CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 3)

A company allows customers to upload PDF documents to its public e-commerce website.
Which of the following would a security analyst most likely recommend?

  1. Utilizing attack signatures in an IDS
  2. Enabling malware detection through a UTM
  3. Limiting the affected servers with a load balancer
  4. Blocking command injections via a WAF

Answer(s): B



A security analyst developed a script to automate a trivial and repeatable task.
Which of the following best describes the benefits of ensuring other team members understand how the script works?

  1. To reduce implementation cost
  2. To identify complexity
  3. To remediate technical debt
  4. To prevent a single point of failure

Answer(s): D



A company is decommissioning its physical servers and replacing them with an architecture that will reduce the number of individual operating systems.
Which of the following strategies should the company use to achieve this security requirement?

  1. Microservices
  2. Containerization
  3. Virtualization
  4. Infrastructure as code

Answer(s): B



An administrator needs to perform server hardening before deployment.
Which of the following steps should the administrator take? (Choose two.)

  1. Disable default accounts.
  2. Add the server to the asset inventory.
  3. Remove unnecessary services.
  4. Document default passwords.
  5. Send server logs to the SIEM.
  6. Join the server to the corporate domain.

Answer(s): A,C



A Chief Information Security Officer would like to conduct frequent, detailed reviews of systems and procedures to track compliance objectives.
Which of the following will be the best method to achieve this objective?

  1. Third-party attestation
  2. Penetration testing
  3. Internal auditing
  4. Vulnerability scans

Answer(s): C



Which of the following security concepts is accomplished with the installation of a RADIUS server?

  1. CIA
  2. AAA
  3. ACL
  4. PEM

Answer(s): B



After creating a contract for IT contractors, the human resources department changed several clauses. The contract has gone through three revisions.
Which of the following processes should the human resources department follow to track revisions?

  1. Version validation
  2. Version changes
  3. Version updates
  4. Version control

Answer(s): D



The executive management team is mandating the company develop a disaster recovery plan. The cost must be kept to a minimum, and the money to fund additional internet connections is not available.
Which of the following would be the best option?

  1. Hot site
  2. Cold site
  3. Failover site
  4. Warm site

Answer(s): B



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!