CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 14)

Which of the following topics would most likely be included within an organization's SDLC?

  1. Service-level agreements
  2. Information security policy
  3. Penetration testing methodology
  4. Branch protection requirements

Answer(s): D



Which of the following control types is AUP an example of?

  1. Physical
  2. Managerial
  3. Technical
  4. Operational

Answer(s): D



An organization is adopting cloud services at a rapid pace and now has multiple SaaS applications in use. Each application has a separate log-in, so the security team wants to reduce the number of credentials each employee must maintain.
Which of the following is the first step the security team should take?

  1. Enable SAML.
  2. Create OAuth tokens.
  3. Use password vaulting.
  4. Select an IdP.

Answer(s): D



A company's online shopping website became unusable shortly after midnight on January 30, 2023.
When a security analyst reviewed the database server, the analyst noticed the following code used for backing up data:

Which of the following should the analyst do next?

  1. Check for recently terminated DBAs.
  2. Review WAF logs for evidence of command injection.
  3. Scan the database server for malware.
  4. Search the web server for ransomware notes.

Answer(s): B



Which of the following would be the best way to test resiliency in the event of a primary power failure?

  1. Parallel processing
  2. Tabletop exercise
  3. Simulation testing
  4. Production failover

Answer(s): D



Which of the following would be the most appropriate way to protect data in transit?

  1. SHA-256
  2. SSL3.0
  3. TLS 1.3
  4. AES-256

Answer(s): C



Which of the following is a common, passive reconnaissance technique employed by penetration testers in the early phases of an engagement?

  1. Open-source intelligence
  2. Port scanning
  3. Pivoting
  4. Exploit validation

Answer(s): A



Which of the following threat actors is the most likely to seek financial gain through the use of ransomware attacks?

  1. Organized crime
  2. Insider threat
  3. Nation-state
  4. Hacktivists

Answer(s): A

Explanation:

Organized crime groups are primarily motivated by financial gain. Ransomware attacks are a popular tool for these groups because they can encrypt a victim's data and demand a ransom payment (often in cryptocurrency) to restore access. This form of attack can yield a high financial return if victims choose to pay.



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!