SY0-701: Security Operations

Security Operations is one of the skill areas tested on the Security+ (SY0-701) exam. Below are free SY0-701 practice questions with worked answers and a concept diagram — each with a plain-language explanation. Practice the first 10 questions of SY0-701 free, no signup.

The concept, in one picture

Concept flowThe incident response lifecycle
The incident response lifecycleThe incident response lifecyclePreparationplans, tooling, trainingDetection & analysisSIEM alerts, triage, scopeContainmentisolate to stop the spreadEradication & recoveryremove, patch, restoreLessons learnedfeed fixes back into prep

2 free SY0-701 Security Operations questions

Sample SY0-701 question

A development team relies on a single shared "break-glass" backup account to reach the source code repository when the normal single sign-on (SSO) service is down. Which solution best protects this shared account while still allowing controlled access during an SSO outage?

  • Privileged access management (PAM) with credential vaulting and checkout
  • Remote Access Service (RAS) for dial-in connectivity
  • Extensible Authentication Protocol (EAP) for the login exchange
  • Security Assertion Markup Language (SAML) assertions
Explanation

A PAM solution vaults the shared account's credential, brokers time-limited checkout, rotates the password after use, and records the session for audit — so the account stays protected and accountable even when SSO is unavailable. SAML is a federation protocol that underpins SSO itself, so it cannot help when SSO is exactly what has failed. RAS only provides remote network connectivity, and EAP is an authentication framework used mainly for network/802.1X access; neither controls or audits use of a shared privileged repository account.

Sample SY0-701 question

A vulnerability management lead has a backlog of hundreds of open findings and limited maintenance windows. Which of the following provides a standardized severity rating that helps rank which flaws should be remediated first?

  • Security orchestration, automation, and response (SOAR)
  • Common Vulnerability Scoring System (CVSS)
  • Security information and event management (SIEM)
  • Common Vulnerabilities and Exposures (CVE)
Explanation

CVSS produces a numeric severity score (0.0-10.0) built from exploitability and impact metrics, giving a consistent, vendor-neutral way to rank findings so the most dangerous ones are patched first. SOAR automates and orchestrates incident response playbooks but does not rate vulnerability severity. SIEM aggregates and correlates log and event data for detection and alerting, not remediation prioritization. CVE is only a naming dictionary that assigns unique identifiers to disclosed vulnerabilities; the identifier itself carries no severity ranking.

Practice SY0-701 free

The first 10 questions of every exam are free. No signup, no email wall.

Start practicing →

Get a free SY0-701 study plan by email

A short plan to work through SY0-701 by skill area, plus a note when we add new questions. Optional — the practice above stays free. No spam, unsubscribe anytime.

More SY0-701 skill areas