CompTIA SY0-701 Practice Exams
Last updated on Oct 01,2026- Exam Code: SY0-701
- Exam Name: CompTIA Security+
- Certification Provider: CompTIA
- Latest update: Oct 01,2026
Which of the following tools can assist with detecting an employee who has accidentally emailed a file containing a customer’s PII?
- A . SCAP
- B . Net Flow
- C . Antivirus
- D . DLP
D
Explanation:
DLP stands for Data Loss Prevention, which is a tool that can assist with detecting and preventing the unauthorized transmission or leakage of sensitive data, such as a customer’s PII (Personally Identifiable Information). DLP can monitor, filter, and block data in motion (such as emails), data at rest (such as files), and data in use (such as applications). DLP can also alert the sender, the recipient, or the administrator of the data breach, and apply remediation actions, such as encryption,
quarantine, or deletion. DLP can help an organization comply with data protection regulations, such as GDPR, HIPAA, or PCI DSS, and protect its reputation and assets.
Reference = CompTIA Security+ Study Guide with over 500 Practice Test Questions: Exam SY0-701, 9th Edition, Chapter 2, page 78. CompTIA Security+ SY0-701 Exam Objectives, Domain 2.5, page 11.
Which of the following is used to protect a computer from viruses, malware, and Trojans being installed and moving laterally across the network?
- A . IDS
- B . ACL
- C . EDR
- D . NAC
C
Explanation:
Endpoint detection and response (EDR) is a technology that monitors and analyzes the activity and behavior of endpoints, such as computers, laptops, mobile devices, and servers. EDR can help to detect and prevent malicious software, such as viruses, malware, and Trojans, from infecting the endpoints and spreading across the network. EDR can also provide visibility and response capabilities to contain and remediate threats. EDR is different from IDS, which is a network-based technology that monitors and alerts on network traffic anomalies. EDR is also different from ACL, which is a list of rules that control the access to network resources. EDR is also different from NAC, which is a technology that enforces policies on the network access of devices based on their identity and compliance status.
Reference: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 2561
Which of the following is an example of a data protection strategy that uses tokenization?
- A . Encrypting databases containing sensitive data
- B . Replacing sensitive data with surrogate values
- C . Removing sensitive data from production systems
- D . Hashing sensitive data in critical systems
B
Explanation:
Detailed
Tokenization replaces sensitive data with non-sensitive surrogate values that retain the necessary format but are meaningless without access to the original data.
Reference: CompTIA Security+ SY0-701 Study Guide, Domain 3: Security Architecture, Section: "Data Masking and Tokenization".
Which of the following would be best suited for constantly changing environments?
- A . RTOS
- B . Containers
- C . Embedded systems
- D . SCADA
B
Explanation:
Containers are a method of virtualization that allows applications to run in isolated environments with their own dependencies, libraries, and configurations. Containers are best suited for constantly changing environments because they are lightweight, portable, scalable, and easy to deploy and update. Containers can also support microservices architectures, which enable faster and more frequent delivery of software features.
Reference: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, Chapter 10: Mobile Device Security, page 512 1
A security consultant needs secure, remote access to a client environment.
Which of the following should the security consultant most likely use to gain access?
- A . EAP
- B . DHCP
- C . IPSec
- D . NAT
C
Explanation:
IPSec is a protocol suite that provides secure communication over IP networks. IPSec can be used to create virtual private networks (VPNs) that encrypt and authenticate the data exchanged between two or more parties. IPSec can also provide data integrity, confidentiality, replay protection, and access control. A security consultant can use IPSec to gain secure, remote access to a client environment by establishing a VPN tunnel with the client’s network.
Reference: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, Chapter 8: Secure Protocols and Services, page 385 1
Which of the following can be used to identify potential attacker activities without affecting production servers?
- A . Honey pot
- B . Video surveillance
- C . Zero Trust
- D . Geofencing
A
Explanation:
A honey pot is a system or a network that is designed to mimic a real production server and attract potential attackers. A honey pot can be used to identify the attacker’s methods, techniques, and objectives without affecting the actual production servers. A honey pot can also divert the attacker’s attention from the real targets and waste their time and resources12.
The other options are not effective ways to identify potential attacker activities without affecting production servers:
Video surveillance: This is a physical security technique that uses cameras and monitors to record and observe the activities in a certain area. Video surveillance can help to deter, detect, and investigate physical intrusions, but it does not directly identify the attacker’s activities on the network or the servers3.
Zero Trust: This is a security strategy that assumes that no user, device, or network is trustworthy by default and requires strict verification and validation for every request and transaction. Zero Trust can help to improve the security posture and reduce the attack surface of an organization, but it does not directly identify the attacker’s activities on the network or the servers4.
Geofencing: This is a security technique that uses geographic location as a criterion to restrict or allow access to data or resources. Geofencing can help to protect the data sovereignty and compliance of an organization, but it does not directly identify the attacker’s activities on the network or the servers5.
Reference = 1: CompTIA Security+ SY0-701 Certification Study Guide, page 542: Honeypots and
Deception C SY0-601 CompTIA Security+: 2.1, video by Professor Messer3: CompTIA Security+ SY0-
701 Certification Study Guide, page 974: CompTIA Security+ SY0-701 Certification Study Guide, page
985: CompTIA Security+ SY0-701 Certification Study Guide, page 99.
Which of the following is the most effective way to protect an application server running software that is no longer supported from network threats?
- A . Air gap
- B . Barricade
- C . Port security
- D . Screen subnet
A
Explanation:
Air-gapping is the most effective way to protect an application server running unsupported software from network threats. By physically isolating the server from any network connection (no wired or wireless communication), it is protected from external cyber threats. While other options like port security or a screened subnet can provide some level of protection, an air gap offers the highest level of security by preventing any network-based attacks entirely.
Reference =
CompTIA Security+ SY0-701 Course Content: Domain 03 Security Architecture.
CompTIA Security+ SY0-601 Study Guide: Chapter on Secure System Design.
A security administrator needs to reduce the attack surface in the company’s data centers.
Which of the following should the security administrator do to complete this task?
- A . Implement a honeynet.
- B . Define Group Policy on the servers.
- C . Configure the servers for high availability.
- D . Upgrade end-of-support operating systems.
D
Explanation:
Upgrading end-of-support operating systems is one of the most effective ways to reduce the attack surface. Unsupported OS versions no longer receive security patches, making them prime targets for attackers. Removing outdated software ensures that known vulnerabilities cannot be exploited. A (honeynet) is used for threat analysis, not reducing the attack surface.
B (Group Policy) helps enforce security policies but does not address outdated vulnerabilities.
C (High availability) focuses on uptime, not security risk reduction.
Reference: CompTIA Security+ SY0-701 Official Study Guide, Security Architecture domain.
Which of the following considerations is the most important for an organization to evaluate as it establishes and maintains a data privacy program?
- A . Reporting structure for the data privacy officer
- B . Request process for data subject access
- C . Role as controller or processor
- D . Physical location of the company
C
Explanation:
The most important consideration when establishing a data privacy program is defining the organization’s role as a controller or processor. These roles, as outlined in privacy regulations such as the General Data Protection Regulation (GDPR), determine the responsibilities regarding the handling of personal data. A controller is responsible for determining the purpose and means of data processing, while a processor acts on behalf of the controller. This distinction is crucial for compliance with data privacy laws.
Reporting structure for the data privacy officer is important, but it is a secondary consideration compared to legal roles.
Request process for data subject access is essential for compliance but still depends on the organization’s role as controller or processor.
Physical location of the company can affect jurisdiction, but the role as controller or processor has a broader and more immediate impact.
An organization wants to improve the company’s security authentication method for remote employees.
Given the following requirements:
• Must work across SaaS and internal network applications
• Must be device manufacturer agnostic
• Must have offline capabilities
Which of the following would be the most appropriate authentication method?
- A . Username and password
- B . Biometrics
- C . SMS verification
- D . Time-based tokens