Skip to content

Security+ Practice Questions

Prepare for SY0-701 with more than an answer.

425 questions in the full set40 sample questionsUpdated Feb 16, 2026

Unlock the full exam and previous versions

  • v1Version 1 425 questions Current
  • SY0-501Legacy Security+ (2020) 980 questions Locked
  • SY0-601Legacy Security+ (2021) 78 questions Locked
Exam fee
$392 USD
Level
Entry-Level to Intermediate
Valid for
3 years
Domains covered on the exam 5
  1. General Security Concepts12%
  2. Threats, Vulnerabilities, and Mitigations22%
  3. Security Architecture18%
  4. Security Operations28%
  5. Security Program Management and Oversight20%
  1. 1

    A manufacturing company relies on a legacy industrial control system running on Windows XP that cannot be patched or upgraded due to vendor constraints. The system must remain connected to the internal network to report telemetry data. Which of the following is the MOST effective compensating control to secure this system?

    Show answer details

    Correct answer: B

    When a legacy system cannot be patched (a vulnerability that cannot be remediated directly), a compensating control is required. Network segmentation places the vulnerable system in a restricted zone. By configuring a firewall to allow only the specific required traffic (telemetry) and blocking all other inbound/outbound connections, the exposure of the vulnerable system is drastically reduced, mitigating the risk of exploitation.

  2. 2

    A security engineer is configuring a web server to ensure that if the server's private key is compromised in the future, past recorded sessions cannot be decrypted. Which cryptographic property must the selected cipher suites support?

    Show answer details

    Correct answer: B

    Perfect Forward Secrecy (PFS) is a property of secure communication protocols where the compromise of long-term keys (like the server's private key) does not compromise past session keys. This is achieved by generating unique session keys for each transaction (often using Ephemeral Diffie-Hellman) that are not derived from the server's static private key.

  3. 3

    A DevOps team plans to integrate a third-party library into their core billing application. The security team insists on a formal review process before the library is added. Which change management component is primarily being addressed by analyzing how this addition might affect the application's security posture and stability?

    Show answer details

    Correct answer: B

    Security Impact Analysis is the process of examining a proposed change to determine its potential effects on the security posture of the system. In this scenario, evaluating the third-party library for vulnerabilities or stability issues before integration is the definition of conducting an impact analysis within the change management framework.

  4. 4

    A government contractor processes highly sensitive classified data. To prevent electromagnetic emanations from leaking information to nearby eavesdroppers, the organization installs copper shielding in the walls and special window treatments in the secure server room. What is this type of physical security control commonly called?

    Show answer details

    Correct answer: B

    A Faraday cage is an enclosure used to block electromagnetic fields. By installing copper shielding and special treatments, the organization is creating a Faraday cage to prevent electromagnetic emanations (such as TEMPEST signals) from escaping the secure room, thereby protecting against eavesdropping on electronic signals.

  5. 5

    A security team wants to detect when attackers attempt to enumerate users in a cloud application. They create a fake user account with administrative privileges in the directory but strictly monitor it for any login attempts. No legitimate user is aware of this account. What type of deception technology is this?

    Show answer details

    Correct answer: B

    A Honeytoken is a piece of data (like a fake user credential, API key, or database entry) that allows organizations to track misuse. Unlike a Honeypot (which is a system), a Honeytoken is a digital asset embedded in production systems. If anyone attempts to use the Honeytoken (in this case, the fake admin account), it triggers an alert, indicating potential reconnaissance or compromise.

  6. 6

    Which of the following threat actors is MOST likely to insert malicious microchips into server hardware during the manufacturing process to facilitate long-term espionage against government targets?

    Show answer details

    Correct answer: B

    Nation-state actors typically have the high level of funding, resources, and sophistication required to compromise hardware supply chains at the manufacturing level. Their motivation is often long-term espionage (Advanced Persistent Threat) against high-value targets like foreign governments or critical infrastructure.

  7. 7

    A user receives a phone call from someone claiming to be from 'Corporate IT Support' asking for their password to resolve a 'critical account sync issue.' At the same time, the user receives an SMS message appearing to be from the same support desk with a verification code. Which TWO social engineering techniques are being combined in this attack? (Select TWO)

    Show answer details

    Correct answer: A, B

    Vishing (Voice Phishing) is the use of phone calls to deceive users into surrendering sensitive information. The attacker claiming to be IT Support over the phone is conducting Vishing.

    Smishing (SMS Phishing) involves using text messages to trick users. The concurrent SMS message with the verification code is an example of Smishing used to reinforce the Vishing attempt.

  8. 8

    While reviewing application logs, a security analyst notices a sequence of operations where a user checks the balance of a gift card and then immediately redeems it. However, due to a delay in updating the database balance, the user is able to redeem the same card multiple times within a few milliseconds. What type of vulnerability is being exploited here?

    Show answer details

    Correct answer: C

    This scenario describes a Race Condition, specifically Time-of-Check to Time-of-Use (TOCTOU). The application checks the balance (Time-of-Check) and finds it sufficient. Before it can deduct the balance and complete the transaction (Time-of-Use), a second request interferes, exploiting the gap in time to perform an unauthorized action (double spending).

  9. 9

    A developer has implemented an API that allows users to retrieve their profile information using the endpoint /api/user/{id}/profile. A security tester discovers that by changing the {id} to another user's ID, they can view that user's private profile data without authorization. Which API vulnerability does this represent?

    Show answer details

    Correct answer: A

    Broken Object Level Authorization (BOLA), also known as Insecure Direct Object Reference (IDOR), occurs when an API exposes a reference to an object (like a user ID) but fails to validate that the authenticated user has permission to access that specific object. Changing the ID to access another user's data is the classic example of this vulnerability.

  10. 10

    A security analyst is investigating a compromised server and observes network traffic attempting to communicate with a known Command and Control (C2) server at regular 5-minute intervals. The traffic payload is small and consistent in size. What type of activity is the analyst observing?

    Show answer details

    Correct answer: B

    Beaconing is the practice of malware sending regular signals (heartbeats) to a Command and Control (C2) server to check for instructions or updates. The regularity (every 5 minutes) and small consistent payload are hallmark indicators of beaconing activity.

  11. 11

    During an incident response investigation, analysts discover malicious code running directly in the RAM of a workstation. There are no associated files on the hard drive, and the malware disappears upon reboot. Which type of malware is this?

    Show answer details

    Correct answer: B

    Fileless malware operates in memory (RAM) and uses existing system tools (like PowerShell or WMI) to execute malicious activity without writing executable files to the disk. This makes it harder for traditional antivirus to detect and it typically does not persist after a reboot unless specific persistence mechanisms are established.

  12. 12

    An attacker calls a company's helpdesk pretending to be a senior executive who has forgotten their password and needs urgent access to a project file before a board meeting. The attacker uses an authoritative tone and creates a sense of panic. Which social engineering principle is the attacker primarily exploiting?

    Show answer details

    Correct answer: B

    The attacker is using 'Authority' by impersonating a senior executive to intimidate the helpdesk staff, and 'Urgency' by claiming the need is for an immediate board meeting. This combination pressures the victim to bypass standard verification procedures.

Create an account to continue.