20+ practice questions focused on General Security Concepts — one of the most tested topics on the Security+ SY0-701 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start General Security Concepts PracticeA company wants one document that tells employees what they are required to do when handling company systems and data. Which document type is the best fit?
Explanation: A policy is the correct document type because it defines mandatory rules and expectations for all employees regarding the handling of company systems and data. Policies are the highest-level directives that set required behavior, while procedures provide step-by-step instructions, standards are detailed mandatory requirements, and guidelines offer optional recommendations. Therefore, a policy is the best fit for a single document that tells employees what they must do.
Which two practices help protect encryption keys? Select two.
Explanation: A hardware security module (HSM) is a dedicated, tamper-resistant hardware device designed to securely generate, store, and manage cryptographic keys. By keeping keys inside the HSM, they never exist in plaintext in system memory or on disk, and operations like signing or decryption occur within the HSM's secure boundary, preventing extraction even if the host is compromised. Additionally, rotating keys on a defined schedule limits the amount of data exposed if a key is compromised, reducing the impact of a potential breach and ensuring that long-term compromise is less likely. Both practices are essential for protecting encryption keys.
A development team signs branch-router firmware before deployment. The same code-signing private key is stored on two build servers, and a compromise of either server would let an attacker sign malicious updates that look legitimate. Which two changes best reduce the cryptographic risk while preserving the ability to sign trusted releases? Select two.
Explanation: Moving the private key into a non-exportable HSM or managed key service ensures the key material never resides on the build servers in a form that can be extracted. Even if a build server is compromised, the attacker cannot steal the private key to sign malicious firmware. This directly addresses the risk of key exposure from server compromise while preserving the ability to sign trusted releases through secure API calls to the HSM. Additionally, using separate signing keys for each product line or release environment limits the blast radius: a compromise of one key does not allow an attacker to sign malicious updates for all products, only the affected product line. This also preserves the ability to sign trusted releases because each product can continue to sign with its own dedicated key.
Which two are common warning signs of phishing messages? Select two.
Explanation: Phishing messages often create a false sense of urgency, such as claiming an account will be locked in 15 minutes, to pressure the recipient into acting without verifying the source. Additionally, unexpected attachments from unknown senders are a common warning sign because they may contain malware or trick the recipient into revealing credentials. Both tactics exploit human tendencies—urgency and curiosity—bypassing rational checks like inspecting the sender's address or hovering over links.
Which two are detective controls? Select two.
Explanation: Security cameras and SIEM log review are both detective controls. A security camera is detective because it records events for after-the-fact review, while log review in a SIEM is detective because it identifies suspicious activity by analyzing collected logs after events occur, rather than preventing them. Neither control prevents an incident but both detect and document it.
+15 more General Security Concepts questions available
Practice all General Security Concepts questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of General Security Concepts. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
General Security Concepts questions on the SY0-701 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. General Security Concepts is tested as part of the Security+ SY0-701 blueprint. Practicing with targeted General Security Concepts questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SY0-701 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but General Security Concepts is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full General Security Concepts practice session with instant scoring and detailed explanations.
Start General Security Concepts Practice →