1.0 General Security Concepts SY0-701 Practice Quiz
164 exam-style questions covering 12% of the SY0-701 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the CompTIA Security+ practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
Which of the following BEST describes a technical security control?
- A. A policy requiring employees to lock their workstations when leaving their desks
- B. A hardware or software mechanism, such as a firewall, encryption, or access control list, that enforces security through technology rather than human action or policy
- C. A physical barrier such as a locked door that prevents unauthorized entry
- D. A governance procedure outlining how security incidents should be reported
Technical controls are implemented through technology, firewalls, encryption, IDS/IPS, and access control lists all enforce security automatically without relying on human action. This is the correct answer.
Which of the following is the BEST example of a managerial security control?
- A. Deploying an intrusion detection system on the network perimeter
- B. Conducting an annual risk assessment to identify and prioritize security risks to the organization
- C. Installing badge readers on all server room doors
- D. Requiring all employees to complete security awareness training
A risk assessment is a managerial (administrative) control, it involves governance, oversight, and decision-making processes rather than technical or physical implementations. This is the correct answer.
A security engineer configures a network to automatically block traffic from IP addresses that exceed 1,000 connection attempts per minute. Which control category does this BEST represent?
- A. Managerial
- B. Physical
- C. Technical
- D. Operational
Automatically blocking connection attempts through network configuration is a technical control, it uses technology to enforce a security requirement without human intervention per event. This is the correct answer.
A CISO develops a data classification policy, an acceptable use policy, and a vendor risk management program. These are BEST categorized as which type of controls?
- A. Technical controls
- B. Physical controls
- C. Managerial controls
- D. Operational controls
Policies, risk programs, and governance frameworks are managerial (administrative) controls, they guide organizational behavior through oversight and governance rather than technical or physical mechanisms. This is the correct answer.
An organization's security program includes mandatory security awareness training, a clean desk policy enforced by daily walkthroughs, and a visitor escort requirement in secure areas. These controls are BEST described as:
- A. Technical controls, they improve overall security posture
- B. Managerial controls, they were defined by senior leadership
- C. Operational controls, they rely on human behavior, procedures, and day-to-day activities to enforce security
- D. Physical controls, they involve the physical workspace
Awareness training, clean desk enforcement, and escort requirements all rely on human behavior and established procedures, the defining characteristic of operational controls. This is the correct answer.
An organization implements full-disk encryption, endpoint EDR agents, and certificate-based authentication across all laptops. A security auditor categorizes these controls. Which statement BEST describes how these controls should be classified?
- A. They are all physical controls since they protect physical devices
- B. They are all technical controls, each uses a technology mechanism to enforce security. However, they serve different control types: FDE is preventive (prevents data access if lost), EDR is detective and corrective (detects and responds to threats), and certificate-based auth is preventive (prevents unauthorized access)
- C. They are operational controls because they require IT staff to deploy and manage them
- D. They are managerial controls because they were mandated by policy
All three are technical controls (technology-based mechanisms), but they serve different control type purposes, illustrating that category and type are independent dimensions of classification. This is the correct answer.
A SIEM system automatically correlates log events, generates an alert for a potential insider threat, and initiates an automated workflow to disable the user's account pending investigation. How many distinct control types does this SINGLE technical system exercise?
- A. One, it is only a detective control since it generates alerts
- B. Two, detective (correlating and alerting on the threat) and corrective (disabling the account to limit damage after detection)
- C. Three, preventive (blocking future actions), detective (alerting), and corrective (remediating)
- D. The SIEM is not a security control, it is only a monitoring tool
The correlation and alerting is detective (identifies a suspected threat), and the automated account disabling is corrective (limits damage and remediates access after detection). A single system can serve multiple control types. This is the correct answer.
An auditor reviewing a financial services firm's security program finds that several security policies exist but have not been reviewed or updated in three years. The technical controls are current and operational controls are followed. What security risk does outdated managerial control documentation create?
- A. No risk, technical and operational controls provide sufficient protection regardless of policy currency
- B. Outdated policies may no longer reflect the current threat landscape, regulatory requirements, or organizational changes, creating gaps between documented governance and actual risk posture, potential compliance failures, and unclear accountability when incidents occur
- C. The risk is purely cosmetic, auditors may flag it but it has no operational impact
- D. Outdated policies automatically become invalid and are replaced by default industry standards
Outdated managerial controls create governance gaps, policies not reflecting current requirements may lead to regulatory non-compliance, unclear incident response authority, and misalignment between documented expectations and operational reality. This is the correct answer.
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/comptia-security-plus/general-security-concepts/
<a href="https://quizbuffet.com/comptia-security-plus/general-security-concepts/">CompTIA Security+ General Security Concepts practice quiz on QuizBuffet</a>
Other SY0-701 Domains
- 2.0 Threats, Vulnerabilities, and Mitigations
- 3.0 Security Architecture
- 4.0 Security Operations
- 5.0 Security Program Management and Oversight
← Back to SY0-701 practice test overview
Questions are written against the published SY0-701 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.