CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 9)

A security administrator is working to find a cost-effective solution to implement certificates for a large number of domains and subdomains owned by the company.
Which of the following types of certificates should the administrator implement?

  1. Wildcard
  2. Client certificate
  3. Self-signed
  4. Code signing

Answer(s): A



An auditor discovered multiple insecure ports on some servers. Other servers were found to have legacy protocols enabled.
Which of the following tools did the auditor use to discover these issues?

  1. Nessus
  2. curl
  3. Wireshark
  4. netcat

Answer(s): A



A security analyst received a tip that sensitive proprietary information was leaked to the public. The analyst is reviewing the PCAP and notices traffic between an internal server and an external host that includes the following:
... 12:47:22.327233 PPPoE [ses 0x8122] IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto IPv6 (41), length 331) 10.5.1.1 > 52.165.16.154: IP6 (hlim E3, next-header TCP (6) paylcad length: 271) 2001:67c:2158:a019::ace.53104 > 2001:0:5ef5:79fd:380c:dddd:a601:24fa.13788: Flags [P.], cksum 0xd7ee (correct), seq 97:348, ack 102, win 16444, length 251 ...
Which of the following was most likely used to exfiltrate the data?

  1. Encapsulation
  2. MAC address spoofing
  3. Steganography
  4. Broken encryption
  5. Sniffing via on-path position

Answer(s): A



A company wants to reduce the time and expense associated with code deployment.
Which of the following technologies should the company utilize?

  1. Serverless architecture
  2. Thin clients
  3. Private cloud
  4. Virtual machines

Answer(s): A



A security administrator is performing an audit on a stand-alone UNIX server, and the following message is immediately displayed:
(Error 13): /etc/shadow: Permission denied.
Which of the following best describes the type of tool that is being used?

  1. Pass-the-hash monitor
  2. File integrity monitor
  3. Forensic analysis
  4. Password cracker

Answer(s): D



A security administrator needs to create firewall rules for the following protocols: RTP, SIP, H.323. and SRTP.
Which of the following does this rule set support?

  1. RTOS
  2. VoIP
  3. SoC
  4. HVAC

Answer(s): B



Which of the following best describes a social engineering attack that uses a targeted electronic messaging campaign aimed at a Chief Executive Officer?

  1. Whaling
  2. Spear phishing
  3. Impersonation
  4. Identity fraud

Answer(s): A



During a penetration test, a flaw in the internal PKI was exploited to gain domain administrator rights using specially crafted certificates.
Which of the following remediation tasks should be completed as part of the cleanup phase?

  1. Updating the CRL
  2. Patching the CA
  3. Changing passwords
  4. Implementing SOAR

Answer(s): B



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!