CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 7)

A city municipality lost its primary data center when a tornado hit the facility.
Which of the following should the city staff use immediately after the disaster to handle essential public services?

  1. BCP
  2. Communication plan
  3. DRP
  4. IRP

Answer(s): C



Which of the following is considered a preventive control?

  1. Configuration auditing
  2. Log correlation
  3. Incident alerts
  4. Segregation of duties

Answer(s): D



A systems administrator notices that a testing system is down.
While investigating, the systems administrator finds that the servers are online and accessible from any device on the server network. The administrator reviews the following information from the monitoring system:

Which of the following is the most likely cause of the outage?

  1. Denial of service
  2. ARP poisoning
  3. Jamming
  4. Kerberoasting

Answer(s): A



A security team has been alerted to a flood of incoming emails that have various subject lines and are addressed to multiple email inboxes. Each email contains a URL shortener link that is redirecting to a dead domain.
Which of the following is the best step for the security team to take?

  1. Create a blocklist for all subject lines.
  2. Send the dead domain to a DNS sinkhole.
  3. Quarantine all emails received and notify all employees.
  4. Block the URL shortener domain in the web proxy.

Answer(s): D



A security administrator is working to secure company data on corporate laptops in case the laptops are stolen.
Which of the following solutions should the administrator consider?

  1. Disk encryption
  2. Data loss prevention
  3. Operating system hardening
  4. Boot security

Answer(s): A



A company needs to keep the fewest records possible, meet compliance needs, and ensure destruction of records that are no longer needed.
Which of the following best describes the policy that meets these requirements?

  1. Security policy
  2. Classification policy
  3. Retention policy
  4. Access control policy

Answer(s): C



Which of the following is a common source of unintentional corporate credential leakage in cloud environments?

  1. Code repositories
  2. Dark web
  3. Threat feeds
  4. State actors
  5. Vulnerability databases

Answer(s): A



Which of the following is the best reason an organization should enforce a data classification policy to help protect its most sensitive information?

  1. End users will be required to consider the classification of data that can be used in documents.
  2. The policy will result in the creation of access levels for each level of classification.
  3. The organization will have the ability to create security requirements based on classification levels.
  4. Security analysts will be able to see the classification of data within a document before opening it.

Answer(s): C



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!