CompTIA Security+ (SY0-701) — Questions and Answers
Question 1: What is the relationship between Access Control & Identity Management and ethical professional conduct?
- There is no connection between technical knowledge and ethics
- Ethics applies only to separate, unrelated decisions
- Ethics is relevant only when legal issues arise
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Access Control & Identity Management, as professional conduct and integrity underpin all aspects of practice in this field.
Question 2: What metric best measures the speed of a DevOps team's deployment process?
- Deployment frequency (Correct answer)
- Change failure rate
- Mean Time to Recovery (MTTR)
- Lead time for changes
Correct answer: Deployment frequency
Deployment frequency measures how often code is successfully released to production, directly reflecting pipeline speed and automation maturity.
Question 3: What is the recommended approach to staying current in Cryptography & Data Protection?
- Reviewing initial training materials once per year
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Relying solely on past experience
- Waiting for regulatory changes to force updates
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Cryptography & Data Protection requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 4: What does 'mean time to recovery' (MTTR) measure in DevOps?
- Average number of deployments per week
- Average time to restore service after a failure (Correct answer)
- Average time to build a container image
- Average time to review a pull request
Correct answer: Average time to restore service after a failure
MTTR measures how quickly a team can restore a system to normal operation after an incident, indicating operational resilience.
Question 5: In IoT security, what is firmware over-the-air (FOTA) update?
- Wirelessly delivering firmware updates to IoT devices remotely (Correct answer)
- Sending firmware files via email attachment
- Physically replacing device hardware in the field
- Updating cloud dashboards without device changes
Correct answer: Wirelessly delivering firmware updates to IoT devices remotely
FOTA allows manufacturers to remotely push security patches and feature updates to deployed IoT devices without physical access.
Question 6: Which best describes the scope of Cryptography & Data Protection in professional practice?
- A narrow topic relevant only to entry-level professionals
- A theoretical framework with no practical applications
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- An outdated concept no longer relevant to modern practice
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Cryptography & Data Protection encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 7: What is the most important competency assessed in Database Management & Security for professionals in this field?
- Years of experience without demonstrated skill
- Academic credentials without practical application
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
Correct answer: Applied knowledge and practical problem-solving ability
Database Management & Security assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 8: Which tool is most commonly used for container orchestration in a DevOps environment?
- Kubernetes (Correct answer)
- Ansible
- Terraform
- Jenkins
Correct answer: Kubernetes
Kubernetes is the industry-standard platform for automating deployment, scaling, and management of containerized applications.
Question 9: What is the primary security risk of using unsegmented flat networks for IoT devices?
- Slower Wi-Fi speeds for laptops
- Higher electricity costs for IoT sensors
- Increased latency for cloud API calls
- Compromised IoT devices can laterally move to attack critical corporate systems (Correct answer)
Correct answer: Compromised IoT devices can laterally move to attack critical corporate systems
Without network segmentation, a compromised IoT device has unrestricted access to the same network as servers and workstations, enabling lateral movement attacks.
Question 10: What does a risk matrix assess?
- Only the financial cost of risks
- The number of employees affected
- The timeline for risk resolution
- The probability and impact of identified risks (Correct answer)
Correct answer: The probability and impact of identified risks
A risk matrix evaluates risks based on two dimensions: the probability (likelihood) of occurrence and the potential impact (severity) if the risk materializes.
Question 11: What is the recommended approach to staying current in System Administration & Configuration?
- Reviewing initial training materials once per year
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Relying solely on past experience
- Waiting for regulatory changes to force updates
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in System Administration & Configuration requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 12: What common challenge do professionals face when applying Cryptography & Data Protection principles?
- Finding the relevant textbook chapter
- The principles are too simple to present any challenge
- Obtaining permission to use the principles
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Cryptography & Data Protection to the practical constraints and varying conditions encountered in real-world settings.
Question 13: What does MDM stand for in enterprise mobility management?
- Managed Desktop Module
- Mobile Device Management (Correct answer)
- Mobile Data Management
- Multi-Device Monitoring
Correct answer: Mobile Device Management
MDM (Mobile Device Management) is the solution IT departments use to monitor, manage, and enforce security policies on employees' mobile devices.
Question 14: What is the purpose of CSMA/CA in IEEE 802.11 wireless networks?
- Authenticate access points to wireless controllers
- Avoid packet collisions on the shared wireless medium (Correct answer)
- Assign dynamic IP addresses to joining clients
- Encrypt wireless frames before transmission
Correct answer: Avoid packet collisions on the shared wireless medium
CSMA/CA (Carrier Sense Multiple Access with Collision Avoidance) reduces collisions by sensing the channel before transmitting and using random backoff timers when the medium is busy.
Question 15: What is the role of a TPM (Trusted Platform Module) chip in IoT security?
- Boosting CPU performance
- Compressing sensor data before transmission
- Securely storing cryptographic keys and device identity credentials in hardware (Correct answer)
- Managing wireless radio frequencies
Correct answer: Securely storing cryptographic keys and device identity credentials in hardware
A TPM provides hardware-based storage for cryptographic keys, certificates, and measurements, enabling secure boot and device attestation.
Question 16: In augmented reality (AR), what is a 'spatial anchor'?
- A physical weight that stabilizes AR glasses
- A persistent coordinate in the real world where AR content is attached (Correct answer)
- A network endpoint for AR streaming
- A GPU optimization technique for AR rendering
Correct answer: A persistent coordinate in the real world where AR content is attached
A spatial anchor is a real-world coordinate saved in a shared space so multiple devices or sessions can display AR content at the exact same physical location.
Question 17: Which protocol does Matter (formerly Project CHIP) use as its underlying IP transport for smart home devices?
- Bluetooth Low Energy only
- Z-Wave only
- Thread (IPv6 mesh) (Correct answer)
- Zigbee only
Correct answer: Thread (IPv6 mesh)
Matter uses Thread as its primary IP-based mesh networking protocol, running over IPv6 to provide reliable, low-power smart home device communication.
Question 18: What is the most important competency assessed in Cryptography & Data Protection for professionals in this field?
- Academic credentials without practical application
- Years of experience without demonstrated skill
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
Correct answer: Applied knowledge and practical problem-solving ability
Cryptography & Data Protection assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 19: What is the relationship between Cryptography & Data Protection and ethical professional conduct?
- Ethics applies only to separate, unrelated decisions
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- There is no connection between technical knowledge and ethics
- Ethics is relevant only when legal issues arise
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Cryptography & Data Protection, as professional conduct and integrity underpin all aspects of practice in this field.
Question 20: Which wireless attack involves creating a fraudulent access point with the same SSID as a legitimate network to intercept traffic?
- De-authentication flood
- Evil Twin attack (Correct answer)
- WPS brute force
- Packet sniffing
Correct answer: Evil Twin attack
An Evil Twin attack deploys a rogue access point mimicking a trusted network's SSID to perform a man-in-the-middle attack and capture victim traffic.
Question 21: What is the relationship between System Administration & Configuration and ethical professional conduct?
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics is relevant only when legal issues arise
- Ethics applies only to separate, unrelated decisions
- There is no connection between technical knowledge and ethics
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into System Administration & Configuration, as professional conduct and integrity underpin all aspects of practice in this field.
Question 22: Which version control workflow uses short-lived feature branches merged frequently into main?
- Release branching
- Gitflow
- Trunk-based development (Correct answer)
- Forking workflow
Correct answer: Trunk-based development
Trunk-based development keeps branches small and short-lived, merging to a single main branch frequently to reduce integration conflicts.
Question 23: What is the primary purpose of a CI/CD pipeline in software development?
- To store source code in version control
- To automate building, testing, and deploying code changes (Correct answer)
- To monitor production server uptime
- To manually review code before release
Correct answer: To automate building, testing, and deploying code changes
A CI/CD pipeline automates the steps of integrating, testing, and deploying code so teams can release software faster and more reliably.
Question 24: What is edge computing in the context of IoT?
- Connecting IoT devices via Bluetooth only
- Processing data closer to the device rather than sending everything to the cloud (Correct answer)
- Using edge routers to block IoT traffic from the internet
- Storing all IoT data in a central cloud data center
Correct answer: Processing data closer to the device rather than sending everything to the cloud
Edge computing moves processing and storage closer to where data is generated, reducing latency and bandwidth usage compared to centralized cloud processing.
Question 25: What is the role of documentation in regulatory compliance?
- It is optional if verbal confirmation is available
- It serves no practical purpose beyond record-keeping
- It is only necessary for international operations
- It provides verifiable evidence that standards are being met (Correct answer)
Correct answer: It provides verifiable evidence that standards are being met
Documentation provides verifiable evidence that regulatory requirements are being met and creates an audit trail for compliance verification.
Question 26: What is the most important competency assessed in Application Security & Development for professionals in this field?
- Applied knowledge and practical problem-solving ability (Correct answer)
- Memorization of textbook definitions only
- Academic credentials without practical application
- Years of experience without demonstrated skill
Correct answer: Applied knowledge and practical problem-solving ability
Application Security & Development assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 27: What is the relationship between Cloud Computing & Virtualization and ethical professional conduct?
- Ethics applies only to separate, unrelated decisions
- There is no connection between technical knowledge and ethics
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- Ethics is relevant only when legal issues arise
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Cloud Computing & Virtualization, as professional conduct and integrity underpin all aspects of practice in this field.
Question 28: What is the recommended approach to staying current in Vulnerability Assessment & Penetration Testing?
- Relying solely on past experience
- Reviewing initial training materials once per year
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Waiting for regulatory changes to force updates
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Vulnerability Assessment & Penetration Testing requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 29: How does Cryptography & Data Protection contribute to overall professional effectiveness?
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It applies only to supervisory-level professionals
- It is relevant only during the certification examination
- It serves only as a credential requirement with no practical impact
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Cryptography & Data Protection directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 30: How does Database Management & Security contribute to overall professional effectiveness?
- It is relevant only during the certification examination
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It serves only as a credential requirement with no practical impact
- It applies only to supervisory-level professionals
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Database Management & Security directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 31: What should be the first action when a new regulation is enacted that affects your practice?
- Wait for enforcement before making changes
- Delegate review to the newest team member
- Review the regulation, assess its impact, and develop an implementation plan (Correct answer)
- Assume existing procedures already comply
Correct answer: Review the regulation, assess its impact, and develop an implementation plan
When new regulations are enacted, professionals should promptly review them, assess their impact on current practices, and develop a structured implementation plan.
Question 32: What common challenge do professionals face when applying Threat Detection & Incident Response principles?
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- Obtaining permission to use the principles
- The principles are too simple to present any challenge
- Finding the relevant textbook chapter
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Threat Detection & Incident Response to the practical constraints and varying conditions encountered in real-world settings.
Question 33: What is a DMZ (Demilitarized Zone) in network architecture?
- A meeting room for discussing network security
- A network segment between internal and external networks that hosts public-facing services (Correct answer)
- A restricted area where damaged equipment is stored
- A backup data center in a remote location
Correct answer: A network segment between internal and external networks that hosts public-facing services
A DMZ is a network segment that sits between the internal network and external networks, hosting public-facing services while protecting the internal network from direct exposure.
Question 34: What is the relationship between Threat Detection & Incident Response and ethical professional conduct?
- Ethics is relevant only when legal issues arise
- Ethics applies only to separate, unrelated decisions
- Ethical considerations are integrated into all aspects of professional practice in this area (Correct answer)
- There is no connection between technical knowledge and ethics
Correct answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Threat Detection & Incident Response, as professional conduct and integrity underpin all aspects of practice in this field.
Question 35: In the context of BYOD policies, what does BYOD stand for?
- Bring Your Own Device (Correct answer)
- Build Your Own Device
- Bind Your Own Domain
- Back Your Own Data
Correct answer: Bring Your Own Device
BYOD (Bring Your Own Device) is a policy allowing employees to use personal devices for work purposes, requiring MDM solutions to balance productivity and security.
Question 36: What common challenge do professionals face when applying Vulnerability Assessment & Penetration Testing principles?
- Obtaining permission to use the principles
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- The principles are too simple to present any challenge
- Finding the relevant textbook chapter
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Vulnerability Assessment & Penetration Testing to the practical constraints and varying conditions encountered in real-world settings.
Question 37: What is a 'pipeline as code' approach?
- Writing deployment scripts in binary format
- Defining CI/CD pipeline configuration in version-controlled files (Correct answer)
- Embedding pipeline logic inside application source code
- Using a GUI to drag and drop pipeline stages
Correct answer: Defining CI/CD pipeline configuration in version-controlled files
Pipeline as code stores the CI/CD configuration in source control alongside the application, enabling versioning, review, and automated execution.
Question 38: Which mode allows two Wi-Fi devices to communicate directly without going through an access point?
- Infrastructure mode
- Wi-Fi Direct (ad-hoc mode) (Correct answer)
- WDS bridging mode
- Monitor mode
Correct answer: Wi-Fi Direct (ad-hoc mode)
Wi-Fi Direct (and the legacy ad-hoc mode) enables peer-to-peer wireless connections between devices without requiring an access point or router.
Question 39: What is the consequence of non-compliance with mandatory regulations?
- A verbal warning with no further consequences
- Penalties including fines, license revocation, and potential legal action (Correct answer)
- Reduced insurance premiums
- Automatic extension of compliance deadline
Correct answer: Penalties including fines, license revocation, and potential legal action
Non-compliance with mandatory regulations can result in serious consequences including financial penalties, loss of licensure, and legal proceedings.
Question 40: What common challenge do professionals face when applying Cloud Computing & Virtualization principles?
- The principles are too simple to present any challenge
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- Obtaining permission to use the principles
- Finding the relevant textbook chapter
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Cloud Computing & Virtualization to the practical constraints and varying conditions encountered in real-world settings.
Question 41: What is the primary function of a Wireless LAN Controller (WLC) in an enterprise network?
- Encrypt all wireless traffic end-to-end
- Authenticate users against Active Directory directly
- Centrally manage and configure multiple access points (Correct answer)
- Assign DHCP addresses to wireless clients
Correct answer: Centrally manage and configure multiple access points
A WLC centralizes management of lightweight access points, handling configuration, firmware updates, roaming, and policy enforcement across the enterprise wireless infrastructure.
Question 42: Which generation of cellular networks first introduced mobile broadband Internet access for smartphones?
- 4G (LTE)
- 2G (GSM)
- 5G (NR)
- 3G (UMTS/HSPA) (Correct answer)
Correct answer: 3G (UMTS/HSPA)
3G networks introduced mobile broadband, enabling smartphones to access the internet with speeds suitable for web browsing, email, and streaming.
Question 43: What distinguishes inherent risk from residual risk?
- Inherent risk is financial; residual risk is operational
- Inherent risk is internal; residual risk is external
- Inherent risk exists before controls; residual risk remains after controls are applied (Correct answer)
- There is no meaningful difference between them
Correct answer: Inherent risk exists before controls; residual risk remains after controls are applied
Inherent risk is the level of risk present before any controls are implemented, while residual risk is the level that remains after controls and mitigations are applied.
Question 44: What is the purpose of a risk register?
- To document, track, and manage all identified risks throughout a project or operation (Correct answer)
- To eliminate all risks before starting work
- To satisfy audit requirements only
- To assign blame when problems occur
Correct answer: To document, track, and manage all identified risks throughout a project or operation
A risk register is a living document that records all identified risks, their assessments, response plans, and status updates throughout the lifecycle of a project or operation.
Question 45: What does SSID stand for in wireless networking?
- Secure Signal Identifier
- System Security ID
- Subnet Segment Identifier
- Service Set Identifier (Correct answer)
Correct answer: Service Set Identifier
SSID (Service Set Identifier) is the human-readable name that identifies a specific wireless network to clients scanning for access points.
Question 46: What is the primary purpose of industry regulations in this field?
- To protect the public and ensure consistent professional standards (Correct answer)
- To create barriers to entry for new professionals
- To generate revenue for regulatory bodies
- To limit competition in the marketplace
Correct answer: To protect the public and ensure consistent professional standards
Industry regulations are primarily designed to protect the public by ensuring professionals meet consistent standards of competence and conduct.
Question 47: Which security concern is most prevalent in IoT deployments?
- Too many software updates
- High CPU utilization
- Excessive RAM usage
- Use of default or hardcoded credentials (Correct answer)
Correct answer: Use of default or hardcoded credentials
Many IoT devices ship with default usernames and passwords that users never change, making them easy targets for botnet attacks like Mirai.
Question 48: What is network segmentation and why is it important?
- Removing old network equipment
- Upgrading all network cables simultaneously
- Increasing the number of network devices
- Dividing a network into smaller segments to contain breaches and control access (Correct answer)
Correct answer: Dividing a network into smaller segments to contain breaches and control access
Network segmentation divides a network into isolated segments, limiting the spread of security breaches and providing granular access control.
Question 49: Which communication protocol is most commonly used for lightweight IoT messaging?
- SMTP
- MQTT (Correct answer)
- FTP
- HTTP/1.1
Correct answer: MQTT
MQTT is a lightweight publish-subscribe protocol designed for constrained devices and low-bandwidth, high-latency IoT networks.
Question 50: What is the first step in the risk management process?
- Risk acceptance — deciding to live with all risks
- Risk transfer — purchasing insurance immediately
- Risk avoidance — canceling all activities
- Risk identification — recognizing potential threats and vulnerabilities (Correct answer)
Correct answer: Risk identification — recognizing potential threats and vulnerabilities
Risk identification is the critical first step in risk management, involving systematic recognition and documentation of potential threats and vulnerabilities.
Question 51: What common challenge do professionals face when applying Application Security & Development principles?
- Finding the relevant textbook chapter
- Obtaining permission to use the principles
- The principles are too simple to present any challenge
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Application Security & Development to the practical constraints and varying conditions encountered in real-world settings.
Question 52: What is the most important competency assessed in Vulnerability Assessment & Penetration Testing for professionals in this field?
- Memorization of textbook definitions only
- Academic credentials without practical application
- Applied knowledge and practical problem-solving ability (Correct answer)
- Years of experience without demonstrated skill
Correct answer: Applied knowledge and practical problem-solving ability
Vulnerability Assessment & Penetration Testing assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 53: Which best describes the scope of System Administration & Configuration in professional practice?
- A narrow topic relevant only to entry-level professionals
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- A theoretical framework with no practical applications
- An outdated concept no longer relevant to modern practice
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
System Administration & Configuration encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 54: What does a VPN provide in terms of network security?
- Automatic virus removal
- Encrypted communication tunnels over public networks (Correct answer)
- Faster internet connection speeds
- Free internet access worldwide
Correct answer: Encrypted communication tunnels over public networks
A VPN (Virtual Private Network) creates encrypted communication tunnels over public networks, protecting data confidentiality during transmission.
Question 55: Which IEEE 802.11 standard, also known as WiGig, operates in the 60 GHz band to achieve multi-gigabit speeds over very short distances?
- 802.11ad (Correct answer)
- 802.11ax
- 802.11ac
- 802.11n
Correct answer: 802.11ad
IEEE 802.11ad (WiGig) operates at 60 GHz, delivering throughput up to 7 Gbps but with extremely limited range due to poor wall penetration at that frequency.
Question 56: How does Vulnerability Assessment & Penetration Testing contribute to overall professional effectiveness?
- It serves only as a credential requirement with no practical impact
- It is relevant only during the certification examination
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It applies only to supervisory-level professionals
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Vulnerability Assessment & Penetration Testing directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 57: How often should compliance procedures be reviewed and updated?
- Regularly, and whenever regulations change or new risks are identified (Correct answer)
- Once at initial certification and never again
- Every ten years regardless of changes
- Only when an audit is scheduled
Correct answer: Regularly, and whenever regulations change or new risks are identified
Compliance procedures should be reviewed regularly and updated whenever regulations change, new risks emerge, or organizational changes occur.
Question 58: Which open-source tool is widely used for monitoring metrics and alerting in DevOps environments?
- Prometheus (Correct answer)
- Splunk
- Datadog
- New Relic
Correct answer: Prometheus
Prometheus is an open-source time-series monitoring system that scrapes metrics from targets and supports alerting via Alertmanager.
Question 59: What is the most important competency assessed in Cloud Computing & Virtualization for professionals in this field?
- Academic credentials without practical application
- Applied knowledge and practical problem-solving ability (Correct answer)
- Memorization of textbook definitions only
- Years of experience without demonstrated skill
Correct answer: Applied knowledge and practical problem-solving ability
Cloud Computing & Virtualization assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 60: Which risk response strategy involves reducing the likelihood or impact of a risk?
- Risk acceptance
- Risk escalation
- Risk transfer
- Risk mitigation (Correct answer)
Correct answer: Risk mitigation
Risk mitigation involves taking proactive steps to reduce either the probability of a risk occurring or its potential impact if it does occur.
Question 61: Which protocol is used to synchronize email, contacts, and calendars between Microsoft Exchange servers and mobile devices?
- IMAP IDLE
- SMTP Push
- POP3 Fetch
- ActiveSync (Correct answer)
Correct answer: ActiveSync
Microsoft ActiveSync enables real-time push synchronization of Exchange email, contacts, calendar, and tasks to mobile devices.
Question 62: What common challenge do professionals face when applying Database Management & Security principles?
- Balancing theoretical best practices with practical constraints and real-world conditions (Correct answer)
- The principles are too simple to present any challenge
- Obtaining permission to use the principles
- Finding the relevant textbook chapter
Correct answer: Balancing theoretical best practices with practical constraints and real-world conditions
Professionals commonly face the challenge of adapting theoretical best practices in Database Management & Security to the practical constraints and varying conditions encountered in real-world settings.
Question 63: What is the primary function of a firewall in network security?
- To increase network speed
- To store network data backups
- To monitor and control incoming and outgoing network traffic based on security rules (Correct answer)
- To manage email distribution
Correct answer: To monitor and control incoming and outgoing network traffic based on security rules
A firewall monitors and controls network traffic based on predetermined security rules, acting as a barrier between trusted and untrusted networks.
Question 64: What is the most important competency assessed in Threat Detection & Incident Response for professionals in this field?
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
- Years of experience without demonstrated skill
- Academic credentials without practical application
Correct answer: Applied knowledge and practical problem-solving ability
Threat Detection & Incident Response assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 65: What is the most important competency assessed in Access Control & Identity Management for professionals in this field?
- Applied knowledge and practical problem-solving ability (Correct answer)
- Years of experience without demonstrated skill
- Memorization of textbook definitions only
- Academic credentials without practical application
Correct answer: Applied knowledge and practical problem-solving ability
Access Control & Identity Management assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 66: Which best describes the scope of Database Management & Security in professional practice?
- An outdated concept no longer relevant to modern practice
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- A theoretical framework with no practical applications
- A narrow topic relevant only to entry-level professionals
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Database Management & Security encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
Question 67: What is the primary purpose of the Remote Wipe feature in mobile device management?
- Erase all data on a lost or stolen device (Correct answer)
- Back up device data to the corporate cloud
- Update device firmware over-the-air
- Reboot an unresponsive device remotely
Correct answer: Erase all data on a lost or stolen device
Remote Wipe allows IT administrators or device owners to erase all data on a mobile device that is lost, stolen, or no longer authorized, protecting sensitive information.
Question 68: What WPA3 feature provides perfect forward secrecy by replacing the Pre-Shared Key handshake?
- PMKID hashing
- 802.1X EAP-TLS
- Simultaneous Authentication of Equals (SAE) (Correct answer)
- AES-256-GCM encryption
Correct answer: Simultaneous Authentication of Equals (SAE)
WPA3's SAE (Simultaneous Authentication of Equals) replaces PSK with a Dragonfly handshake that provides perfect forward secrecy, preventing offline dictionary attacks on captured handshakes.
Question 69: What is the purpose of intrusion detection systems (IDS)?
- To prevent all unauthorized access automatically
- To speed up network performance
- To monitor network traffic for suspicious activity and known threats (Correct answer)
- To manage network IP addresses
Correct answer: To monitor network traffic for suspicious activity and known threats
IDS monitors network traffic for suspicious activity, known attack patterns, and policy violations, alerting administrators to potential security threats.
Question 70: Which 5G NR feature allows operators to create multiple isolated virtual networks on a single physical infrastructure?
- Carrier aggregation
- Beamforming
- Network slicing (Correct answer)
- Massive MIMO
Correct answer: Network slicing
Network slicing, introduced with 5G NR, allows a physical network to be divided into multiple logical networks, each tailored for specific use cases like IoT or eMBB.
Question 71: What is the most important competency assessed in Operating Systems & Platforms for professionals in this field?
- Academic credentials without practical application
- Memorization of textbook definitions only
- Applied knowledge and practical problem-solving ability (Correct answer)
- Years of experience without demonstrated skill
Correct answer: Applied knowledge and practical problem-solving ability
Operating Systems & Platforms assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
Question 72: What is the purpose of a feature flag in continuous delivery?
- Encrypting sensitive environment variables
- Controlling which Git branches are merged
- Enabling or disabling features at runtime without redeployment (Correct answer)
- Tagging Docker image versions
Correct answer: Enabling or disabling features at runtime without redeployment
Feature flags allow teams to deploy code to production while keeping new functionality hidden or restricted until it is ready to be revealed.
Question 73: Why is regular risk reassessment important?
- Because regulators require it exactly once per year
- Because initial assessments are always wrong
- Because it provides work for risk management teams
- Because the risk landscape changes as conditions, activities, and environments evolve (Correct answer)
Correct answer: Because the risk landscape changes as conditions, activities, and environments evolve
Regular risk reassessment is essential because risks are dynamic — new threats emerge, existing risks change in severity, and the effectiveness of controls may vary over time.
Question 74: What is the recommended approach to staying current in Cloud Computing & Virtualization?
- Reviewing initial training materials once per year
- Waiting for regulatory changes to force updates
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Relying solely on past experience
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Cloud Computing & Virtualization requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 75: Which approach to compliance is considered most effective?
- A proactive approach that integrates compliance into daily operations (Correct answer)
- A reactive approach that addresses issues only after violations
- Focusing compliance efforts only on areas that have been cited previously
- Hiring a consultant once a year for a brief review
Correct answer: A proactive approach that integrates compliance into daily operations
A proactive compliance approach that integrates regulatory requirements into daily operations is most effective at preventing violations and maintaining standards.
Question 76: How does Access Control & Identity Management contribute to overall professional effectiveness?
- It is relevant only during the certification examination
- It serves only as a credential requirement with no practical impact
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It applies only to supervisory-level professionals
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Access Control & Identity Management directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 77: What is quantum key distribution (QKD) used for?
- Generating random numbers for IoT sensors
- Speeding up RSA key generation
- Securely exchanging encryption keys using quantum mechanics principles (Correct answer)
- Distributing quantum computers globally
Correct answer: Securely exchanging encryption keys using quantum mechanics principles
QKD uses quantum physics properties to exchange cryptographic keys in a way that detects any eavesdropping attempt, providing theoretically unbreakable key exchange.
Question 78: What cybersecurity framework specifically addresses IoT device security requirements in the US?
- SOC 2
- PCI DSS
- NIST IR 8259 (Correct answer)
- ISO 27001
Correct answer: NIST IR 8259
NIST IR 8259 provides a baseline of cybersecurity activities for IoT device manufacturers to improve the security of their products sold in the US market.
Question 79: Which IEEE 802.11 standard is officially branded as Wi-Fi 6 by the Wi-Fi Alliance?
- 802.11ac
- 802.11ax (Correct answer)
- 802.11n
- 802.11ad
Correct answer: 802.11ax
IEEE 802.11ax was branded Wi-Fi 6 by the Wi-Fi Alliance, introducing OFDMA and improved efficiency over 802.11ac (Wi-Fi 5).
Question 80: What is the recommended approach to staying current in Access Control & Identity Management?
- Waiting for regulatory changes to force updates
- Reviewing initial training materials once per year
- Regular professional development, industry publications, and peer collaboration (Correct answer)
- Relying solely on past experience
Correct answer: Regular professional development, industry publications, and peer collaboration
Staying current in Access Control & Identity Management requires ongoing professional development, reading industry publications, and collaborating with peers to share knowledge and best practices.
Question 81: Which AI technique enables IoT devices to collaboratively train a model without sharing raw data?
- Transfer learning
- Federated learning (Correct answer)
- Supervised batch learning
- Reinforcement learning
Correct answer: Federated learning
Federated learning trains a shared model across distributed devices by exchanging model updates rather than raw data, preserving privacy on each device.
Question 82: What does a digital twin represent in IoT?
- A secondary IoT sensor for redundancy
- A backup cloud server
- An encrypted copy of device firmware
- A virtual replica of a physical device or system for simulation (Correct answer)
Correct answer: A virtual replica of a physical device or system for simulation
A digital twin is a virtual model that mirrors a physical asset in real time, enabling simulation, monitoring, and predictive maintenance.
Question 83: Which practice involves automatically rolling back a deployment when error rates exceed a threshold?
- Automated rollback (Correct answer)
- Blue-green deployment
- Canary release
- Feature flagging
Correct answer: Automated rollback
Automated rollback uses monitoring thresholds to detect failures and revert to the previous stable version without manual intervention.
Question 84: What is the principle of least privilege in network security?
- Access permissions should be updated annually
- All users should have administrator access for convenience
- New users should receive the same access as their managers
- Users should have only the minimum access needed to perform their job functions (Correct answer)
Correct answer: Users should have only the minimum access needed to perform their job functions
The principle of least privilege restricts user access to only the resources and permissions necessary for their specific job functions, minimizing potential damage from compromised accounts.
Question 85: How does Threat Detection & Incident Response contribute to overall professional effectiveness?
- It is relevant only during the certification examination
- It serves only as a credential requirement with no practical impact
- It provides essential knowledge and skills that directly impact quality of work and outcomes (Correct answer)
- It applies only to supervisory-level professionals
Correct answer: It provides essential knowledge and skills that directly impact quality of work and outcomes
Threat Detection & Incident Response directly contributes to professional effectiveness by providing essential knowledge and skills that improve the quality of work and outcomes across all career levels.
Question 86: In infrastructure as code (IaC), what does Terraform primarily manage?
- Cloud and on-premises infrastructure resources (Correct answer)
- Application source code versions
- Container images
- CI/CD pipeline stages
Correct answer: Cloud and on-premises infrastructure resources
Terraform uses declarative configuration files to provision and manage infrastructure across multiple cloud providers.
Question 87: In a microservices architecture, what tool category handles service discovery and load balancing?
- Secret manager
- Service mesh (Correct answer)
- Log aggregator
- Object-relational mapper
Correct answer: Service mesh
A service mesh like Istio or Linkerd handles service-to-service communication, load balancing, and observability within a microservices environment.
Question 88: Which emerging technology uses distributed ledger to enable automated, self-executing contracts?
- Smart contracts on blockchain (Correct answer)
- Differential privacy
- Quantum computing
- Federated learning
Correct answer: Smart contracts on blockchain
Smart contracts are self-executing programs stored on a blockchain that automatically enforce agreement terms when predefined conditions are met.
Question 89: Which strategy deploys a new version to a small subset of users before a full rollout?
- Rolling deployment
- Blue-green deployment
- Shadow deployment
- Canary release (Correct answer)
Correct answer: Canary release
A canary release routes a small percentage of traffic to the new version, allowing teams to validate it in production before exposing all users.
Question 90: Which best describes the scope of Access Control & Identity Management in professional practice?
- A theoretical framework with no practical applications
- A comprehensive area covering both theoretical foundations and practical applications (Correct answer)
- An outdated concept no longer relevant to modern practice
- A narrow topic relevant only to entry-level professionals
Correct answer: A comprehensive area covering both theoretical foundations and practical applications
Access Control & Identity Management encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
CompTIA Security+ (SY0-701)
CompTIA Security+ is a globally recognized entry-level cybersecurity certification that validates foundational skills in network security, risk management, access control, cryptography, and security operations. It covers five core domains including threats & vulnerabilities, security architecture, security operations, and security program management.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds