Exam Details

  • Exam Code
    :SY0-701
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :700 Q&As
  • Last Updated
    :Mar 24, 2025

CompTIA CompTIA Certifications SY0-701 Questions & Answers

  • Question 61:

    A company tested and validated the effectiveness of network security appliances within the corporate network. The IDS detected a high rate of SQL injection attacks against the company's servers, and the company's perimeter firewall is at capacity. Which of the following would be the best action to maintain security and reduce the traffic to the perimeter firewall?

    A. Set the appliance to IPS mode and place it in front of the company firewall.

    B. Convert the firewall to a WAF and use IPSec tunnels to increase throughput.

    C. Set the firewall to fail open if it is overloaded with traffic and send alerts to the SIEM.

    D. Configure the firewall to perform deep packet inspection and monitor TLS traffic.

  • Question 62:

    An organization is adopting cloud services at a rapid pace and now has multiple SaaS applications in use. Each application has a separate log-in, so the security team wants to reduce the number of credentials each employee must maintain. Which of the following is the first step the security team should take?

    A. Enable SAML

    B. Create OAuth tokens.

    C. Use password vaulting.

    D. Select an IdP

  • Question 63:

    A security analyst is investigating an alert that was produced by endpoint protection software. The analyst determines this event was a false positive triggered by an employee who attempted to download a file. Which of the following is the most likely reason the download was blocked?

    A. A misconfiguration in the endpoint protection software

    B. A zero-day vulnerability in the file

    C. A supply chain attack on the endpoint protection vendor

    D. Incorrect file permissions

  • Question 64:

    Which of the following best represents an application that does not have an on-premises requirement and is accessible from anywhere?

    A. Pass

    B. Hybrid cloud

    C. Private cloud

    D. IaaS

    E. SaaS

  • Question 65:

    Which of the following would be used to detect an employee who is emailing a customer list to a personal account before leaving the company?

    A. DLP

    B. FIM

    C. IDS

    D. EDR

  • Question 66:

    Which of the following risks can be mitigated by HTTP headers?

    A. SQLi

    B. XSS

    C. DoS

    D. SSL

  • Question 67:

    A vendor needs to remotely and securely transfer files from one server to another using the command line. Which of the following protocols should be implemented to allow for this type of access? (Select two).

    A. SSH

    B. SNMP

    C. RDP

    D. S/MIME

    E. SMTP

    F. SFTP

  • Question 68:

    Which of the following describes the category of data that is most impacted when it is lost?

    A. Confidential

    B. Public

    C. Private

    D. Critical

  • Question 69:

    A network administrator deployed a DNS logging tool that logs suspicious websites that are visited and then sends a daily report based on various weighted metrics. Which of the following best describes the type of control the administrator put in place?

    A. Preventive

    B. Deterrent

    C. Corrective

    D. Detective

  • Question 70:

    Callers speaking a foreign language are using company phone numbers to make unsolicited phone calls lo a partner organization. A security analyst validates through phone system logs that the calls are occurring and the numbers are not being spoofed. Which of the following is the most likely explanation?

    A. The executive team is traveling internationally and trying to avoid roaming charges

    B. The company's SIP server security settings are weak.

    C. Disgruntled employees are making calls to the partner organization.

    D. The service provider has assigned multiple companies the same numbers

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-701 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.