CompTIA Security+ (SY0-701)/Topics/Security Architecture & Controls
Security Architecture & Controls practice test: free CompTIA Security+ (SY0-701) questions
Drill 30 Security Architecture & Controls questions with instant explanations and official citations.
Topic overview & passing targets
Security Architecture & Controls Domain Overview
The Security Architecture & Controls module is a core testing domain on the CompTIA Security+ (SY0-701). QuizCram provides 30 practice questions for this domain with verified handbook rationales.
- Target Passing Benchmark: 83% (SY0-701 · maximum of 90 items · 90-minute limit · 750/900 to pass)
- Domain Questions: 30 items
- Source Material: Official Handbooks
Sample Practice Questions for Security Architecture & Controls
- Question 1Ref: CompTIA Security+ SY0-701 — 2.1 High Availability Concepts
A company wants to implement redundancy for its critical web servers. Which architecture provides automatic failover if one server becomes unavailable?
Show Answer & Explanation
Correct Answer
B. Load balancing with active-passive clusteringLoad balancing with active-passive clustering provides automatic failover by routing traffic to a standby server when the active server becomes unavailable. RAID protects against disk failures, CDN caching improves performance, and snapshots facilitate recovery but do not provide automatic failover.
- Question 2Ref: CompTIA Security+ SY0-701 — 2.1 Secure Network Architecture
A network architect is designing a segmented network for a hospital. Patient record servers must be isolated from guest Wi-Fi. Which architecture model BEST achieves this?
Show Answer & Explanation
Correct Answer
A. Deploy a zero-trust architecture with micro-segmentationZero-trust architecture with micro-segmentation provides granular isolation between network segments, ensuring patient record servers are completely separated from guest Wi-Fi. A flat network with VLAN tagging offers less isolation, a single DMZ is inappropriate, and a three-tier architecture with ACLs may not provide sufficient segmentation.
- Question 3Ref: CompTIA Security+ SY0-701 — 2.4 Secure Coding Practices
A developer is building a web application that processes user input. Which coding practice BEST prevents command injection vulnerabilities?
Show Answer & Explanation
Correct Answer
D. Implementing input validation and parameterized queriesThe keyed answer is "Implementing input validation and parameterized queries". Input validation and parameterized queries prevent command injection by ensuring user input is treated as data rather than executable code. While encryption, HTTPS, and client-side validation improve security, they do not prevent injection attacks at the application layer.
- Question 4Ref: CompTIA Security+ SY0-701 — 2.3 Secure Access Solutions
A company wants to allow remote employees to access internal resources without exposing the entire network. Which solution provides the MOST granular access control?
Show Answer & Explanation
Correct Answer
A. Software-defined perimeter (SDP) with single-packet authorizationA software-defined perimeter (SDP) with single-packet authorization provides zero-trust access, hiding resources and granting access only after authentication. This offers more granular control than traditional VPNs, which grant broader network access, or RDP gateways, which are limited to specific applications.
Frequently Asked Questions About Security Architecture & Controls
QuizCram covers 30 practice questions in the Security Architecture & Controls domain, mapped directly to the official examination blueprint.
The benchmark score is 83% (SY0-701 · maximum of 90 items · 90-minute limit · 750/900 to pass).
Yes. All questions on QuizCram are written against official handbooks and blueprint specifications with legal citations.