SY0-701: Security Architecture

Security Architecture is one of the skill areas tested on the Security+ (SY0-701) exam. Below are free SY0-701 practice questions with worked answers and a concept diagram — each with a plain-language explanation. Practice the first 10 questions of SY0-701 free, no signup.

The concept, in one picture

Concept flowDefence in depth
Defence in depthDefence in depthPerimeterfirewall, IPS, DMZ / screened subnetNetworksegmentation, VLANs, zero trustHosthardening, EDR, patchingApplicationinput validation, secure SDLCDataencryption at rest & in transit, DLP

2 free SY0-701 Security Architecture questions

Sample SY0-701 question

A financial services firm has contracted an overseas support team that will use its own personal computers. Company policy requires that all finance data remain stored and processed on corporate-controlled systems, and the firm will not ship or fund any hardware for these contractors. Which solution best satisfies both constraints?

  • Enroll each contractor's laptop in mobile device management (MDM)
  • Publish hosted desktops through virtual desktop infrastructure (VDI)
  • Give the contractors an IPsec VPN client to reach the internal network
  • Segment the finance servers inside a dedicated virtual private cloud (VPC)
Explanation

VDI streams a centrally hosted desktop to the endpoint, so the operating system, applications, and data all live and execute on company-controlled servers while only screen pixels and keystrokes travel to the contractor's own device. That meets both requirements: data never resides on the personal PC, and no corporate hardware has to be issued. MDM is wrong because it manages the endpoint itself and typically presumes a company-owned or trusted device, and data still runs locally. A VPN only provides an encrypted tunnel to the network; files could still be copied down to the personal machine. A VPC is a cloud network boundary for the servers and says nothing about how a contractor accesses data or where it is processed.

Sample SY0-701 question

An operations team is deploying dozens of low-power, Wi-Fi-connected environmental sensors that will continuously report temperature and humidity readings to a collection server. The devices run minimal firmware and cannot host an endpoint agent. Which action should the security team take to best reduce the risk these devices pose to the corporate network?

  • Segment the sensors onto their own isolated VLAN with restricted routing to only the collection server
  • Disconnect the sensors' wireless radios and cable them directly to the core switch
  • Document the sensor firmware as an entry in the corporate risk register and take no further action
  • Mandate that each sensor negotiate TLS 1.2 before it is permitted to join the wireless network
Explanation

Constrained IoT devices can't run robust host protections, so the strongest control is network segmentation: an isolated VLAN with tightly scoped routing keeps a compromised sensor from reaching the rest of the network and limits lateral movement. Air-gapping (or hard-wiring away the radios) defeats the whole point of Wi-Fi sensors that must transmit telemetry, so it isn't a viable option. Adding the firmware to the risk register is a governance step that records the risk but applies no technical control to reduce it. Requiring TLS 1.2 protects data in transit but many minimal sensors can't perform it, and encryption alone does nothing to contain a device that is already on the flat network.

Practice SY0-701 free

The first 10 questions of every exam are free. No signup, no email wall.

Start practicing →

Get a free SY0-701 study plan by email

A short plan to work through SY0-701 by skill area, plus a note when we add new questions. Optional — the practice above stays free. No spam, unsubscribe anytime.

More SY0-701 skill areas