← Back to blog
Cybersecurity and Security+

Security+ Practice Questions With Answers

Security+ SY0-701 practice questions with answers: 12 scenario questions from 12 course units, each with the reasoning, from Encodr's free exam deck.

These are 12 practice questions from Encodr's free Security+ exam deck, one each from 12 of the course's 16 units. Security+ questions are mostly short scenarios: a situation is described and you pick the term, control or attack that fits best. The skill being tested is matching the scenario to the right concept, so each answer below comes with the reason it fits and the nearby options do not.

How to use this set

Read the scenario, cover the options, and say the answer out loud before you look. Recalling the answer from memory is active recall, and it is a better use of time than reading the explanations first. When you miss one, notice what in the scenario you skipped past. Security+ questions usually hide the answer in a single phrase, such as "inline", "decrypted" or "without ever transmitting it".

The last question uses the quantitative risk formulas. If you want to try your own numbers, the Security Risk Calculator works out SLE and ALE and shows the working.

The questions

1. Security foundations

An attacker silently copies a company database and reads customer records without authorization, but changes nothing and the system stays online. Which CIA property is BEST described as violated?

Answer: A. Confidentiality

Why: Reading data without authorization, with nothing altered, is a confidentiality breach specifically.

2. Cryptography

A VPN needs to encrypt a large volume of bulk traffic efficiently, but the two endpoints have no pre-shared secret. Which approach do real-world systems use to get both efficiency and secure key setup?

Answer: A. A hybrid approach: asymmetric encryption negotiates a symmetric key, then symmetric encryption handles the bulk data

Why: This hybrid pattern, asymmetric key exchange followed by symmetric bulk encryption, is exactly how modern protocols like TLS operate in practice.

3. Networking for security

A mail client needs to check an inbox using an encrypted connection instead of the older unencrypted IMAP port. Which port should it connect to?

Answer: A. 993

Why: IMAPS, the TLS-encrypted version of IMAP, uses port 993, while plain IMAP uses port 143.

4. Threat actors and attack surfaces

A frustrated employee with legitimate database access deliberately deletes records the week before leaving the company. Which threat actor type is this?

Answer: C. Insider threat

Why: An insider threat is someone inside the organization, such as a disgruntled employee, who uses existing legitimate access with intent to harm, commonly for revenge.

5. Social engineering and malware

A user types their bank's correct web address exactly, but their browser lands on a fake site because the attacker altered DNS records. What is this attack?

Answer: C. Pharming

Why: Pharming manipulates DNS or a local hosts file so that even a correctly typed, legitimate URL resolves to a spoofed site.

6. Application, network and password attacks

An attacker posts a comment containing a script tag on a forum; when other users view the comment, the script runs in their browsers and steals their session cookies. What attack is this?

Answer: B. Cross-site scripting

Why: Cross-site scripting is a vulnerability where unsanitized user input lets an attacker inject a client-side script that later runs in a different, unsuspecting user's browser.

7. Network security architecture

A device is placed inline, detects a known exploit signature, and drops the malicious packets in real time before they reach the server. Which control is it acting as?

Answer: B. IPS

Why: A detection system that can also stop traffic in real time is, by definition, acting as an IPS rather than a detection-only IDS.

8. Secure infrastructure and cloud

In the IaaS model, who is responsible for managing the operating system and the application running on the provisioned infrastructure?

Answer: A. The customer

Why: In IaaS, the customer is still responsible for the operating system and application, managing everything from the OS up through the application, while the provider secures the physical infrastructure and virtualization layer beneath it.

9. Data protection

Which state of data is almost always in decrypted, plaintext form?

Answer: A. Data in use

Why: Data in use must generally be decrypted to be processed by the CPU, so it is almost always in plaintext form in memory.

10. Identity and access management

A cloud application must grant access only when the request comes from a managed device, during business hours, and from an employee in the finance department. Which access control model is the BEST fit?

Answer: D. ABAC

Why: ABAC computes access decisions dynamically from multiple attributes of the subject, resource, and environment (device, time, department), which fits this multi-condition policy best.

11. Security operations

A SOC wants a single system that automatically runs a documented playbook, isolating an infected host and disabling its account, every time a malware alert fires, without an analyst manually repeating those steps. Which tool BEST fits?

Answer: B. SOAR

Why: SOAR automates the response workflow through playbooks, exactly matching the need to run documented, repeatable response steps automatically once an alert fires.

12. Governance, risk and compliance

A company wants to prioritize which of several risks to address first using dollar-value comparisons. Which single figure BEST supports ranking risks by their expected yearly cost?

Answer: C. Annualized loss expectancy (ALE)

Why: ALE combines both the per-occurrence dollar loss (SLE) and the yearly frequency (ARO) into a single expected annual cost, making it the figure suited for ranking risks.

Where to go from here

Tally your score by unit rather than overall. Two misses in one area, such as access control or attack names, tell you where the next hour of study should go.

Encodr turns this into a habit: study anything in a feed, and it schedules the rest.

Get started free

Related posts

More on Cybersecurity and Security+

All Cybersecurity and Security+ posts →