CompTIA Security+ SY0-701 Certification Exam

CompTIA Security+ SY0-701

The CompTIA Security+ SY0-701 certification validates the core skills needed to secure networks, endpoints and cloud services. The exam covers general security concepts, threats, vulnerabilities and mitigations, security architecture, security operations, and security program management and oversight. Candidates demonstrate knowledge of control types, cryptographic solutions, threat actors and attack surfaces, indicators of malicious activity, zero trust and resilient design, data protection, identity and access management, vulnerability and incident response, automation, and governance, risk and compliance. The exam consists of 90 questions over 90 minutes, with a 75% passing score.

Certification Overview

  • Exam name: Security+ SY0-701
  • Vendor: CompTIA
  • Exam code: SY0-701
  • Duration: 90 minutes
  • Total questions: 90
  • Passing score: 75%

Who Should Take This Exam?

Security Administrator, Systems Administrator, Network Administrator, Security Analyst, SOC Analyst, Security Specialist, Junior IT Auditor, Junior Penetration Tester

Prerequisites

No formal prerequisite. CompTIA recommends Network+ and about two years of experience in IT administration with a security focus.

Topics Covered

  • General Security Concepts
  • Threats, Vulnerabilities, and Mitigations
  • Security Architecture
  • Security Operations
  • Security Program Management and Oversight

Question Types

  • Multiple Choice (Single Answer)
  • Multiple Choice (Multiple Answers)
  • Drag and Drop
  • Scenario-Based

Security+ SY0-701 Practice Questions

Our question bank contains 846+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.

General Security Concepts

A company runs mandatory phishing-awareness training for all employees. Which control category does this program fall under?
  • Technical
  • Operational
  • Physical
  • Managerial
Which control type is intended to discourage a potential attacker from attempting an intrusion, for example by displaying a warning sign?
  • Compensating
  • Corrective
  • Directive
  • Deterrent
Which element of the CIA triad ensures that data has not been altered by an unauthorized party?
  • Integrity
  • Confidentiality
  • Availability
  • Non-repudiation

Threats, Vulnerabilities, and Mitigations

Which type of threat actor is typically driven by political or social beliefs and often defaces websites to make a statement?
  • Organized crime group
  • Hacktivist
  • Unskilled attacker
  • Competitor
Which threat actor typically has the largest budget and most advanced capabilities, and is often motivated by espionage?
  • Unskilled attacker
  • Hacktivist
  • Insider
  • Nation-state
A user receives a text message claiming a parcel delivery failed and containing a link to a fake tracking page. What is this attack called?
  • Smishing
  • Vishing
  • Pharming
  • Whaling

Security Architecture

In an infrastructure-as-a-service deployment, who is responsible for patching the guest operating system on a virtual machine?
  • The cloud provider
  • The customer
  • The hypervisor vendor
  • The internet service provider
What best describes an air-gapped network?
  • A network protected by a next-generation firewall at its edge
  • A network where all traffic runs through encrypted tunnels
  • A network split into VLANs with access control lists applied
  • A network with no connection to other networks or the internet
Data that is currently being processed in a computer's memory is in which state?
  • Data in use
  • Data at rest
  • Data in transit
  • Data in archive

Security Operations

Which wireless security standard replaces the pre-shared key handshake with Simultaneous Authentication of Equals?
  • WPA2-PSK with TKIP
  • WPA3
  • WEP
  • WPA with TKIP
Which tool lets an organization enforce policies on employee smartphones and remotely wipe them if lost?
  • Network access control
  • Load balancer
  • Proxy server
  • Mobile device management
Which asset management activity maintains a list of all hardware and software an organization owns?
  • Inventory
  • Sanitization
  • Disposal
  • Procurement

Security Program Management and Oversight

Which document defines what employees may and may not do with company IT resources?
  • Business impact analysis
  • Acceptable use policy
  • Service level agreement
  • Incident response playbook
In data privacy terms, which role determines the purposes and means of processing personal data?
  • Data processor
  • Data custodian
  • Data subject
  • Data controller
A company buys cyber insurance to cover potential breach costs. Which risk response is this?
  • Transfer
  • Avoid
  • Accept
  • Mitigate

Frequently Asked Questions

How many questions are on the exam?

The Security+ SY0-701 exam contains 90 questions.

What is the passing score?

You need 75% to pass.

How long is the exam?

You have 90 minutes to complete the exam.

More CompTIA Practice Exams

Practice with realistic mock exams to prepare for your CompTIA certification.