Free practice test

Security+ SY0-701 practice test — 25 questions

Weighted across the SY0-701 blueprint like the real exam. No feedback until you submit, then a grade, a per-domain breakdown, and a full explanation for every question. No signup, nothing collected — grading happens in your browser. From Ascert, a spaced-repetition study app for IT certs on iPhone.

1.0 General Security Concepts
Q1. A security team is drafting an organization-wide risk assessment schedule and updating the corporate security policy. Which control category do these activities BEST represent?
1.0 General Security Concepts
Q2. A legacy network allows any host on the internal LAN to reach any server without further verification because everything 'inside' is considered safe. Which concept does Zero Trust seek to minimize in this design?
1.0 General Security Concepts
Q3. A web browser and server need to establish a shared secret over an untrusted network so they can switch to fast symmetric encryption for the session. Which cryptographic concept does this BEST describe?
2.0 Threats, Vulnerabilities, and Mitigations
Q4. A security team discovers that a well-funded group has maintained undetected access to a defense contractor's network for 18 months, slowly exfiltrating aircraft design documents. The tooling is custom-built and previously unseen. Which of the following threat actors is MOST likely responsible?
2.0 Threats, Vulnerabilities, and Mitigations
Q5. An employee installs an unapproved project-management SaaS tool to hit a deadline, unintentionally storing client data outside company control. Why is this classified as shadow IT rather than an insider threat?
2.0 Threats, Vulnerabilities, and Mitigations
Q6. A sales representative connects to a coffee shop's open wireless network and logs in to a web application that does not use encryption. An attacker on the same network captures the credentials. Which of the following threat vectors enabled the capture?
2.0 Threats, Vulnerabilities, and Mitigations
Q7. Researchers disclose a flaw in the low-level code that initializes a popular router before its operating system loads. Exploitation survives factory resets and OS reinstalls. Which of the following vulnerability types does this describe?
2.0 Threats, Vulnerabilities, and Mitigations
Q8. Overnight, malware spreads from one unpatched server to hundreds of hosts by exploiting a network file-sharing vulnerability, with no user opening any file or link. Which of the following malware types behaves this way?
2.0 Threats, Vulnerabilities, and Mitigations
Q9. An attacker who compromised a low-privilege web service account exploits an unpatched local vulnerability to gain SYSTEM-level rights on the server. Which of the following BEST describes this stage of the attack?
3.0 Security Architecture
Q10. A company migrates its application servers to virtual machines in an IaaS cloud. According to the shared responsibility model, who is responsible for patching the guest operating systems?
3.0 Security Architecture
Q11. Which of the following BEST describes a high-availability architecture?
3.0 Security Architecture
Q12. A firewall permits TCP port 443 to a web server but cannot detect malicious commands hidden inside the HTTPS application payload. At which OSI layer is this firewall operating?
3.0 Security Architecture
Q13. A clinician has a patient's record open on screen while the application processes it in memory. Which data state applies, and which control BEST protects it?
4.0 Security Operations
Q14. A security administrator creates a documented set of secure configuration settings for all new Windows servers, deploys it through configuration management, and schedules quarterly reviews to update it. Which of the following BEST describes this activity?
4.0 Security Operations
Q15. A malware analyst wants to observe a suspicious attachment's behavior without risking production systems. Which of the following techniques should the analyst use?
4.0 Security Operations
Q16. A security analyst references a public catalog that assigns a unique identifier, such as CVE-2024-12345, to each publicly disclosed vulnerability. Which of the following does this catalog provide?
4.0 Security Operations
Q17. Which of the following monitoring tools relies primarily on known patterns to identify and block malicious files on endpoints, and therefore must be updated regularly?
4.0 Security Operations
Q18. Before allowing any device onto the corporate network, a control checks that the device has current antivirus, disk encryption, and required patches, and places noncompliant devices into a remediation VLAN. Which of the following is being described?
4.0 Security Operations
Q19. Current password guidance favors which of the following as the PRIMARY driver of password strength?
4.0 Security Operations
Q20. An incident response team gathers in a conference room and talks through its ransomware playbook against a fictional scenario, without touching any production systems. Which type of exercise is this?
5.0 Security Program Management and Oversight
Q21. A security manager is drafting a document that recommends, but does not require, specific approaches for hardening workstations. Department leads may adapt the recommendations to their environments. Which of the following BEST describes this document?
5.0 Security Program Management and Oversight
Q22. A multinational corporation lets each regional office set its own security policies and make security decisions locally rather than deferring to headquarters. Which governance structure does this describe?
5.0 Security Program Management and Oversight
Q23. A board sets a broad statement that the company is "willing to accept moderate risk in pursuit of digital innovation." The security team then defines the degree of variation from that level it will accept for each system. Which terms describe the board's statement and the team's per-system limits, respectively?
5.0 Security Program Management and Oversight
Q24. During vendor selection, a procurement committee member fails to disclose that their spouse is a senior executive at one of the bidding vendors. Which vendor selection risk does this situation represent?
5.0 Security Program Management and Oversight
Q25. Under privacy regulations, which of the following BEST describes a data subject?
0 of 25 answered
Results

How you did

0%
Keep what you just learned

The app schedules every one of these — and the rest of the Security+ bank — with spaced repetition, so the ones you missed come back until they stick. The first 100 questions are free.

Ascert for Security+

Free to try on iPhone · the full Security+ bank is $9.99 once, no subscription.

See pricing