Foundational cybersecurity certification covering security concepts, threats and mitigations, security architecture, operations, and program management for the CompTIA Security+ SY0-701 exam.
Free sample questions
No account needed. Every question has a worked explanation, just like the full bank.
lock_openFree sampleGeneral Security Conceptseasy
A hospital's electronic health record system goes offline for four hours during a ransomware incident, blocking clinicians from reading patient charts. Which pillar of the CIA triad is most directly impacted by this outage?
- AAvailability, because authorised users were unable to access the data when needed.check_circle Correct
- BConfidentiality, because clinicians could not see records they are authorised to view.
- CIntegrity, because the records could not be trusted to be accurate during the outage.
- DNon-repudiation, because the source of the records could not be verified during the outage.
Identify which pillar of the CIA triad is impacted when authorised users cannot reach a system because of an outage. The CIA triad defines confidentiality (preventing unauthorised disclosure), integrity (preventing unauthorised modification), and availability (ensuring timely authorised access). A ransomware-driven outage that prevents clinicians from reading charts directly degrades availability, regardless of whether the data itself was altered or disclosed.
Why A is correct: Availability is the assurance that authorised users can reach systems and data when required. A four-hour outage that blocks clinical access is the textbook impact on availability.
Why B is wrong: Confidentiality concerns unauthorised disclosure, not denial of access to authorised users. The incident may also affect confidentiality if data was exfiltrated, but the four-hour read outage described is fundamentally an availability problem, so this is the wrong best fit.
Why C is wrong: Integrity concerns unauthorised modification or corruption of data. The scenario describes inability to reach the records, not altered content, so integrity is a tempting but incorrect choice.
Why D is wrong: Non-repudiation prevents a party from denying an action they performed and is usually achieved through digital signatures and logging. It is not the pillar harmed by a system being offline, so this option is incorrect.
lock_openFree sampleSecurity Operationseasy
A logistics company is retiring forty laptops that previously held delivery manifests and payroll files. The IT manager wants the drives processed so that the data cannot be recovered even by a forensic lab, but the chassis themselves will be donated to a local charity in working order. Which disposal action best meets both requirements?
- ARun a quick format from the operating system installer on each laptop before handing the units over to the charity.
- BPerform a vendor-certified cryptographic erase or multi-pass overwrite of each drive, then verify and document the sanitisation before donation.check_circle Correct
- CPhysically shred each drive in an approved media destruction bin and pass the laptops on with the empty drive bays.
- DDelete the user profiles, empty the recycle bin, and rely on full disk encryption being enabled at the time of donation.
Recognise that secure disposal must destroy data on storage media while matching the reuse plan for the surrounding hardware. Secure disposal balances data sanitisation with the future use of the device. Cryptographic erase and verified multi-pass overwrite are recognised sanitisation methods that render data non-recoverable while preserving the drive and chassis for reuse or donation, and the resulting certificate provides documented evidence for the asset record.
Why A is wrong: A quick format only rewrites filesystem metadata and leaves the underlying sectors intact, so commodity recovery tools can restore the manifests and payroll files. It is tempting because it appears to wipe the disk, but it does not satisfy the forensic non-recoverability requirement.
Why B is correct: A certified cryptographic erase or NIST-aligned multi-pass overwrite destroys the readable contents of the drive while leaving the hardware usable, and the verified certificate of sanitisation supports an auditable chain of custody. This satisfies both the non-recoverability and the working-order requirements.
Why C is wrong: Shredding does destroy the data beyond forensic recovery, but it also removes the storage that makes the laptops functional, so the charity would receive incomplete units. The requirement is to keep the chassis in working order, which this approach breaks.
Why D is wrong: Deleting profiles and emptying the recycle bin leaves the underlying data blocks recoverable, and an unrevoked encryption key on a donated machine still permits decryption by the recipient. Candidates may pick this because encryption sounds protective, but without key destruction it does not sanitise the drive.
lock_openFree sampleThreats, Vulnerabilities, and Mitigationseasy
A marketing team frustrated by slow IT procurement signs up for a third-party analytics SaaS using a corporate credit card and uploads customer contact lists to it. The security team only learns about the service after a data protection audit. Which risk category does this situation most directly illustrate?
- AShadow IT, where business units adopt unsanctioned technology that bypasses security and governance review.check_circle Correct
- BAn advanced persistent threat campaign carried out by a sophisticated external nation-state intrusion set.
- CA malicious insider deliberately exfiltrating sensitive records to harm the employer's reputation and revenue.
- DHacktivism in which ideologically driven outsiders pressure the organisation by leaking confidential customer details online.
Identify unsanctioned business adoption of cloud services as shadow IT rather than a malicious insider or external campaign. Shadow IT describes technology adopted without IT or security oversight, often well-intentioned but creating data governance, compliance, and exposure risks. The defining trait is bypassing approved procurement and security review, exactly what the marketing team did when uploading customer data to an unvetted SaaS provider.
Why A is correct: Marketing procured and used a SaaS outside the formal IT process, which is the textbook definition of shadow IT and the source of unmanaged data exposure.
Why B is wrong: APT campaigns involve covert external attackers exploiting systems, not authorised employees openly buying a SaaS subscription with corporate funds for daily marketing tasks.
Why C is wrong: Tempting because data left the perimeter, but the marketing team's intent was operational efficiency rather than sabotage, which distinguishes shadow IT from a malicious insider.
Why D is wrong: No external ideologically motivated party is involved and no public leak has occurred, so the scenario does not match hacktivist behaviour or motivation.
More free SY0-701 practice questions with worked answersFrequently asked questions
- How many questions are on the SY0-701 exam?
- The CompTIA Security+ (SY0-701) exam has Maximum of 90 questions questions and runs for 90 minutes. The format is multiple choice and performance-based, at pearson vue testing center or online proctored.
- What score do I need to pass SY0-701?
- The pass mark is 750 / 900. Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
- How much does the SY0-701 exam cost?
- The exam costs 425 USD to sit. Practising on Examworthy is free to start, with a worked explanation on every question.
- Is there a SY0-701 practice exam?
- Yes. Examworthy's exam mode runs a timed SY0-701 practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand against the blueprint. Timed mocks are free with an account.
- How does Examworthy help me prepare for SY0-701?
- Every practice question carries a worked explanation and a per-distractor rationale, mapped to the official blueprint domains. You learn why each answer is right or wrong, not just the letter.
- Is Examworthy affiliated with CompTIA?
- No. Examworthy is not affiliated with or endorsed by CompTIA. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.
Examworthy is not affiliated with or endorsed by CompTIA. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. SY0-701 and related marks belong to their respective owners.