Popular
COMPTIA · SY0-701

CompTIA Security+ SY0-701 Exam Practice Questions

611 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 611 questions in this pack

Question 1

Which of the following threat actors is the most likely to be hired by a foreign government to attack critical systems located in other countries?

  1. Hacktivist
  2. Whistleblower
  3. Organized crime
  4. Unskilled attacker
Show answer and explanation

Correct answer: C. Organized crime

Organized crime groups have the resources, capability, and profit motive to be hired by foreign governments for sophisticated cyberattacks on critical infrastructure. They operate as professional entities with established business relationships and can be contracted for high-value operations. Hacktivists are ideologically motivated rather than mercenary, whistleblowers leak information rather than attack systems, and unskilled attackers lack the sophistication required for critical infrastructure targeting.

Why the other options are wrong

  • A. Hacktivists are ideologically motivated, not hired for profit by governments.
  • B. Whistleblowers disclose information rather than conduct attacks.
  • D. Unskilled attackers lack the sophistication to target critical systems effectively.

Question 2

Which of the following is used to add extra complexity before using a one-way data transformation algorithm?

  1. Key stretching
  2. Data masking
  3. Steganography
  4. Salting
Show answer and explanation

Correct answer: D. Salting

Salting adds random data to input before applying a one-way hash function, increasing complexity and preventing rainbow table attacks. It is specifically designed to add extra complexity before hashing. Key stretching is a related but distinct technique that applies hashing multiple times, data masking obscures sensitive data visibility, and steganography hides information within other media.

Why the other options are wrong

  • A. Key stretching applies the algorithm repeatedly, not adding complexity before transformation.
  • B. Data masking obscures data visibility rather than adding cryptographic complexity.
  • C. Steganography hides information within media, unrelated to hash algorithms.

Question 3

An employee clicked a link in an email from a payment website that asked the employee to update contact information. The employee entered the log-in information but received a “page not found” error message. Which of the following types of social engineering attacks occurred?

  1. Brand impersonation
  2. Pretexting
  3. Typosquatting
  4. Phishing
Show answer and explanation

Correct answer: D. Phishing

This scenario describes a classic phishing attack where an employee received a deceptive email from what appeared to be a payment website, clicked a link, and entered credentials on a fraudulent page. The 'page not found' error is typical when the phishing site has captured the credentials. Brand impersonation is the technique used but phishing is the attack type; pretexting involves creating false scenarios verbally; typosquatting involves domain name mimicry.

Why the other options are wrong

  • A. Brand impersonation is the technique used within the phishing attack, not the attack type itself.
  • B. Pretexting typically involves direct communication and building false relationships, not fake websites.
  • C. Typosquatting involves slightly misspelled domain names, not exact impersonation in emails.

See all 10 free questions Get the full pack, US$39

611 practice questions for CompTIA Security+ (SY0-701), with full explanations.

Every question comes with the correct answer, a clear explanation, and a note on why each other option is wrong, across MCQs, PBQs, simulations and open-ended questions.

  • 611 questions, MCQs, PBQs and simulations, mapped to the SY0-701 objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed SY0-701 attempt costs the full US$439 voucher again. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 611 questions

What makes the Security+ hard

Security+ is the most widely recognised entry-level cybersecurity certification globally, and the exam is not just multiple choice: performance-based questions, simulations and open-ended items are all in the mix, so you need to have practised every question type before you sit down.

This pack has 611 practice questions covering the complete question set: MCQs, PBQs, simulations and open-ended questions, all mapped to the current SY0-701 objectives, so nothing on exam day is a new format.

About the exam

The CompTIA Security+ is the most widely recognised entry-level cybersecurity certification globally. It is vendor-neutral, DoD-approved, and required or preferred by thousands of employers for roles such as security analyst, systems administrator and IT auditor. Current version V7, series code SY0-701, launched 7 November 2023.

Exam domains

  • General security concepts: 12%
  • Threats, vulnerabilities and mitigations: 22%
  • Security architecture: 18%
  • Security operations: 28%
  • Security program management and oversight: 20%

Up to 90 questions including PBQs, 90 minutes, pass mark 750 out of 900, US$439 per voucher, available in English, Japanese, Portuguese, Spanish and Thai, valid for three years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the CompTIA Security+ SY0-701 pack?

611 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.