HomeSY0-701Practice questionsSecurity Architecture
SY0-701 · CompTIA · Security Architecture · Bank updated 2026-09-20

SY0-701 practice questions: Security Architecture

5 free questions from 13 on this area · answer and explanation for each · no sign-up

These 5 questions come from the Security Architecture section of our SY0-701 bank (13 questions on this area, which carries 18% of the real exam). Every question is original, with the correct answer explained and linked to the source it is drawn from.

Start 6 free in study mode → All SY0-701 sample questions
1/5 · Security Architecture
A retailer runs its inventory application on virtual machine instances rented from a public cloud provider. An intrusion is traced to a missing operating system patch inside one of those instances, published by the OS vendor eleven weeks earlier. During the post-incident review, counsel asks who should have installed that patch. Which of the following BEST describes the split under the provider's responsibility matrix?
AThe provider, for everything running on its infrastructure
BThe provider, for the compute service it operates
CThe customer, for the data held inside the instance
DThe customer, for the guest operating system and its software
Show answer & explanation
D is correct. Objective 3.1 names the cloud responsibility matrix as an architecture concept. The AWS shared responsibility model states that AWS is responsible for protecting the infrastructure that runs the cloud services, while the customer handles, for an instance service, management of the guest operating system including updates and security patches, the application software installed, and the configuration of the provider-supplied firewall.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 3: Security Architecture
2/5 · Security Architecture
During an incident a campus network team must block one protocol between every user VLAN across 140 access switches within the hour, confirm that the block is in force everywhere, and remove it again in a single action afterwards. The team has also been told that nothing about this measure may remain in any switch's saved configuration once it is withdrawn. Which architectural change BEST supports that?
AA configuration management system pushing ACLs
BNetwork access control enforced at each port
CA software-defined network control plane
DNext-generation firewalls in each building
Show answer & explanation
C is correct. Objective 3.1 lists software-defined networking alongside physical isolation and logical segmentation under network infrastructure. The security-relevant property is the separation of the control plane from the data plane: policy is expressed once in the controller and installed as forwarding state, so it can be verified and withdrawn from one place and leaves nothing behind in a saved configuration. The competing answers are centrally administered too, which is the point of the item - a central console that writes into 140 device configurations is not a central control plane, and the difference shows up precisely when a temporary measure has to be proved and then reversed.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 3: Security Architecture
3/5 · Security Architecture
Contractors regularly plug personal laptops into wall jacks in shared meeting rooms and immediately receive an address on a corporate VLAN. Management wants one mechanism that serves both those jacks and the staff wireless, that withholds network access until the connecting device or user has proved an identity, and that then decides which VLAN the session lands on. Which control BEST meets that?
APort-based network access control with EAP
BMAC authentication bypass on the access switches
CWPA2-Enterprise on the wireless network
DA captive portal with directory sign-in
Show answer & explanation
A is correct. Objective 3.2 lists 802.1X and the Extensible Authentication Protocol under port security. RFC 3748 describes EAP as an authentication framework supporting multiple methods that typically runs directly over data link layers such as PPP or IEEE 802 without requiring IP - which is why a single mechanism reaches a copper port and a wireless association alike, and why the authentication server's reply can carry a VLAN assignment back to the device that holds the port closed. The wireless-only and web-only options are built from parts of the same idea, so deciding between them is a matter of knowing at which layer each one actually operates.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 3: Security Architecture
4/5 · Security Architecture
A regional insurer must resume claims processing within eight hours of losing its primary data center. Finance will not fund a continuously synchronized duplicate of production. The recovery team proposes a leased facility that already has power, cooling, network links, installed servers and storage of the right specification, but no current software or claims data; backups would be retrieved and restored into it after a declaration. Which site type does this describe?
AA hot site
BA cold site
CA mobile site
DA warm site
Show answer & explanation
D is correct. Objective 3.4 lists hot, cold, warm and geographic dispersion under site considerations. NIST SP 800-34 Rev. 1 describes warm sites as locations with the basic infrastructure of a cold site plus sufficient computer and telecommunications equipment installed and available to operate the system, where the equipment is not loaded with the software or data required to operate it.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 3: Security Architecture
5/5 · Security Architecture · hard
A platform team proposes consolidating twenty single-purpose virtual machines into containers running on four shared hosts to raise density and shorten deployment times. The security architect is asked what changes about the boundary between two workloads that previously sat in separate virtual machines on the same hypervisor. Which statement BEST describes the change?
AContainers on a host share one kernel
BEach container runs on its own kernel
CThe hypervisor isolates containers like virtual machines
DNothing changes about the workload boundary
Show answer & explanation
A is correct. Objective 3.1 contrasts containerization and virtualization. NIST SP 800-190 states that while containers provide a strong degree of isolation, they do not offer as clear and concrete a security boundary as a VM, because containers share the same kernel and can run with varying capabilities and privileges on a host - so segmentation between them is far less than a hypervisor provides.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 3: Security Architecture
Practise all 13 Security Architecture questions - start free → See the whole SY0-701 bank

Other SY0-701 areas

The same kind of free sample for every other section of the SY0-701 bank:

Security Operations20 qThreats, Vulnerabilities, and Mitigations15 qSecurity Program Management and Oversight14 qGeneral Security Concepts8 q

Study Security Architecture with instant feedback

6 free questions · filter study mode by area and difficulty · error log with spaced repetition · no card, no dumps, no ads.

Create your free account →
ExamDeck is an independent study tool, not affiliated with, endorsed by, or sponsored by CompTIA. SY0-701 and related marks are trademarks of their respective owners, used for identification only. Exam facts checked against official CompTIA materials (as of September 2026); always confirm current details with the vendor before booking.