Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

SY0-701 Exam Questions & Answers

CompTIA Security+ Certification Exam (2026)  •  CompTIA

902 Questions 90 min Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample SY0-701 Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

Which of the following is a common source of unintentional corporate credential leakage in cloud environments?

Correct Answer: A
Explanation:

Code repositories are a common source of unintentional corporate credential leakage, especially in cloud environments. Developers may accidentally commit and push sensitive information, such as API keys, passwords, and other credentials, to public or poorly secured repositories. These credentials can then be accessed by unauthorized users, leading to security breaches. Ensuring that repositories are properly secured and that sensitive data is never committed is critical for protecting against this type of leakage.

Reference =

CompTIA Security+ SY0-701 Course Content: Domain 03 Security Architecture.

CompTIA Security+ SY0-601 Study Guide: Chapter on Threats and Vulnerability Management.

Q2 MultipleChoice

A company is developing a business continuity strategy and needs to determine how many staff members would be required to sustain the business in the case of a disruption. Which of the following best describes this step?

Correct Answer: A
Explanation:

Capacity planning is the process of determining the resources needed to meet the current and future demands of an organization. Capacity planning can help a company develop a business continuity strategy by estimating how many staff members would be required to sustain the business in the case of a disruption, such as a natural disaster, a cyberattack, or a pandemic. Capacity planning can also help a company optimize the use of its resources, reduce costs, and improve performance.Reference=CompTIA Security+ Study Guide with over 500 Practice Test Questions: Exam SY0-701, 9th Edition, Chapter 4, page 184. CompTIA Security+ (SY0-701) Certification Exam Objectives, Domain 4.1, page 14.Business Continuity -- SY0-601 CompTIA Security+ : 4.1

Q3 MultipleChoice

A systems administrator works for a local hospital and needs to ensure patient data is protected and secure. Which of the following data classifications should be used to secure patient data?

Correct Answer: C
Explanation:

Data classification is a process of categorizing data based on its level of sensitivity, value, and impact to the organization if compromised. Data classification helps to determine the appropriate security controls and policies to protect the data from unauthorized access, disclosure, or modification. Different organizations may use different data classification schemes, but a common one is the four-tier model, which consists of the following categories: public, private, sensitive, and critical.

Public data is data that is intended for public access and disclosure, and has no impact to the organization if compromised. Examples of public data include marketing materials, press releases, and public web pages.

Private data is data that is intended for internal use only, and has a low to moderate impact to the organization if compromised. Examples of private data include employee records, financial reports, and internal policies.

Sensitive data is data that is intended for authorized use only, and has a high impact to the organization if compromised. Examples of sensitive data include personal information, health records, and intellectual property.

Critical data is data that is essential for the organization's operations and survival, and has a severe impact to the organization if compromised. Examples of critical data include encryption keys, disaster recovery plans, and system backups.

Patient data is a type of sensitive data, as it contains personal and health information that is protected by law and ethical standards. Patient data should be used only by authorized personnel for legitimate purposes, and should be secured from unauthorized access, disclosure, or modification. Therefore, the systems administrator should use the sensitive data classification to secure patient data.

Reference=CompTIA Security+ SY0-701 Certification Study Guide, page 90-91;Professor Messer's CompTIA SY0-701 Security+ Training Course, video 5.5 - Data Classifications, 0:00 - 4:30.

Q4 MultipleChoice

Which of the following actions must an organization take to comply with a person's request for the right to be forgotten?

Correct Answer: C
Explanation:

Theright to be forgotten, as outlined in regulations such as theGeneral Data Protection Regulation (GDPR), requires organizations topermanently delete an individual's personal dataupon request, unless there is a legal or contractual obligation to retain it.

Purging personally identifiable attributes (A)removes some identifying data but does not fully satisfy the request.

Encrypting the data (B)does not remove it, and the data is still accessible with the decryption key.

Obfuscating data (D)makes data unreadable but does not permanently remove it.

To comply withthe right to be forgotten, organizations mustremove all of the person's dataunless an exception applies.

Q5 MultipleChoice

A security analyst needs to improve the company's authentication policy following a password audit. Which of the following should be included in the policy? (Select two).

Correct Answer: A, B
Explanation:

A strong authentication policy should enforcepassword length(e.g., minimum of 12-16 characters) andcomplexity(mix of uppercase, lowercase, numbers, and symbols). These measures significantlyreduce the risk of brute-force attacks.

Least privilege (C)relates to access control, not authentication policies.

Something you have (D)andbiometrics (F)pertain to multi-factor authentication (MFA) but are not password policy requirements.

Get access to all 902 verified questions with detailed answers.

Unlock All SY0-701 Questions

Frequently Asked Questions

The SY0-701 exam covers five main domains: General Security Concepts (12%), Threats, Vulnerabilities, and Mitigations (22%), Security Architecture (16%), Security Operations (26%), and Security Program Management and Governance (24%). These domains encompass a comprehensive range of security topics from foundational concepts to advanced operational and governance practices.

The SY0-701 exam contains 90 questions that must be completed within 90 minutes. The passing score is 750 out of a possible 900 points, which typically translates to approximately 83% correct answers needed to pass.

CompTIA recommends that candidates have at least 2 years of experience in IT administration with a focus on security, or equivalent education and experience. There are no mandatory prerequisites, but Security+ is often considered a mid-level certification that builds upon CompTIA A+ and Network+ knowledge.

The Security+ certification is valid for three years from the date of passing the exam. To maintain the certification beyond three years, you must either retake the exam or earn continuing education credits through approved training and professional activities.

The SY0-701 exam typically costs between $380-$420 USD, depending on your location and testing center. CompTIA recommends using official study guides, practice exams, instructor-led training, and online courses to prepare; popular resources include Professor Messer's video courses and Darril Gibson's study guides.
Exam Details
  • Exam CodeSY0-701
  • VendorCompTIA
  • Total Questions902
  • Duration90 min
  • LanguageEnglish
  • Last UpdatedSep 5, 2026
4.9/5

Pass SY0-701 First Time

Get all 902 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals