SY0-701: Security+ 2023 Practice Exam — SY0-701: Security+ 2023

1. The question bank is cloud-based and updates automatically, with no need for re-acquisition.

2. Available in Chinese and English. It supports online practice, mock exams and PDF downloads.

3. You can practice questions via mini-program or desktop web page. The service is valid for one year.

4. For inquiries, please contact customer service via WeChat, WhatsApp or Line.

Exam information

SY0-701: CompTIA Security+

-Exam Overview: Targeted at entry-level cybersecurity roles. It verifies knowledge of security fundamentals, threat management, identity management and security architecture, a widely recognized foundational certification in cybersecurity.

-Key Specifications:

 - Exam Duration: 90 minutes

 - Number of Questions: Up to 90 (Single choice, multiple choice, scenario-based and performance-based questions)

 - Total Score / Passing Score: 900 / 750

 - Exam Fee: Approximately $392 USD

 - Supported Languages: English, Japanese, etc.

 - Official Registration Link: https://www.comptia.org/certifications/security

-Core Topics:

 - Security fundamentals, threats and vulnerability management

 - Identity and access management, cryptography

 - Security architecture, automation and compliance


Sample questions

SY0-701: Security+ 2023 · Q1
Topic 1 Question #1 Which of the following threat actors is the most likely to be hired by a foreign government to attack critical systems located in other countries?
  • A.
    Hacktivist
  • B.
    Whistleblower
  • C.
    Organized crime
  • D.
    Unskilled attacker

Answer: C

Organized crime groups are often hired by foreign governments to conduct targeted attacks on critical systems; they possess advanced resources and expertise for such operations. Hacktivists act for ideological reasons, whistleblowers expose wrongdoing, and unskilled attackers lack the capability for critical system attacks.
SY0-701: Security+ 2023 · Q2
Topic 1 Question #2 Which of the following is used to add extra complexity before using a one-way data transformation algorithm?
  • A.
    Key stretching
  • B.
    Data masking
  • C.
    Steganography
  • D.
    Salting

Answer: D

Salting adds a unique random value to data before applying a one-way hash function, increasing complexity and preventing rainbow table attacks. Key stretching lengthens key derivation time, data masking obscures sensitive data, and steganography hides data in other media.
SY0-701: Security+ 2023 · Q3
Topic 1 Question #3 An employee clicked a link in an email from a payment website that asked the employee to update contact information. The employee entered the log-in information but received a “page not found” error message. Which of the following types of social engineering attacks occurred?
  • A.
    Brand impersonation
  • B.
    Pretexting
  • C.
    Typosquatting
  • D.
    Phishing

Answer: D

Phishing is a social engineering attack where attackers send fraudulent communications (e.g., fake payment website emails) to trick users into revealing sensitive information like login credentials. Brand impersonation is a subset, but phishing is the direct attack type here; pretexting uses a false scenario, and typosquatting involves fake domain names with typos.
SY0-701: Security+ 2023 · Q4
Topic 1 Question #4 An enterprise is trying to limit outbound DNS traffic originating from its internal network. Outbound DNS requests will only be allowed from one device with the IP address 10.50.10.25. Which of the following firewall ACLs will accomplish this goal?
  • A.
    Access list outbound permit 0.0.0.0/0 0.0.0.0/0 port 53Access list outbound deny 10.50.10.25/32 0.0.0.0/0 port 53
  • B.
    Access list outbound permit 0.0.0.0/0 10.50.10.25/32 port 53Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
  • C.
    Access list outbound permit 0.0.0.0/0 0.0.0.0/0 port 53Access list outbound deny 0.0.0.0/0 10.50.10.25/32 port 53
  • D.
    Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53

Answer: D

Firewall ACLs process rules top-to-bottom. Permitting only 10.50.10.25/32 for DNS (port 53) outbound first, then denying all other IPs for port 53, enforces the requirement. The other options have incorrect source/destination ordering or deny the allowed IP first.
SY0-701: Security+ 2023 · Q5
Topic 1 Question #5 A data administrator is configuring authentication for a SaaS application and would like to reduce the number of credentials employees need to maintain. The company prefers to use domain credentials to access new SaaS applications. Which of the following methods would allow this functionality?
  • A.
    SSO
  • B.
    LEAP
  • C.
    MFA
  • D.
    PEAP

Answer: A

Single Sign-On (SSO) allows users to authenticate once with domain credentials and access multiple SaaS applications without retyping credentials, reducing the number of credentials employees manage. LEAP and PEAP are wireless authentication protocols; MFA adds extra authentication factors.

FAQ

How many practice questions are available for SY0-701: Security+ 2023?

This question bank includes 611 SY0-701: Security+ 2023 practice questions covering single and multiple choice, each with answers and explanations.

Are SY0-701: Security+ 2023 practice questions available in Chinese and English?

Yes, SY0-701: Security+ 2023 practice questions are provided in both Chinese and English.

Can I try SY0-701: Security+ 2023 practice questions for free?

Yes. Free sample questions are available on this page, and the full question bank is available after signing up on Zhangxuetu.