CompTIA Security+ (SY0-701) Practice Test

296 preguntas disponibles

Retiro programado

Este examen se retira el viernes, 11 de junio de 2027.

CompTIA no ha anunciado un reemplazo directo.

Gana confianza para CompTIA Security+ (SY0-701). Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.

Probar una pregunta
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
Examen de certificación
90 Preguntas del examen
1 hora 30 minutos Límite de Tiempo
Tu práctica
296 Preguntas de práctica
4 horas 56 minutos Tiempo de Práctica
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
El listón a superar 750/900 Puntuación mínima publicada para obtener esta certificación.
Explora los temas del examen Objetivos oficiales de CompTIA
CompTIA296 preguntas de prácticaBanco actualizado el 2026-07-24
Temario verificadoVerificado con CompTIA official objectivesMetadatos verificados 2026-09-17Cómo verificamos

Descripción y detalles del examen

La certificación CompTIA Security+ SY0-701 es la credencial estándar de nivel inicial en ciberseguridad de la industria, que valida las habilidades básicas necesarias para realizar funciones de seguridad principales y perseguir una carrera en seguridad IT. El examen cubre seis dominios: General Security Concepts, Threats Vulnerabilities and Mitigations, Security Architecture, Security Operations, Security Program Management and Oversight, y Cryptography and PKI, y está actualizada desde la versión SY0-601 para enfatizar la automatización, la zero-trust architecture y la seguridad en entornos híbridos. Security+ es DoD 8570 compliant, es ampliamente requerida por contratistas gubernamentales, agencias federales y organizaciones empresariales como credencial básica de ciberseguridad, y sirve como prerrequisito para certificaciones intermedias como CompTIA CySA+ y CompTIA CASP+.

Preguntas de Muestra

Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.

General security concepts

A company wants to ensure that the software it develops will not be tampered with after the final version is completed. Which of the following should the company most likely use?

Security architecture

A SaaS company wants to be able to compute statistics on customer billing data without ever decrypting it. Which encryption technique BEST fits this design goal?

Security architecture

A facilities manager is upgrading the power design of a small data center. The objective is to keep IT loads online for at least 15 minutes during a utility outage so that diesel generators can start and stabilize before any equipment loses power. Which device BEST meets the requirement?

Threats, vulnerabilities, and mitigations

A logistics company learns that a software update from a small open-source library used by its inventory system was tampered with by an attacker who compromised the maintainer's CI/CD pipeline. The malicious update was installed on hundreds of customers before it was discovered. Which attack vector category BEST describes this incident?

Explicación:

Un ataque de cadena de suministro compromete un componente de confianza de la parte superior (proveedor, MSP, biblioteca o sistema de compilación) de modo que los consumidores posteriores reciban código malicioso a través de un canal normalmente confiable. La propiedad definitoria es que el entorno propio de la víctima no fue atacado directamente; el componente de confianza sí lo fue. Phishing apunta a usuarios individualmente. Watering hole compromete un sitio visitado con frecuencia. La amenaza interna es interna. Sólo un ataque de cadena de suministro coincide con la subversión de un pipeline del mantenedor para empujar una actualización maliciosa.

Security operations

An identity team is implementing multifactor authentication. The first factor is a password (something you know). For the second factor, the team selects a hardware security key that the user must physically tap. Which factor category does the hardware key represent?

Oportunidades profesionales y salario

Salario medio: $129,180mercado de EE. UU.– Information Security Analysts

Fuente: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.

Qué temas cubre este examen

Usa las ponderaciones publicadas de los dominios para planificar tu estudio. Los resultados de práctica no predicen tu puntuación en el examen de certificación.

01Security operations

28%

Addresses computing resources management, asset tracking practices, and detailed vulnerability management procedures required to maintain operational stability and rapid incident response readiness within enterprise technology structures across all networks.

Temas

  • Computing resources
  • Asset management
  • Vulnerability management
  • Alerting and monitoring
  • Enterprise security
  • Identity and access management
  • Automation and orchestration
  • Incident response
  • Data sources

Objetivos de aprendizaje

  • Computing resources: applying secure baselines, mobile solutions, hardening, wireless security, application security, sandboxing, and monitoring
  • Asset management: explaining acquisition, disposal, assignment, and monitoring/tracking of hardware, software, and data assets
  • Vulnerability management: identifying, analyzing, remediating, validating, and reporting vulnerabilities
  • Alerting and monitoring: explaining monitoring tools and computing resource activities
  • Enterprise security: modifying firewalls, IDS/IPS, DNS filtering, DLP (data loss prevention), NAC (network access control), and EDR/XDR (endpoint/extended detection and response)
  • Identity and access management: implementing provisioning, SSO (single sign-on), MFA (multifactor authentication), and privileged access tools
  • Automation and orchestration: explaining automation use cases, scripting benefits, and considerations
  • Incident response: implementing processes, training, testing, root cause analysis, threat hunting, and digital forensics
  • Data sources: using log data and other sources to support investigations

02Threats, vulnerabilities, and mitigations

22%

Focuses extensively on identifying various threat actors, distinct threat vectors, expanding attack surfaces, and a wide assortment of different types of vulnerabilities that affect modern computing systems and organizational networks today.

Temas

  • Threat actors and motivations
  • Threat vectors and attack surfaces
  • Vulnerabilities
  • Malicious activity
  • Mitigation techniques

Objetivos de aprendizaje

  • Threat actors and motivations: comparing nation-states, unskilled attackers, hacktivists, insider threats, organized crime, shadow IT, and motivations like data exfiltration, espionage, and financial gain
  • Threat vectors and attack surfaces: explaining message-based, unsecure networks, social engineering, file-based, voice call, supply chain, and vulnerable software vectors
  • Vulnerabilities: explaining application, hardware, mobile device, virtualization, operating system (OS)-based, cloud-specific, web-based, and supply chain vulnerabilities
  • Malicious activity: analyzing malware attacks, password attacks, application attacks, physical attacks, network attacks, and cryptographic attacks
  • Mitigation techniques: using segmentation, access control, configuration enforcement, hardening, isolation, and patching

03Security program management and oversight

20%

Deals directly with security governance structures, structured risk management frameworks, compliance requirements, and specific third-party risk considerations necessary for maintaining organizational security posture and oversight across all connected business units.

Temas

  • Security governance
  • Risk management
  • Third-party risk
  • Security compliance
  • Audits and assessments
  • Security awareness

Objetivos de aprendizaje

  • Security governance: summarizing guidelines, policies, standards, procedures, external considerations, monitoring, governance structures, and roles/responsibilities
  • Risk management: explaining risk identification, assessment, analysis, register, tolerance, appetite, strategies, reporting, and business impact analysis (BIA)
  • Third-party risk: managing vendor assessment, selection, agreements, monitoring, questionnaires, and rules of engagement
  • Security compliance: summarizing compliance reporting, consequences of non-compliance, monitoring, and privacy
  • Audits and assessments: explaining attestation, internal/external audits, and penetration testing
  • Security awareness: implementing phishing training, anomalous behavior recognition, user guidance, reporting, and monitoring

04Security architecture

18%

Explores complex architecture models, enterprise infrastructure configurations, and advanced data protection methods designed to secure information assets across distributed corporate networks and cloud environments effectively during daily operations.

Temas

  • Architecture models
  • Enterprise infrastructure
  • Data protection
  • Resilience and recovery

Objetivos de aprendizaje

  • Architecture models: comparing on-premises, cloud, virtualization, Internet of Things (IoT), industrial control systems (ICS), and infrastructure as code (IaC)
  • Enterprise infrastructure: applying security principles to infrastructure considerations, control selection, and secure communication/access
  • Data protection: comparing data types, securing methods, general considerations, and classifications
  • Resilience and recovery: explaining high availability, site considerations, testing, power, platform diversity, backups, and continuity of operations

05General security concepts

12%

Covers basic security concepts, including the implementation of standard security controls, the management of organizational change, and the understanding of fundamental principles required for securing modern network environments and systems against potential failures.

Temas

  • Security controls
  • Fundamental concepts
  • Change management
  • Cryptographic solutions

Objetivos de aprendizaje

  • Security controls: comparing technical, preventive, managerial, deterrent, operational, detective, physical, corrective, compensating, and directive controls
  • Fundamental concepts: summarizing confidentiality, integrity, and availability (CIA); non-repudiation; authentication, authorization, and accounting (AAA); zero trust; and deception/disruption technology
  • Change management: explaining business processes, technical implications, documentation, and version control
  • Cryptographic solutions: using public key infrastructure (PKI), encryption, obfuscation, hashing, digital signatures, and blockchain

Detalles del Examen SY0-701 | $404 USD | 1 hora 30 minutos

Código del Examen SY0-701
Proveedor CompTIA
Costo del Examen $404 USD
Puntaje Mínimo 750/900
Límite de Tiempo 1 hora 30 minutos
Preguntas del examen 90
Tipos de PreguntasAún no disponible en este idioma
Política de Repetición No waiting period required before first retake. After the second failed attempt, candidates must wait 14 calendar days before any subsequent attempt. No limit on total attempts.
Formato del Examen Linear
Supervisión en Línea Disponible
Disponible En
EnglishJapanesePortugueseSimplified Chinese

Preguntas Frecuentes

How should I use this practice bank?

Where can I check the official exam scope?

Does a practice score predict my certification result?