CompTIA Security+ (SY0-701)/Topics/Security Operations & Incident Response
Security Operations & Incident Response practice test: free CompTIA Security+ (SY0-701) questions
Drill 44 Security Operations & Incident Response questions with instant explanations and official citations.
Topic overview & passing targets
Security Operations & Incident Response Domain Overview
The Security Operations & Incident Response module is a core testing domain on the CompTIA Security+ (SY0-701). QuizCram provides 44 practice questions for this domain with verified handbook rationales.
- Target Passing Benchmark: 83% (SY0-701 · maximum of 90 items · 90-minute limit · 750/900 to pass)
- Domain Questions: 44 items
- Source Material: Official Handbooks
Sample Practice Questions for Security Operations & Incident Response
- Question 1Ref: CompTIA Security+ SY0-701 — 3.4 Vulnerability Management
A security team is implementing a vulnerability management program. Which step should immediately follow vulnerability scanning?
Show Answer & Explanation
Correct Answer
C. Risk prioritization and remediation planningThe keyed answer is "Risk prioritization and remediation planning". After scanning, the next step is risk prioritization to determine which vulnerabilities to address first based on severity, exploitability, and business impact. Immediate patching without prioritization may cause operational issues, and training should occur before scanning begins.
- Question 2Ref: CompTIA Security+ SY0-701 — 3.6 Data Destruction and Sanitization
A system administrator needs to remove sensitive data from a decommissioned hard drive. Which method provides the MOST secure data destruction?
Show Answer & Explanation
Correct Answer
D. Degaussing followed by physical destructionThe keyed answer is "Degaussing followed by physical destruction". Degaussing destroys the magnetic field on the drive making data unrecoverable, and physical destruction ensures the platters cannot be accessed. While overwriting provides some assurance, degaussing combined with physical destruction is the most secure method for highly sensitive data.
- Question 3Ref: CompTIA Security+ SY0-701 — 3.4 Vulnerability Assessment Tools
A security analyst is performing a vulnerability assessment on a web server. Which tool would BEST identify misconfigurations in the server settings?
Show Answer & Explanation
Correct Answer
B. Web application vulnerability scannerThe keyed answer is "Web application vulnerability scanner". A web application vulnerability scanner is designed to identify misconfigurations and vulnerabilities in web server settings and applications. Nmap scans network hosts and ports, password crackers test authentication strength, and packet analyzers examine network traffic.
- Question 4Ref: CompTIA Security+ SY0-701 — 3.1 Indicators of Compromise
A security analyst notices unusual outbound traffic from a server at 3:00 AM using an uncommon port and encrypted protocol. What type of indicator is this?
Show Answer & Explanation
Correct Answer
A. Indicator of attack (IoA)An indicator of attack (IoA) describes the behavior and intent of an active threat rather than just a forensic artifact left behind. IoCs are forensic artifacts like malware hashes, false positives are erroneous alerts, and baseline deviations are statistical observations.
- Question 5Ref: CompTIA Security+ SY0-701 — 3.4 Patch Management
A company is implementing a patch management process. Which approach ensures patches are tested before full deployment to production?
Show Answer & Explanation
Correct Answer
D. Use a phased rollout starting with a pilot groupThe keyed answer is "Use a phased rollout starting with a pilot group". A phased rollout starting with a pilot group allows patches to be tested in a controlled environment before broader deployment, reducing the risk of widespread operational disruption. Simultaneous deployment is risky, and ignoring non-critical patches leaves security gaps.
- Question 6Ref: CompTIA Security+ SY0-701 — 3.3 Digital Forensics
A security team is investigating a malware infection on a workstation. Which step should they perform FIRST to preserve forensic evidence?
Show Answer & Explanation
Correct Answer
C. Document the system state and create a forensic disk imageThe keyed answer is "Document the system state and create a forensic disk image". Documenting the system state and creating a forensic disk image preserves volatile and non-volatile evidence before any changes are made. Disconnecting may alert the attacker, running antivirus could alter evidence, and reinstalling destroys all forensic data needed for investigation.
- Question 7Ref: CompTIA Security+ SY0-701 — 3.1 Security Monitoring
A SOC analyst is configuring a SIEM to detect brute-force attacks. Which log event correlation rule would be MOST effective?
Show Answer & Explanation
Correct Answer
D. Alert when a single account has more than 10 failed logins within 5 minutesThe keyed answer is "Alert when a single account has more than 10 failed logins within 5 minutes". Monitoring for multiple failed login attempts within a short timeframe is the classic detection method for brute-force attacks. While geographic anomalies and password changes are suspicious, they do not directly indicate brute-force activity like repeated authentication failures do.
Frequently Asked Questions About Security Operations & Incident Response
QuizCram covers 44 practice questions in the Security Operations & Incident Response domain, mapped directly to the official examination blueprint.
The benchmark score is 83% (SY0-701 · maximum of 90 items · 90-minute limit · 750/900 to pass).
Yes. All questions on QuizCram are written against official handbooks and blueprint specifications with legal citations.