CompTIA Security+ SY0-701 Fundamental Security Concepts Practice Test

 

Topic 02 focuses on Fundamental Security Concepts for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

What is the security objective of preventing unauthorized disclosure of information?

  1. Bollard
  2. Non-repudiation
  3. Confidentiality
  4. Honeypot

Correct Answer: C

 

Correct Answer

Answer C is correct because Confidentiality means the security objective of preventing unauthorized disclosure of information.

Incorrect Answers

Answer A is incorrect because Bollard represents a different security function. Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas.

Answer B is incorrect because Non-repudiation would fit a different scenario. Non-repudiation refers to assurance that a party cannot credibly deny having performed a specific action or sent a specific message.

Answer D is incorrect because Honeypot addresses a different requirement. Honeypot refers to a decoy system or service intended to attract and observe malicious activity.

 

Question 2

To ensure information remains accurate, complete, and trustworthy, which security approach should be selected?

  1. Gap analysis
  2. Policy enforcement point
  3. Integrity
  4. Bollard

Correct Answer: C

 

Correct Answer

Answer C is correct because Integrity means the security objective of preventing unauthorized or undetected modification of data and systems.

Incorrect Answers

Answer A is incorrect because Gap analysis addresses a different requirement. Gap analysis refers to a comparison of the current security state with a required or desired target state.

Answer B is incorrect because Policy enforcement point would fit a different scenario. Policy enforcement point refers to the component that actually allows, blocks, or terminates traffic according to policy decisions.

Answer D is incorrect because Bollard addresses a different security requirement. Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas.

 

Question 3

What is the security objective of keeping systems and information accessible to authorized users when needed?

  1. Policy engine
  2. Honeynet
  3. Policy administrator
  4. Availability

Correct Answer: D

 

Correct Answer

Answer D is correct because Availability means the security objective of keeping systems and information accessible to authorized users when needed.

Incorrect Answers

Answer A is incorrect because Policy engine would fit a different scenario. Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed.

Answer B is incorrect because Honeynet addresses a different requirement. Honeynet refers to a network of decoy systems designed to provide a broader deception environment.

Answer C is incorrect because Policy administrator represents a different security function. Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.

 

Question 4

To provide strong evidence linking an action or transaction to its originator, which security approach should be selected?

  1. Policy administrator
  2. Non-repudiation
  3. Zero Trust
  4. Authorization

Correct Answer: B

 

Correct Answer

Answer B is correct because Non-repudiation means assurance that a party cannot credibly deny having performed a specific action or sent a specific message.

Incorrect Answers

Answer A is incorrect because Policy administrator would fit a different scenario. Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.

Answer C is incorrect because Zero Trust addresses a different requirement. Zero Trust refers to a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access.

Answer D is incorrect because Authorization addresses a different security requirement. Authorization refers to the process of determining what an authenticated identity is allowed to do.

 

Question 5

What is the process of verifying the identity of a user, device, or other entity?

  1. Non-repudiation
  2. Authentication
  3. Accounting
  4. Policy administrator

Correct Answer: B

 

Correct Answer

Answer B is correct because Authentication means the process of verifying the identity of a user, device, or other entity.

Incorrect Answers

Answer A is incorrect because Non-repudiation addresses a different requirement. Non-repudiation refers to assurance that a party cannot credibly deny having performed a specific action or sent a specific message.

Answer C is incorrect because Accounting represents a different security function. Accounting refers to the recording and tracking of security-relevant actions for auditing and accountability.

Answer D is incorrect because Policy administrator would fit a different scenario. Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.

 

Question 6

To grant or deny permissions after identity has been established, which security approach should be selected?

  1. Authorization
  2. Policy engine
  3. Access control vestibule
  4. Honeytoken

Correct Answer: A

 

Correct Answer

Answer A is correct because Authorization means the process of determining what an authenticated identity is allowed to do.

Incorrect Answers

Answer B is incorrect because Policy engine addresses a different security requirement. Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed.

Answer C is incorrect because Access control vestibule would fit a different scenario. Access control vestibule refers to a physical entry design that uses two controlled doors so only one is open at a time.

Answer D is incorrect because Honeytoken addresses a different requirement. Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched.

 

Question 7

What is the recording and tracking of security-relevant actions for auditing and accountability?

  1. Policy enforcement point
  2. Accounting
  3. Authentication
  4. Honeytoken

Correct Answer: B

 

Correct Answer

Answer B is correct because Accounting means the recording and tracking of security-relevant actions for auditing and accountability.

Incorrect Answers

Answer A is incorrect because Policy enforcement point addresses a different requirement. Policy enforcement point refers to the component that actually allows, blocks, or terminates traffic according to policy decisions.

Answer C is incorrect because Authentication represents a different security function. Authentication refers to the process of verifying the identity of a user, device, or other entity.

Answer D is incorrect because Honeytoken would fit a different scenario. Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched.

 

Question 8

To identify missing controls, capabilities, or compliance requirements, which security approach should be selected?

  1. Access badge
  2. Confidentiality
  3. Gap analysis
  4. Availability

Correct Answer: C

 

Correct Answer

Answer C is correct because Gap analysis means a comparison of the current security state with a required or desired target state.

Incorrect Answers

Answer A is incorrect because Access badge addresses a different security requirement. Access badge refers to a physical or electronic credential used to identify and permit authorized personnel into a facility.

Answer B is incorrect because Confidentiality would fit a different scenario. Confidentiality refers to the security objective of preventing unauthorized disclosure of information.

Answer D is incorrect because Availability addresses a different requirement. Availability refers to the security objective of keeping systems and information accessible to authorized users when needed.

 

Question 9

Which security approach avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access?

  1. Zero Trust
  2. Honeytoken
  3. Confidentiality
  4. Honeynet

Correct Answer: A

 

Correct Answer

Answer A is correct because Zero Trust means a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access.

Incorrect Answers

Answer B is incorrect because Honeytoken would fit a different scenario. Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched.

Answer C is incorrect because Confidentiality addresses a different requirement. Confidentiality refers to the security objective of preventing unauthorized disclosure of information.

Answer D is incorrect because Honeynet represents a different security function. Honeynet refers to a network of decoy systems designed to provide a broader deception environment.

 

Question 10

To calculate an access decision from identity, device, risk, and policy information, which security approach should be selected?

  1. Honeynet
  2. Authentication
  3. Access control vestibule
  4. Policy engine

Correct Answer: D

 

Correct Answer

Answer D is correct because Policy engine means the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed.

Incorrect Answers

Answer A is incorrect because Honeynet would fit a different scenario. Honeynet refers to a network of decoy systems designed to provide a broader deception environment.

Answer B is incorrect because Authentication addresses a different requirement. Authentication refers to the process of verifying the identity of a user, device, or other entity.

Answer C is incorrect because Access control vestibule addresses a different security requirement. Access control vestibule refers to a physical entry design that uses two controlled doors so only one is open at a time.

 

Question 11

Which Zero Trust component establishes or terminates the communication path after receiving the policy decision?

  1. Policy administrator
  2. Authorization
  3. Availability
  4. Accounting

Correct Answer: A

 

Correct Answer

Answer A is correct because Policy administrator means the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.

Incorrect Answers

Answer B is incorrect because Authorization would fit a different scenario. Authorization refers to the process of determining what an authenticated identity is allowed to do.

Answer C is incorrect because Availability addresses a different requirement. Availability refers to the security objective of keeping systems and information accessible to authorized users when needed.

Answer D is incorrect because Accounting represents a different security function. Accounting refers to the recording and tracking of security-relevant actions for auditing and accountability.

 

Question 12

To enforce the access decision at the boundary between a subject and a resource, which security approach should be selected?

  1. Zero Trust
  2. Bollard
  3. Policy enforcement point
  4. Accounting

Correct Answer: C

 

Correct Answer

Answer C is correct because Policy enforcement point means the component that actually allows, blocks, or terminates traffic according to policy decisions.

Incorrect Answers

Answer A is incorrect because Zero Trust would fit a different scenario. Zero Trust refers to a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access.

Answer B is incorrect because Bollard addresses a different requirement. Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas.

Answer D is incorrect because Accounting addresses a different security requirement. Accounting refers to the recording and tracking of security-relevant actions for auditing and accountability.

 

Question 13

Which decoy system or service is intended to attract and observe malicious activity?

  1. Honeynet
  2. Integrity
  3. Access badge
  4. Honeypot

Correct Answer: D

 

Correct Answer

Answer D is correct because Honeypot means a decoy system or service intended to attract and observe malicious activity.

Incorrect Answers

Answer A is incorrect because Honeynet would fit a different scenario. Honeynet refers to a network of decoy systems designed to provide a broader deception environment.

Answer B is incorrect because Integrity represents a different security function. Integrity refers to the security objective of preventing unauthorized or undetected modification of data and systems.

Answer C is incorrect because Access badge addresses a different requirement. Access badge refers to a physical or electronic credential used to identify and permit authorized personnel into a facility.

 

Question 14

To observe attacker behavior across multiple realistic decoy assets, which security approach should be selected?

  1. Confidentiality
  2. Policy administrator
  3. Integrity
  4. Honeynet

Correct Answer: D

 

Correct Answer

Answer D is correct because Honeynet means a network of decoy systems designed to provide a broader deception environment.

Incorrect Answers

Answer A is incorrect because Confidentiality addresses a different requirement. Confidentiality refers to the security objective of preventing unauthorized disclosure of information.

Answer B is incorrect because Policy administrator would fit a different scenario. Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.

Answer C is incorrect because Integrity addresses a different security requirement. Integrity refers to the security objective of preventing unauthorized or undetected modification of data and systems.

 

Question 15

Which fake credential, record, API key, or other data element has no legitimate use and can reveal unauthorized access when touched?

  1. Honeytoken
  2. Access badge
  3. Policy engine
  4. Availability

Correct Answer: A

 

Correct Answer

Answer A is correct because Honeytoken means a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched.

Incorrect Answers

Answer B is incorrect because Access badge would fit a different scenario. Access badge refers to a physical or electronic credential used to identify and permit authorized personnel into a facility.

Answer C is incorrect because Policy engine represents a different security function. Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed.

Answer D is incorrect because Availability addresses a different requirement. Availability refers to the security objective of keeping systems and information accessible to authorized users when needed.

 

Question 16

To reduce tailgating and tightly control entry into a restricted area, which security approach should be selected?

  1. Access control vestibule
  2. Confidentiality
  3. Authentication
  4. Bollard

Correct Answer: A

 

Correct Answer

Answer A is correct because Access control vestibule means a physical entry design that uses two controlled doors so only one is open at a time.

Incorrect Answers

Answer B is incorrect because Confidentiality addresses a different security requirement. Confidentiality refers to the security objective of preventing unauthorized disclosure of information.

Answer C is incorrect because Authentication would fit a different scenario. Authentication refers to the process of verifying the identity of a user, device, or other entity.

Answer D is incorrect because Bollard addresses a different requirement. Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas.

 

Question 17

What is a sturdy physical barrier positioned to prevent vehicles from reaching protected areas?

  1. Bollard
  2. Accounting
  3. Honeynet
  4. Zero Trust

Correct Answer: A

 

Correct Answer

Answer A is correct because Bollard means a sturdy physical barrier positioned to prevent vehicles from reaching protected areas.

Incorrect Answers

Answer B is incorrect because Accounting addresses a different requirement. Accounting refers to the recording and tracking of security-relevant actions for auditing and accountability.

Answer C is incorrect because Honeynet represents a different security function. Honeynet refers to a network of decoy systems designed to provide a broader deception environment.

Answer D is incorrect because Zero Trust would fit a different scenario. Zero Trust refers to a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access.

 

Question 18

To control and record entry to restricted locations, which security approach should be selected?

  1. Policy administrator
  2. Authentication
  3. Access badge
  4. Bollard

Correct Answer: C

 

Correct Answer

Answer C is correct because Access badge means a physical or electronic credential used to identify and permit authorized personnel into a facility.

Incorrect Answers

Answer A is incorrect because Policy administrator would fit a different scenario. Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.

Answer B is incorrect because Authentication addresses a different security requirement. Authentication refers to the process of verifying the identity of a user, device, or other entity.

Answer D is incorrect because Bollard addresses a different requirement. Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas.

 

Question 19

To keep sensitive information available only to authorized subjects, which security approach should be selected?

  1. Authentication
  2. Access control vestibule
  3. Authorization
  4. Confidentiality

Correct Answer: D

 

Correct Answer

Answer D is correct because Confidentiality means the security objective of preventing unauthorized disclosure of information.

Incorrect Answers

Answer A is incorrect because Authentication represents a different security function. Authentication refers to the process of verifying the identity of a user, device, or other entity.

Answer B is incorrect because Access control vestibule would fit a different scenario. Access control vestibule refers to a physical entry design that uses two controlled doors so only one is open at a time.

Answer C is incorrect because Authorization addresses a different security requirement. Authorization refers to the process of determining what an authenticated identity is allowed to do.

 

Question 20

What is the security objective of preventing unauthorized or undetected modification of data and systems?

  1. Integrity
  2. Honeytoken
  3. Authorization
  4. Bollard

Correct Answer: A

 

Correct Answer

Answer A is correct because Integrity means the security objective of preventing unauthorized or undetected modification of data and systems.

Incorrect Answers

Answer B is incorrect because Honeytoken represents a different security function. Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched.

Answer C is incorrect because Authorization addresses a different security requirement. Authorization refers to the process of determining what an authenticated identity is allowed to do.

Answer D is incorrect because Bollard addresses a different requirement. Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas.

 

Question 21

To maintain reliable access despite failures, attacks, or capacity problems, which security approach should be selected?

  1. Integrity
  2. Availability
  3. Honeytoken
  4. Gap analysis

Correct Answer: B

 

Correct Answer

Answer B is correct because Availability means the security objective of keeping systems and information accessible to authorized users when needed.

Incorrect Answers

Answer A is incorrect because Integrity addresses a different security requirement. Integrity refers to the security objective of preventing unauthorized or undetected modification of data and systems.

Answer C is incorrect because Honeytoken represents a different security function. Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched.

Answer D is incorrect because Gap analysis would fit a different scenario. Gap analysis refers to a comparison of the current security state with a required or desired target state.

 

Question 22

Which term describes assurance that a party cannot credibly deny having performed a specific action or sent a specific message?

  1. Policy administrator
  2. Non-repudiation
  3. Authorization
  4. Confidentiality

Correct Answer: B

 

Correct Answer

Answer B is correct because Non-repudiation means assurance that a party cannot credibly deny having performed a specific action or sent a specific message.

Incorrect Answers

Answer A is incorrect because Policy administrator addresses a different requirement. Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.

Answer C is incorrect because Authorization represents a different security function. Authorization refers to the process of determining what an authenticated identity is allowed to do.

Answer D is incorrect because Confidentiality addresses a different security requirement. Confidentiality refers to the security objective of preventing unauthorized disclosure of information.

 

Question 23

To confirm who or what is requesting access, which security approach should be selected?

  1. Policy enforcement point
  2. Honeynet
  3. Authentication
  4. Confidentiality

Correct Answer: C

 

Correct Answer

Answer C is correct because Authentication means the process of verifying the identity of a user, device, or other entity.

Incorrect Answers

Answer A is incorrect because Policy enforcement point would fit a different scenario. Policy enforcement point refers to the component that actually allows, blocks, or terminates traffic according to policy decisions.

Answer B is incorrect because Honeynet represents a different security function. Honeynet refers to a network of decoy systems designed to provide a broader deception environment.

Answer D is incorrect because Confidentiality addresses a different security requirement. Confidentiality refers to the security objective of preventing unauthorized disclosure of information.

 

Question 24

What is the process of determining what an authenticated identity is allowed to do?

  1. Confidentiality
  2. Authorization
  3. Policy engine
  4. Honeynet

Correct Answer: B

 

Correct Answer

Answer B is correct because Authorization means the process of determining what an authenticated identity is allowed to do.

Incorrect Answers

Answer A is incorrect because Confidentiality addresses a different requirement. Confidentiality refers to the security objective of preventing unauthorized disclosure of information.

Answer C is incorrect because Policy engine represents a different security function. Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed.

Answer D is incorrect because Honeynet addresses a different security requirement. Honeynet refers to a network of decoy systems designed to provide a broader deception environment.

 

Question 25

To maintain evidence of who did what, when, and from where, which security approach should be selected?

  1. Honeytoken
  2. Honeynet
  3. Authorization
  4. Accounting

Correct Answer: D

 

Correct Answer

Answer D is correct because Accounting means the recording and tracking of security-relevant actions for auditing and accountability.

Incorrect Answers

Answer A is incorrect because Honeytoken addresses a different security requirement. Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched.

Answer B is incorrect because Honeynet represents a different security function. Honeynet refers to a network of decoy systems designed to provide a broader deception environment.

Answer C is incorrect because Authorization would fit a different scenario. Authorization refers to the process of determining what an authenticated identity is allowed to do.

 

Question 26

What is a comparison of the current security state with a required or desired target state?

  1. Zero Trust
  2. Confidentiality
  3. Integrity
  4. Gap analysis

Correct Answer: D

 

Correct Answer

Answer D is correct because Gap analysis means a comparison of the current security state with a required or desired target state.

Incorrect Answers

Answer A is incorrect because Zero Trust addresses a different security requirement. Zero Trust refers to a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access.

Answer B is incorrect because Confidentiality represents a different security function. Confidentiality refers to the security objective of preventing unauthorized disclosure of information.

Answer C is incorrect because Integrity addresses a different requirement. Integrity refers to the security objective of preventing unauthorized or undetected modification of data and systems.

 

Question 27

To limit access through explicit verification and least-privilege decisions, which security approach should be selected?

  1. Honeytoken
  2. Non-repudiation
  3. Zero Trust
  4. Policy engine

Correct Answer: C

 

Correct Answer

Answer C is correct because Zero Trust means a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access.

Incorrect Answers

Answer A is incorrect because Honeytoken addresses a different security requirement. Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched.

Answer B is incorrect because Non-repudiation would fit a different scenario. Non-repudiation refers to assurance that a party cannot credibly deny having performed a specific action or sent a specific message.

Answer D is incorrect because Policy engine represents a different security function. Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed.

 

Question 28

Which Zero Trust decision component evaluates policy and contextual signals to determine whether access should be allowed?

  1. Access badge
  2. Policy engine
  3. Authorization
  4. Policy enforcement point

Correct Answer: B

 

Correct Answer

Answer B is correct because Policy engine means the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed.

Incorrect Answers

Answer A is incorrect because Access badge addresses a different security requirement. Access badge refers to a physical or electronic credential used to identify and permit authorized personnel into a facility.

Answer C is incorrect because Authorization addresses a different requirement. Authorization refers to the process of determining what an authenticated identity is allowed to do.

Answer D is incorrect because Policy enforcement point represents a different security function. Policy enforcement point refers to the component that actually allows, blocks, or terminates traffic according to policy decisions.

 

Question 29

To translate an access decision into actions that create or remove a session, which security approach should be selected?

  1. Policy administrator
  2. Honeypot
  3. Policy engine
  4. Honeynet

Correct Answer: A

 

Correct Answer

Answer A is correct because Policy administrator means the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.

Incorrect Answers

Answer B is incorrect because Honeypot addresses a different security requirement. Honeypot refers to a decoy system or service intended to attract and observe malicious activity.

Answer C is incorrect because Policy engine represents a different security function. Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed.

Answer D is incorrect because Honeynet would fit a different scenario. Honeynet refers to a network of decoy systems designed to provide a broader deception environment.

 

Question 30

Which component actually allows, blocks, or terminates traffic according to policy decisions?

  1. Non-repudiation
  2. Policy enforcement point
  3. Integrity
  4. Access control vestibule

Correct Answer: B

 

Correct Answer

Answer B is correct because Policy enforcement point means the component that actually allows, blocks, or terminates traffic according to policy decisions.

Incorrect Answers

Answer A is incorrect because Non-repudiation represents a different security function. Non-repudiation refers to assurance that a party cannot credibly deny having performed a specific action or sent a specific message.

Answer C is incorrect because Integrity addresses a different requirement. Integrity refers to the security objective of preventing unauthorized or undetected modification of data and systems.

Answer D is incorrect because Access control vestibule addresses a different security requirement. Access control vestibule refers to a physical entry design that uses two controlled doors so only one is open at a time.

img