Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CompTIA Security+ SY Editionquestions and answers with rationales/graded A+/2026 update/100% correct /instant download

Rating
-
Sold
-
Pages
28
Grade
A+
Uploaded on
11-05-2026
Written in
2025/2026

CompTIA Security+ SY Editionquestions and answers with rationales/graded A+/2026 update/100% correct /instant download

Institution
Course

Content preview

CompTIA Security+ SY0-701 2026
Edition\\\questions and answers with
rationales/graded A+/2026
update/100% correct /instant
download
Domain 1: General Security Concepts (12-15%)
1. A security architect is designing a new facility. To prevent malicious actors
from gaining physical access to server racks, they install a mantrap at the
entrance. Which type of control is this primarily considered?
A. Deterrent
B. Detective
C. Preventive
D. Compensating
Correct Answer: C. Preventive
Rationale: A mantrap is a physical access control that physically prevents
unauthorized individuals from following an authorized person through a door
(piggybacking). While it may deter (A), its primary function is to prevent access.
Detective (B) controls identify events (CCTV), while compensating (D) controls are
alternative safeguards.
2. A SaaS provider wants to ensure that if their primary data center goes
offline, customer data remains accessible from a secondary site without any
intervention. Which principle is the organization prioritizing?
A. Non-repudiation
B. High Availability
C. Integrity
D. Authentication
Correct Answer: B. High Availability
Rationale: High availability (HA) ensures systems are operational and accessible
despite failures, often through redundancy (clusters or failover sites).

,Confidentiality ensures secrecy, Integrity ensures data is unaltered, and
Authentication verifies identity.
3. A user receives a text message claiming their bank account is locked,
containing a link that looks nearly identical to the real bank URL but with a
".tk" TLD. Which of the following attacks is this?
A. Phishing
B. Vishing
C. Whaling
D. Pharming
Correct Answer: A. Phishing
Rationale: This describes a standard phishing attempt via SMS (Smishing is a
subset, but if the option is just "Phishing" and it fits the broad definition, Phishing
is correct). Vishing (B) uses voice. Whaling (C) targets executives. Pharming (D)
poisons DNS to redirect traffic without a malicious link.
4. A company decides to implement "Trust but Verify" for every access
request, regardless of whether the request originates from inside the corporate
network or a coffee shop. This strategy is known as:
A. Defense in Depth
B. Network Segmentation
C. Zero Trust Architecture
D. Role-Based Access Control
Correct Answer: C. Zero Trust Architecture
Rationale: Zero Trust explicitly removes the concept of a "trusted internal
network." It assumes breach and verifies every session explicitly. Defense in Depth
(A) is layering controls, while RBAC (D) is an access model that Zero Trust often
uses.
5. An attacker intercepts a communication between two parties and modifies
the message content before re-sending it. Which of the following fundamental
security goals is being directly violated?
A. Availability
B. Authorization
C. Integrity
D. Accounting

, Correct Answer: C. Integrity
Rationale: Integrity ensures that data has not been tampered with or altered by
unauthorized parties. Hashing and digital signatures are used to verify integrity.
6. (HOTSPOT) Match the security control to its function:
1. Firewall Rule -> (Preventive/Technical)
2. Security Guard -> (Deterrent/Physical)
3. Video Surveillance -> (Detective/Physical)
4. Antivirus Quarantine -> (Corrective/Technical)
7. A software developer signs their code with a digital certificate before
releasing it to the public. What security goal does this primarily support?
A. Availability
B. Non-repudiation
C. Anonymity
D. Tokenization
Correct Answer: B. Non-repudiation
Rationale: Signing code proves the origin of the software. The developer cannot
later deny they released that specific version because the signature is
cryptographically tied to their identity.
Domain 2: Threats, Vulnerabilities, and Mitigations (22-25%)
8. The threat actor group "Midnight Blizzard" (Nobelium) gains access to a
network, stays dormant for months, and uses sophisticated custom tools to
avoid detection while exfiltrating intellectual property. Which description best
fits this actor?
A. Script Kiddie
B. Hacktivist
C. Advanced Persistent Threat (APT)
D. Insider Threat
Correct Answer: C. Advanced Persistent Threat (APT)
Rationale: APTs are characterized by nation-state level resources, high skill, long-
term persistence, and specific goals (espionage).
9. A cybersecurity analyst reviews logs and sees that a single IP address sent
10,000 HTTP GET requests to a web server in 2 seconds, causing the server to

Written for

Course

Document information

Uploaded on
May 11, 2026
Number of pages
28
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$28.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
trustednurse NURSING
Follow You need to be logged in order to follow users or courses
Sold
944
Member since
3 year
Number of followers
411
Documents
9678
Last sold
1 day ago

On this platform, you will discover a variety of meticulously crafted study materials, including detailed documents, comprehensive bundles, and expertly designed flashcards provided by the seller, Trustednurse. These resources are thoughtfully prepared to support your learning journey and make your studies and exam preparations smooth and effective. I am here to offer any assistance or answer any questions you may have regarding your academic needs. Please don’t hesitate to reach out for guidance or support—I am more than happy to help you achieve success in your courses and exams. Wishing you a seamless and rewarding learning experience. Thank you so much for choosing these resources!

Read more Read less
4.9

2502 reviews

5
2395
4
30
3
36
2
17
1
24

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions