Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
A security administrator is deploying a DLP solution to prevent the exfiltration of sensitive customer data. Which of the following should the administrator do first?
Data classification is the process of assigning labels or tags to data based on its sensitivity, value, and risk. Data classification is the first step in a data loss prevention (DLP) solution, as it helps to identify what data needs to be protected and how. By applying classifications to the data, the security administrator can define appropriate policies and rules for the DLP solution to prevent the exfiltration of sensitive customer data.Reference: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, Chapter 8: Data Protection, page 323. CompTIA Security+ Practice Tests: Exam SY0-701, 3rd Edition, Chapter 8: Data Protection, page 327.
A malicious insider from the marketing team alters records and transfers company funds to a personal account. Which of the following methods would be the best way to secure company records in the future?
To secure company records against malicious insiders who can both alter records and authorize financial transactions, the best approach is to implement segregation of duties (SoD). This control ensures that no single individual can complete a critical transaction alone—for example, one person requests a fund transfer, another approves it, and a third executes it. This way, even a malicious insider cannot unilaterally alter records and transfer funds without detection or collusion.
During a penetration test in a hypervisor, the security engineer is able to use a script to inject a malicious payload and access the host filesystem. Which of the following best describes this vulnerability?
Comprehensive and Detailed Explanation From Exact Extract:
VM escape occurs when an attacker inside a virtual machine breaks out of the guest OS and gains access to the underlying host hypervisor or other virtual machines. In this scenario, the penetration tester executes a script to inject a malicious payload that allows access to the host filesystem---this is the textbook definition of VM escape.
The SY0-701 exam specifically identifies VM escape as one of the most critical virtualization vulnerabilities, as it defeats isolation and can compromise entire virtual environments. This typically results from flaws in hypervisor software, improper sandboxing, or insecure VM tools.
Cross-site scripting (B) affects web applications and browsers, not hypervisors. Malicious updates (C) involve tampered patch delivery. SQL injection (D) targets databases through application input fields.
Because the attacker moved from a VM to the host system, the correct classification is VM escape, a high-severity virtualization vulnerability.
Which of the following alert types is the most likely to be ignored over time?
A false positive is an alert that incorrectly identifies benign activity as malicious. Over time, if an alerting system generates too many false positives, security teams are likely to ignore these alerts, resulting in 'alert fatigue.' This increases the risk of missing genuine threats.
True positives and true negatives are accurate and should be acted upon.
False negatives are more dangerous because they fail to identify real threats, but they are not 'ignored' since they do not trigger alerts.
Which of the following would best explain why a security analyst is running daily vulnerability scans on all corporate endpoints?
Running daily vulnerability scans on all corporate endpoints is primarily done to track the status of patching installations. These scans help identify any missing security patches orvulnerabilities that could be exploited by attackers. Keeping the endpoints up-to-date with the latest patches is critical for maintaining security.
Finding shadow IT cloud deployments and monitoring hardware inventory are better achieved through other tools.
Hunting for active attackers would typically involve more real-time threat detection methods than daily vulnerability scans.
930 questions covering all exam domains, starting from $20
Exam domains verified against: Official CompTIA SY0-701 exam guide, last checked September 2026.
IT security professionals and system administrators learn various security controls and fundamental security principles. This domain emphasizes the importance of change management in maintaining security and the significance of using appropriate cryptographic solutions.
Cybersecurity analysts and risk managers compare different threat actors and their motivations. The domain covers common threat vectors, attack surfaces, types of vulnerabilities, indicators of malicious activity in different scenarios, and mitigation techniques to secure enterprises.
Security architects and infrastructure designers study the security implications of different architecture models. This domain applies security principles to protect enterprise infrastructure, compares data protection strategies, and emphasizes resilience and recovery.
Sample question from this domain above: Q4
Security operations teams and IT managers apply common security techniques to computing resources. The domain addresses security implications of managing hardware, software, and data assets, manages vulnerabilities, explains security alerting and monitoring concepts, and implements identity and access management.
This domain discusses elements of effective security governance and the risk management process. It covers third-party risk assessment and management processes, security compliance requirements, types and purposes of audits and assessments, and implementing security awareness practices.
Common questions about the exam itself