CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 6)

Which of the following best describes a use case for a DNS sinkhole?

  1. Attackers can see a DNS sinkhole as a highly valuable resource to identify a company's domain structure.
  2. A DNS sinkhole can be used to draw employees away from known-good websites to malicious ones owned by the attacker.
  3. A DNS sinkhole can be used to capture traffic to known-malicious domains used by attackers.
  4. A DNS sinkhole can be set up to attract potential attackers away from a company's network resources.

Answer(s): C



An incident analyst finds several image files on a hard disk. The image files may contain geolocation coordinates.
Which of the following best describes the type of information the analyst is trying to extract from the image files?

  1. Log data
  2. Metadata
  3. Encrypted data
  4. Sensitive data

Answer(s): B



Which of the following most likely describes why a security engineer would configure all outbound emails to use S/MIME digital signatures?

  1. To meet compliance standards
  2. To increase delivery rates
  3. To block phishing attacks
  4. To ensure non-repudiation

Answer(s): D



During a recent company safety stand-down, the cyber-awareness team gave a presentation on the importance of cyber hygiene. One topic the team covered was best practices for printing centers.
Which of the following describes an attack method that relates to printing centers?

  1. Whaling
  2. Credential harvesting
  3. Prepending
  4. Dumpster diving

Answer(s): D



Which of the following considerations is the most important regarding cryptography used in an IoT device?

  1. Resource constraints
  2. Available bandwidth
  3. The use of block ciphers
  4. The compatibility of the TLS version

Answer(s): A



A coffee shop owner wants to restrict internet access to only paying customers by prompting them for a receipt number.
Which of the following is the best method to use given this requirement?

  1. WPA3
  2. Captive portal
  3. PSK
  4. IEEE 802.1X

Answer(s): B



While performing digital forensics, which of the following is considered the most volatile and should have the contents collected first?

  1. Hard drive
  2. RAM
  3. SSD
  4. Temporary files

Answer(s): B



A hosting provider needs to prove that its security controls have been in place over the last six months and have sufficiently protected customer data.
Which of the following would provide the best proof that the hosting provider has met the requirements?

  1. NIST CSF
  2. SOC 2 Type 2 report
  3. CIS Top 20 compliance reports
  4. Vulnerability report

Answer(s): B



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!