Objective 3.3SY0-701

3.3 Compare and contrast concepts and strategies to protect data

Objective 3.3 sits in Security Architecture, which carries 18% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Security ArchitectureModerateChoose 3

An organization transmits customer records across the internet without encrypting the traffic. Which attacks does this expose the organization to?

Correct.

The concept

Encryption on the wire is what makes an observer's position useless. Without it, anyone who can see the path can read what crosses it, alter it, or take over a session already in progress, because there is no integrity check and no secret binding the session to one party. Everything that depends on being on the path becomes available at once, while threats aimed at the application's own input handling or at people are unaffected either way.

Why this answer

Unencrypted traffic is directly susceptible to interception and session takeover, matching person-in-the-middle, eavesdropping, and session hijacking.

  • Correct: unencrypted traffic can be intercepted through a person-in-the-middle attack.
  • Correct: plaintext traffic can be read directly through eavesdropping.
  • Correct: unencrypted sessions can be hijacked once traffic is exposed.
  • DSQL injection targets application input handling, not the encryption state of network traffic.
  • EPhishing targets end users through social engineering, unrelated to transit encryption.
Read the sourceAzure data encryption best practices
Verified against learn.microsoft.com · 2026-07-27
data-in-transitnetwork-attacksencryption

Now you: objective 3.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Security ArchitectureModerate

An analyst configures Microsoft Purview to automatically flag any document containing a string matching a known credit card number format. Which classification method is being used?

Sample question 2 of 3

Security ArchitectureEasy

In Microsoft Purview data classification, what does document fingerprinting identify?

Sample question 3 of 3

Security ArchitectureModerate

A compliance team wants Purview to recognize resumes even though the wording and layout vary widely between documents. Which classification method should they use?

That’s 3 of the full Security+ bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practicing

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Architecture