CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 1)

A company purchased cyber insurance to address items listed on the risk register.
Which of the following strategies does this represent?

  1. Accept
  2. Transfer
  3. Mitigate
  4. Avoid

Answer(s): B



Which of the following is the most likely to be used to document risks, responsible parties, and thresholds?

  1. Risk tolerance
  2. Risk transfer
  3. Risk register
  4. Risk analysis

Answer(s): C



HOTSPOT (Drag and Drop is not supported)
You are a security administrator investigating a potential infection on a network.
INSTRUCTIONS
Click on each host and firewall. Review all logs to determine which host originated the infection and then identify if each remaining host is clean or infected.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.






Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



A systems administrator notices that the research and development department is not using the company VPN when accessing various company-related services and systems.
Which of the following scenarios describes this activity?

  1. Espionage
  2. Data exfiltration
  3. Nation-state attack
  4. Shadow IT

Answer(s): D



Which of the following threat vectors is most commonly utilized by insider threat actors attempting data exfiltration?

  1. Unidentified removable devices
  2. Default network device credentials
  3. Spear phishing emails
  4. Impersonation of business units through typosquatting

Answer(s): A



Which of the following agreement types defines the time frame in which a vendor needs to respond?

  1. SOW
  2. SLA
  3. MOA
  4. MOU

Answer(s): B



Which of the following is a feature of a next-generation SIEM system?

  1. Virus signatures
  2. Automated response actions
  3. Security agent deployment
  4. Vulnerability scanning

Answer(s): B



To improve the security at a data center, a security administrator implements a CCTV system and posts several signs about the possibility of being filmed.
Which of the following best describe these types of controls? (Choose two.)

  1. Preventive
  2. Deterrent
  3. Corrective
  4. Directive
  5. Compensating
  6. Detective

Answer(s): B,F



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!