SY0-701: General Security Concepts
General Security Concepts is one of the skill areas tested on the Security+ (SY0-701) exam. Below are free SY0-701 practice questions with worked answers and a concept diagram — each with a plain-language explanation. Practice the first 10 questions of SY0-701 free, no signup.
The concept, in one picture
2 free SY0-701 General Security Concepts questions
An organization follows a formal change management process. Before a proposed configuration change can be deployed to production, it must first be vetted so that its security impact is understood and formally authorized. Which element of the change management process provides this gate?
- ✓ Approval by the change advisory board or management
- Executing a full performance and stress test
- Sending downtime notices to affected users
- Rewriting the operational runbooks
A formal approval process, typically handled by a change advisory board (CAB) or management, is the governance gate that authorizes a change after its impact and risk have been assessed. This is the step that ensures a change is reviewed and sanctioned before it reaches production. Stress testing validates capacity, not security authorization. Maintenance notifications inform stakeholders about a change that is already scheduled, and updating runbooks/procedures is documentation work that generally follows implementation. Only the approval process functions as the pre-implementation authorization step.
An insurance company wants to move sensitive policyholder records to a public cloud and run analytics that compute on those records, but the cloud provider must never be able to read the underlying plaintext even while the calculations are performed. Leadership has accepted that the approach will be significantly slower and more resource-intensive than normal processing. Which cryptographic approach best satisfies this requirement?
- ✓ Homomorphic encryption
- Elliptic-curve (asymmetric) encryption
- AES in GCM mode (symmetric)
- Perfect forward secrecy with ephemeral keys
Homomorphic encryption uniquely permits mathematical operations to be carried out directly on ciphertext, so the cloud provider can process the data while it stays encrypted and never sees the plaintext. Its well-known drawback is heavy computational cost and slow performance, which the scenario explicitly says is acceptable. Elliptic-curve and AES/GCM protect data at rest or in transit but require decryption before any computation, exposing plaintext during processing. Ephemeral keys with perfect forward secrecy protect past session traffic if a key is later compromised; they do not enable computing on encrypted data.
Practice SY0-701 free
The first 10 questions of every exam are free. No signup, no email wall.
Start practicing →Get a free SY0-701 study plan by email
A short plan to work through SY0-701 by skill area, plus a note when we add new questions. Optional — the practice above stays free. No spam, unsubscribe anytime.