CompTIAIntermediateCompTIACybersecuritySecurity OperationsRisk Management
CompTIA Security+ (SY0-701)
SY0-701
The CompTIA Security+ (SY0-701) exam validates essential cybersecurity skills across threats and vulnerabilities, security architecture, security operations, program management, and oversight.
Take a timed, 90-question mock exam that simulates the real test — or browse every question with answers and explanations at your own pace.
Questions
View all →- 1Which of the following threat actors is the most likely to be hired by a foreign government to attack critical systems located in other countries?
- 2Which of the following is used to add extra complexity before using a one-way data transformation algorithm?
- 3An employee clicked a link in an email from a payment website that asked the employee to update contact information. The employee entered the log-in information but received a “page not found” error message. Which of the following types of social engineering attacks occurred?
- 4An enterprise is trying to limit outbound DNS traffic originating from its internal network. Outbound DNS requests will only be allowed from one device with the IP address 10.50.10.25. Which of the following firewall ACLs will accomplish this goal?
- 5A data administrator is configuring authentication for a SaaS application and would like to reduce the number of credentials employees need to maintain. The company prefers to use domain credentials to access new SaaS applications. Which of the following methods would allow this functionality?
- 6Which of the following scenarios describes a possible business email compromise attack?
- 7A company prevented direct access from the database administrators’ workstations to the network segment that contains database servers. Which of the following should a database administrator use to access the database servers?
- 8An organization’s internet-facing website was compromised when an attacker exploited a buffer overflow. Which of the following should the organization deploy to best protect against similar attacks in the future?
- 9An administrator notices that several users are logging in from suspicious IP addresses. After speaking with the users, the administrator determines that the employees were not logging in from those IP addresses and resets the affected users’ passwords. Which of the following should the administrator implement to prevent this type of attack from succeeding in the future?
- 10An employee receives a text message that appears to have been sent by the payroll department and is asking for credential verification. Which of the following social engineering techniques are being attempted? (Choose two.)