CompTIA Security+ (SY0-701) Exam

00

hours hour

00

minutes minute

00

seconds second

Question 1 of 86

John, a citizen of a country that strictly follows the General Data Protection Regulation (GDPR), used a global online shopping platform for a year. He decided to stop using the platform and requested the deletion of all his personal data. What is the online platform’s primary obligation concerning John’s request under the “Right to be Forgotten” principle?

Question 2 of 86

WebMasters LLC, a popular web hosting company, wants to ensure the robust security of their hosted websites. They initiate a security challenge, inviting ethical hackers worldwide to find vulnerabilities without giving any details about their servers, databases, or applications. Which penetration testing method is WebMasters LLC utilizing?

Question 3 of 86

A company is implementing a system to ensure that code released to production is both unaltered and approved by a specific team member, providing both integrity and non-repudiation. Which of the following cryptographic techniques should they implement?

Question 4 of 86

During an IT audit, a company’s encryption practices come under scrutiny. The IT auditor recommends increasing the encryption key length for certain applications to improve security. What is the PRIMARY reason to increase the encryption key length?

Question 5 of 86

Sarah is working on a project where she needs to validate the integrity and authenticity of assets over time, without a centralized authority. Which technology would be most appropriate for this use case?

Question 6 of 86

A journalist wants to send a confidential message to her editor without raising suspicion. Instead of sending a coded or encrypted text, she embeds the message within a harmless-looking photograph. What method is she employing to keep the message concealed?

Question 7 of 86

A security administrator needs to apply a configuration change to a critical service, requiring a service restart. Before initiating the restart, which of the following steps is MOST important to ensure continuous service availability?

Question 8 of 86

A security analyst at DataCorp is tasked with preventing users from running unauthorized applications. Which approach should the analyst primarily rely on to achieve this?

Question 9 of 86

Which of the following options is most suitable as a risk transference strategy?

Question 10 of 86

Alice needs to provide proof of the authenticity of a digital document she’s sending to Bob. Which of the following cryptographic elements should Alice use to accomplish this task and ensure Bob knows the document came from her?

Question 11 of 86

Carla, a security analyst, receives an alert that one of the company’s server certificates may have been exposed in a recent data breach. What is the most immediate action Carla should take to ensure that the exposed certificate cannot be used maliciously?

Question 12 of 86

A database administrator is concerned about identical hashes being produced for users who select the same password. To mitigate this risk, what cryptographic technique should the administrator implement?

Question 13 of 86

During a scheduled maintenance window, a security administrator plans to apply a critical update to the company’s firewall. Which of the following actions is MOST crucial to ensure minimized downtime during this process?

Question 14 of 86

A web server hosting the company’s e-commerce site is set for an OS upgrade. The company has a cluster of web servers, only one of which needs the upgrade. The upgrade is expected to last 30 minutes. What should be a primary consideration to minimize customer impact due to potential downtime?

Question 15 of 86

Sarah, a security analyst, is concerned about potential man-in-the-middle attacks on the company’s internal portal. To mitigate this risk, she recommends obtaining a digital certificate from a trusted entity. Which of the following is responsible for issuing such certificates?

Question 16 of 86

The finance department at a large firm still relies on a legacy application for their quarterly reporting. This application is known to have some security flaws, but due to its critical nature, it cannot be easily replaced. How can the firm BEST mitigate the risks associated with this application?

Question 17 of 86

A multinational corporation is concerned about the possibility of losing access to encrypted data due to the loss or compromise of private keys. They’ve approached a third party organization for a solution. Which of the following is a system that allows the third party to securely hold a copy of the corporation’s cryptographic keys to ensure data recoverability?

Question 18 of 86

NexTech, a cloud-based software company, recently faced a security breach due to inconsistent practices among its system administrators. To avoid such inconsistencies in the future, what should NexTech emphasize in its operations?

Question 19 of 86

Carlos is responsible for managing IT services for a university. The university has numerous departments, each with its subdomain, like arts.university.com, science.university.com, and sports.university.com. Carlos wants a solution that ensures HTTPS security while being cost effective. However, he’s wary of potential risks. What might be a drawback of using a Wildcard Certificate for the university’s subdomains?

Question 20 of 86

Sophia, the CFO of a medium-sized company, received a call from an individual claiming to be from the IT department. The caller requested her login details for a “critical system update.” Suspecting something wasn’t right, Sophia hung up and contacted her IT department, which confirmed no such call was made by them. Which type of attack did Sophia most likely experience?

Question 21 of 86

A company’s website was temporarily defaced with a humorous meme, but no sensitive data was stolen or any significant damage done. The attacker left a message bragging about their first successful hack. Which type of threat actor is MOST likely responsible for this attack?

Question 22 of 86

A company named TechFlow is planning to produce a new line of smart home devices. They have opted to use a single supplier for a crucial component in their devices. Which of the following represents the MOST significant security risk associated with this decision?

Question 23 of 86

An e-commerce platform reported a series of breaches over the past month. With each breach, financial and personal data of thousands of users were exfiltrated. The perpetrators subsequently sold the data on the dark web. Which type of threat actor is MOST likely behind these breaches?

Question 24 of 86

Alex, a new intern at an IT company, wanted to access the internal company portal. Instead of typing “companyportal.com,” he accidentally typed “comapnyportal.com” and ended up on a site that looked identical but asked him to download a malicious file. This scenario best describes which type of attack?

Question 25 of 86

John, a security analyst, noticed an increase in unauthorized devices connecting to the company’s wireless network. To identify the reason, he realized that the wireless access points were still using an old encryption standard. Which outdated encryption standard is likely in use that is known to be easily compromised?

Question 26 of 86

In a routine security assessment, Claire found that a newly deployed database server within her organization is still using its default login credentials. Which of the following is the PRIMARY security risk associated with this finding?

Question 27 of 86

An employee receives a call from someone claiming to be from the IT department. The caller says there’s an urgent update required on the employee’s computer and asks for login credentials to perform the update remotely. The employee becomes suspicious because of which red flag regarding impersonation?

Question 28 of 86

Maria, a network administrator, receives a report detailing several open service ports on critical company servers. She wants to verify the accuracy of the report. Which of the following tools would be BEST for Maria to use to validate the findings?

Question 29 of 86

Jane, a security analyst, receives a report about network slowdowns happening at specific times of the day. After investigating, she discovers that a single device is flooding the network with traffic, causing legitimate requests to be dropped. Which type of attack is this device likely performing?

Question 30 of 86

While conducting a security assessment, Lucy found that a specific application crashes when she inputs a string that is much longer than what the input field is designed to handle. This could potentially allow her to execute arbitrary code in the application’s context. What vulnerability is Lucy likely trying to exploit?

Question 31 of 86

XYZ Corp is implementing a new vulnerability scanning solution. The security team wants a solution that does not require any software to be installed on the target machines but can still identify vulnerabilities. Which type of vulnerability scanning solution should they choose?

Question 32 of 86

An organization’s e-commerce platform experienced a data breach where attackers exploited a known vulnerability. Post-incident analysis revealed that a patch was available for this vulnerability two months before the breach but was not applied. Which of the following would have been the MOST effective measure to prevent this breach?

Question 33 of 86

The IT department of an e-commerce company is configuring access controls for a new online product inventory system. They want the sales team to update the inventory levels and product details but don’t want them to access financial data from the accounting department. Which access control principle is the IT department applying?

Question 34 of 86

During a routine security audit, a company discovered an unauthorized wireless access point using the same SSID as the company’s official wireless network. Additionally, this rogue access point was configured without any encryption. What type of wireless attack is this scenario most indicative of?

Question 35 of 86

A security analyst discovers that an external IP address has been repeatedly trying every possible combination of characters to gain access to the company’s VPN portal for the past two days. Which type of password attack is this MOST likely describing?

Question 36 of 86

A software developer at XYZ Corp included a piece of code in the company’s software that would corrupt the application’s databases if his name was ever removed from the list of contributors in the application credits. Months after he left the company, the application databases were corrupted after an update. What type of malware was responsible for this action?

Question 37 of 86

Kara, a financial analyst, began to notice unusual account activity tied to her credentials. She is sure she hasn’t initiated these transactions. Upon further investigation, IT discovered a program on her computer that was recording her inputs. What type of malware was found on Kara’s computer?

Question 38 of 86

A finance department employee, Maya, is transferred to the HR department. The IT department is considering her access requirements. Which of the following actions aligns best with the principle of least privilege?

Question 39 of 86

A developer has implemented a new feature on a company’s website that allows users to search for products by their names. Within a few days, the IT team noticed abnormal activities where entire tables from the database were being exfiltrated. Which vulnerability might the new feature have introduced?

Question 40 of 86

During a routine security assessment, Jake, a penetration tester, discovers that by modifying a configuration file located in a public directory, he can assign himself administrative permissions in the application. What type of activity is Jake performing?

Question 41 of 86

The IT department of a large corporation is performing a vulnerability assessment on its virtualized infrastructure. They come across a potential threat where a user from within a VM can interact and possibly compromise the host system. What is this type of vulnerability commonly referred to as?

Question 42 of 86

A technology company recently released a new line of routers. After a short period, security researchers discovered that some of these routers contain malicious chips embedded during the manufacturing process. This incident most likely represents what type of vulnerability?

Question 43 of 86

A web application requires users to authenticate using a token sent to their email. Alex, a security analyst, observes that once logged in, if he presents the same token again, he is granted access without any restrictions. What type of vulnerability does this situation depict?

Question 44 of 86

During a routine check, an IT technician notices several files on a company server have been renamed with a “.locked” extension and there’s a new file named “README_TO_RECOVER_FILES.txt” present in the root directory. Based on these indicators, which type of malicious activity is most likely in progress?

Question 45 of 86

Ella, a security analyst, is reviewing the logs of a web application and notices that an attacker attempted to use the following input in a login form: ' OR '1'='1' --. This input was used in an effort to manipulate the application’s backend database. What type of injection attack is this an example of?

Question 46 of 86

A company plans to upgrade its email server to ensure that email transmission between their mail server and client applications is encrypted. Which of the following protocols would be the most appropriate for this purpose?

Question 47 of 86

A medium-sized company has just deployed a new file server for the HR department. They want to ensure that only HR employees can view and edit HR-specific documents, while the IT department should only be able to perform system maintenance tasks. What should the company implement to achieve this requirement?

Question 48 of 86

DataFin, a financial analytics firm, experienced a minor fire incident in one of its server rooms. Fortunately, they had backups stored in another wing of the building, allowing for quick data recovery. However, management realizes that in a major disaster, both primary and backup data might be destroyed. To address this, which backup strategy should DataFin consider?

Question 49 of 86

BetaTech is implementing a new authentication mechanism for its data center technicians. Instead of using key cards, technicians will now have to look into a device that maps a specific pattern in their eyes to authenticate their identity. Which of the following is BetaTech likely implementing?

Question 50 of 86

Alice wants to access a restricted online portal. The portal asks her to enter a unique username and a secret passphrase only she should know. This process helps the system ensure that Alice is who she claims to be. What security concept is the portal employing?

Question 51 of 86

Employees at a renowned software development firm frequently visit an industry-related forum to discuss the latest trends and technologies. Over the past month, several employees reported malware infections shortly after accessing the forum. An investigation suggests the forum was compromised to target the company’s developers specifically. Which type of attack most accurately describes this scenario?

Question 52 of 86

A cybersecurity analyst at XYZ Corp is looking to deploy a system that appears to be vulnerable and enticing to attackers. The main goal is to study the tactics, techniques, and procedures (TTPs) of potential adversaries, without them realizing that they’re interacting with a decoy. Which of the following would BEST meet this requirement?

Question 53 of 86

A large financial organization wants to ensure that all employees understand the importance of cybersecurity and the role they play in safeguarding company assets. Which of the following managerial security controls will be MOST effective in achieving this?

Question 54 of 86

During a regular review of system logs, Alex, a security analyst, noticed an unusual pattern of network traffic originating from a single IP address. Instead of waiting for an automated system to flag this as suspicious, he decides to manually dive deeper into the data to identify any potential threats. What is Alex engaging in?

Question 55 of 86

Which of the following forensic documents tracks personnel who had physical contact with the evidence?

Question 56 of 86

SecureNet, a cybersecurity firm, is implementing an Intrusion Detection System (IDS) for its enterprise client. Where should the IDS be placed for optimal detection of malicious activities?

Question 57 of 86

In a microservices architecture, each service should be designed with a specific principle to ensure it performs a specific task and interacts with other services through well-defined interfaces. What principle is this referring to?

Question 58 of 86

DeltaCorp has a password policy in place which requires users to change their passwords every 30 days. However, some users complain that this results in them choosing simpler passwords or writing them down to remember them. How can DeltaCorp maintain security while addressing these concerns?

Question 59 of 86

An organization is concerned about the theft of secret blueprints and designs for its semiconductor chips. What data classification BEST represents this information?

Question 60 of 86

A financial institution recently discovered that a large number of confidential customer records were being accessed and copied during off-business hours. Upon investigation, it was found that the access came from an authenticated user within the company, who had recently been refused a promotion. Which of the following controls would have helped in this instance?

Question 61 of 86

OmegaHealth, a large healthcare provider, is integrating automation into its operations. When a new healthcare worker is hired, they require access to multiple systems. Why would OmegaHealth automate the user provisioning process across these systems?

Question 62 of 86

After detecting an unauthorized intrusion into their network, a financial institution wants to implement a control that will restore compromised systems to a known good state. Which of the following would be the MOST appropriate corrective control?

Question 63 of 86

In preparation for a potential lawsuit, Meg, a cybersecurity analyst, has been asked to ensure that specific digital evidence remains intact and is not altered or deleted. What measure should Meg implement to ensure this requirement?

Question 64 of 86

Yasmina has been appointed to a new role that involves software engineering, ensuring that software is developed securely from the beginning of the process, in line with best practices. What is the BEST description of this job role?

Question 65 of 86

In an IaaS (Infrastructure as a Service) model, which of the following tasks is typically the responsibility of the cloud customer in a standard Cloud Responsibility Matrix?

Question 66 of 86

TechBlitz Inc. recently underwent an IT audit, and one of the suggestions was to reduce the attack surface. Which of the following measures would be MOST effective in accomplishing this?

Question 67 of 86

Dima has implemented a security control where corporate mobile devices will only function if they are physically inside the company headquarters. What is this technology?

Question 68 of 86

A company wants to ensure that security incidents are detected and addressed as quickly as possible by on-duty personnel. Which of the following operational security controls would be BEST to implement for this purpose?

Question 69 of 86

XYZ Corporation recently faced a major power outage that affected their primary data center. During the incident, it was found that there was no clear guidance on the steps to maintain or quickly restore business operations. To address this, which of the following policies should XYZ Corporation prioritize implementing?

Question 70 of 86

After deploying wireless access points in a large manufacturing facility, employees report inconsistent wireless connectivity in some areas. What tool would be most effective for the IT team to use to visualize areas of weak wireless signal strength?

Question 71 of 86

A company is evaluating its data storage options. They need a solution that provides them with the highest level of control over their hardware, software, and network configurations, allowing for customized security controls and measures. Which deployment model would best suit their needs?

Question 72 of 86

ABC Corp recently adopted a Bring Your Own Device (BYOD) policy. The IT department is concerned about the potential risks associated with personal devices accessing the corporate network. Which of the following solutions would be MOST effective for enforcing security policies on these personal mobile devices?

Question 73 of 86

AcmeTech, a software development firm, recently experienced a major data breach that was traced back to a vulnerability in their custom-built application. Post-incident analysis revealed that the vulnerability had been introduced during the coding phase and was never detected during testing. To avoid such vulnerabilities in the future, which control should AcmeTech emphasize to ensure secure practices are maintained throughout the development process?

Question 74 of 86

A software development team in a large corporation decided to use an unauthorized cloud-based tool to host and manage their source code. The team believed it would increase their productivity, even though it was not approved by the IT department. A few weeks later, unauthorized access to their project data was detected. Which threat actor concept BEST describes the situation?

Question 75 of 86

MegaTech Inc. is in the process of outlining a strategy to ensure that after any disaster, critical applications can be restored to a working state within 4 hours. The organization also wants to make sure that the data loss does not exceed 1 hour. Which of the following policies is most relevant to achieving this objective?

Question 76 of 86

A large financial institution is planning to upgrade its IT infrastructure to allow for a more efficient use of hardware resources, faster deployment of applications, and reduced server provisioning times. While evaluating different technologies, which of the following would directly address these needs?

Question 77 of 86

An online banking website employs a system that automatically logs out users after 10 minutes of inactivity to ensure that if a user forgets to log out, no one else can alter the user’s banking details. Which principle of the CIA triad is the banking website MOST directly addressing?

Question 78 of 86

A software development company is looking to migrate its legacy applications to a more modern infrastructure. They want to ensure the applications can be deployed consistently across multiple environments without the challenges of varying dependencies and configurations. Which approach would best achieve this goal?

Question 79 of 86

An online gaming platform experiences latency issues during multiplayer sessions, affecting the gameplay experience of its users. The company wants to ensure real-time responsiveness for its players worldwide. Which of the following solutions would BEST mitigate these availability issues?

Question 80 of 86

A startup company anticipates rapid growth in its user base over the next year. They are considering an architectural model for their application that can handle the projected growth without performance issues. Which of the following would be the BEST design consideration for this situation?

Question 81 of 86

MedGuard, a health tech company, has developed an AI-driven software that predicts potential health risks based on patient data. Before launching in the U.S. market, which of the following compliance laws should be the primary focus?

Question 82 of 86

A financial institution wants to ensure that customers are aware of the bank’s policies on information sharing and how their personal data is used. Which of the following security controls would BEST communicate this to customers?

Question 83 of 86

AlphaCorp is migrating to cloud infrastructure and wants to ensure all virtual machines (VMs) are securely configured from the onset. Before deploying multiple VM instances, what should AlphaCorp do to ensure each VM starts from a secure configuration?

Question 84 of 86

SecureNet Ltd. wants to protect user accounts from brute force attacks. They want to implement a measure where, after a certain number of failed login attempts, the account would become temporarily inaccessible. Which standard best suits this requirement?

Question 85 of 86

A medical company has recently deployed a device to monitor patient heart rates in real time. This device uses a real-time operating system (RTOS) to guarantee immediate response times. The security team is concerned about potential risks. Which of the following would be a KEY recommendation to enhance the security of such devices?

Question 86 of 86

A medical company has recently deployed a device to monitor patient heart rates in real time. This device uses a real-time operating system (RTOS) to guarantee immediate response times. The security team is concerned about potential risks. Which of the following would be a KEY recommendation to enhance the security of such devices?