CompTIA Security+ (SY0-701)/Topics/Security Architecture & Controls

Security Architecture & Controls practice test: free CompTIA Security+ (SY0-701) questions

Drill 30 Security Architecture & Controls questions with instant explanations and official citations.

Practice domain

Topic overview & passing targets

Security Architecture & Controls Domain Overview

The Security Architecture & Controls module is a core testing domain on the CompTIA Security+ (SY0-701). QuizCram provides 30 practice questions for this domain with verified handbook rationales.

  • Target Passing Benchmark: 83% (SY0-701 · maximum of 90 items · 90-minute limit · 750/900 to pass)
  • Domain Questions: 30 items
  • Source Material: Official Handbooks

Sample Practice Questions for Security Architecture & Controls

  1. Question 1Ref: CompTIA Security+ SY0-701 — 2.1 High Availability Concepts

    A company wants to implement redundancy for its critical web servers. Which architecture provides automatic failover if one server becomes unavailable?

    Show Answer & Explanation

    Correct Answer
    B. Load balancing with active-passive clustering

    Load balancing with active-passive clustering provides automatic failover by routing traffic to a standby server when the active server becomes unavailable. RAID protects against disk failures, CDN caching improves performance, and snapshots facilitate recovery but do not provide automatic failover.

  2. Question 2Ref: CompTIA Security+ SY0-701 — 2.1 Secure Network Architecture

    A network architect is designing a segmented network for a hospital. Patient record servers must be isolated from guest Wi-Fi. Which architecture model BEST achieves this?

    Show Answer & Explanation

    Correct Answer
    A. Deploy a zero-trust architecture with micro-segmentation

    Zero-trust architecture with micro-segmentation provides granular isolation between network segments, ensuring patient record servers are completely separated from guest Wi-Fi. A flat network with VLAN tagging offers less isolation, a single DMZ is inappropriate, and a three-tier architecture with ACLs may not provide sufficient segmentation.

  3. Question 3Ref: CompTIA Security+ SY0-701 — 2.4 Secure Coding Practices

    A developer is building a web application that processes user input. Which coding practice BEST prevents command injection vulnerabilities?

    Show Answer & Explanation

    Correct Answer
    D. Implementing input validation and parameterized queries

    The keyed answer is "Implementing input validation and parameterized queries". Input validation and parameterized queries prevent command injection by ensuring user input is treated as data rather than executable code. While encryption, HTTPS, and client-side validation improve security, they do not prevent injection attacks at the application layer.

  4. Question 4Ref: CompTIA Security+ SY0-701 — 2.3 Secure Access Solutions

    A company wants to allow remote employees to access internal resources without exposing the entire network. Which solution provides the MOST granular access control?

    Show Answer & Explanation

    Correct Answer
    A. Software-defined perimeter (SDP) with single-packet authorization

    A software-defined perimeter (SDP) with single-packet authorization provides zero-trust access, hiding resources and granting access only after authentication. This offers more granular control than traditional VPNs, which grant broader network access, or RDP gateways, which are limited to specific applications.

Frequently Asked Questions About Security Architecture & Controls

QuizCram covers 30 practice questions in the Security Architecture & Controls domain, mapped directly to the official examination blueprint.

The benchmark score is 83% (SY0-701 · maximum of 90 items · 90-minute limit · 750/900 to pass).

Yes. All questions on QuizCram are written against official handbooks and blueprint specifications with legal citations.