HomeSY0-701Practice questionsSecurity Operations
SY0-701 · CompTIA · Security Operations · Bank updated 2026-09-20

SY0-701 practice questions: Security Operations

5 free questions from 20 on this area · answer and explanation for each · no sign-up

These 5 questions come from the Security Operations section of our SY0-701 bank (20 questions on this area, which carries 28% of the real exam). Every question is original, with the correct answer explained and linked to the source it is drawn from.

Start 6 free in study mode → All SY0-701 sample questions
1/5 · Security Operations
A distributor manages two sets of handsets through one mobile device management platform. For the first set, counsel has confirmed that the company may erase the entire handset when it is reported lost, including photographs and messages the holder saved for personal use. For the second set, counsel has confirmed that the company may erase only the work profile and must leave the rest of the device untouched. Both sets are enrolled before first use, and policy permits personal use on both. Which deployment models are in play?
AThe first set is BYOD; the second is COPE
BBoth sets are CYOD under one policy
CThe first set is CYOD; the second is COPE
DThe first set is COPE; the second is BYOD
Show answer & explanation
D is correct. Objective 4.1 lists BYOD, COPE and CYOD as the mobile deployment models. Two questions separate them - who owns the hardware and who chooses it - and only the first has operational consequences worth testing. Ownership sets the limit of what management may do: a corporate-owned handset can be wiped completely, while on a personally owned device the organisation may act on the container it created and nothing else. Enrolment, a management platform and permitted personal use appear in all three models and identify none of them.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 4: Security Operations
2/5 · Security Operations
An independent researcher emails a working proof of concept for an authentication bypass in a company's public application and asks where such findings should be sent. Legal and security want a standing arrangement that publishes what is in scope and what testing is permitted, protects good-faith reporters, and keeps outside researchers returning to the application month after month instead of reporting once and moving on. Which identification method BEST fits?
AA responsible disclosure policy page
BA scheduled penetration test engagement
CA recurring process and control audit
DA bug bounty program for the application
Show answer & explanation
D is correct. Objective 4.3 lists responsible disclosure programs with bug bounty programs among identification methods, alongside penetration testing, threat feeds and system or process audits. The first two share their scope statement, their rules of engagement and their safe-harbour language and differ in one respect: whether a valid submission is paid for. That is what turns a channel which receives whatever happens to arrive into an arrangement that competes for researchers' attention over time, which is the requirement stated here.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 4: Security Operations
3/5 · Security Operations
Threat intelligence supplies a daily list of the names malware uses to reach its operators. The team must stop endpoints on the corporate network from reaching those names, whichever program on an endpoint makes the attempt. Which capability BEST meets the requirement?
AA web filter with the names in its block rules
BFirewall rules built from the names each day
CNetwork access control at the switch ports
DFiltering at the corporate resolvers
Show answer & explanation
D is correct. Objective 4.5 lists DNS filtering separately from web filtering and from network access control. The four capabilities differ in the identifier each one works from and in how much traffic each one sees: a resolver stands in front of nearly every outbound connection whatever the application or protocol and works in the same identifier the intelligence is published in, an address-based control has to keep translating names that move, and a proxy sees only what is routed to it. That is why name-based intelligence is applied as DNS filtering at the resolver rather than at the firewall or in the browser.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 4: Security Operations
4/5 · Security Operations
Twelve engineers hold permanent membership of the domain administrators group so that any of them can respond to an outage at any hour. An audit now requires that the group's membership list, whenever it is pulled, name only engineers with an open change record. Which of the following BEST satisfies the requirement?
AEphemeral credentials issued for each session
BJust-in-time activation of privileged roles
CPassword vaulting with checkout and rotation
DA privileged session gateway with recording
Show answer & explanation
B is correct. Objective 4.6 lists just-in-time permissions, password vaulting and ephemeral credentials as privileged access management tools, and all three are easily read as time-bounded. They bound different things. Vaulting and ephemeral credentials bound the life of a secret while the entitlement behind it is untouched, which is why an audit that samples group membership finds standing rights either way. Just-in-time bounds the assignment itself: Microsoft documents the model in Privileged Identity Management as eligible assignments that require activation, with approval and with a start and end time, after which the role is removed.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 4: Security Operations
5/5 · Security Operations
A payment service was unreachable for two hours when the TLS certificate on its load balancer expired. Responders installed a replacement the same evening, the ticket records every action with a timestamp, and the duty manager signed it off. Eleven weeks later a reporting service in the same estate is unreachable for the same reason. Which finding from the first outage is the root cause?
AThe engineer did not renew the certificate in time
BNothing warns the estate before a certificate expires
CCustomers reported the outage before monitoring did
DThe replacement certificate was issued for twelve months
Show answer & explanation
B is correct. Objective 4.8 lists root cause analysis alongside the incident response process phases, training, testing, threat hunting and digital forensics. A root cause analysis asks why the incident was possible, which is a different question from what happened and who did what: the ticket answers the second question completely and the same failure still occurred eleven weeks later in another team. NIST SP 800-61 Rev. 2 puts the same distinction into post-incident activity, where the questions to be answered include what corrective actions can prevent similar incidents in the future - an action that follows from the condition that permitted the incident, not from the individual step that was missed on the night.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 4: Security Operations
Practise all 20 Security Operations questions - start free → See the whole SY0-701 bank

Other SY0-701 areas

The same kind of free sample for every other section of the SY0-701 bank:

Threats, Vulnerabilities, and Mitigations15 qSecurity Program Management and Oversight14 qSecurity Architecture13 qGeneral Security Concepts8 q

Study Security Operations with instant feedback

6 free questions · filter study mode by area and difficulty · error log with spaced repetition · no card, no dumps, no ads.

Create your free account →
ExamDeck is an independent study tool, not affiliated with, endorsed by, or sponsored by CompTIA. SY0-701 and related marks are trademarks of their respective owners, used for identification only. Exam facts checked against official CompTIA materials (as of September 2026); always confirm current details with the vendor before booking.