
CompTIASecurity+
Domain 4Objective 8
Incident Response SY0-701 Practice Questions (Page 4)
Part of the Security operations domain, which accounts for 28% of the SY0-701 exam. CompTIA does not publish an official question count, but from its 90-minute exam (~35–60 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
6concepts
28%of the exam
Questions 16–20
- 16
Which technique is commonly used to identify the root cause of a security incident?
Select an answer first - 17
After a malware outbreak, the incident response team discovers that the malware was introduced via a software update from a compromised vendor portal. The team removed the malware and restored systems, but management wants to prevent a recurrence. Which action is the MOST direct application of root cause analysis?
Select an answer first - 18
A security manager is planning a training program to prepare employees for their roles during a security incident. What is a primary objective of incident response training?
Select an answer first - 19
A security analyst is reviewing logs and finds that a user account has been successfully logging in from a foreign country at times when the user is known to be in the office. The analyst has no other alerts. Which action is the MOST appropriate to determine if this is a real threat?
Select an answer first - 20
An organization wants to evaluate the effectiveness of its incident response plan by simulating a realistic cyberattack. Which type of testing activity is most appropriate for this purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “SY0-701” is a trademark of its owner, used for identification only.