{"id":11571,"date":"2026-09-14T10:30:07","date_gmt":"2026-09-14T10:30:07","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11571"},"modified":"2026-09-14T11:08:38","modified_gmt":"2026-09-14T11:08:38","slug":"comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-10-q181-200\/","title":{"rendered":"CompTIA Security+ SY0-701 Practice Test Questions and Exam Dumps \u2014 Part 10 (Q181\u2013200)"},"content":{"rendered":"<h3>View Full\u00a0<a href=\"https:\/\/www.examlabs.com\/sy0-701-exam-dumps\">CompTIA SY0-701 Exam Dumps<\/a>\u00a0and Practice Test Dumps.<\/h3>\n<p>&nbsp;<\/p>\n<h3><b>Question 181<\/b><\/h3>\n<p><b>Which security control is primarily used to identify and block unauthorized devices from connecting to a network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FIM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Network Access Control (NAC) evaluates devices before or during network access and can prevent unauthorized or noncompliant devices from connecting to protected resources.<\/span><\/p>\n<h3><b>Question 182<\/b><\/h3>\n<p><b>Which attack involves intercepting communication between two parties without their knowledge?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Man-in-the-middle<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A man-in-the-middle (MITM) attack occurs when an attacker positions themselves between communicating parties to intercept or potentially modify information.<\/span><\/p>\n<h3><b>Question 183<\/b><\/h3>\n<p><b>Which protocol is commonly used to securely transfer files over an SSH connection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Secure File Transfer Protocol (SFTP) transfers files through an encrypted SSH connection, protecting credentials and file contents from network interception.<\/span><\/p>\n<h3><b>Question 184<\/b><\/h3>\n<p><b>Which security mechanism can identify repeated failed login attempts and generate an alert for security personnel?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Patch panel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A Security Information and Event Management (SIEM) system collects and correlates security logs from multiple sources. It can detect patterns such as repeated authentication failures and generate alerts.<\/span><\/p>\n<h3><b>Question 185<\/b><\/h3>\n<p><b>Which type of malware can automatically replicate itself and spread across networks without requiring a user to execute an infected file?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trojan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A worm is self-propagating malware that can spread from one system to another, often by exploiting vulnerabilities or weaknesses in network services.<\/span><\/p>\n<h3><b>Question 186<\/b><\/h3>\n<p><b>An attacker uses stolen usernames and passwords obtained from another website to access corporate accounts. What attack is this?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Credential stuffing uses previously compromised username-and-password combinations against other services. It is especially effective when users reuse passwords.<\/span><\/p>\n<h3><b>Question 187<\/b><\/h3>\n<p><b>Which control requires two employees to participate in a sensitive operation so that one person cannot complete the task alone?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job enrichment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Separation of duties divides critical responsibilities among multiple individuals. This reduces the possibility of fraud, abuse, or unauthorized actions by a single employee.<\/span><\/p>\n<h3><b>Question 188<\/b><\/h3>\n<p><b>Which technology can inspect encrypted web traffic to identify malicious content?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSL\/TLS inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> SSL\/TLS inspection allows security devices to decrypt, inspect, and re-encrypt protected traffic. This can help identify threats hidden inside encrypted connections.<\/span><\/p>\n<h3><b>Question 189<\/b><\/h3>\n<p><b>Which type of attack attempts to execute malicious JavaScript in a victim&#8217;s web browser?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">XSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS poisoning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Cross-Site Scripting (XSS) injects malicious scripts into web content that is viewed by other users. The script may steal session information or perform unauthorized actions.<\/span><\/p>\n<h3><b>Question 190<\/b><\/h3>\n<p><b>Which backup method copies only data that has changed since the last full backup?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incremental<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Differential<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Synthetic<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A differential backup copies data changed since the most recent full backup. As additional differential backups are created, their size can increase until the next full backup.<\/span><\/p>\n<h3><b>Question 191<\/b><\/h3>\n<p><b>Which security technology is designed to detect suspicious activity on a network and alert administrators without directly blocking the traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> An Intrusion Detection System (IDS) monitors network activity and generates alerts when suspicious behavior is detected. An IPS can additionally take action to block or prevent threats.<\/span><\/p>\n<h3><b>Question 192<\/b><\/h3>\n<p><b>Which type of authentication uses a hardware token, smart card, or security key?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you have<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you are<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Somewhere you are<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A hardware token, smart card, or security key represents the \u201csomething you have\u201d authentication factor because the user must possess the physical item.<\/span><\/p>\n<h3><b>Question 193<\/b><\/h3>\n<p><b>A company replaces sensitive customer account numbers with randomly generated values that have no exploitable meaning. Which technique is being used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Steganography<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Tokenization replaces sensitive information with a non-sensitive token. The original data is stored separately and can be retrieved through an appropriate tokenization system.<\/span><\/p>\n<h3><b>Question 194<\/b><\/h3>\n<p><b>Which physical security control uses two interlocking doors to prevent unauthorized individuals from entering a secure facility?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bollard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mantrap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Turnstile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A mantrap consists of two doors arranged so that one door generally must close before the other opens. This helps prevent unauthorized individuals from following an authorized person into a restricted area.<\/span><\/p>\n<h3><b>Question 195<\/b><\/h3>\n<p><b>Which principle requires an organization to verify a user&#8217;s identity and authorization before granting access to each requested resource?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network flattening<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Zero trust assumes that users and devices should not automatically be trusted. Access decisions are based on identity, authorization, device state, and other relevant security conditions.<\/span><\/p>\n<h3><b>Question 196<\/b><\/h3>\n<p><b>Which technology protects data stored on a laptop if the device is lost or stolen?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full-disk encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Full-disk encryption encrypts data stored on the device. If the laptop is lost or stolen, unauthorized individuals cannot easily access the protected information without the required authentication or encryption key.<\/span><\/p>\n<h3><b>Question 197<\/b><\/h3>\n<p><b>Which type of social engineering attack involves an attacker pretending to be a trusted person or organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Impersonation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dumpster diving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Impersonation occurs when an attacker pretends to be someone the victim trusts, such as a manager, technician, vendor, or company representative, to manipulate the victim into performing an action.<\/span><\/p>\n<h3><b>Question 198<\/b><\/h3>\n<p><b>Which security process identifies weaknesses in systems and ranks them according to their potential impact and likelihood?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data destruction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident containment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A risk assessment identifies threats and vulnerabilities and evaluates their likelihood and potential impact. Organizations use this information to prioritize security efforts.<\/span><\/p>\n<h3><b>Question 199<\/b><\/h3>\n<p><b>Which device security feature can prevent unauthorized computers from connecting to a specific switch port?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Switch port security can restrict which devices are allowed to use a particular physical port, often by controlling permitted MAC addresses.<\/span><\/p>\n<h3><b>Question 200<\/b><\/h3>\n<p><b>Which recovery metric specifies the maximum amount of time a system can remain unavailable after an incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTBF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTD<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> The Recovery Time Objective (RTO) defines the maximum acceptable amount of time a system or service can be unavailable before it needs to be restored.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full\u00a0CompTIA SY0-701 Exam Dumps\u00a0and Practice Test Dumps. &nbsp; Question 181 Which security control is primarily used to identify and block unauthorized devices from connecting to a network? NAC DLP FIM SIEM Correct Answer: 1 Explanation Network Access Control (NAC) evaluates devices before or during network access and can prevent unauthorized or noncompliant devices from [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11571"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11571"}],"version-history":[{"count":3,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11571\/revisions"}],"predecessor-version":[{"id":11634,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11571\/revisions\/11634"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11571"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11571"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11571"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}