HomeSY0-701Practice questionsGeneral Security Concepts
SY0-701 · CompTIA · General Security Concepts · Bank updated 2026-09-20

SY0-701 practice questions: General Security Concepts

5 free questions from 8 on this area · answer and explanation for each · no sign-up

These 5 questions come from the General Security Concepts section of our SY0-701 bank (8 questions on this area, which carries 12% of the real exam). Every question is original, with the correct answer explained and linked to the source it is drawn from.

Start 6 free in study mode → All SY0-701 sample questions
1/5 · General Security Concepts · easy
A security operations manager wants earlier warning about new scanning patterns and exploitation attempts reaching the corporate network. The team provisions one additional server in the data center subnet. It serves no business purpose, no employee has any reason to connect to it, and every packet it receives is captured and analyzed by the incident response staff. Which deception technique has the team deployed?
AA honeyfile
BA honeytoken
CA honeypot
DA honeynet
Show answer & explanation
C is correct. Objective 1.2 lists honeypot, honeynet, honeyfile and honeytoken under deception and disruption technology. NIST SP 800-94 section 8.3.4 describes honeypots as hosts that have no authorized users other than their administrators because they serve no business function, so all activity directed at them is considered suspicious - and notes they supplement, never replace, intrusion detection.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 1: General Security Concepts
2/5 · General Security Concepts
A manufacturer runs a 12-year-old scheduling application that cannot support multifactor authentication and will not be replaced for 18 months. Rather than remove the application, the security team restricts its use to one dedicated administrative workstation, isolates it behind its own firewall rule set, and forwards every authentication event to the SIEM for daily review. An auditor asks how these measures should be recorded in the control inventory. Which of the following BEST describes them?
ADetective controls
BCorrective controls
CCompensating controls
DDirective controls
Show answer & explanation
C is correct. Objective 1.1 of the SY0-701 objectives lists six control types: preventive, deterrent, detective, corrective, compensating and directive. A compensating control is the one chosen when the intended control cannot be applied to a system and an alternative has to carry the same intent - here, isolation plus monitoring standing in for an authentication requirement the legacy application cannot meet.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 1: General Security Concepts
3/5 · General Security Concepts
At 02:00 an administrator patches a shared cryptographic library on twenty application servers. The package installs cleanly and the change is closed as successful. Over the following week, vulnerability scans keep reporting the old library version on three of those servers, while the package manager on all twenty reports the new one. Which omission in the change plan BEST explains the scanner findings?
AThe change did not schedule downtime for the dependent database tier
BThe change did not lift the allow list entry for the package
CThe change did not replace the legacy application pinned to that library
DThe change did not restart the services that had loaded that library
Show answer & explanation
D is correct. Objective 1.3 lists downtime, service restart, application restart, legacy applications and dependencies among the technical implications of a change. A shared library is a dependency of every process that links it: the installer replaces the file, the package database records the new release, and each already-running service continues to execute the image it mapped when it started. The scanner reads the running system, which is why the three hosts that were never restarted keep reporting the superseded version.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 1: General Security Concepts
4/5 · General Security Concepts · hard
In a zero trust deployment, an engineer's laptop loses its compliance status halfway through an active session to an internal application. Within seconds the session is revoked, the event is written to the access log with the reason, and the gateway in front of the application drops the connection. Which component is responsible for making and logging the revocation decision itself?
AThe policy enforcement point
BThe policy engine component
CThe policy administrator service
DThe implicit trust zone
Show answer & explanation
B is correct. Objective 1.2 lists the zero trust control plane components: adaptive identity, threat scope reduction, policy-driven access control, Policy Administrator, Policy Engine. NIST SP 800-207 states in section 3, Logical Components of Zero Trust Architecture, in the text that introduces the core components under Figure 2, that the policy engine makes and logs the decision as approved or denied while the policy administrator executes it, and that the policy enforcement point enables, monitors and eventually terminates the connection.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 1: General Security Concepts
5/5 · General Security Concepts · hard
A brokerage settles transfers on instructions submitted through an internal portal. A dispute has gone to an external arbitrator who is not a party to the brokerage or to its systems. The brokerage must give the arbitrator everything needed to establish which trader approved a given instruction, and must not at the same time give the arbitrator, or anyone else who later receives the same material, the ability to produce an identical record for an instruction that was never approved. Which mechanism BEST meets that requirement?
AA SHA-256 digest of each instruction in a write-once archive
BAn HMAC computed with a key issued to that trader alone
CA TLS client certificate presented by the trader's workstation
DA digital signature made with the trader's own private key
Show answer & explanation
D is correct. Objective 1.2 names non-repudiation as a fundamental security concept and Objective 1.4 separates hashing, digital signatures and key exchange. NIST SP 800-57 Part 1 Rev. 5 section 3.5 and its glossary define non-repudiation as a service that uses a digital signature to support a third party's determination of whether a message was signed by a given entity. The property that carries it is asymmetry: the value is produced with a key held by one party and checked with one that may be published, so verification material never doubles as forgery material - which is why a keyed hash cannot deliver it however carefully the key is issued.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 1: General Security Concepts
Practise all 8 General Security Concepts questions - start free → See the whole SY0-701 bank

Other SY0-701 areas

The same kind of free sample for every other section of the SY0-701 bank:

Security Operations20 qThreats, Vulnerabilities, and Mitigations15 qSecurity Program Management and Oversight14 qSecurity Architecture13 q

Study General Security Concepts with instant feedback

6 free questions · filter study mode by area and difficulty · error log with spaced repetition · no card, no dumps, no ads.

Create your free account →
ExamDeck is an independent study tool, not affiliated with, endorsed by, or sponsored by CompTIA. SY0-701 and related marks are trademarks of their respective owners, used for identification only. Exam facts checked against official CompTIA materials (as of September 2026); always confirm current details with the vendor before booking.