CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 4)

An administrator at a small business notices an increase in support calls from employees who receive a blocked page message after trying to navigate to a spoofed website.
Which of the following should the administrator do?

  1. Deploy multifactor authentication.
  2. Decrease the level of the web filter settings.
  3. Implement security awareness training.
  4. Update the acceptable use policy.

Answer(s): C



Which of the following teams is best suited to determine whether a company has systems that can be exploited by a potential, identified vulnerability?

  1. Purple team
  2. Blue team
  3. Red team
  4. White team

Answer(s): C



A company is reviewing options to enforce user logins after several account takeovers. The following conditions must be met as part of the solution:
-Allow employees to work remotely or from assigned offices around the world.
-Provide a seamless login experience.
-Limit the amount of equipment required.
Which of the following best meets these conditions?

  1. Trusted devices
  2. Geotagging
  3. Smart cards
  4. Time-based logins

Answer(s): A



Which of the following methods can be used to detect attackers who have successfully infiltrated a network? (Choose two.)

  1. Tokenization
  2. CI/CD
  3. Honeypots
  4. Threat modeling
  5. DNS sinkhole
  6. Data obfuscation

Answer(s): C,E



A company wants to ensure that the software it develops will not be tampered with after the final version is completed.
Which of the following should the company most likely use?

  1. Hashing
  2. Encryption
  3. Baselines
  4. Tokenization

Answer(s): A



An organization completed a project to deploy SSO across all business applications last year. Recently, the finance department selected a new cloud-based accounting software vendor.
Which of the following should most likely be configured during the new software deployment?

  1. RADIUS
  2. SAML
  3. EAP
  4. OpenID

Answer(s): B



A user, who is waiting for a flight at an airport, logs in to the airline website using the public Wi-Fi, ignores a security warning and purchases an upgraded seat.
When the flight lands, the user finds unauthorized credit card charges.
Which of the following attacks most likely occurred?

  1. Replay attack
  2. Memory leak
  3. Buffer overflow attack
  4. On-path attack

Answer(s): D



A network engineer deployed a redundant switch stack to increase system availability. However, the budget can only cover the cost of one ISP connection.
Which of the following best describes the potential risk factor?

  1. The equipment MTBF is unknown.
  2. The ISP has no SLA.
  3. An RPO has not been determined.
  4. There is a single point of failure.

Answer(s): D



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!