extended period, while a separate attacker's primary goal is to steal and sell a company's customer database. Which two motivations, respectively, does this describe?

Explanation

Espionage motivation drives covert, sustained intelligence gathering, such as targeting sensitive government information over an extended period, typically associated with nation-state or highly sophisticated threat actors. Data exfiltration motivation instead specifically drives stealing data, such as a customer database, often with the explicit goal of selling it for financial gain, which is a more directly profit-oriented motivation than long-term intelligence gathering. Distinguishing between these motivations helps predict both the likely persistence of an attacker's presence and what they are likely to actually do with any data or access they successfully obtain.

Submit

19. A security team deploys tools to continuously observe network traffic and system behavior, specifically to detect anomalies that might indicate a security incident in progress. What mitigation technique does this represent?

Explanation

Monitoring continuously observes network traffic and system behavior specifically to detect anomalies that might indicate an incident in progress, providing ongoing visibility that complements preventive controls by catching threats that manage to get past initial defenses. Isolation instead separates systems or network segments from each other, which is a different mitigation approach from actively watching for anomalous activity. Effective monitoring requires not just deploying the right tools but also establishing a clear baseline of normal behavior, since without that baseline it becomes much harder to recognize what actually constitutes a meaningful anomaly worth investigating.

Submit

20. A web filter logs repeated attempts by a specific internal host to reach known malicious domains, with each attempt being automatically blocked before completing. What indicator does this represent?

Explanation

Blocked content flags repeated attempts to reach known malicious domains that are automatically blocked before completing, which is a strong indicator that the internal host attempting these connections may already be compromised, even though the specific malicious connections themselves were successfully prevented. Missing logs instead indicates an absence of expected log entries, which is a very different signal from a web filter's log showing repeated blocked attempts. Repeated blocked content attempts from the same internal host, rather than a single isolated attempt, should generally elevate the priority of investigating that specific host for a broader compromise.

Submit

21. A vulnerability allows a malicious process running inside one virtual machine to break out and access the underlying hypervisor or other virtual machines on the same host, and separately a misconfigured cloud storage bucket is left publicly accessible. Which two vulnerability categories, respectively, does this describe?

Explanation

Virtualization vulnerabilities include VM escape, where a malicious process breaks out of its intended virtual machine boundary to access the underlying hypervisor or other virtual machines sharing the same physical host, representing a serious breach of the isolation virtualization is supposed to provide. Cloud-specific vulnerabilities instead include issues like a misconfigured, publicly accessible storage bucket, which is a configuration mistake specific to how cloud resources are provisioned and secured rather than a flaw in virtualization isolation itself. Both categories reflect security concerns that become newly relevant specifically because of virtualized and cloud-based infrastructure, distinct from vulnerabilities that would exist regardless of deployment model.

Submit

22. An attacker calls an employee pretending to be from the IT help desk, fabricating a plausible scenario to convince the employee to reveal their password. What social engineering technique is this?

Explanation

Pretexting fabricates a plausible scenario, such as posing as IT help desk staff, to convince a target to reveal information or take an action they otherwise would not, relying on a constructed narrative rather than simply asking directly. A watering hole attack instead compromises a website the target is likely to visit, which is a completely different mechanism from a fabricated phone conversation. Pretexting attacks succeed specifically because the fabricated scenario feels plausible and often creates a sense of urgency or authority, which is why training employees to verify unusual requests through an independent channel is such an effective countermeasure.

Submit

23. A well-resourced government-backed group conducts a multi-year espionage campaign against a defense contractor, using custom-developed tools and maintaining persistent covert access. What threat actor category best fits this?

Explanation

A nation-state actor is typically well-resourced and government-backed, capable of conducting sophisticated, multi-year campaigns using custom-developed tools and maintaining persistent covert access, which matches this scenario's described level of sophistication and sustained espionage focus. An unskilled attacker instead typically lacks the resources and technical capability for this kind of sustained, custom-tooled campaign, representing essentially the opposite end of the sophistication spectrum. Recognizing nation-state level sophistication helps organizations, particularly those in sensitive sectors like defense, calibrate their defenses toward the advanced persistent threat level these actors typically represent.

Submit

24. A single digital certificate is issued to secure an entire domain and all of its subdomains, such as mail, blog, and shop subdomains, rather than requiring a separate certificate for each one. This type of certificate is called a ____ certificate.

Explanation

A wildcard certificate secures an entire domain and all of its subdomains with a single certificate, rather than requiring a separate certificate to be issued and managed for each individual subdomain, which significantly simplifies certificate management for organizations running many subdomains. This convenience comes with a tradeoff, since if the wildcard certificate's private key is ever compromised, every subdomain covered by that single certificate becomes vulnerable simultaneously, unlike individually issued certificates where a single compromise would only affect one subdomain. Organizations must weigh this management convenience against the concentrated risk a wildcard certificate represents when deciding whether it is the right choice for their specific environment.

Submit

25. A Zero Trust architecture deliberately limits what a single compromised account or device could actually reach, minimizing the potential blast radius of any single compromise. What Zero Trust control plane concept does this reflect?

Explanation

Threat scope reduction deliberately limits what a single compromised account or device could actually reach, minimizing the potential blast radius of any single compromise, which is a core Zero Trust principle applied within the control plane's policy-driven access decisions. The Policy Engine and Policy Administrator instead are specific components that evaluate and communicate access decisions respectively, which are the mechanisms that help implement threat scope reduction rather than being the underlying principle itself. Achieving genuine threat scope reduction typically requires combining several Zero Trust elements together, including microsegmentation and least privilege access, rather than any single control alone.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A file system continuously records pending changes to a separate log...
A penetration tester is given limited information, such as general...
One organization decides how and why personal data will be used, while...
Before selecting a vendor, an organization thoroughly researches the...
A risk team calculates a specific dollar-value annualized loss...
A company establishes a dedicated group of senior leaders who meet...
A security tool automatically generates a scheduled summary of key...
An access control system automatically grants or denies access based...
A security tool establishes a baseline of each user's typical login...
A security team uses a standardized protocol to automate checking...
After applying a patch to address a known vulnerability, a team...
An organization defines exactly how long different categories of data...
Before deploying wireless access points across an office, a team walks...
An organization installs a fence around its data center perimeter and...
A developer hides a secret message within the pixel data of an...
An organization adopts a converged, cloud-delivered service combining...
An application and all of its dependencies are packaged together into...
One attacker's primary goal is to covertly gather sensitive government...
A security team deploys tools to continuously observe network traffic...
A web filter logs repeated attempts by a specific internal host to...
A vulnerability allows a malicious process running inside one virtual...
An attacker calls an employee pretending to be from the IT help desk,...
A well-resourced government-backed group conducts a multi-year...
A single digital certificate is issued to secure an entire domain and...
A Zero Trust architecture deliberately limits what a single...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!