Exam Details

  • Exam Code
    :SY0-701
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :718 Q&As
  • Last Updated
    :Apr 11, 2025

CompTIA CompTIA Certifications SY0-701 Questions & Answers

  • Question 211:

    A user is attempting to navigate to a website from inside the company network using a desktop. When the user types in the URL. https://www.site.com, the user is presented with a certificate mismatch warning from the browser. The user does not receive a warning when visiting http://www.anothersite.com. Which of the following describes this attack?

    A. On-path

    B. Domain hijacking

    C. DNS poisoning

    D. Evil twin

  • Question 212:

    Which of the following is a known security risk associated with data archives that contain financial information?

    A. Data can become a liability if archived longer than required by regulatory guidance

    B. Data must be archived off-site to avoid breaches and meet business requirements

    C. Companies are prohibited from providing archived data to e-discovery requests

    D. Unencrypted archives should be preserved as long as possible and encrypted

  • Question 213:

    Which of the following tools is effective in preventing a user from accessing unauthorized removable media?

    A. USB data blocker

    B. Faraday cage

    C. Proximity reader

    D. Cable lock

  • Question 214:

    An organization is migrating several SaaS applications that support SSO. The security manager wants to ensure the migration is completed securely. Which of the following should the organization consider before implementation? (Select TWO).

    A. The back-end directory source

    B. The identity federation protocol

    C. The hashing method

    D. The encryption method

    E. The registration authority

    F. The certificate authority

  • Question 215:

    A recent audit cited a risk involving numerous low-criticality vulnerabilities created by a web application using a third-party library. The development staff state there are still customers using the application even though it is end of life and it would be a substantial burden to update the application for compatibility with more secure libraries. Which of the following would be the MOST prudent course of action?

    A. Accept the risk if there is a clear road map for timely decommission

    B. Deny the risk due to the end-of-life status of the application.

    C. Use containerization to segment the application from other applications to eliminate the risk

    D. Outsource the application to a third-party developer group

  • Question 216:

    Which of the following control types is focused primarily on reducing risk before an incident occurs?

    A. Preventive

    B. Deterrent

    C. Corrective

    D. Detective

  • Question 217:

    Which of the following is the most likely outcome if a large bank fails an internal PCI DSS compliance assessment?

    A. Fines

    B. Audit findings

    C. Sanctions

    D. Reputation damage

  • Question 218:

    An organization has hired a red team to simulate attacks on its security posture. Which of the following will the blue team do after detecting an IoC?

    A. Reimage the impacted workstations

    B. Activate runbooks for incident response

    C. Conduct forensics on the compromised system

    D. Conduct passive reconnaissance to gather information

  • Question 219:

    A company wants to improve end users experiences when they tog in to a trusted partner website The company does not want the users to be issued separate credentials for the partner website Which of the following should be implemented to allow users to authenticate using their own credentials to log in to the trusted partner's website?

    A. Directory service

    B. AAA server

    C. Federation

    D. Multifactor authentication

  • Question 220:

    Which of the following is the MOST effective control against zero-day vulnerabilities?

    A. Network segmentation

    B. Patch management

    C. Intrusion prevention system

    D. Multiple vulnerability scanners

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-701 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.