CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 24)

A penetration tester enters an office building at the same time as a group of employees despite not having an access badge.
Which of the following attack types is the penetration tester performing?

  1. Tailgating
  2. Shoulder surfing
  3. RFID cloning
  4. Forgery

Answer(s): A

Explanation:

Tailgating is a social engineering technique where an unauthorized person gains access to a restricted area by following closely behind authorized individuals without their knowledge or consent. In this scenario, the penetration tester enters the office building at the same time as a group of employees despite not having an access badge, which exemplifies tailgating.



Which of the following enables the ability to receive a consolidated report from different devices on the network?

  1. IPS
  2. DLP
  3. SIEM
  4. Firewall

Answer(s): C

Explanation:

SIEM (Security Information and Event Management) systems aggregate and analyze log data from various devices across a network, enabling the collection, correlation, and analysis of security-related events. SIEM provides a consolidated report of activities, helping to identify potential security incidents by correlating data from multiple sources, which enhances visibility and response capabilities across the network.



Which of the following should an organization focus on the most when making decisions about vulnerability prioritization?

  1. Exposure factor
  2. CVSS
  3. CVE
  4. Industry impact

Answer(s): B

Explanation:

The Common Vulnerability Scoring System (CVSS) is a widely used standard that provides a numerical score reflecting the severity of a vulnerability. Organizations use CVSS scores to prioritize vulnerabilities based on their potential impact and exploitability, which helps in assessing which vulnerabilities need urgent remediation. This approach enables systematic vulnerability prioritization based on quantifiable metrics.



An organization needs to monitor its users’ activities in order to prevent insider threats.
Which of the following solutions would help the organization achieve this goal?

  1. Behavioral analytics
  2. Access control lists
  3. Identity and access management
  4. Network intrusion detection system

Answer(s): A

Explanation:

Behavioral analytics involves monitoring and analyzing user behaviors to detect unusual or suspicious patterns that may indicate insider threats. By establishing a baseline of normal behavior, behavioral analytics solutions can identify deviations that could signal potential malicious or risky activities by users, helping to prevent insider threats. This approach is effective in detecting unauthorized actions that traditional access control or identity management systems might miss.



A customer of a large company receives a phone call from someone claiming to work for the company and asking for the customer’s credit card information. The customer sees the caller ID is the same as the company's main phone number.
Which of the following attacks is the customer most likely a target of?

  1. Phishing
  2. Whaling
  3. Smishing
  4. Vishing

Answer(s): D

Explanation:

Vishing (voice phishing) is a social engineering attack where attackers impersonate a trusted entity over the phone to obtain sensitive information, such as credit card details. In this case, the attacker spoofed the company's main phone number on the caller ID to gain the customer’s trust, making it likely that the customer is the target of a vishing attack.



A security analyst is reviewing logs to identify the destination of command-and-control traffic originating from a compromised device within the on-premises network.
Which of the following is the best log to review?

  1. IDS
  2. Antivirus
  3. Firewall
  4. Application

Answer(s): C

Explanation:

Firewall logs are ideal for identifying the destination of command-and-control (C2) traffic because they log all inbound and outbound connections, including IP addresses, ports, and protocols used. By reviewing firewall logs, a security analyst can trace where the compromised device is attempting to send data and potentially identify the external command-and-control server, aiding in the containment of the threat.



When trying to access an internal website, an employee reports that a prompt displays, stating that the site is insecure.
Which of the following certificate types is the site most likely using?

  1. Wildcard
  2. Root of trust
  3. Third-party
  4. Self-signed

Answer(s): D

Explanation:

A self-signed certificate is not issued by a trusted certificate authority, which often causes browsers to flag it as insecure.
When accessing a site with a self-signed certificate, users typically receive a warning about the site’s security since the certificate cannot be automatically trusted, making it likely that the internal website is using a self-signed certificate.



Which of the following would most likely be deployed to obtain and analyze attacker activity and techniques?

  1. Firewall
  2. IDS
  3. Honeypot
  4. Layer 3 switch

Answer(s): C

Explanation:

A honeypot is a decoy system or network resource designed to attract attackers and observe their activity. It is intentionally left vulnerable to capture and analyze attacker behavior, techniques, and tools, providing valuable insights into potential threats without risking actual production systems. This makes it the ideal choice for studying attacker tactics and patterns.



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!