
CompTIASecurity+
Domain 4Objective 8
Incident Response SY0-701 Practice Questions (Page 3)
Part of the Security operations domain, which accounts for 28% of the SY0-701 exam. CompTIA does not publish an official question count, but from its 90-minute exam (~35–60 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
6concepts
28%of the exam
Questions 11–15
- 11
An organization is investigating a suspected insider threat. The security team needs to collect evidence from an employee's laptop, but the employee is a senior executive and the laptop contains sensitive business data. The team must preserve evidence for potential legal action. Which action is the MOST appropriate?
Select an answer first - 12
After a security incident, an analyst investigates why a misconfigured firewall rule allowed unauthorized access. What is the primary goal of this root cause analysis?
Select an answer first - 13
Which of the following is a common method used to deliver incident response training to staff?
Select an answer first - 14
What is the purpose of creating a forensic image of a storage device during an investigation?
Select an answer first - 15
An organization's incident response plan has been updated. To ensure the plan is effective, the security manager wants to test the technical capabilities of the team, including their ability to detect and respond to a simulated attack on a non-production system. Which testing method is MOST appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “SY0-701” is a trademark of its owner, used for identification only.