CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 10)

A company wants to implement MFA. Which of the following enables the additional factor while using a smart card?

  1. PIN
  2. Hardware token
  3. User ID
  4. SMS

Answer(s): A



A company hired an external consultant to assist with required system upgrades to a critical business application. A systems administrator needs to secure the consultant's access without sharing passwords to critical systems.
Which of the following solutions should most likely be utilized?

  1. TACACS+
  2. SAML
  3. An SSO platform
  4. Role-based access control
  5. PAM software

Answer(s): E



A newly implemented wireless network is designed so that visitors can connect to the wireless network for business activities. The legal department is concerned that visitors might connect to the network and perform illicit activities.
Which of me following should the security team implement to address this concern?

  1. Configure a RADIUS server to manage device authentication.
  2. Use 802.1X on all devices connecting to wireless.
  3. Add a guest captive portal requiring visitors to accept terms and conditions.
  4. Allow for new devices to be connected via WPS.

Answer(s): C



Which of the following data roles is responsible for identifying risks and appropriate access to data?

  1. Owner
  2. Custodian
  3. Steward
  4. Controller

Answer(s): A



Which of the following physical controls can be used to both detect and deter? (Choose two.)

  1. Lighting
  2. Fencing
  3. Signage
  4. Sensor
  5. Bollard
  6. Lock

Answer(s): A,D



A multinational bank hosts several servers in its data center. These servers run a business-critical application used by customers to access their account information.
Which of the following should the bank use to ensure accessibility during peak usage times?

  1. Load balancer
  2. Cloud backups
  3. Geographic dispersal
  4. Disk multipathing

Answer(s): A



The author of a software package is concerned about bad actors repackaging and inserting malware into the software. The software download is hosted on a website, and the author exclusively controls the website's contents.
Which of the following techniques would best ensure the software's integrity?

  1. Input validation
  2. Code signing
  3. Secure cookies
  4. Fuzzing

Answer(s): B



A third-party vendor is moving a particular application to the end-of-life stage at the end of the current year.
Which of the following is the most critical risk if the company chooses to continue running the application?

  1. Lack of security updates
  2. Lack of new features
  3. Lack of support
  4. Lack of source code access

Answer(s): A



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!