CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 21)

Which of the following data states applies to data that is being actively processed by a database server?

  1. In use
  2. At rest
  3. In transit
  4. Being hashed

Answer(s): A

Explanation:

Data "in use" refers to data actively being accessed, processed, or modified by an application or system, such as a database server. This is distinct from data "at rest," which is stored but not actively accessed, and data "in transit," which is being transmitted over a network.



Which of the following architectures is most suitable to provide redundancy for critical business processes?

  1. Network-enabled
  2. Server-side
  3. Cloud-native
  4. Multitenant

Answer(s): C

Explanation:

Cloud-native architectures are designed with scalability, redundancy, and resilience in mind. They leverage the distributed nature of cloud infrastructure, allowing for automatic failover, load balancing, and redundancy across multiple geographic regions. This ensures high availability and continuous operation for critical business processes, even in the event of hardware or regional failures.



After a security incident, a systems administrator asks the company to buy a NAC platform.
Which of the following attack surfaces is the systems administrator trying to protect?

  1. Bluetooth
  2. Wired
  3. NFC
  4. SCADA

Answer(s): B

Explanation:

Network Access Control (NAC) platforms are primarily used to secure access to the organization's network, typically focusing on wired and wireless connections. By implementing NAC, the administrator can control which devices are allowed to connect to the network and enforce security policies, reducing the risk of unauthorized access via the wired network.



While reviewing logs, a security administrator identifies the following code:
<script>function (send_info)</script>
Which of the following best describes the vulnerability being exploited?

  1. XSS
  2. SQLi
  3. DDoS
  4. CSRF

Answer(s): A

Explanation:

The <script> tags in the code suggest a Cross-Site Scripting (XSS) attack, where malicious scripts are injected into web pages viewed by other users. XSS vulnerabilities allow attackers to execute scripts in the context of a user's browser, which can lead to data theft, session hijacking, and other malicious actions.



An organization issued new laptops to all employees and wants to provide web filtering both in and out of the office without configuring additional access to the network.
Which of the following types of web filtering should a systems administrator configure?

  1. Agent-based
  2. Centralized proxy
  3. URL scanning
  4. Content categorization

Answer(s): A

Explanation:

An agent-based web filtering solution installs a software agent directly on the laptops. This approach allows the filtering to work regardless of the device's location (in or out of the office) without requiring additional network configuration. The agent enforces web filtering policies locally on each laptop, ensuring consistent protection across various network environments.



Which of the following should be used to aggregate log data in order to create alerts and detect anomalous activity?

  1. SIEM
  2. WAF
  3. Network taps
  4. IDS

Answer(s): A

Explanation:

A SIEM solution collects and aggregates log data from various sources across the network, enabling real-time monitoring, correlation, and alerting on security events. It is designed to detect anomalous activity and provide insights into potential security incidents by analyzing patterns and behaviors across the log data.



Which of the following provides the best protection against unwanted or insecure communications to and from a device?

  1. System hardening
  2. Host-based firewall
  3. Intrusion detection system
  4. Anti-malware software

Answer(s): B

Explanation:

A host-based firewall monitors and controls incoming and outgoing network traffic on a specific device, based on predetermined security rules. It provides protection by blocking unauthorized or potentially harmful communications, ensuring that only trusted traffic can access the device. This helps prevent both inbound and outbound threats at the device level.



Which of the following is the primary purpose of a service that tracks log-ins and time spent using the service?

  1. Availability
  2. Accounting
  3. Authentication
  4. Authorization

Answer(s): B

Explanation:

Accounting involves tracking and recording user activities, such as log-ins and time spent using a service. This information can be used for auditing, billing, usage analysis, and ensuring compliance with policies. Accounting is one of the components of the AAA model (Authentication, Authorization, and Accounting).



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!