PassFish

SY0-701 practice questions — 10 free

CompTIA Security+ · every answer carries the reasoning, and why each other option fails.
2,147 questions
9 chapters of notes
EN + ZH languages

Tap an option to see the answer, the reasoning, and why the other three fail.

Question 1 of 10

Which of the following threat actors is the most likely to be hired by a foreign government to attack critical systems located in other countries?

Why C is correct

The determining fact is "hired by a foreign government": being paid, organized, and attacking another nation's critical systems on order is the classic pattern of organized crime being used as a state proxy — the government pays for capability while retaining plausible deniability. The exam objectives distinguish threat actors along three lines: resources/funding, technical sophistication, and motivation. Organized crime is well-funded, technically mature, and driven purely by profit, so the target can be anyone as long as the price is right. The trap is reflexively jumping to "nation-state" the moment "foreign government" appears — but that option isn't even on the list here, and the word "hired" itself rules out the government's own military cyber units, since your own staff isn't something you hire.

Question 2 of 10

Which of the following should a security administrator adhere to when setting up a new set of firewall rules?

Why D is correct

Firewall rules directly determine what traffic can pass in and out of the network — getting even one rule wrong can disrupt business or open an unintended pathway — so this is a textbook controlled change: it must go through a change request, impact analysis, a defined implementation and rollback window, approval, and then execution, with the rule documentation and network diagrams updated afterward. The change management procedure is exactly what governs this whole set of actions, delivering an approval trail, the ability to roll back, and after-the-fact auditability. The determining factor is that the prompt asks what should be followed "when setting up new rules," which lands on the routine authorization process for operations. The trap is being drawn to the names of the three emergency-related plans, but disaster recovery, business continuity, and incident response are all plans triggered after something has already gone wrong — they are not on the same timeline as day-to-day configuration changes.

Question 3 of 10

An organization is building a new backup data center with cost-benefit as the primary requirement and RTO and RPO values around two days. Which of the following types of sites is the best for this scenario?

Why D is correct

Choosing a site type is essentially a balance between cost and recovery speed: a hot site has full hardware with real-time data synchronization and can switch over in minutes, but is the most expensive; a cold site has only the site and power, taking weeks to recover but being the cheapest; a warm site sits between the two — it has hardware and networking, with data synchronized periodically, and can typically be brought into service in one to a few days. The RTO and RPO given in the question are both around two days, and cost-benefit is stated as the top priority, which lands squarely in the capability range of a warm site. The point being tested is matching each of the three site types to its recovery time and cost. The trap is letting the phrase "cost-benefit as the primary requirement" push you toward the cold site: a cold site is indeed the cheapest, but recovery is measured in weeks and cannot meet a two-day target.

Question 4 of 10

What type of gap analysis involves evaluating an organization's current technical infrastructure and identifying areas where it falls short of required technical capabilities?

Why A is correct

Correct Answer: A) Technical gap analysis

Question 5 of 10

What is the purpose of a Certificate Signing Request (CSR)?

Why D is correct

Correct Answer: D A CSR is used to request a digital certificate from a Certificate Authority (CA) by providing necessary information about the entity requesting the certificate, including its public key.

Question 6 of 10

What is a potential consequence of non-compliance with regulatory considerations?

Why C is correct

Answer: C. Non-compliance with regulatory considerations can lead to severe penalties and reputational damage for organizations, affecting their financial stability, credibility, and trustworthiness in the market.

Question 7 of 10

What role does encryption play in data backups?

Why C is correct

Answer: C) Protecting data from unauthorized access Encryption in data backups helps protect data from unauthorized access and potential breaches. It ensures data confidentiality and integrity, safeguarding sensitive information from prying eyes.

Question 8 of 10

In which scenario would DTLS be a preferred security protocol?

Why B is correct

Answer: B) Securing real-time video streaming DTLS is particularly useful for securing real-time applications such as video streaming, VoIP, online gaming, and other UDP-based communications. Its ability to provide encryption and integrity for UDP traffic makes it suitable for scenarios where low-latency and efficient data transmission are critical, such as in real-time media streaming.

Question 9 of 10

How does missing logs contribute to indicators of compromise?

Why B is correct

Answer: B. Missing logs indicate anomalies in system log files, potentially suggesting tampering or deletion by attackers to cover their tracks and evade detection.

Question 10 of 10

Why is internal reporting considered the first line of defense in vulnerability management?

Why C is correct

C) It identifies, documents, and communicates vulnerabilities within the organization Internal reporting is considered the first line of defense in vulnerability management because it involves identifying, documenting, and communicating vulnerabilities within the organization's structure. This allows for timely remediation and improved security posture.

These 10 are a sample

See the full bank