DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free CompTIA SY0-701 Practice Questions & Answers 2026 Part3 | CompTIA Security+

Are you preparing for the CompTIA SY0-701 certification exam? SPOTO offers the CompTIA SY0-701 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
A third-party vendor is moving a particular application to the end-of-life stage at the end of the current year. Which of the following is the most critical risk if the company chooses to continue running the application?
A. Lack of security updates
B. Lack of new features
C. Lack of support
D. Lack of source code access
View answer
Correct Answer: A

View The Updated SY0-701 Exam Questions

SPOTO Provides 100% Real SY0-701 Exam Questions for You to Pass Your SY0-701 Exam!

Question #2
An organization experienced a security breach that allowed an attacker to send fraudulent wire transfers from a hardened PC exclusively to the attacker's bank through remote connections. A security analyst is creating a timeline of events and has found a different PC on the network containing malware. Upon reviewing the command history, the analyst finds the following:PS>.\mimikatz.exe "sekurlsa::pth /user:localadmin /domain:corp-domain.com / ntlm:F327Which of the following best describes how the attacker gained access to the hardened PC?
A. The attacker created fileless malware that was hosted by the banking platform
B. The attacker performed a pass-the-hash attack using a shared support account
C. The attacker utilized living-off-the-land binaries to evade endpoint detection and response software
D. The attacker socially engineered the accountant into performing bad transfers
View answer
Correct Answer: B
Question #3
Which of the following is the best way to securely store an encryption key for a data set in a manner that allows multiple entities to access the key when needed?
A. Public key infrastructure
B. Open public ledger
C. Public key encryption
D. Key escrow
View answer
Correct Answer: D
Question #4
A security analyst recently read a report about a flaw in several of the organization's printer models that causes credentials to be sent over the network in cleartext, regardless of the encryption settings. Which of the following would be best to use to validate this finding?
A. Wireshark
B. netcat
C. Nessus
D. Nmap
View answer
Correct Answer: A
Question #5
A data administrator is configuring authentication for a SaaS application and would like to reduce the number of credentials employees need to maintain. The company prefers to use domain credentials to access new SaaS applications. Which of the following methods would allow this functionality?
A. SO
B. EAP
C. FA
D. EAP
View answer
Correct Answer: A
Question #6
A software company currently secures access using a combination of traditional username/password configurations and one-time passwords for MFA. However, employees still struggle to maintain both a password manager and the authenticator application. The company wants to migrate to a single, integrated authentication solution that is more secure and provides a smoother login experience for its employees. Which of the following solutions will best satisfy the company's needs?
A. Migrating to FIDO2 passkeys, utilizing built-in device biometrics for user authentication
B. Implementing SMS-based one-time passwords as the primary second factor for all logins
C. Implementing SAML federation across authentication servers so employees can use SSO to access applications
D. Deploying a PKI system that requires all employees to use smart cards for login access
View answer
Correct Answer: A
Question #7
A newly implemented wireless network is designed so that visitors can connect to the wireless network for business activities. The legal department is concerned that visitors might connect to the network and perform illicit activities. Which of me following should the security team implement to address this concern?
A. Configure a RADIUS server to manage device authentication
B. Use 802
C. Add a guest captive portal requiring visitors to accept terms and conditions
D. Allow for new devices to be connected via WPS
View answer
Correct Answer: C
Question #8
Which of the following activities is included in the post-incident review phase?
A. Determining the root cause of the incident
B. Developing steps to mitigate the risks of the incident
C. Validating the accuracy of the evidence collected during the investigation
D. Reestablishing the compromised system's configuration and settings
View answer
Correct Answer: A
Question #9
Which of the following best describes a use case for a DNS sinkhole?
A. Attackers can see a DNS sinkhole as a highly valuable resource to identify a company's domain structure
B. A DNS sinkhole can be used to draw employees away from known-good websites to malicious ones owned by the attacker
C. A DNS sinkhole can be used to capture traffic to known-malicious domains used by attackers
D. A DNS sinkhole can be set up to attract potential attackers away from a company's network resources
View answer
Correct Answer: C
Question #10
A network administrator is working on a project to deploy a load balancer in the company's cloud environment. Which of the following fundamental security requirements does this project fulfil?
A. rivacy
B. vailability
C. ntegrity
D. onfidentiality
View answer
Correct Answer: B
Question #11
An administrator notices that several users are logging in from suspicious IP addresses. After speaking with the users, the administrator determines that the employees were not logging in from those IP addresses and resets the affected users’ passwords. Which of the following should the administrator implement to prevent this type of attack from succeeding in the future?
A. Multifactor authentication
B. Permissions assignment
C. Access management
D. Password complexity
View answer
Correct Answer: A
Question #12
A security administrator needs a method to secure data in an environment that includes some form of checks so that the administrator can track any changes.
A. SPF
B. GPO
C. NAC
D. FIM
View answer
Correct Answer: D
Question #13
Which of the following is the most relevant reason a DPO would develop a data inventory?
A. To manage data storage requirements better
B. To determine the impact in the event of a breach
C. To extend the length of time data can be retained
D. To automate the reduction of duplicated data
View answer
Correct Answer: B
Question #14
Which of the following threat actors is the most likely to be hired by a foreign government to attack critical systems located in other countries?
A. acktivist
B. histleblower
C. rganized crime
D. nskilled attacker
View answer
Correct Answer: C
Question #15
A company is redesigning its infrastructure and wants to reduce the number of physical servers in use. Which of the following architectures is best suited for this goal?
A. Isolation
B. Segmentation
C. Virtualization
D. Redundancy
View answer
Correct Answer: C
Question #16
An administrator at a small business notices an increase in support calls from employees who receive a blocked page message after trying to navigate to a spoofed website. Which of the following should the administrator do?
A. Deploy multifactor authentication
B. Decrease the level of the web filter settings
C. Implement security awareness training
D. Update the acceptable use policy
View answer
Correct Answer: C
Question #17
An administrator wants to perform a risk assessment without using proprietary company information. Which of the following methods should the administrator use to gather information?
A. Network scanning
B. Penetration testing
C. Open-source intelligence
D. Configuration auditing
View answer
Correct Answer: C
Question #18
During an investigation, a security analyst discovers traffic going out to a command-and-control server. The analyst must find out if any data exfiltration has occurred. Which of the following would best help the analyst determine this?
A. etwork log
B. pplication log
C. acket capture
D. etadata
View answer
Correct Answer: C
Question #19
Which of the following describes the maximum allowance of accepted risk?
A. isk indicator
B. isk level
C. isk score
D. isk threshold
View answer
Correct Answer: D
Question #20
An employee receives a text message that appears to have been sent by the payroll department and is asking for credential verification. Which of the following social engineering techniques are being attempted? (Choose two.)
A. Typosquatting
B. Phishing
C. Impersonation
D. Vishing
E. Smishing
F. Misinformation
View answer
Correct Answer: CE
Question #21
Which of the following is a social engineering attack in which a bad actor impersonates a web URL?
A. Pretexting
B. Misinformation
C. Typosquatting
D. Watering-hole
E. Reveal Answer
View answer
Correct Answer: C
Question #22
Which of the following exercises should an organization use to improve its incident response process?
A. abletop
B. eplication
C. ailover
D. ecovery
View answer
Correct Answer: A
Question #23
A user is requesting Telnet access to manage a remote development web server. Insecure protocols are not allowed for use within any environment. Which of the following should be configured to allow remote access to this server?
A. HTTPS
B. SNMPv3
C. SSH
D. RDP
E. SMTP
View answer
Correct Answer: C
Question #24
A systems administrator notices that a testing system is down. While investigating, the systems administrator finds that the servers are online and accessible from any device on the server network. The administrator reviews the following information from the monitoring system:Which of the following is the most likely cause of the outage?
A. Denial of service
B. ARP poisoning
C. Jamming
D. Kerberoasting
View answer
Correct Answer: A
Question #25
A systems administrator would like to set up a system that will make it difficult or impossible to deny that someone has performed an action. Which of the following is the administrator trying to accomplish?
A. Corrective
B. Transfer
C. Detective
D. Preventive
View answer
Correct Answer: A
Question #26
An employee clicked a link in an email from a payment website that asked the employee to update contact information. The employee entered the log-in information but received a “page not found” error message. Which of the following types of social engineering attacks occurred?
A. Brand impersonation
B. Pretexting
C. Typosquatting
D. Phishing
View answer
Correct Answer: D
Question #27
Which of the following is used to conceal credit card information in a database log file?
A. Tokenization
B. Masking
C. Hashing
D. Obfuscation
View answer
Correct Answer: B
Question #28
During a penetration test, a flaw in the internal PKI was exploited to gain domain administrator rights using specially crafted certificates. Which of the following remediation tasks should be completed as part of the cleanup phase?
A. Updating the CRL
B. Patching the CA
C. Changing passwords
D. Implementing SOAR
View answer
Correct Answer: B
Question #29
Which of the following addresses individual rights such as the right to be informed, the right of access, and the right to be forgotten?
A. GDPR
B. PCI DSS
C. NIST
D. ISO
View answer
Correct Answer: A
Question #30
An employee receives a text message that appears to have been sent by the payroll department and is asking for credential verification. Which of the following social engineering techniques are being attempted? (Choose two.)
A. yposquatting
B. hishing
C. mpersonation
D. ishing
E. mishing
F. isinformation
View answer
Correct Answer: CE
Question #31
Which of the following tasks is typically included in the BIA process?
A. Estimating the recovery time of systems
B. Identifying the communication strategy
C. Evaluating the risk management plan
D. Establishing the backup and recovery procedures
E. Developing the incident response plan
View answer
Correct Answer: A
Question #32
The executive management team is mandating the company develop a disaster recovery plan. The cost must be kept to a minimum, and the money to fund additional internet connections is not available. Which of the following would be the best option?
A. Hot site
B. Cold site
C. Failover site
D. Warm site
View answer
Correct Answer: B
Question #33
A security analyst discovers that a large number of employee credentials had been stolen and were being sold on the dark web. The analyst investigates and discovers that some hourly employee credentials were compromised, but salaried employee credentials were not affected.Most employees clocked in and out while they were Inside the building using one of the kiosks connected to the network. However, some clocked out and recorded their time after leaving to go home. Only those who clocked in and out while Inside the building had credentials stolen. Each of the kiosks are on different floors, and there are multiple routers, since the business segments environments for certain business functions.Hourly employees are required to use a website called acmetimekeeping.com to clock in and out. This website is accessible from the internet. Which of the following Is the most likely reason for this compromise?
A. A brute-force attack was used against the time-keeping website to scan for common passwords
B. A malicious actor compromised the time-keeping website with malicious code using an unpatched vulnerability on the site, stealing the credentials
C. The internal DNS servers were poisoned and were redirecting acmetimkeeping
D. ARP poisoning affected the machines in the building and caused the kiosks lo send a copy of all the submitted credentials to a machine
E. Reveal Answer
View answer
Correct Answer: B
Question #34
Which of the following describes the procedures a penetration tester must follow while conducting a test?
A. Rules of engagement
B. Rules of acceptance
C. Rules of understanding
D. Rules of execution
View answer
Correct Answer: A
Question #35
A city municipality lost its primary data center when a tornado hit the facility. Which of the following should the city staff use immediately after the disaster to handle essential public services?
A. CP
B. ommunication plan
C. RP
D. RP
View answer
Correct Answer: C
Question #36
An administrator is installing an LDAP browser tool in order to view objects in the corporate LDAP directory. Secure connections to the LDAP server are required. When the browser connects to the server, certificate errors are being displayed, and then the connection is terminated. Which of the following is the most likely solution?
A. he administrator should request that the secure LDAP port be opened to the server
B. he administrator needs to increase the TLS version on the organization's RA
C. he administrator should allow SAN certificates in the browser configuration
D. he administrator needs to install the server certificate into the local truststore
View answer
Correct Answer: D
Question #37
While analyzing SIEM alerts for a company's WAF, an incident response analyst observes the following:https://corporate-A.com/loadimage?filename=/etc/https://corporate-A.com/loadimage?filename=../../etc/passwdhttps://corporate-A.com/loadimage?filename=./etc/passwdWhich of the following best describes the observed behavior?
A. Credential replay
B. Directory traversal
C. Brute-force attack
D. Resource exhaustion
View answer
Correct Answer: B
Question #38
Which of the following provides the details about the terms of a test with a third-party penetration tester?
A. Rules of engagement
B. Supply chain analysis
C. Right to audit clause
D. Due diligence
View answer
Correct Answer: A
Question #39
Which of the following types of controls decreases the likelihood of a cybersecurity breach occurring?
A. Containment
B. Lessons learned
C. Eradication
D. Detection
View answer
Correct Answer: D
Question #40
An organization’s internet-facing website was compromised when an attacker exploited a buffer overflow. Which of the following should the organization deploy to best protect against similar attacks in the future?
A. NGFW
B. WAF
C. TLS
D. SD-WAN
View answer
Correct Answer: B
Question #41
A company needs to keep the fewest records possible, meet compliance needs, and ensure destruction of records that are no longer needed. Which of the following best describes the policy that meets these requirements?
A. Security policy
B. Classification policy
C. Retention policy
D. Access control policy
View answer
Correct Answer: C
Question #42
An organization completed a project to deploy SSO across all business applications last year. Recently, the finance department selected a new cloud-based accounting software vendor. Which of the following should most likely be configured during the new software deployment?
A. RADIUS
B. SAML
C. EAP
D. OpenID
View answer
Correct Answer: B
Question #43
After failing an audit twice, an organization has been ordered by a government regulatory agency to pay fines.Which of the following causes this action?
A. Non-compliance
B. Contract violations
C. Government sanctions
D. Rules of engagement
View answer
Correct Answer: A
Question #44
A threat actor was able to use a username and password to log in to a stolen company mobile device. Which of the following provides the best solution to increase mobile data security on all employees' company mobile devices?
A. Application management
B. Full disk encryption
C. Remote wipe
D. Containerization
View answer
Correct Answer: C
Question #45
A systems administrator works for a local hospital and needs to ensure patient data is protected and secure. Which of the following data classifications should be used to secure patient data?
A. ritical
B. rivate
C. ensitive
D. ublic
View answer
Correct Answer: C
Question #46
Which of the following cryptographic solutions protects data at rest?
A. Digital signatures
B. Full disk encryption
C. Private key
D. Steganography
View answer
Correct Answer: B
Question #47
A company is reviewing options to enforce user logins after several account takeovers. The following conditions must be met as part of the solution:Allow employees to work remotely or from assigned offices around the world.Provide a seamless login experience.Limit the amount of equipment required.Which of the following best meets these conditions?
A. Trusted devices
B. Geotagging
C. Smart cards
D. Time-based logins
View answer
Correct Answer: A
Question #48
Which of the following is best to use when determining the severity of a vulnerability?
A. CVE
B. OSINT
C. SOAR
D. CVSS
View answer
Correct Answer: D
Question #49
Which of the following is prevented by proper data sanitization?
A. Hackers' ability to obtain data from used hard drives
B. Devices reaching end-of-life and losing support
C. Disclosure of sensitive data through incorrect classification
D. Incorrect inventory data leading to a laptop shortage
View answer
Correct Answer: A
Question #50
A security engineer is installing an IPS to block signature-based attacks in the environment.Which of the following modes will best accomplish this task?
A. onitor
B. ensor
C. udit
D. ctive
View answer
Correct Answer: D

View The Updated CompTIA Exam Questions

SPOTO Provides 100% Real CompTIA Exam Questions for You to Pass Your CompTIA Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us