{"id":11577,"date":"2026-09-14T10:32:58","date_gmt":"2026-09-14T10:32:58","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11577"},"modified":"2026-09-14T11:08:18","modified_gmt":"2026-09-14T11:08:18","slug":"comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-13-q241-260\/","title":{"rendered":"CompTIA Security+ SY0-701 Practice Test Questions and Exam Dumps \u2014 Part 13 (Q241\u2013260)"},"content":{"rendered":"<h3>View Full\u00a0<a href=\"https:\/\/www.examlabs.com\/sy0-701-exam-dumps\">CompTIA SY0-701 Exam Dumps<\/a>\u00a0and Practice Test Dumps.<\/h3>\n<p>&nbsp;<\/p>\n<h3><b>Question 241<\/b><\/h3>\n<p><b>Which security principle limits access to information based on a user&#8217;s need to perform a specific task?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Need to know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> The need-to-know principle restricts access to information only to users who require it for their assigned responsibilities. This reduces unnecessary exposure of sensitive data.<\/span><\/p>\n<h3><b>Question 242<\/b><\/h3>\n<p><b>Which type of vulnerability occurs when a program writes more data into a memory area than it was designed to hold?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Race condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A buffer overflow occurs when more data is written to a memory buffer than it can accommodate. Attackers may exploit this to crash applications or potentially execute malicious code.<\/span><\/p>\n<h3><b>Question 243<\/b><\/h3>\n<p><b>Which security solution is primarily used to prevent sensitive information from being copied to unauthorized removable media?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Data Loss Prevention (DLP) can monitor and restrict sensitive data transfers, including attempts to copy protected information to USB drives or other removable media.<\/span><\/p>\n<h3><b>Question 244<\/b><\/h3>\n<p><b>Which protocol is commonly used to retrieve email securely while keeping messages on the mail server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IMAPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> IMAPS is the secure version of IMAP and uses TLS encryption to protect email communications while allowing messages to remain stored on the mail server.<\/span><\/p>\n<h3><b>Question 245<\/b><\/h3>\n<p><b>Which attack involves secretly observing a user&#8217;s screen or keyboard to obtain confidential information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pharming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS poisoning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Shoulder surfing is a form of physical or visual information theft in which an attacker observes a victim entering passwords, PINs, or other sensitive information.<\/span><\/p>\n<h3><b>Question 246<\/b><\/h3>\n<p><b>Which security control automatically restores a system or application to a previously known-good state after a failure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deterrent control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preventive control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directive control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Recovery controls help restore systems and services after an incident or failure. Backups and system restoration procedures are common examples.<\/span><\/p>\n<h3><b>Question 247<\/b><\/h3>\n<p><b>Which attack involves stealing or taking control of a user&#8217;s active web session?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Smishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dumpster diving<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Session hijacking occurs when an attacker obtains or manipulates a valid session identifier or token and uses it to impersonate an authenticated user.<\/span><\/p>\n<h3><b>Question 248<\/b><\/h3>\n<p><b>Which security mechanism verifies the identity of a website and helps establish encrypted communication with clients?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital certificate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password hash<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access control list<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baseline<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A digital certificate binds an identity to a public key and is commonly used with TLS to authenticate websites and establish encrypted connections.<\/span><\/p>\n<h3><b>Question 249<\/b><\/h3>\n<p><b>Which type of malware is designed to secretly monitor a user&#8217;s activities and collect information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Logic bomb<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Boot sector virus<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Spyware secretly monitors user activity and may collect information such as browsing behavior, credentials, or other sensitive data.<\/span><\/p>\n<h3><b>Question 250<\/b><\/h3>\n<p><b>Which security control is used to restrict network communication between different segments of an organization&#8217;s infrastructure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Network segmentation divides a network into separate security zones. It can limit lateral movement and restrict communication between systems that do not need to communicate directly.<\/span><\/p>\n<h3><b>Question 251<\/b><\/h3>\n<p><b>Which type of attack uses fraudulent websites or messages to redirect users to a malicious destination while appearing legitimate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pharming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute force<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Pharming redirects users to fraudulent websites, often through manipulation of DNS or host information. The goal is usually to steal credentials or other sensitive information.<\/span><\/p>\n<h3><b>Question 252<\/b><\/h3>\n<p><b>Which security control provides a physical barrier to prevent vehicles from entering a restricted area?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bollard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mantrap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Badge reader<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Motion detector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Bollards are sturdy vertical barriers used to prevent or restrict vehicle access. They are commonly installed around buildings, entrances, and other protected areas.<\/span><\/p>\n<h3><b>Question 253<\/b><\/h3>\n<p><b>Which process ensures that security patches are tested and deployed to systems in a controlled manner?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Patch management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat hunting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account provisioning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Patch management involves identifying, testing, approving, deploying, and verifying software updates. Regular patching reduces exposure to known vulnerabilities.<\/span><\/p>\n<h3><b>Question 254<\/b><\/h3>\n<p><b>Which type of security assessment attempts to actively exploit vulnerabilities to determine their real-world impact?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration test<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A penetration test actively attempts to exploit vulnerabilities in an authorized environment. This helps determine whether identified weaknesses can actually be used to compromise systems.<\/span><\/p>\n<h3><b>Question 255<\/b><\/h3>\n<p><b>Which security technology provides centralized management of highly privileged administrative accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PAM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Privileged Access Management (PAM) controls and monitors privileged accounts. It can provide features such as credential vaulting, session monitoring, and temporary privileged access.<\/span><\/p>\n<h3><b>Question 256<\/b><\/h3>\n<p><b>Which type of attack attempts to guess a password by systematically trying many possible combinations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replay attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MITM attack<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A brute-force attack systematically attempts different password combinations until the correct credential is discovered. Strong passwords and account lockout mechanisms can reduce this risk.<\/span><\/p>\n<h3><b>Question 257<\/b><\/h3>\n<p><b>Which security technology can prevent users from accessing known malicious or inappropriate websites based on domain or URL information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> DNS filtering compares requested domains against security or policy lists and can block access to malicious, suspicious, or prohibited websites.<\/span><\/p>\n<h3><b>Question 258<\/b><\/h3>\n<p><b>Which security property ensures that authorized users can access systems and information when needed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Non-repudiation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Availability ensures that systems, services, and information remain accessible to authorized users when required. Redundancy, backups, and fault-tolerant systems can improve availability.<\/span><\/p>\n<h3><b>Question 259<\/b><\/h3>\n<p><b>Which security practice involves assigning a sensitivity level such as public, confidential, or restricted to information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data destruction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Data classification categorizes information according to its sensitivity and business value. Classification helps determine the appropriate security controls for protecting each type of data.<\/span><\/p>\n<h3><b>Question 260<\/b><\/h3>\n<p><b>Which recovery metric measures the amount of time required to repair and restore a system after a failure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTBF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Mean Time to Repair (MTTR) measures the average time required to repair a failed system or restore it to operational status. A lower MTTR generally indicates faster recovery.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full\u00a0CompTIA SY0-701 Exam Dumps\u00a0and Practice Test Dumps. &nbsp; Question 241 Which security principle limits access to information based on a user&#8217;s need to perform a specific task? Need to know Open access Separation of duties Job rotation Correct Answer: 1 Explanation The need-to-know principle restricts access to information only to users who require it [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11577"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11577"}],"version-history":[{"count":2,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11577\/revisions"}],"predecessor-version":[{"id":11631,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11577\/revisions\/11631"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}