Security+ Practice Questions (Ethical) with Clear Explanations — SY0-701
Ethical, original, and exam-style scenarios. Learn the “why” behind each answer, build judgment, and boost confidence—without touching dumps or shortcuts.
Table of Contents
- How to Use These Questions
- Domain 1 — Threats, Attacks & Vulnerabilities
- Domain 2 — Architecture & Design
- Domain 3 — Implementation (IAM, Crypto, Network)
- Domain 4 — Operations & Incident Response
- Domain 5 — Governance, Risk & Compliance (GRC)
- 30-Day Study Plan (Realistic)
- Cheat Sheets & Decision Tables
- Security+ Practice FAQ
- Get Security+ SY0-701 — Secure & Fast
- Attribution & Reuse Notice
How to Use These Questions
First, attempt each question without peeking. Then review the explanation and write a one-line takeaway in your notes. Finally, convert missed items into flashcards. Over time, your accuracy and speed will improve naturally.
Domain 1 — Threats, Attacks & Vulnerabilities
Q1. A user reports a sudden MFA prompt flood. Shortly after, there’s a successful login from the same device. What happened?
- Credential stuffing with legacy auth
- MFA fatigue attack that finally gained approval
- SIM swap enabling SMS interception
- Session fixation on a public kiosk
Q2. After a phishing campaign, several accounts create new mailbox rules to auto-forward mail externally. What control should trigger first?
- End-user training emails
- Quarterly access reviews
- An alert on suspicious mailbox forwarding rules
- Annual password rotation
Q3. A web app shows a unique token in the URL. Later, another user reuses that URL to access the previous session. Which flaw fits best?
- Command injection
- Insecure direct object reference / session leakage
- Buffer overflow
- XML entity expansion
Q4. Which scenario best indicates a supply-chain compromise?
- Admin sets a weak password
- Phishing email bypasses a filter
- Trusted software update adds a malicious DLL
- Rogue AP discovered in a branch office
Domain 2 — Architecture & Design
Q5. You’re segmenting a flat network. Which first step reduces risk fastest with minimal disruption?
- Implement full zero trust in one sprint
- Create user, server, and guest VLANs with default-deny
- Deploy a new SIEM before any changes
- Purchase a second data center
Q6. A partner requires temporary access to a single internal API. Which design choice is most appropriate?
- Full site-to-site VPN to the core network
- Grant partner accounts domain-admin
- Reverse proxy in a DMZ with narrow allow-lists
- Expose the API directly to the internet
Q7. Which principle is central to zero trust?
- Encrypt data at rest only
- Verify explicitly and grant least privilege
- Allow by default inside the LAN
- Disable all remote work options
Domain 3 — Implementation (IAM, Crypto, Network)
Q8. A team wants to store user passwords securely. Which statement is best?
- Encrypt passwords so admins can read them
- Hash without salt for speed
- Use salted hashing and keep a separate pepper
- Store in plain text but restrict access
Q9. During a TLS handshake, why is asymmetric crypto used first?
- It is faster for bulk data
- It authenticates the server and sets up a session key
- It compresses files
- It rotates symmetric keys
Q10. Which control best enforces least privilege for admins?
- One shared local admin account
- Break-glass accounts, JIT elevation, and auditing
- Permanent global admin for convenience
- Unlogged sudo sessions
Q11. A remote worker connects over public Wi-Fi. Which combination is strongest?
- HTTP portal + SMS OTP
- Split-tunnel VPN + local admin rights
- Full-tunnel VPN + device posture + phishing-resistant MFA
- RDP open to the internet
Domain 4 — Operations & Incident Response
Q12. You see a sudden spike in outbound DNS from a single host. What is the best next step?
- Disable the SIEM rule
- Investigate the host and contain if needed
- Reboot the domain controller
- Ignore because DNS is normal
Q13. Which order reflects basic evidence volatility?
- Disk → RAM → Logs
- Logs → Disk → RAM
- RAM → Temp files → Disk → Remote logs
- Archive → Disk → RAM
Q14. After containing a malware outbreak, what proves systems are clean before go-live?
- Team consensus
- Disabling logging
- Validation against a golden baseline plus monitoring
- Extending admin rights temporarily
Domain 5 — Governance, Risk & Compliance (GRC)
Q15. Leadership asks for a risk treatment that removes exposure entirely. Which option fits?
- Mitigate
- Transfer
- Avoid
- Accept
Q16. A card-processing app is being redesigned. Which statement aligns with PCI DSS concepts?
- Mix cardholder data with general traffic
- Segment and monitor the cardholder data environment
- Disable logging to protect privacy
- Ignore quarterly scans
Mixed Scenario Set — Pulling It Together
Q17. A contractor’s unmanaged laptop connects to Wi-Fi and immediately accesses HR data. Which two controls would have helped most?
- Port mirroring and SPAN
- NAC posture checks and VLAN quarantine
- Disable TLS
- Guest SSID bridged to the LAN
Q18. You discover an expired TLS certificate on a public site. What is the correct action order?
- Reboot the web server; ignore the error
- Change the DNS record only
- Renew/replace the certificate, update bindings, and verify chain
- Disable HTTPS temporarily
Q19. A developer proposes storing API keys in code for speed. Which safer alternative is best?
- Hard-code secrets but obfuscate
- Keep keys in a public repo for visibility
- Use a secrets manager with role-based access
- Email keys to the team weekly
Q20. Which set most directly supports “defense in depth” for remote access?
- Public RDP + local admin + shared passwords
- VPN + MFA + least privilege + logs to SIEM
- Guest Wi-Fi bridged to servers
- SNMPv1 for all routers
30-Day Study Plan (Realistic)
Week 1 — Core Concepts
- Threats and common attacks
- Crypto basics: hashing vs encryption vs HMAC
- Network segmentation and secure protocols
- Daily: 10–15 original questions + review
Week 2 — Design & IAM
- Zero trust, NAC, VPN concepts
- Access models and MFA choices
- Daily: 15 questions + 30-min lab note
Week 3 — IR & Ops
- IR phases, SIEM triage, evidence basics
- Two tabletops (phishing, malware)
- Daily: 15 questions + playbook edit
Week 4 — GRC & Final Review
- NIST/ISO ideas; risk register walkthrough
- Two timed mixed sets (25 Q each)
- One-page quick sheet: protocols, IAM, IR steps
Cheat Sheets & Decision Tables
When to Use What (Quick Map)
| Need | Pick | Why |
|---|---|---|
| Integrity + authenticity | Digital signature or HMAC | Verify origin and detect changes |
| Confidentiality in transit | TLS/VPN concepts | Encrypt and verify peer identity |
| Limit lateral movement | VLANs + default deny | Shrink blast radius |
| Unmanaged device | NAC + quarantine | Block access until compliant |
| Evidence integrity | Chain of custody + hashing | Maintain authenticity |
Security+ Practice FAQ
How many questions should I do per day?
Start with 10–15. Then increase to 25 mixed questions as your speed improves.
Should I memorize answers?
No. Understand the reasoning. Because the exam is scenario-based, judgment matters more than recall.
How do I close weak gaps?
Track misses in a notebook. Next, read the explanation. Finally, build a flashcard and retest in 48 hours.
Get CompTIA Security+ SY0-701 — Secure & Fast
For a secure and fast path to your CompTIA Security+ SY0-701 certification, start here. Then follow ethical registration and preparation steps:
Get Security+ SY0-701 — Start Now
Attribution & Reuse Notice
You may copy or republish this article, provided you include proper attribution with the site name and URL:
CertGet — www.Certget.com.