CompTIA Security+ SY0-701 Security Controls Practice Test
Topic 01 focuses on Security Controls for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
Which safeguard is implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism?
Correct Answer: A
Correct Answer
Answer A is correct because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.
Incorrect Answers
Answer B is incorrect because Deterrent control represents a different security function. Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence.
Answer C is incorrect because Managerial control addresses a different requirement. Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Answer D is incorrect because Corrective control would fit a different scenario. Corrective control refers to a control used to repair, restore, or reduce damage after an undesirable event.
Question 2
To set organizational expectations, accountability, and risk direction, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Incorrect Answers
Answer A is incorrect because Directive control addresses a different requirement. Directive control refers to a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions.
Answer B is incorrect because Compensating control addresses a different security requirement. Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.
Answer C is incorrect because Deterrent control would fit a different scenario. Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence.
Question 3
Which safeguard is carried out primarily by people and day-to-day processes rather than by a purely technical mechanism?
Correct Answer: B
Correct Answer
Answer B is correct because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.
Incorrect Answers
Answer A is incorrect because Corrective control represents a different security function. Corrective control refers to a control used to repair, restore, or reduce damage after an undesirable event.
Answer C is incorrect because Compensating control would fit a different scenario. Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.
Answer D is incorrect because Technical control addresses a different requirement. Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.
Question 4
To restrict or deter physical access to systems and facilities, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures.
Incorrect Answers
Answer A is incorrect because Compensating control addresses a different requirement. Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.
Answer B is incorrect because Technical control would fit a different scenario. Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.
Answer C is incorrect because Preventive control addresses a different security requirement. Preventive control refers to a control intended to stop an unwanted event before it occurs.
Question 5
Which control is intended to stop an unwanted event before it occurs?
Correct Answer: C
Correct Answer
Answer C is correct because Preventive control means a control intended to stop an unwanted event before it occurs.
Incorrect Answers
Answer A is incorrect because Managerial control would fit a different scenario. Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Answer B is incorrect because Operational control addresses a different requirement. Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.
Answer D is incorrect because Detective control represents a different security function. Detective control refers to a control designed to discover or alert on suspicious activity that has occurred or is occurring.
Question 6
To make undesirable behavior less attractive without necessarily blocking it technically, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Deterrent control means a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence.
Incorrect Answers
Answer A is incorrect because Managerial control addresses a different requirement. Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Answer B is incorrect because Compensating control addresses a different security requirement. Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.
Answer C is incorrect because Operational control would fit a different scenario. Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.
Question 7
Which control designed to discover or alert on suspicious activity has occurred or is occurring?
Correct Answer: C
Correct Answer
Answer C is correct because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring.
Incorrect Answers
Answer A is incorrect because Technical control represents a different security function. Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.
Answer B is incorrect because Directive control would fit a different scenario. Directive control refers to a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions.
Answer D is incorrect because Deterrent control addresses a different requirement. Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence.
Question 8
To return systems or processes to an acceptable state after an incident, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Corrective control means a control used to repair, restore, or reduce damage after an undesirable event.
Incorrect Answers
Answer B is incorrect because Deterrent control would fit a different scenario. Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence.
Answer C is incorrect because Operational control addresses a different security requirement. Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.
Answer D is incorrect because Compensating control addresses a different requirement. Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.
Question 9
Which alternative safeguard is used when the preferred control cannot be implemented but equivalent risk reduction is still required?
Correct Answer: B
Correct Answer
Answer B is correct because Compensating control means an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.
Incorrect Answers
Answer A is incorrect because Deterrent control represents a different security function. Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence.
Answer C is incorrect because Managerial control would fit a different scenario. Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Answer D is incorrect because Operational control addresses a different requirement. Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.
Question 10
To communicate mandatory security behavior and expected actions, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions.
Incorrect Answers
Answer B is incorrect because Corrective control would fit a different scenario. Corrective control refers to a control used to repair, restore, or reduce damage after an undesirable event.
Answer C is incorrect because Preventive control addresses a different requirement. Preventive control refers to a control intended to stop an unwanted event before it occurs.
Answer D is incorrect because Physical control addresses a different security requirement. Physical control refers to a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures.
Question 11
To enforce a security requirement automatically through hardware or software, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.
Incorrect Answers
Answer B is incorrect because Operational control represents a different security function. Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.
Answer C is incorrect because Managerial control would fit a different scenario. Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Answer D is incorrect because Directive control addresses a different security requirement. Directive control refers to a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions.
Question 12
Which governance-oriented safeguard directs security through policies, risk decisions, oversight, and management processes?
Correct Answer: C
Correct Answer
Answer C is correct because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Incorrect Answers
Answer A is incorrect because Physical control addresses a different security requirement. Physical control refers to a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures.
Answer B is incorrect because Compensating control addresses a different requirement. Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.
Answer D is incorrect because Detective control represents a different security function. Detective control refers to a control designed to discover or alert on suspicious activity that has occurred or is occurring.
Question 13
To use repeatable human procedures such as security operations, training, or manual review, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.
Incorrect Answers
Answer A is incorrect because Technical control represents a different security function. Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.
Answer B is incorrect because Directive control addresses a different security requirement. Directive control refers to a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions.
Answer C is incorrect because Deterrent control would fit a different scenario. Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence.
Question 14
Which safeguard protects facilities, equipment, or people through tangible barriers or environmental measures?
Correct Answer: B
Correct Answer
Answer B is correct because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures.
Incorrect Answers
Answer A is incorrect because Managerial control addresses a different requirement. Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Answer C is incorrect because Compensating control represents a different security function. Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.
Answer D is incorrect because Operational control addresses a different security requirement. Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.
Question 15
To block or reduce the likelihood of a security incident before impact, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Preventive control means a control intended to stop an unwanted event before it occurs.
Incorrect Answers
Answer B is incorrect because Physical control represents a different security function. Physical control refers to a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures.
Answer C is incorrect because Compensating control addresses a different security requirement. Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.
Answer D is incorrect because Managerial control would fit a different scenario. Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Question 16
Which control is intended to discourage an attacker or policy violation by increasing perceived risk or consequence?
Correct Answer: C
Correct Answer
Answer C is correct because Deterrent control means a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence.
Incorrect Answers
Answer A is incorrect because Technical control addresses a different security requirement. Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.
Answer B is incorrect because Physical control represents a different security function. Physical control refers to a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures.
Answer D is incorrect because Detective control addresses a different requirement. Detective control refers to a control designed to discover or alert on suspicious activity that has occurred or is occurring.
Question 17
To identify security events so responders can investigate and act, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring.
Incorrect Answers
Answer A is incorrect because Directive control would fit a different scenario. Directive control refers to a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions.
Answer B is incorrect because Technical control represents a different security function. Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.
Answer C is incorrect because Managerial control addresses a different security requirement. Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Question 18
Which control is used to repair, restore, or reduce damage after an undesirable event?
Correct Answer: B
Correct Answer
Answer B is correct because Corrective control means a control used to repair, restore, or reduce damage after an undesirable event.
Incorrect Answers
Answer A is incorrect because Preventive control addresses a different requirement. Preventive control refers to a control intended to stop an unwanted event before it occurs.
Answer C is incorrect because Managerial control represents a different security function. Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Answer D is incorrect because Physical control addresses a different security requirement. Physical control refers to a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures.
Question 19
To provide substitute protection when a primary requirement is impractical, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Compensating control means an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.
Incorrect Answers
Answer A is incorrect because Preventive control represents a different security function. Preventive control refers to a control intended to stop an unwanted event before it occurs.
Answer C is incorrect because Operational control would fit a different scenario. Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.
Answer D is incorrect because Detective control addresses a different security requirement. Detective control refers to a control designed to discover or alert on suspicious activity that has occurred or is occurring.
Question 20
Which control tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions?
Correct Answer: C
Correct Answer
Answer C is correct because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions.
Incorrect Answers
Answer A is incorrect because Managerial control represents a different security function. Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.
Answer B is incorrect because Preventive control addresses a different security requirement. Preventive control refers to a control intended to stop an unwanted event before it occurs.
Answer D is incorrect because Technical control addresses a different requirement. Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.
Popular posts
Recent Posts
