COMPTIA · SY0-701 SECURITY+

CompTIA Security+

The most-requested entry-level cybersecurity certification. Threats, architecture, operations and governance - tested the way CompTIA actually asks.

Unlock SY0-701 - 90-day access

6 full-length premium mock exams with full explanations on every question, review mode, practice mode and unlimited retakes for 90 days. New exams added to this track during your window are included.

Pass guarantee: average 85%+ across this track's mocks, sit the real exam, and if you fail we refund you in full. 14-day money-back on top. Terms.

Start the free diagnostic - no account needed Create account

Free Diagnostic Exam Free

15 questions · 25 min · pass mark 83% · Find out if you'd pass SY0-701 today

Practice Exam 1 Premium

90 questions · 90 min · pass mark 83% · Full-length SY0-701 format: 90 questions in 90 minutes across all five domains. Performance-based items are represented as scenario questions.

Practice Exam 2 Premium

90 questions · 90 min · pass mark 83% · Full-length SY0-701 format: 90 questions in 90 minutes across all five domains. Performance-based items are represented as scenario questions.

Practice Exam 3 Premium

90 questions · 90 min · pass mark 83% · Full-length SY0-701 format: 90 questions in 90 minutes across all five domains. Performance-based items are represented as scenario questions.

Practice Exam 4 Premium

90 questions · 90 min · pass mark 83% · Full-length SY0-701 format: 90 questions in 90 minutes across all five domains. Performance-based items are represented as scenario questions.

Practice Exam 5 Premium

90 questions · 90 min · pass mark 83% · Full-length SY0-701 format: 90 questions in 90 minutes across all five domains. Performance-based items are represented as scenario questions.

Practice Exam 6 Premium

90 questions · 90 min · pass mark 83% · Full-length SY0-701 format: 90 questions in 90 minutes across all five domains. Performance-based items are represented as scenario questions.

Sample questions from this bank

Straight from the premium SY0-701 exams, explanation included. Judge the quality before you spend a cent.

Security Operations

A company's antivirus misses fileless attacks. The security team wants endpoint software that continuously records process behavior, detects suspicious activity patterns, and supports remote isolation and forensic investigation of hosts. What should they deploy?

  • A Signature-based antivirus with daily updates
  • B A protocol analyzer
  • C EDR (Endpoint Detection and Response)
  • D A host-based firewall
Show answer and explanation

Correct: C

EDR agents record endpoint telemetry, apply behavioral analytics to catch fileless and novel attacks, and give responders remote containment and investigation tools. Host firewalls filter traffic only, signature AV is exactly what's failing, and a protocol analyzer inspects network captures, not endpoints.

Reference: https://csrc.nist.gov/glossary/term/endpoint_detection_and_response

Security Architecture Choose all that apply

An administrator must ensure that only company-managed laptops can connect to the wired office network. Which two technologies work together to enforce this? (Choose TWO.)

  • A MAC address spoofing
  • B 802.1X port-based authentication
  • C A captive portal splash page
  • D Network Access Control (NAC) with device posture checks
  • E An open guest VLAN
Show answer and explanation

Correct: B, D

802.1X authenticates the device (typically via certificates against RADIUS) before the switch port passes traffic, and NAC layers posture assessment - patch level, disk encryption, agent presence - before granting access. Captive portals are for guest Wi-Fi acceptance, MAC spoofing is an attack, and an open VLAN is the opposite of enforcement.

Reference: https://csrc.nist.gov/glossary/term/network_access_control

General Security Concepts

A browser reports that a website's certificate has been revoked. Which mechanism allows a client to check revocation status in real time WITHOUT downloading the CA's entire revocation list?

  • A CSR
  • B CRL
  • C OCSP
  • D HSTS
Show answer and explanation

Correct: C

The Online Certificate Status Protocol queries the CA's responder for the status of a single certificate in real time (often delivered via OCSP stapling). A CRL is the full downloadable revocation list, a CSR is a certificate signing request, and HSTS forces HTTPS but says nothing about revocation.

Reference: https://datatracker.ietf.org/doc/html/rfc6960

Every question in the bank ships with an explanation at this depth. See how our questions are made.

About the SY0-701 exam

What the real exam looks like and how PassForge gets you ready for it.

Format Up to 90 questions, 90 minutes. Multiple choice plus performance-based questions (drag-and-drop and simulations).
Passing score 750 out of 900 on a scaled score. PassForge sets its pass mark at 83% to line up with that bar.
Real exam cost About 439 USD direct from CompTIA (partners often sell vouchers for less).

Domains and official weights

Every PassForge mock in this track mirrors these proportions, so your practice score maps to the real one.

General Security Concepts 12%
Threats, Vulnerabilities, and Mitigations 22%
Security Architecture 18%
Security Operations 28%
Security Program Management and Oversight 20%

How scoring works

Security+ is scored 100 to 900 and you need 750 to pass. Performance-based questions appear first and are weighted more heavily than single multiple-choice items, so budget time for them on the real exam.

How to pass with PassForge

  1. Take the free diagnostic to find your weakest of the five domains.
  2. Review the explanation and reference on every miss to close knowledge gaps fast.
  3. Drill Security Operations and Threats first, they carry the most weight.
  4. Run full-length timed mocks until you clear the pass mark with time left over.
  5. Book the real exam once you are steady above the bar.