CompTIA Security+ (SY0-701) Exam

00

hours hour

00

minutes minute

00

seconds second

Question 1 of 90

Which Wi-Fi term describes the name of the WLAN?

Question 2 of 90

Which type of cloud is owned and used by a single organization?

Question 3 of 90

Which term describes a specialized computer interface that controls industrial devices like manufacturing robots?

Question 4 of 90

Which type of malicious actor is characterized by lacking sophisticated technical skills and using cracking tools created by others?

Question 5 of 90

Which type of authentication server uses IEEE 802.1x network access control?

Question 6 of 90

Which term is most closely related to social engineering?

Question 7 of 90

Which type of planning is designed to deal with security events as they happen?

Question 8 of 90

Which type of algorithm below uses a single key for encryption and decryption?

Question 9 of 90

Which of the following Wi-Fi configurations is considered to be the weakest?

Question 10 of 90

Packet filter firewalls operate on which layer of the OSI model?

Question 11 of 90

Which of the following authentication messages generates a time-sensitive, single-use password to improve the strength of MFA?

Question 12 of 90

You need to subscribe to a threat intelligence feed using your Unified Threat Management (UTM) solution. Which standard application-later protocol is used by UTM tools to exchange threat intelligence information?

Question 13 of 90

When your UTM platform receives new data from your threat intelligence feed provider, in which standardised, structured format will the threat intelligence be saved?

Question 14 of 90

You are reviewing Web server logs after a Web application security breach. To what type of security control do log reviews relate?

Question 15 of 90

Which type of security flaw is not known by the vendor?

Question 16 of 90

A major CA with a global presence instructs its CISO to secure the CA's private key at the top of the trust hierarchy. The CISO decides to secure this key by hosting it on a physically isolated, air-gapped server. What is the most likely description of this?

Question 17 of 90

Your company has determined that incident response to security events must be automated to reduce incident response time. What type of solution should be implemented?

Question 18 of 90

Which type of potentially malicious device records everything a user types?

Question 19 of 90

You are performing a Wi-Fi site survey due to complaints about slow wireless network connectivity. You have produced a heat map. Which of the following is the best solution?

Question 20 of 90

You have been asked to ensure clients cannot connect to inappropriate Websites at work, while also ensuring client IP addresses are not directly exposed to the Internet while browsing. What device should you implement?

Question 21 of 90

Your hotel provides free Wi-Fi to guests. The Wi-Fi network is secured. You would like to provide a safe, convenient way for guests to immediately connect to the Wi-Fi network using their smartphones. What should you do?

Question 22 of 90

A small group of highly-skilled hackers belonging to one nation is funded by their government to commit offensive cyber operations. They receive resources from their government but they are not directly employed by any government or military agency. What is the BEST descriptor for this group?

Question 23 of 90

Which physical security control is designed to stop a vehicle from being driven into a building?

Question 24 of 90

When gathering digital evidence, what is the most volatile evidence here?

Question 25 of 90

An enterprise organization wants to implement Multi-Factor Authentication (MFA) for its remote workforce. The security posture requires the MOST secure, phishing-resistant authentication mechanism available. Cost is not a concern. Which of the following should the administrator deploy?

Question 26 of 90

Which term refers to hiding files within other files?

Question 27 of 90

You are planning the configuration of HTTPS for a Web site. Which of the following is the strongest configuration setting?

Question 28 of 90

A company wishes to protect its encrypted datastreams against future advances in brute-force computational power by generating ephemeral session keys that are not transmitted in the cipherstream nor stored. What is the best description for this concept?

Question 29 of 90

Which term describes the result of plaintext that has been fed into an encryption algorithm along with an encryption key?

Question 30 of 90

You are decrypting a secret message sent to you by David over the network. The message is a "key exchange", containing a text file with a symmetric key. The only person who should be able to open the message is you. Which key will you use to decrypt the message?

Question 31 of 90

Next, you need to verify David's digital signature, to prove that the message came from David and that the hash integrity is intact. Which key will you use to verify the digital signature?

Question 32 of 90

Which protocol is used for configuring remote devices and gathering statistics on a network?

Question 33 of 90

After analysing the risk associated with working with an external organization to fulfil a government contract, you decide to enter into a contractual agreement after applying security controls to the external organization that you hope will reduce both the likelihood and impact of any successful supply-chain attack. What type of risk treatment is this?

Question 34 of 90

After taking actions to reduce risk, the CISO calculates that there is still a 3.7% annual likelihood of the risk occurring, which cannot be mitigated further. What is the best description for this concept?

Question 35 of 90

Your company runs sensitive medical research equipment and servers on a network named RNET-A. You need to ensure external network access to RNET-A is impossible. Which technique should you use?

Question 36 of 90

What is the most common goal of an invoice scam?

Question 37 of 90

After analysing a cyberattack, you determine the attackers used MITRE ATT&ACK Technique T1037, "Boot or Logon Initialization Scripts". They created a PowerShell script in Windows that would automatically open an external connection on port 443 every time Windows was started or restarted. What was the MOST LIKELY goal of this action?

Question 38 of 90

Which of the following inbuilt Linux tools may be used as part of a Living-off-the-Land (LotL) approach by threat actors?

Question 39 of 90

Erin is working through the Cyber Kill Chain and has completed the initial access and exploitation phases as part of a penetration test. What step would come next?

Question 40 of 90

Jason wants to prevent misuse of administrator accounts, so he installs a system to generate temporary administrator passwords. Which of the following has he installed?

Question 41 of 90

Nigel wishes to implement a form of on-site login security that allows Windows users to access multiple applications, without ever exposing users’ passwords over the network. Which of the following would you recommend?

Question 42 of 90

Which backup type only copies files that have changed since the last full backup?

Question 43 of 90

A penetration tester called a help desk staff member at a company and claimed to be a senior executive who needed her password changed immediately due to an important meeting they needed to conduct that would start in a few minutes. The help desk changed the executive’s password to a password that the penetration tester provided. What social engineering principle did the penetration tester leverage to accomplish this attack?

Question 44 of 90

An organization is establishing a secure code-signing process for internally developed applications. Developers need to ensure that end-users can verify the software originates from the company and has not been altered since compilation. Which of the following cryptographic processes BEST achieves this?

Question 45 of 90

Which of the following constitutes Multi-Factor Authentication (MFA)?

Question 46 of 90

A company has installed a highly secure iris scan biometric authentication system that can process 5 logins per hour. The CISO is concerned about speed and availability of the system. What is the best description for the CISO's concerns?

Question 47 of 90

Gary has created an application that new staff in his organization are asked to use as part of their training. The application shows them examples of phishing emails and asks the staff members to identify the emails that are suspicious and why. Correct answers receive points, and incorrect answers subtract points. What type of user training technique is this?

Question 48 of 90

A penetration tester is attempting SQL injection attacks against a client website. Which tool are they most likely to use?

Question 49 of 90

Your company has numerous public-facing Web sites that use the same domain. You need to use PKI to secure each Web site. Which solution involves the least amount of administrative effort and money?

Question 50 of 90

You need to ensure that DNS client query responses are authentic and have not been tampered with. What should you configure?

Question 51 of 90

What type of attack hijacks authenticated sessions between a client and a trusted server?

Question 52 of 90

What concept is being used when user accounts are created by one employee and user permissions are configured by another employee?

Question 53 of 90

Which type of security problem stems from improper memory handling?

Question 54 of 90

Which type of risk assessment is based on subjective opinions regarding threat likelihood and threat impact severity?

Question 55 of 90

Which of the following inbuilt Windows tools may be used as part of a Living-off-the-Land (LotL) approach by threat actors?

Question 56 of 90

An employee has been the victim of a Reflected XSS attack. Where does a Reflected XSS attack execute?

Question 57 of 90

Enrique is concerned about backup data being infected by malware. The company backs up key servers to digital storage on a backup server. Which of the following would be MOST effective in preventing the backup data being infected by malware?

Question 58 of 90

A company has recently implemented a microservices architecture. To ensure high availability and ease of maintenance, the engineers insisted that each microservice app only handles one function or purpose. What is the best description of this?

Question 59 of 90

A CISO is concerned that the perimeter firewall is no longer enough to protect the company from hackers and insider threats. The CISO wishes to deperimeterise by verifying every network request, even from inside the company. What is the best description of this concept?

Question 60 of 90

A CSP promises a customer "five nines" of availability and offers to pay a financial penalty if they fail to meet this target. Which contractual document would cover this situation?

Question 61 of 90

Which of the following is the best explanation of ARP poisoning?

Question 62 of 90

You are responsible for network security at an e-commerce company. You want to ensure that you are using best practices for the e-commerce website your company hosts. What standard would be the best for you to review?

Question 63 of 90

Mike needs to implement encryption on a system with limited computing power. What is the BEST solution?

Question 64 of 90

Your company is hiring new employees that may come into contact with sensitive data during the course of their jobs. Which type of document is normally signed by employees during the user on-boarding process to ensure that they will not disclose sensitive data?

Question 65 of 90

Which of the following principles stipulates that multiple changes to a computer system should not be made at the same time and that any such changes must be documented?

Question 66 of 90

You are ordering laptops for sales executives that travel for work. The laptops will run the Windows 11 Enterprise operating system. You need to ensure that protection of data at rest is enabled for internal laptop disks. The encryption must be tied to the specific laptop. What should you do?

Question 67 of 90

What is the most common reason to feature a privacy policy on a website?

Question 68 of 90

Sammy is building a cloud system and wants to ensure that it can adapt to changes in its workload by provisioning or deprovisioning resources automatically. Her goal is to ensure that the environment is not overprovisioned or underprovisioned and that she is efficiently spending money on her infrastructure. What concept describes this?

Question 69 of 90

Naomi discovers that, during a recent breach, a hacker attached proprietary data to emails and sent them out of the company. What solution should Naomi implement to prevent this in future, while allowing normal operations to continue?

Question 70 of 90

A CERT is responding to a security breach on a critical national network. They have analysed the scope of the intrusion and detected the location of the threat actor. Which important step follows next in the Incident Response Lifecycle?

Question 71 of 90

Which technique is used to enhance the security of password hashes?

Question 72 of 90

Which type of attack takes advantage of precomputed hash values for weak or common passwords?

Question 73 of 90

Which load balancing algorithm sends each request to the next backend VM or server in the cluster, with no other criteria?

Question 74 of 90

The Lead Web Engineer of your organisation insists on "fuzzing" the website in a safe testing environment before it is launched to the public. They explain that the Website should be attacked by tens of thousands of varying injection payloads and deliberate errors in an automated, systematic way. What is the best description of this testing process?

Question 75 of 90

A user gains access to a secure Web application resource using a digitally signed security token in the form of a browser cookie created with the "Remember me on this website" function. Which term best describes this action?

Question 76 of 90

You are building a Web app for your company's customers. One important feature is that they should be able to authenticate with their Google account rather than making a new account. Which term best describes this scenario?

Question 77 of 90

While comparing previous and current network traffic patterns, you notice several new DNS queries for TXT records. What might this indicate?

Question 78 of 90

You are a systems administrator configuring SSH authentication for a Linux server. One of your staff members wishes to authenticate remotely using their asymmetric key. Which key will you store on the Linux server?

Question 79 of 90

You are configuring a Windows file server containing Personally Identifiable Information (PII). You need to ensure that only employees from the Finance department can access the files, and only employees who work full-time from Monday to Friday. What type of access control model are you implementing?

Question 80 of 90

You need a network security solution that can both detect and stop suspicious activity. What should you implement?

Question 81 of 90

Which technique adds location metadata to social media posts and pictures?

Question 82 of 90

TCP port numbers apply to which layer of the OSI model?

Question 83 of 90

Which is the best term to describe an end-user device attempting to connect to an IEEE 802.1x Wi-Fi network?

Question 84 of 90

Which Wi-Fi EAP mode uses both client and server certificates?

Question 85 of 90

Which type of hypervisor runs within an existing operating system?

Question 86 of 90

A company that stores sensitive medical information instructs its data custodian to implement encryption at rest on the database. The employees who use the data on a daily basis can decrypt the data when needed, then use it for internal analysis. What is the best description for these employees that use the medical data for analysis on a daily basis?

Question 87 of 90

Which cloud security control enforces security policies when accessing cloud resources?

Question 88 of 90

Which cryptographic algorithm uses shorter keys but provides just as much brute force resistance as other algorithms with larger key spaces?

Question 89 of 90

Which term describes installing a smart phone app directly, without going through an official app store?

Question 90 of 90

Tony’s company wants to limit their risk due to customer data. What practice should they put in place early in the data lifecycle to ensure that they have only the data needed for their business purposes?