SY0-701 practice questions
CompTIA · SY0-701 · 300 questions
Original practice questions for the CompTIA Security+ (SY0-701) exam, covering general security concepts, threats and vulnerabilities and mitigations, security architecture, security operations, and security program management and oversight.
This course contains the use of artificial intelligence.
About the SY0-701 exam
- Time allowed
- 1 hour 30 minutes
- Questions
- Maximum of 90
- Passing score
- 750 (scale 100-900)
- Format
- Multiple-choice and performance-based
Exam details published by the vendor, checked 28 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
General Security Concepts · 36 questions
- A county board installs a new badge reader on the data-center door and asks whether that control is technical or physical. How should the security analyst classify the badge reader?
- A city CISO notices staff calling every firewall rule 'detective.' Which statement correctly contrasts a blocking firewall rule with a SIEM alert that only notifies after traffic has already occurred?
- Public works posts 'Authorized Personnel Only' signs on a pump-station fence. Which control type best describes the signs by themselves?
- After ransomware hits the library, IT restores systems from backups and rebuilds servers. Which control type best describes those restoration actions?
- A transit agency cannot yet replace an end-of-life ticket kiosk operating system, so it isolates the kiosk VLAN and adds extra monitoring. Which control type best describes those alternate safeguards?
- HR publishes a mandatory password-change policy for all municipal accounts. Which control category best fits that written policy?
- Nightly log review by SOC analysts is framed as which control category, distinct from the SIEM product itself?
- City council issues a binding directive that all departments must encrypt laptops. Which control type best describes that mandate?
- A school district maps controls on both category and type axes. How should a lobby security camera primarily be labeled?
- A mayor asks what 'integrity' means for property-tax records. Which explanation is most accurate?
- During a storm, the city's 911 CAD system goes down even though no records were stolen. Which CIA objective was primarily violated?
- A contractor denies approving a fraudulent wire after their account was used. Which security concept makes repudiation harder by providing reliable evidence of who authorized an action?
- Library patrons treat 'logging in' as the entire AAA model. Which statement correctly separates the AAA functions?
- After a gap analysis, the water utility lists missing MFA on VPN as a control gap versus policy. What does that gap analysis primarily represent?
- A county moves from trusting the internal LAN by default to verifying every access request. Which principle best describes that shift?
- In a zero-trust design discussion, which pairing correctly places the policy decision and the policy enforcement roles?
- A courthouse lobby uses vehicle bollards outside and an access-control vestibule (mantrap) at the entrance. Which statement best identifies these measures?
- Parks IT creates a honeytoken service account that should never log in; any use triggers a high-fidelity alert. What is the primary purpose of that account?
- A small city runs a honeynet segment that mimics SCADA HMI hosts. How does a honeynet differ from a honeypot?
- Before a firewall cutover, the change board insists on an approval process and a named owner. Why are those steps security-relevant?
- A rushed switch upgrade skips impact analysis and overnight permit systems go dark. What should impact analysis have provided before the change?
- An identity-provider upgrade fails and staff cannot restore the prior configuration because no backout plan exists. Which change-management artifact was missing?
- A vendor patches VPN concentrators at noon on tax-filing day, ignoring maintenance windows and SOPs. Which change-management practice was primarily violated?
- Updates to allow lists and deny lists on the city web filter are treated as restricted activities needing change control. Why?
- After a successful network change, diagrams and procedures are left stale, and later incident responders work from outdated maps. Which change-management requirement was neglected?
- Before cutting over the city's online payment portal, which change-management practice best reduces security and business-process risk?
- A public-health clinic issues laptops that may hold PHI. Which encryption approach best protects that data if a laptop is stolen while powered off?
- A municipal VPN establishes a session by exchanging secrets with public-key cryptography, then encrypts bulk traffic with a shared session key. Which statement correctly separates those roles?
- A records clerk proposes hashing archived city council minutes so the files stay confidential yet can be opened and read later. Why is that proposal incorrect?
- The city identity store hashes passwords and adds a unique salt per account. What security problem does salting primarily address?
- Election equipment receives a vendor software update. Which cryptographic result does verifying the publisher's digital signature on the package primarily provide?
- City laptops use a TPM to protect device keys, while the certificate authority team evaluates an HSM for root and intermediate key operations. How do these technologies differ at a purpose level?
- A recreation-fee system replaces stored cardholder numbers with tokens for processing, and the cashier screen shows only the last four PAN digits. Which statement best contrasts those techniques?
- A city CA issued a certificate that was later revoked after a private-key compromise. What should relying parties do before trusting that certificate?
- An internal library kiosk presents a self-signed TLS certificate with no public CA chain. What is the main trust implication compared with a certificate from a trusted third-party CA?
- The password vault that protects shared municipal admin secrets uses key stretching with a strong algorithm and adequate key length. What is the primary security benefit of key stretching in this context?
Threats, Vulnerabilities, and Mitigations · 66 questions
- Sophisticated probes against the dam SCADA vendor portal appear aimed at long-term intelligence collection and show high funding and custom tooling. Which threat-actor profile best fits?
- Overnight logs show repeated default-password attempts against the public library Wi-Fi admin page using widely published tools. Which actor attribute set is most accurate?
- After a contentious city council vote, attackers deface the mayor's public website with political slogans but make no ransom demand. Which motivation and actor type best describe the activity?
- A public-works employee with legitimate GIS access copies sensitive infrastructure layers to personal media shortly before resigning. Which threat category does this primarily illustrate?
- Attackers encrypt the county permit system and demand payment to restore operations. Which threat-actor motivation pairing is most consistent with this pattern?
- A parks department quietly adopts an unsanctioned public SaaS form tool for event registrations without IT review. How should security classify this situation?
- Analysts compare two campaigns against the municipal utility: one is external with high funding and advanced tooling; the other is internal with limited skill. Which attribute pairing best describes the well-resourced external campaign?
- Intruders quietly steal voter-roll exports from a county system and prepare them for sale, without knocking services offline. Which motivation best matches this behavior?
- After sensitive HR files are stolen from a city shared drive, attackers threaten to publish them unless officials meet demands. Which motivation framing is most accurate?
- A former contractor, angry after a contract non-renewal, targets the city's ticketing system to cause damage. Which motivation best classifies this activity?
- Destructive malware hits municipal water-treatment controls in the same week as escalating geopolitical conflict, with no ransom note. Which motivation category is most consistent?
- An outside researcher accesses a city system without permission, then claims an 'ethical' motive after publicly posting findings. How should the city treat that access?
- A finance clerk receives an unexpected email urging an immediate change to vendor wire instructions. Which threat vector best describes this attack?
- City employees receive text messages pretending to be the municipal MFA reset help line and asking for one-time codes. Which attack type is this?
- A city help desk receives a phone call from someone claiming to be the CIO who urgently demands a password reset for a privileged account and refuses to use the ticket portal. Which threat vector best describes this attempt?
- Accounts payable at the county construction office receives an email from what looks like a long-time vendor asking to redirect the next progress payment to a new bank account. The From domain is one character off the real vendor domain. Which attack best matches this scenario?
- Security finds several unlabeled USB drives left in the visitor parking lot outside city hall, some labeled "Q4 budget draft." An employee plugs one into a clerk workstation and malware begins beaconing. Which threat vector is primarily illustrated?
- The DMV still runs public-facing Windows 7 kiosks that are joined to the staff network and no longer receive vendor security updates. Which attack-surface concern does this primarily represent?
- A scanner finds a public-facing municipal jump host with Remote Desktop exposed to the Internet and the vendor default administrator password still in use. Which combination of vectors does this primarily illustrate?
- Attackers breach the remote-support platform used by the city’s managed service provider and then reach multiple municipal endpoints through that trusted tooling. Which attack surface best describes this event?
- Threat intelligence reports that attackers compromised a niche municipal-procurement discussion forum that purchasing staff visit weekly, then served malware to visitors. Which threat vector is this?
- A caller tells the facilities clerk they are conducting an unannounced physical-security audit for the county and need today’s badge door codes "for the checklist." Which social-engineering technique is primarily in play?
- False boil-water alerts flood the city’s social channels, creating public panic while attackers simultaneously phish residents toward fake "emergency portal" login pages. Which threat vector is primarily illustrated by the false alerts?
- A library guest Wi-Fi SSID is bridged into the same VLAN as staff workstations with no client isolation, allowing a visitor laptop to reach clerk file shares. Which threat vector best describes this condition?
- Transit GIS staff open a "map update" image that later appears to have delivered a malicious payload through embedded content rather than a normal office document. At Security+ depth, which threat vector should analysts primarily consider?
- Clerk workstations still run an unpatched browser plugin that agentless network scans never inventory, and several drive-by attempts target that plugin. Which attack-surface issue is most directly highlighted?
- A building-permit web application concatenates citizen form fields directly into SQL statements, and testers can alter queries to return other applicants’ records. Which vulnerability type is this?
- A citizen-comment portal reflects unsanitized input into pages other residents view, and a crafted script steals session cookies from those browsers. Which vulnerability is demonstrated?
- A legacy document-scanning service crashes when fed an oversized input, and analysis shows adjacent memory was overwritten before a suspicious process started. Which application vulnerability class best fits?
- On a shared municipal app server, a process checks a file’s permissions, then an attacker replaces the file before it is used, gaining unauthorized access. Which vulnerability does this describe?
- Building-badge door controllers still run firmware last updated years ago, and the vendor has published critical fixes the city never applied. Which vulnerability class is primarily involved?
- The city’s edge firewall has reached vendor end-of-life and will receive no further security patches, yet it still terminates Internet traffic for several departments. Which vulnerability concern is most accurate?
- A single hypervisor hosts both a low-trust guest Wi-Fi captive portal VM and finance application VMs with weak isolation controls. Leadership asks what vulnerability would let an attacker break out of the portal guest. Which concept applies?
- A county open-data project discovers a cloud storage bucket holding draft resident datasets is configured for public read without authentication. Which vulnerability type best describes this finding?
- A trusted software vendor’s update channel is compromised and a malicious build is pushed to municipal workstations that auto-install the update. Which vulnerability / attack theme does this primarily represent?
- Inspectors jailbreak city-issued tablets and sideload unapproved field apps, bypassing MDM restrictions that blocked those installs. Which mobile vulnerability theme is most accurate?
- Researchers disclose a critical flaw in the VPN appliance the city uses, but the vendor has not released a patch yet and active exploitation is reported elsewhere. Which vulnerability class best fits?
- A parking-payment kiosk still allows a weak legacy TLS cipher suite that security scanners flag as outdated and breakable with known attacks. Which vulnerability type is primarily indicated?
- Domain-joined clerk PCs remain missing a published OS security update that enables local privilege escalation, and attackers who phish one user become local admins. Which vulnerability class best describes the missing fix?
- County clerk workstations suddenly show ransom notes on the desktop and many files have unfamiliar encrypted extensions. Which malware indicator best matches this activity?
- A public-works technician installs a 'helpful' remote-support utility that arrived in email. Investigators later find a hidden backdoor. Which malware classification best fits the original installer?
- Malware on the city network is hopping from host to host across a VLAN without clerks clicking attachments. How does this behavior primarily differ from a classic file-infecting virus?
- Before an ACH batch leaves finance, malware on a clerk PC quietly records every keystroke. Which malware class best describes this behavior?
- A contractor's access ends Friday, and Saturday morning a script on a records server deletes selected case files. Which malware pattern does this most clearly illustrate?
- On a municipal jump server, local antivirus shows a clean bill of health, yet an offline integrity tool reveals hidden processes and altered system binaries. Which malware category best explains the concealment?
- Security cameras show a stranger lingering at the city garage badge reader with a handheld device, and the next morning an unused cloned badge opens the door. Which attack indicator is this?
- The city's public website is unreachable while edge logs show huge inbound UDP replies from many third-party resolvers after small spoofed queries. Which network attack pattern best matches these indicators?
- Payroll staff report the familiar portal URL opening a lookalike login page. Recursive resolver cache shows unexpected A records for the official hostname. Which malicious activity indicator fits best?
- On city hall guest Wi-Fi, several browsers suddenly warn about unexpected certificates and session contents appear altered mid-transfer. Which attack indicator does this describe?
- Identity logs show many municipal accounts receiving one or two failed logons with the same common password, then quiet periods, rather than thousands of guesses against one account. Which attack pattern is this?
- A legacy utility appliance renegotiates its management session to outdated weak ciphers after an attacker interferes with the handshake. Which cryptographic attack is occurring?
- An analyst sees a successful city VPN login from headquarters, then another success from overseas minutes later for the same user. Which identity anomaly indicator should be treated as suspicious?
- After a suspected intrusion on a critical permits server, investigators find large gaps where security and authentication logs should exist. What malicious indicator does this most strongly suggest?
- Web logs for the municipal document portal show requests with sequences like ../ and paths resembling /etc/passwd under the application URL. Which application attack indicator is this?
- After a phishing wave hits enterprise IT, leadership wants to reduce the chance that malware can reach water-plant SCADA. Which mitigation best limits that blast radius?
- Too many departments can write to the city finance file share after a permissions creep review. Which mitigation best reduces unauthorized access?
- Election clerk workstations must run only a small set of approved voting-support programs. Which mitigation enforces that control?
- A critical CVE on the city's VPN concentrator now has public exploit code circulating. Which mitigation should be prioritized first for that vulnerability?
- Lobby information kiosks need stronger endpoint hardening beyond signature AV alone. Which pair of controls best matches common host-hardening mitigations?
- New access-layer switches arrive with default credentials and many unused services enabled. Which baseline hardening steps should operations apply before production use?
- A CAD workstation used for public-works drawings is confirmed malware-infected. Which mitigation contains the host while still supporting investigation?
- Sensitive backup tapes must leave the records center for off-site storage. Which mitigation best protects confidentiality if a courier loses a case?
- Hardened workstation images disable RDP, but weeks later drift re-enables it on several clerk PCs. Which mitigation keeps the secure baseline from eroding?
- Retired municipal file servers still sit online with old shares after their replacements go live. Which mitigation best reduces lingering exposure?
- A county launches a new public permitting portal and wants to catch misuse quickly after go-live. Which mitigation pairs best with the new exposure?
- A vendor appliance in the municipal data center has a critical patch, but a change freeze blocks immediate installation. Which interim mitigation best reduces exposure until the patch window opens?
Security Architecture · 54 questions
- A city migrates staff email to a SaaS provider. Under the cloud shared responsibility model, which split is most accurate?
- A county keeps on-premises Active Directory while rolling out cloud apps for permitting. Which hybrid architecture consideration should security prioritize?
- Public works wants a third-party SaaS product for online permitting. Which architecture implication should the security architect emphasize first?
- The city's cloud team uses infrastructure-as-code templates to deploy identical hardened network baselines for each department. Which security implication is most accurate?
- A library chatbot will run as serverless functions. Which security implication should the architect highlight?
- The 311 application is redesigned as microservices. Which security implication is most important for the new architecture?
- Election tabulation gear must stay isolated from the county office network. How do an air-gapped lab and a logically segmented VLAN differ?
- The transit authority evaluates software-defined networking for its core. Which architecture implication of SDN is most accurate?
- City leadership debates a centralized SOC with shared tooling versus letting each department run its own security stack. Which tradeoff is most accurate?
- A legacy permitting module will be packaged in containers. Which security implication should the architect call out?
- The municipal virtualization cluster hosts many VMs on each physical host to save cost. Which security consideration is most relevant?
- Smart streetlight sensors are being added across downtown. Which IoT architecture implication should security emphasize?
- Wastewater SCADA prioritizes plant uptime and safety, and some controllers cannot be patched on desktop-like schedules. Which implication best reflects ICS/SCADA security architecture?
- Traffic-signal controllers run a real-time operating system with limited security tooling. Which statement best captures the architecture implication?
- Architects are placing controls for a citizen portal and for privileged admin access to backend servers. Which placement best matches secure infrastructure practice?
- The city needs a public web presence and a protected finance network. Which zoning approach best reduces attack surface?
- Facilities debates door-controller failure behavior versus traffic-signal safety behavior during outages. Which guidance is most appropriate?
- Network engineers must choose between an inline IPS and a tap/monitor IDS for a county uplink. Which distinction is correct?
- City hall wants controlled outbound web access with content filtering for staff browsers. Which appliance role fits best?
- The 311 portal needs traffic spread across several web servers and may terminate TLS at the edge. Which appliance primarily provides that role?
- Council chambers switches must stop unknown devices and rogue access points from getting LAN access. Which approach best fits?
- Attackers are targeting the citizen portal with HTTP application attacks such as injection and abusive web requests. Which control is the best fit for that threat layer?
- Remote municipal staff need protected access to internal systems over the Internet. Which approach best matches secure remote access architecture?
- A county library system wants branch sites to share a centrally managed WAN policy for encrypted paths and traffic steering without building a full MPLS mesh. Which technology best matches that goal?
- A city moves to a cloud-first model where remote staff access SaaS and municipal apps from many locations. Leadership wants networking and security services delivered together near the user. Which concept describes that approach?
- A municipal data center needs visibility into east-west traffic between application tiers so an IDS can detect lateral movement. Where should sensors be placed to support that goal?
- A remote pump station has very limited bandwidth back to the operations center. How should that constraint shape the monitoring architecture?
- Remote vendors dial into city systems using only longer passwords. Which control selection most effectively reduces remote-access risk?
- A small township wants one appliance that consolidates firewall, intrusion prevention, and related security functions instead of managing many separate boxes. Which solution fits that need?
- Administrators currently expose Remote Desktop Protocol directly to the Internet. Which change best reduces that attack surface?
- A records officer must label data correctly: 911 call recordings versus published park event schedules. Which classification approach is appropriate?
- An unpublished GIS map detailing water-valve vulnerabilities is kept internal because disclosure would aid saboteurs. Which data type best describes that map for protection decisions?
- Backup disks sit encrypted in a vault, a nightly job copies them over TLS to the DR site, and analysts query live datasets in memory. Which pairing correctly matches those data states?
- A public-health department must keep resident health records stored in-region due to legal placement rules. Which requirement is being applied?
- Developers must protect SSN fields in a database, store passwords safely, and show only partial payment card numbers on clerk screens. Which combination of methods is appropriate?
- Regulated employee data lives on an HR file share. How should access be constrained?
- Security staff handle both a human-readable PDF employee roster and binary SCADA sensor dumps. Why does readability matter for protection approaches?
- SCADA setpoint files that keep water treatment stable are far more critical than marketing PDFs on the public website. How should protections differ?
- A city parking system must store payment references without retaining raw primary account numbers in the municipal database. Which method best meets that goal?
- Police records subject to CJIS-adjacent handling rules sit beside ordinary office memos. What should drive control strength for those police records?
- A vendor demo needs production-like municipal data in a test environment. Which practice appropriately reduces exposure?
- Backup tapes leave the building nightly, and USB ports on clerk PCs are a known exfiltration path. Which layered approach addresses both risks?
- 911 dispatch needs near-immediate failover capacity, while a rarely used archive system can tolerate long rebuild time. Which site strategy fits?
- Municipal IT currently runs both primary and backup data centers in the same floodplain building complex. What resilience change addresses regional disaster risk?
- The utility customer portal must stay available if one web node fails. How do load balancing and clustering differ as high-availability approaches?
- A single cloud vendor outage halted several municipal services last year. Which resilience strategy reduces that common-mode failure risk?
- Before ransomware hits, leadership wants staff to walk through decision-making without taking production systems offline. Which testing type fits?
- The tax database requires reliable recovery after corruption or ransomware. Which backup design elements are most appropriate?
- Before a major upgrade to the county permitting database, the team needs a quick restore point on the same host, while the disaster-recovery site must stay nearly current for day-to-day failover. Which pairing best matches those needs?
- City hall loses utility power for two minutes, then later faces a multi-hour outage during a storm. Which power-resilience pairing correctly describes UPS and generator roles?
- Before hurricane season, the municipal emergency-ops team must scale permit and shelter systems. What should capacity planning cover?
- A flood closes the primary city offices, but residents still need building permits issued. Which plan focus best keeps that essential function running from an alternate facility?
- During a scheduled failover test for the library catalog, cutover is delayed because DNS TTLs keep clients pointed at the old site. What does this outcome mainly illustrate?
- Transit dispatch can lose at most a few minutes of data, while a low-priority archive can tolerate overnight loss. How should recovery objectives influence backup versus replication choices?
Security Operations · 84 questions
- After imaging clerk workstations for the tax office, security wants consistent hardened settings that stay current. Which approach best applies secure baselines?
- Network staff are locking down servers, switches, and routers that support utility billing. Which hardening focus is most appropriate?
- Inspectors need phones for field work. The city will enroll devices in MDM and must choose how much corporate control versus personal choice to allow. Which statement best matches common deployment models?
- Before placing access points in a concrete courthouse with thick walls, wireless engineers want evidence of coverage and dead zones. What should they use?
- Staff Wi-Fi at the public works yard must use modern encryption and per-user enterprise authentication. Which settings best fit?
- Developers are hardening the city's online payments site against injection and session theft. Which application-security pairing is most relevant?
- Before releasing an internal mobile app for code-enforcement officers, the city wants flaws found in source and assurance the binary is authentic. Which techniques fit?
- Clerks receive citizen email with untrusted attachments. What technique best contains potential malware before files open on the clerk PC?
- After baseline hardening of city IoT cameras and water-plant ICS devices, what ongoing practice should accompany those controls?
- The county is hardening cloud-hosted workloads for records search. Which practice set best fits cloud infrastructure hardening?
- Field assessors connect tablets over cellular, public Wi-Fi, and Bluetooth peripherals. Which statement best reflects security implications of those connection methods?
- Parking-meter controllers run embedded/RTOS software that is rarely patchable. Which primary techniques best compensate?
- Facilities wants to buy a new badge access system. What asset-management step should happen in acquisition?
- IT issues laptops to remote planners. Which assignment practice best supports accountability?
- A closet audit finds undocumented switches bridging segments in city hall. Which asset-management activity most directly finds such shadow devices?
- Old clerk PCs will be sold at a surplus auction. What disposal step is required for the drives first?
- Failed SSDs from the courts cannot be reliably sanitized with available wipe tools. What disposal method is most appropriate?
- Retired backup tapes leave the records office with a destruction vendor. What evidence should the city obtain?
- Security wants incident logs kept long enough for investigations yet not retained forever without justification. Which policy approach fits?
- A county IT team needs a repeatable way to find missing patches and known weaknesses on the public web farm before citizens notice outages. Which vulnerability-management activity best identifies those known issues?
- City development is shipping a custom permitting app and wants coverage for insecure code, runtime flaws, and risky third-party libraries. Which approach best combines application security testing for vulnerability management?
- A municipal SOC learns of emerging VPN appliance flaws from open-source intel, an ISAC bulletin, and a paid feed, then raises patch priority for city remote-access gateways. What vulnerability-management practice is the team applying?
- A researcher emails the city's responsible-disclosure inbox with a clear XSS proof against the citizen portal instead of posting the bug publicly. How should the municipality treat this channel within vulnerability management?
- A vulnerability scanner flags dozens of findings on county servers, but analysts must confirm which alerts are real before briefing the council. Which analysis step best reduces panic from inaccurate scanner noise?
- Two CVEs have similar base CVSS scores: one affects the city's public permitting site and one affects an offline label printer in a locked basement. How should the vulnerability team prioritize remediation?
- A vendor patch for a city payment appliance is delayed, so security segments the device and documents a time-bound exception while continuing to pursue the patch. Which remediation approach does this describe?
- After the library district patches a critical web server CVE, management asks how the team will prove the fix worked. Which validation activity is most appropriate?
- The city CISO must update leadership on open vulnerabilities, remediation progress, and residual risk for critical citizen services. Which vulnerability-management activity does this communication fulfill?
- Authorized testers chain a weak DMZ host, stolen credentials, and a misconfigured jump path to reach an internal municipal database that scanners listed only as separate medium findings. What identification method primarily demonstrated the combined exploitable path?
- An internal audit of water-utility OT finds no defined vulnerability-management cadence for controllers and HMIs even though IT servers are scanned monthly. How should this audit result feed vulnerability management?
- The municipal SOC needs one place that collects firewall, Active Directory, and endpoint logs and correlates them into security events. Which tool best matches that purpose?
- City VPN concentrators suddenly show bursts of failed logons across many accounts. Which monitoring activities best help the SOC notice and act on that pattern?
- Analysts are overwhelmed by low-value firewall 'allow' alerts and miss higher-severity events. Which monitoring improvement best restores focus on true threats?
- County server admins must prove that hardened build settings still match an approved security baseline after each patch cycle. Which monitoring approach best automates that configuration-compliance check?
- A city water-utility OT network has controllers with tiny CPU and memory budgets that cannot host endpoint agents. How should the SOC choose monitoring coverage for those devices?
- During a suspected data exfiltration from the county tax database, analysts need to identify which internal hosts are talking the most to unusual external destinations. Which tool best surfaces that traffic metadata?
- Network ops for city hall suddenly receives notifications that several switch interfaces are flapping up and down. Which monitoring signal is most likely delivering those infrastructure alerts?
- Endpoints that process resident tax filings need malware detection plus controls that stop sensitive returns from being copied to USB or emailed outside policy. Which tooling pair best belongs in that monitoring and control stack?
- A vulnerability scan of the city network shows several unused services reachable from the Internet through overly broad firewall rules. What enterprise-capability change best reduces that unnecessary exposure?
- Architects are redesigning how the city's public website reaches the Internet so a compromise of that host cannot freely traverse into internal finance systems. Which network pattern best supports that goal?
- Threat intel reports a new exploit kit targeting services the county still runs at the edge. What IDS/IPS maintenance actions best keep detections current and useful?
- City employees keep browsing into phishing and malware-hosting sites during work hours. Which web-filtering capability set best reduces that risk whether traffic exits through a central proxy or an endpoint agent?
- Security wants one scalable control that stops city-hall workstations and servers from resolving known-malicious domains no matter which browser or app makes the request. Which control best fits?
- Residents receive forged messages that appear to come from [email protected] asking for gift-card payments. Which email-security controls best help receiving systems detect and reject that domain spoofing?
- A county IT team must lock down domain-joined workstations so local admin rights are removed for staff and idle screens auto-lock after a short timeout. Which OS security mechanism best enforces those settings consistently across the fleet?
- Public-works engineers still open network gear with Telnet and push firmware over FTP, and cleartext credentials appear in packet captures. Which change best improves administrative protocol security?
- Election-office content servers must alert if campaign-filing PDFs or web binaries change outside a change window. Which capability best detects unauthorized file modifications?
- A city NAC solution finds employee laptops missing required patches and disk encryption before they join the staff Wi-Fi. Where should those devices be placed until posture checks pass?
- Finance analysts report odd PowerShell activity on a workstation that touches ACH files. Which enterprise capability is best suited to investigate and contain that endpoint behavior?
- A clerk's account authenticates from City Hall at 9 a.m. and from another continent an hour later while downloading unusually large case archives. Which analytics approach best flags this pattern?
- HR onboards seasonal parks staff on day one and terminates others the same afternoon. What IAM lifecycle practice best limits leftover access?
- Seasonal election workers need ballot-check software for three weeks only. Which permission approach best follows least privilege?
- Contractors need privileged badges and elevated accounts for datacenter work. What must happen before those credentials are issued?
- County employees should sign in once to reach a state benefits portal without separate local passwords on that portal. Which approach best describes this design?
- A mobile 311 app must call city APIs on a resident's behalf without embedding the resident's password in the app. Which technology best fits?
- Multiple municipal applications need a common place to look up user objects, group membership, and attributes. Which directory access protocol is commonly used for that?
- Most city staff access systems by job role, a few apps must also consider time-of-day and building location, and a small set of highly labeled records require system-enforced labels users cannot override. Which access-control mix best matches that need?
- Remote staff VPN into county resources. Leadership wants MFA that combines a memorized secret with a hardware security key, and may later add biometric unlock on managed phones. Which statement best reflects MFA factor classes?
- The library CIO wants stronger passwords without theater: favor length, ban reuse, push a vault, and explore passwordless options for staff apps. Which recommendation best matches modern password guidance?
- Domain admins currently hold standing privileges all year. The county wants just-in-time elevation and short-lived credentials checked out of a vault. Which discipline delivers that model?
- Managers must periodically confirm that their staff still need access to finance systems after role changes. What IAM process is this?
- A legacy permitting app cannot speak SAML, yet the county refuses to weaken MFA for everyone. Which interoperability approach is most appropriate?
- Orphan accounts linger because HR terminations never reliably reach IT. Which automation use case best addresses this?
- New cloud resources for a smart-city project sometimes appear with open security groups. What automation pattern best hardens them at birth?
- When the SIEM raises a critical severity alert, analysts sometimes notice hours later. Which automation improves response speed?
- A municipal DevOps pipeline deploys code to production Friday nights. Leadership wants security checks before release. Where should those checks run?
- The SOC wants leadership buy-in for more playbook automation. Which statement best captures the security-operations benefits?
- Before expanding SOAR across every municipal tool, architects warn about downsides. Which set best lists automation considerations and risks?
- The county wants one playbook to disable an account in IAM, open a ticket, and isolate a host in EDR during an incident. What enables that cross-tool workflow?
- After ransomware hits a county tax system, the IR lead must apply the lifecycle in the right order. Which sequence is correct?
- A city SOC wants to avoid improvising during the next water-utility incident. Which investment best reflects the preparation phase of IR?
- Malware is confirmed on several workstations in a city's billing VLAN. The IR team immediately isolates that VLAN from the rest of the network. Which IR phase does this action represent?
- After containing a library ransomware outbreak, responders delete attacker accounts and persistence, then restore catalog servers from clean backups. Which pair correctly labels those two steps?
- Following a successful phishing incident at the clerk’s office, which action best belongs in the lessons-learned phase?
- A transit agency’s IR plan looks complete on paper, but leadership worries the team has never practiced it. Which activity best keeps the IR capability ready?
- Investigators confirm a county breach began through an unpatched VPN appliance. Which activity ensures fixes address that underlying cause rather than only wiping infected PCs?
- A municipal SOC notices stealthy persistence may exist even when no high-severity alert fired. Which approach best describes threat hunting in this context?
- Courts may later need a laptop seized during a city HR fraud investigation. Which practice best preserves forensic integrity?
- A public-facing outage hits the city’s permit portal during an active incident. Which IR coordination practice is most appropriate?
- Analysts are investigating an after-hours admin login to a utility management console. Which data sources best help reconstruct that access event?
- A school-district SOC sees suspicious process creation on a teacher laptop and a matching unusual sign-in. Which investigative approach strengthens the conclusion?
- A court IT team suspects large data exfiltration, but application logs do not show transfer volume. Which sources are most appropriate to estimate egress?
- Responders believe attackers entered a parks-and-recreation portal via a known CVE. Which investigative context best supports that hypothesis?
- During a county IR exercise, several critical servers have little or no retained authentication history. What should leadership prioritize before the next real incident?
Security Program Management and Oversight · 60 questions
- City IT discovers staff running personal cryptocurrency miners on servers. Which governance artifact most directly prohibits that use of organizational resources?
- A records manager asks how municipal governance documents differ. Which statement correctly contrasts them?
- A mayor’s office wants distinct written policies for information security, business continuity, disaster recovery, incident response, secure development, and change control. Why separate them?
- Public-works IT must enforce measurable password length, MFA for remote access, badge requirements for server rooms, and approved encryption algorithms. Which artifact type sets those mandatory specifics?
- HR and security need consistent steps when hiring and terminating staff who access citizen data systems, plus a ransomware response playbook. Which artifacts operationalize those steps?
- A border-city CISO must shape governance that reflects privacy statutes, court orders, industry baselines, and both local and national obligations. Which statement best describes these inputs?
- After a major incident and as the calendar year turns, which governance practice keeps municipal policies effective?
- A county needs clear oversight for IT security direction across departments. Which option best identifies governance structures that decide and oversee that direction?
- A public-health dataset of clinic encounters is stored by IT and processed by a contracted analytics firm under the health department’s instructions. Which role pairing is most accurate?
- Engineers want to push emergency firewall changes to a city data center with no ticket, approval, or backout plan because “it is faster.” Which governance response is correct?
- A county CIO must justify spending on a warm alternate site for tax and permitting systems. Which governance artifact most clearly sets the recovery expectations that the technical disaster-recovery design must meet?
- A city applications team wants to push a new citizen-portal build straight to production tonight. Which policy requirement should stop that deploy until security gates are complete?
- During a municipal risk identification workshop, finance and IT list ransomware that encrypts property-tax databases as a top concern. What is the workshop primarily accomplishing?
- A county must choose risk-assessment cadences for three systems: a rarely changed archival land-record vault, a permitting app that ships monthly features, and a 911 CAD platform that changes configuration daily. Which pairing best matches assessment type to change rate and criticality?
- A city council must decide whether to issue bonds that fund a multi-million-dollar SCADA upgrade and wants a dollar-based annual risk figure for outage exposure. Which analysis approach best fits that decision?
- A utility estimates that a payment-portal outage would cost $50,000 in lost fees and overtime (SLE) and expects such an outage twice per year (ARO = 2). What is the ALE?
- A flood model shows that if the riverside 911 radio shed floods, 40% of the $200,000 equipment value would be destroyed. In quantitative risk terms, what does that 40% figure represent?
- A county risk officer needs a living record that names each top risk, assigns an owner, records thresholds, and tracks key risk indicators for leadership reviews. Which artifact should they maintain?
- The city council states it is willing to take moderate cyber risk to keep online permitting fast for businesses, while IT must keep residual risk inside a defined band around that stance. How should appetite and tolerance be distinguished here?
- After MFA, immutable backups, and segmentation, a school district still faces residual ransomware financial exposure. Which risk strategy best describes buying a cyber insurance policy for that remainder?
- A library kiosk still runs a legacy catalog plugin that cannot support MFA. The risk is rated low, the catalog is air-gapped from payment systems, and leadership documents a time-boxed exemption. Which strategy is being used?
- A parks department plans public Wi-Fi kiosks that would expose unsegmented access into the utility SCADA VLAN. Redesign will take months and residual risk exceeds appetite. What strategy should leadership apply until a safe design exists?
- A transit agency faces ransomware risk against fare-collection servers. Leadership wants to reduce both likelihood of compromise and impact of encryption. Which action set best illustrates risk mitigation?
- Before a quarterly meeting, the CISO must brief the municipal audit committee on top cyber risks, treatment status, and trend indicators. Which activity is required?
- A city's BIA shows online building permits can be offline for 72 hours with limited harm, while 911 CAD must resume within 15 minutes and lose no more than 30 seconds of call data. What do those figures primarily represent?
- Facilities notes that aging courthouse badge controllers fail often and take many hours to restore. Which pair of metrics best frames that resilience discussion in a BIA or risk context?
- A county is selecting a cloud backup provider for court records and needs contractual ability to verify the vendor's security claims after signing. Which assessment requirement should be negotiated first?
- While evaluating a SaaS case-management vendor for public health, the procurement team reviews SOC reports and summaries of the vendor's recent internal audits. What is the team primarily doing?
- An elections office must understand not only the ballot-system integrator but also who builds firmware and hardware components upstream. Which third-party activity addresses that need?
- Before awarding a 24×7 security-monitoring contract, a city requires financial checks, reference calls, and a review of whether evaluation panelists have financial ties to bidders. Which vendor-selection practices are being applied?
- A township hires an MSP to run endpoint detection and shares network diagrams during onboarding. Which pair of agreements best matches uptime/response commitments versus protecting the diagrams?
- A city and a neighboring county want to document intent to share SOC analysts without creating a detailed commercial statement of work yet. Which agreement type best fits that early intergovernmental partnership?
- Six months after signing, a city's EHR hosting vendor changes subprocessors and suffers a regional outage. Why is ongoing vendor monitoring still required?
- HR wants a scalable way to collect control evidence from multiple SaaS benefits vendors before renewal. Which method best fits that need?
- A water utility will hire a third party to penetration-test the customer portal and selected OT jump hosts. What must be defined before testing begins?
- A SaaS vendor that hosts the city’s permit portal sends its own penetration-test report as proof of security. What is the most appropriate way for the city to treat that evidence?
- A grant-funded housing assistance system must show security status both to the city’s CIO and to the state grant office. Which distinction should the compliance lead apply first?
- After missing mandated cybersecurity reporting for a regulated utility billing system, which set of outcomes best illustrates realistic consequences of non-compliance?
- The county wants ongoing proof that privacy and security controls for resident services stay in place—not only a once-a-year binder review. Which approach best matches compliance monitoring?
- A regional tourism portal stores visitor contact data that may involve local ordinance, state privacy law, and cross-border guests. What should the privacy lead emphasize about legal implications?
- A resident submits a right-to-be-forgotten request through the city’s online services portal. What should the privacy process emphasize first?
- A vendor hosts the city’s constituent CRM and processes resident records only on the city’s documented instructions. How should controller versus processor roles be assigned?
- Before a compliance audit of records management, which pair of artifacts most directly helps the city prove it knows what data it holds and how long it keeps it?
- After mandatory compliance training on handling grant-funded case files, what evidence best shows staff understood and accepted their obligations?
- Automation flags permit archives kept past the city’s retention policy. How does this use of automation support compliance monitoring?
- The city auditor reviews security control evidence for a public-works system, while a state regulator later conducts a formal examination of the same environment. Which statement best distinguishes these activities?
- A federal grantor asks for a formal assurance statement on security controls for a homelessness-services platform. Which engagement type is designed to provide that kind of assurance reporting?
- Security findings from recent assessments need council-level visibility. Which body typically provides oversight of such findings in the municipal assurance ecosystem?
- Parking payment kiosks that handle cardholder data need unbiased assurance before peak festival season. Which assessment approach best fits?
- Facilities wants a test that walks locked doors and badge controls at city hall, while IT wants network exploitation testing, and leadership wants both views combined. Which pentest-type framing matches those goals?
- For a web application test of the library catalog, leadership can give testers full architecture notes, limited hints, or almost no insider detail. Which knowledge framing should guide the engagement design?
- Before a third-party assessment of the transit website, analysts gather public OSINT quietly, then propose port scans against production. What distinction matters most?
- A state cybersecurity bureau schedules a mandatory examination of the county’s emergency-alert systems, while the county also buys a voluntary security assessment from a consulting firm. How should leaders treat the regulatory examination?
- Human resources wants staff to get better at spotting and reporting fake 'payroll update' emails. Which awareness practice best addresses that goal?
- A supervisor notices a clerk emailing large case exports to a personal address at odd hours without a business need. Which awareness theme does this scenario highlight for training?
- Remote permitting clerks work from home with laptops and occasional USB drives. Which awareness content set best matches practical user guidance for that hybrid municipal workforce?
- After launching security awareness for new hires, leadership asks whether training stays effective over time. What should the program measure and schedule?
- A department head proposes 'sending one cautionary email' as the entire security awareness effort for the year. What should the CISO require instead?
- Employees use the report-phish button, but tickets often sit untouched for days. What awareness-related operational fix is most important?
- During awareness month, HR wants staff warned that outsiders might recruit or pressure employees for access—without encouraging casual accusations against coworkers. What should the module emphasize?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by CompTIA.