SY0-701 Sample Questions

SY0-701 Sample Questions & Answers

Security operations carries the most weight, alongside threat actors, attack vectors and mitigations, enterprise architecture, core ideas such as control types and change management, and oversight of risk and third parties.

Launch the full SY0-701 simulator →

Showing 20 of 40 free samples.

  1. Question 1Intermediate

    What does the CIA triad stand for in cybersecurity?

    Show answer & explanation

    Correct answer: A

    The CIA triad in cybersecurity stands for Confidentiality, Integrity, and Availability, which are the core principles for securing information.

  2. Question 2Intermediate

    Which type of malware is specifically designed to provide unauthorized access to a system?

    Show answer & explanation

    Correct answer: C

    A Trojan Horse is a type of malware that disguises itself as legitimate software, providing unauthorized access to a system once executed.

  3. Question 3Intermediate

    Which security principle helps protect data by ensuring that only authorized users can access sensitive information?

    Show answer & explanation

    Correct answer: D

    Confidentiality is a security principle that ensures only authorized individuals can access sensitive information, protecting it from unauthorized disclosure.

  4. Question 4Intermediate

    Which of the following is an example of a physical security control?

    Show answer & explanation

    Correct answer: C

    A security guard is a physical security control that helps protect facilities and personnel by monitoring access and deterring unauthorized entry.

  5. Question 5Intermediate

    Which method involves hiding data within another file, such as an image or video?

    Show answer & explanation

    Correct answer: A

    Steganography is the practice of hiding data within another file, such as an image or video, to conceal its presence.

  6. Question 6IntermediateSelect 2

    Which of the following are considered security operations tasks? Select TWO.

    Show answer & explanation

    Correct answers: A, C

    Security operations tasks typically include vulnerability scanning and incident response, both of which are essential for maintaining system security.

    Security operations tasks typically include vulnerability scanning and incident response, both of which are essential for maintaining system security.

  7. Question 7IntermediateSelect 2

    Which of the following are benefits of using cloud-native security tools? Select TWO.

    Show answer & explanation

    Correct answers: B, E

    Cloud-native security tools provide increased flexibility and can often lead to lower costs due to their scalable and efficient nature.

    Cloud-native security tools provide increased flexibility and can often lead to lower costs due to their scalable and efficient nature.

  8. Question 8IntermediateSelect 2

    Which practices help ensure secure software development? Select TWO.

    Show answer & explanation

    Correct answers: A, C

    Code reviews and penetration testing are critical practices in secure software development, helping to identify and address vulnerabilities.

    Code reviews and penetration testing are critical practices in secure software development, helping to identify and address vulnerabilities.

  9. Question 9IntermediateSelect 3

    In cloud computing, which elements are crucial for maintaining data sovereignty? Select ALL that apply.

    Show answer & explanation

    Correct answers: B, C, D

    Data encryption, geolocation, and legal compliance are essential elements for maintaining data sovereignty in cloud computing.

    Data encryption, geolocation, and legal compliance are essential elements for maintaining data sovereignty in cloud computing.

    Data encryption, geolocation, and legal compliance are essential elements for maintaining data sovereignty in cloud computing.

  10. Question 10Advanced

    Threats, Vulnerabilities, and Mitigations · Given a scenario, analyze indicators of malicious activity

    A SOC analyst is reviewing firewall logs and notices a large volume of inbound DNS query responses from multiple external IP addresses. These responses are significantly larger than the initial outbound queries sent from a single server within the internal network. The target server is now unresponsive. What type of DDoS attack is MOST likely occurring?

    graph TD subgraph Attacker Controlled A[Attacker] --> R1[Reflector 1] A --> R2[Reflector 2] A --> R3[Reflector 3] end subgraph Victim Network S[Internal Server] V[Victim Server] end A -- small spoofed query (source=V) --> R1 A -- small spoofed query (source=V) --> R2 A -- small spoofed query (source=V) --> R3 R1 -- large response --> V R2 -- large response --> V R3 -- large response --> V

    Show answer & explanation

    Correct answer: A

    This scenario perfectly describes a DNS amplification and reflection attack. The 'reflection' part comes from the attacker spoofing the victim's IP address and sending queries to third-party DNS servers (reflectors). The 'amplification' part comes from crafting a small query that elicits a very large response. The reflectors then send these large responses to the victim, overwhelming its network bandwidth and resources. The key indicators are the use of DNS and the response size being much larger than the query.

Ready for the real thing?

The full SY0-701 simulator has every exam-style question, timed mode, and instant scoring.