Home › SY0-701 › Practice questions
SY0-701 · CompTIA · Updated September 2026

SY0-701 practice questions

Original & expert-reviewed · explanation for every option · no dumps

Practise SY0-701 with original, expert-reviewed questions — each with an explanation for every option, linked to the source, across the full exam blueprint. No dumps, no ads, 6 free to start.

Try 6 free SY0-701 questions → See the SY0-701 bank

Free: 6 questions in study mode, no card. Full SY0-701 bank with mock exams and the error log: $15 one-time, or every exam with All-Access for $19/mo or $119/yr.

6
Free to start
90
On the real exam
5
exam domains
$0
To begin

What makes these different from dumps

📚 An explanation for every option

Not just the right answer — why each wrong option is wrong, linked to the source. Wrong answers teach the most.

⏱️ Real-format timed mocks

Sit full 90-question, 90-minute exams and get a readiness report by area — know when you're ready.

↻ Spaced-repetition error log

Every miss comes back on a 1 → 3 → 7 → 16-day schedule, so the fixes actually stick.

🔖 Original & reviewed

Every question is written to test the concepts and reviewed before it ships — never copied or leaked “dumps”.

Try 10 real SY0-701 questions — free, no sign-up

A representative slice of the bank: every exam domains, mixed difficulty (hard ones included). Answers are one tap away — no email wall.

1/10 · Security Operations
A discovery sweep of one address range finds 61 devices holding active leases that IT cannot match to anything it manages; twelve of them answer on management ports. The batch is investigated and cleaned up over two weeks. Which practice BEST keeps the same gap from re-forming?
ARecurring enumeration of the address space
BAn asset inventory maintained for every device
CChange approval required before any deployment
DClassification applied at the point of acquisition
Show answer & explanation
B is correct. Objective 4.2 separates inventory from enumeration under monitoring and asset tracking, and lists ownership and classification under assignment and accounting. Enumeration is a discovery activity that reports what answered today; an inventory is a durable record with an owner, which is what turns a device that answers but has no entry into a visible exception rather than an ordinary sight. NIST SP 800-53 Rev. 5 control CM-8 requires an inventory of system components that accurately reflects the system and includes all components within it - a standing record rather than a periodic sweep.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 4: Security Operations
2/10 · Threats, Vulnerabilities, and Mitigations
A regional sales director subscribes to a document signing service on a departmental card, uploads two years of signed customer contracts containing national identification numbers, and shares the workspace with three colleagues. No procurement, legal or security review takes place. Security learns that the workspace exists eleven months later, when the provider issues a breach notification to its customers. Which of the following BEST describes the source of the exposure?
AAn insider threat within the sales team
BA service provider compromise at the vendor
CAn unskilled attacker outside the company
DShadow IT inside the sales organization
Show answer & explanation
D is correct. Objective 2.1 lists shadow IT alongside insider threat, nation-state, unskilled attacker, hacktivist and organized crime among threat actors. What separates shadow IT from insider threat is sanction rather than skill or intent: the technology itself sits outside procurement, review and monitoring, which is why its failures surface through a supplier notice or a finance query instead of through security tooling. Intent is deliberately not the test - a department acting entirely in good faith produces the same unmanaged surface as one acting carelessly.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 2: Threats, Vulnerabilities, and Mitigations
3/10 · Security Program Management and Oversight
A vendor's data sheet for a power module quotes two figures: 140,000 hours and 4 hours. A contingency planner has to decide how many spare modules to hold at each site, and whether a four-hour site recovery commitment is achievable with a spare on the shelf. Which reading of the two figures is correct?
A140,000 hours is the MTTR; 4 hours is the MTBF
B140,000 hours is the MTBF; 4 hours is the RTO
C140,000 hours is the RPO; 4 hours is the MTTR
D140,000 hours is the MTBF; 4 hours is the MTTR
Show answer & explanation
D is correct. Objective 5.2 lists recovery time objective, recovery point objective, mean time to repair and mean time between failures under business impact analysis. Two of the four are targets the organisation sets - what it will accept in downtime and in data loss - and two are observed properties of equipment that a supplier measures and publishes. Mixing the halves produces a plan whose recovery commitment silently rests on a number nobody in the business ever agreed to, which is why a vendor data sheet can supply an MTTR and never an RTO.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 5: Security Program Management and Oversight
Like these? Try 6 more SY0-701 questions with instant feedback, free →
4/10 · Security Architecture
A group's default storage configuration replicates every bucket to a second region on another continent for durability. A national regulator informs the group's subsidiary that records about that country's citizens remain subject to its law wherever they are held, and that they must be kept on servers inside its borders. Which of the listed data considerations BEST names the principle the regulator is applying?
AGeolocation
BGeographic restrictions
CData retention limits
DData sovereignty
Show answer & explanation
D is correct. Objective 3.3 lists data sovereignty and geolocation among general data considerations and geographic restrictions among the methods to secure data - three location words sitting on two different shelves. Sovereignty is a legal claim: the data is governed by the law of a jurisdiction. Geolocation is a fact about position. A geographic restriction is a control that acts on that fact. Keeping them apart is what makes the remedy obvious, since a sovereignty requirement is answered by constraining replication targets rather than by adjusting who may read the records.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 3: Security Architecture
5/10 · General Security Concepts
While building a control inventory, an analyst has to file three items: the written information security policy, the annual risk assessment schedule, and the vendor review procedure that governs which suppliers may be onboarded. Into which of the following categories do all three items fall?
AManagerial
BOperational
CTechnical
DPhysical
Show answer & explanation
A is correct. Objective 1.1 divides controls into four categories: technical, managerial, operational and physical. Policies, risk assessment programs and governance procedures are managerial, because they direct decision making; the people-executed activities they trigger are what fall into the operational category.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 1: General Security Concepts
6/10 · Security Operations
A credit union's online banking sign-in asks the member for a password and then for the answer to a security question chosen at enrollment. The security team is replacing that second step. Which replacement makes the sign-in multifactor?
AA PIN chosen by the member at enrollment
BA code from a registered hardware token
CThe answer to a second enrollment question
DThe last four digits of the account number
Show answer & explanation
B is correct. Objective 4.6 lists the factors as something you know, something you have, something you are and somewhere you are, and a sign-in is multifactor only when its steps come from different categories. A password and the answer to a security question are both things the member knows. NIST SP 800-63B Section 5.1.1.2, Memorized Secret Verifiers, addresses that kind of second step directly: memorized secret verifiers SHALL NOT permit the subscriber to store a hint that is accessible to an unauthenticated claimant, and verifiers SHALL NOT prompt subscribers to use specific types of information, the document's own example being the name of a first pet, when choosing memorized secrets. A code from a registered hardware token is something the member holds, which is the category the sign-in is missing.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 4: Security Operations
7/10 · Threats, Vulnerabilities, and Mitigations
Suppliers report signing in to what they took to be a manufacturer's invoice portal. The page copies the real one and is served over HTTPS with a certificate issued for the domain it sits on. The manufacturer runs its own portal on its main domain; this page sits on a separate domain, registered eleven days before the campaign, that carries the manufacturer's name together with the word it uses for its supplier programme. Suppliers arrived from a link in an email and, in two cases, after a telephone call about an overdue invoice. Credentials typed there are replayed against the genuine portal within minutes. Which human vector does the campaign turn on?
ATyposquatting of the portal domain
BBrand impersonation of the manufacturer
CBusiness email compromise at a supplier
DPretexting in the overdue-invoice calls
Show answer & explanation
B is correct. Objective 2.2 lists phishing, impersonation, business email compromise, pretexting, watering hole, brand impersonation and typosquatting as separate human vectors, and the pair routinely collapsed into one is the last two. Typosquatting is defined by the alteration of the name and depends on the reader making or overlooking an error. Brand impersonation needs no error at all: a correctly spelled name inside a plausible new domain is its ordinary form. The difference decides the response as well, because registering the nearby misspellings does nothing about a domain that carries the name correctly.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 2: Threats, Vulnerabilities, and Mitigations
8/10 · Security Program Management and Oversight
A company is finalizing paperwork with a hosting provider, and several documents will be signed together. One of them must commit the provider to a monthly availability percentage, to defined response times for each incident severity, to the method by which both will be measured, and to the credits payable when the commitments are missed. Which agreement type is being drafted?
AA service-level agreement
BA master service agreement
CA statement of work and schedule
DA business partners agreement
Show answer & explanation
A is correct. Objective 5.3 lists SLA, MOA, MOU, MSA, WO/SOW, NDA and BPA as agreement types, and a commercial engagement normally produces several of them at once rather than one. They divide by function rather than by formality: the master agreement holds the legal terms, the statement of work holds the scope, and the service-level agreement is the only member of the set that states a measurable performance level, how it will be measured, and what is owed when it is missed.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 5: Security Program Management and Oversight
9/10 · Security Operations · hard
A finding carries a published base score in the critical range. The affected server sits on an isolated test segment with no route to or from other networks, holds only synthetic data, and can be rebuilt in minutes. The vulnerability management lead wants the recorded severity for this instance to reflect those facts without editing the published score or ignoring the finding. Which part of the scoring system is designed for that adjustment?
AThe base metric group
BThe temporal metric group
CThe qualitative severity rating scale
DThe environmental metric group
Show answer & explanation
D is correct. Objective 4.3 lists CVSS, exposure factor, environmental variables and organizational impact under analysis. The CVSS v3.1 specification states that the Base score reflects intrinsic characteristics constant over time and across user environments, Temporal metrics adjust for factors that change over time, and Environmental metrics adjust the base and temporal severities to a specific computing environment.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 4: Security Operations
10/10 · Security Operations · hard
A wealth manager is retiring 400 solid-state drives that held client records. The drives are to be sold to a refurbisher, so they must remain usable afterwards, and the firm's standard requires that recovery of the previous contents be infeasible even with state-of-the-art laboratory techniques. Which disposal action BEST meets the standard?
AOverwrite each drive once using standard write commands
BShred the drives and document the destruction
CApply the drives' sanitize command and verify it
DReformat each drive and install a fresh operating system
Show answer & explanation
C is correct. Objective 4.2 lists sanitization, destruction and certification under disposal. NIST SP 800-88 Rev. 1 defines Clear as logical techniques protecting against simple non-invasive recovery, Purge as physical or logical techniques that render data recovery infeasible using state of the art laboratory techniques, and Destroy as achieving that while also making the media unusable - and it notes Purge may be preferred when the media is to be reused, sold or donated.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 4: Security Operations
Try 6 more free SY0-701 questions → See the whole SY0-701 bank

Practice by knowledge area

Five more free questions for each section of the SY0-701 bank, drawn from that area only, with the answer explained and linked to the source:

Security Operations30 qThreats, Vulnerabilities, and Mitigations25 qSecurity Program Management and Oversight24 qSecurity Architecture23 qGeneral Security Concepts18 q

Covering every exam domains

The bank spans the whole SY0-701 blueprint, weighted toward what the exam tests most:

Security Operations28%Threats, Vulnerabilities, and Mitigations22%Security Program Management and Oversight20%Security Architecture18%General Security Concepts12%

Start practising SY0-701 free

6 free questions in study mode · no card · full SY0-701 bank: $15 one-time · no dumps, no ads.

Start SY0-701 free →

SY0-701 practice — FAQ

Should I wait for SY0-801 or take SY0-701 now?

Take SY0-701 now if you can be ready before mid-2027. CompTIA lists June 11, 2027 as the English retirement date for SY0-701, and the certification you earn is valid for three years regardless of which exam version you passed.

What are performance-based questions and can I practise them here?

PBQs are interactive items — configuring a rule set, ordering incident-response steps, matching log lines to attacks. ExamDeck covers the underlying knowledge with scenario questions, but the drag-and-drop interface itself is not reproduced; use CompTIA's exam sandbox to see the format.

Is SY0-701 required for US government jobs?

Security+ is one of the certifications listed for DoD 8140 work roles, which is why it appears as a hard requirement in many US federal and contractor postings. Check the specific role's requirement, as some now accept alternatives.

How many questions is the SY0-701 exam and how long is it?

A maximum of 90 questions in 90 minutes at a Pearson VUE test centre or online.

What is the passing score for SY0-701?

The passing score is 750 on a scale of 100–900 (roughly 83%). Aim for a consistent 80–85% on realistic practice exams before booking.

What is the SY0-701 pass rate?

CompTIA does not publish official pass rates, so any exact percentage quoted online is unverified. The readiness signal that actually predicts passing: consistently holding 80–85% on realistic, full-length practice exams before you book.

What are the SY0-701 eligibility requirements?

No prerequisites — anyone can buy a voucher and schedule the exam. CompTIA recommends holding Network+ and having two years of experience in a security or systems administrator role; many candidates pass with less, using structured study.

How much does SY0-701 cost?

The US list price is $439 USD per attempt (CompTIA raised prices in June 2026 — verify on comptia.org; prices differ by country, and academic-store and training-partner vouchers cost less). Renewal through Continuing Education carries a $50 USD annual CE fee ($150 over the three-year cycle).

How long should I study for SY0-701?

For most candidates, commonly reported 60–100 hours for candidates with some IT background (CompTIA publishes no official figure). What matters most is practising questions and analysing why each option is right or wrong — not just reading.

Does the SY0-701 certification need recertification?

valid for 3 years; renew with 50 Continuing Education Units (CEUs) plus the CE fee, by passing the latest Security+ exam, or by earning a higher-level CompTIA certification.

Are ExamDeck's SY0-701 questions exam dumps?

No — every question is original, written to test the concepts and reviewed before it ships, with an explanation linked to the source for every option. Dumps are stale, often wrong, and against CompTIA's policies.

ExamDeck is an independent study tool, not affiliated with, endorsed by, or sponsored by CompTIA. SY0-701 and related marks are trademarks of their respective owners, used for identification only. Exam facts checked against official CompTIA materials (as of September 2026); always confirm current details with the vendor before booking.