SEC+ SY0-701 V7 Security architecture and operations Fictional web platform recovery · 4 of 4 Runs in your browser · no setup Preview · not independently reviewed

Approve and recover a hosted application release

Interpret a fail-fast deployment, preserve layered MFA, protect secrets and content approvals, then prove recovery readiness.

Estimated22 min
DifficultyAdvanced
Points20
Scenario brief

Northwind Orchard is preparing a public learning portal and a separate owner-only review console. The bootstrap created the database and protected environment file, but the application never started. Complete the security review without bypassing readiness checks or exposing internal credentials.

Content record

Preview · not independently reviewed

Mapped to CompTIA SY0-701 objectives · Internal validation 2026-08-13 · Available as preview practice, but a named independent subject-matter expert has not yet verified the question and answer key.

Community review →
4.6Given a scenario, implement and maintain identity and access management. 3.2Given a scenario, apply security principles to secure enterprise infrastructure. 4.5Given a scenario, modify enterprise capabilities to enhance security. 3.4Explain the importance of resilience and recovery in security architecture.
Show review record and official sources

Method: Mapped to SY0-701 objectives 3.2, 3.4, 4.5, and 4.6; layered authentication, fail-fast deployment evidence, secret handling, approval binding, backup validation, and rollback were checked against primary documentation and application tests.

Current-profile check: 2026-08-12 · Next review due 2026-12-15

01

Inspect the evidence

Use only the information provided to complete the tasks.

Deployment state

table
ArtifactState
Database role and empty databasePresent
ACL-protected environment file outside GitPresent
OAuth client IDs and staff subjectBlank
Django migration tableAbsent
Startup task and TCP 8443 listenerAbsent
Source-restricted host firewall ruleAbsent
Public hostnameHTTP 502

Installer order

list
  • Create virtual environment and install pinned requirements
  • Run strict hosted-settings check
  • Run framework deployment checks
  • Apply migrations and collect static assets
  • Register the startup task, add the firewall rule, and start the application

Owner console boundaries

list
  • Cloud account TOTP protects the provider dashboard
  • Access-gateway TOTP protects entry to the admin hostname
  • Application TOTP protects the inner owner session
  • The gateway can validate its signed JWT before proxying
  • The browser never receives the internal review API bearer token
02

Complete the response

Partial credit is available for matching, ordering, and multi-select tasks.

01
matching

Match each authentication control to the boundary it protects.

5 pts
Need a hint?

Start with the row and choice that have the most distinctive purpose, then use that pair to narrow the rest.

Show another hint

For each remaining pair, explain the relationship in one sentence before selecting it.

02
multi select

The gateway interrupts a POST to `/login/totp` and later resumes that URL with GET. Select the THREE safe fixes or diagnostics.

3 pts
Need a hint?

Evaluate each option independently against the scenario evidence instead of treating the list as one decision.

Show another hint

Choose only options that directly satisfy the prompt; being generally true is not enough.

03
single choice

What is the strongest inference from the deployment state and installer order?

3 pts
Need a hint?

Restate the exact outcome or failure the prompt asks about before comparing choices.

Show another hint

Eliminate choices that solve a nearby problem, change more than requested, or do not fit the evidence.

04
multi select

Select the FOUR controls required before releasing the portal.

4 pts
Need a hint?

Evaluate each option independently against the scenario evidence instead of treating the list as one decision.

Show another hint

Choose only options that directly satisfy the prompt; being generally true is not enough.

05
ordering

Order the rollback if final public verification fails after deployment.

5 pts

Drag the rows or use the arrow buttons to reorder.

  1. 1 Disable only this application's published route if public error traffic must stop
  2. 2 Stop the application task without deleting shared tunnel or proxy services
  3. 3 Preserve application, proxy, and deployment logs plus the protected environment file
  4. 4 Restore the known-good checkout and tested pre-deployment database archive
  5. 5 Recheck backend, local proxy, and public layers in that order before re-enabling traffic
Need a hint?

Identify the prerequisite that must happen first and the verification or documentation that belongs last.

Show another hint

For the middle steps, ask what must already be true before each action can safely happen.

Ready to check your work?Submit to finish this session and review your feedback. Extra practice is optional.
Persistent progress

Attempt history

Every submission is retained. Starting another attempt never replaces or unlocks the previous one.

No attempts yet

Your first submitted score and detailed answer review will appear here.

Community quality control

Question or answer look wrong?

Proposals and votes help staff prioritize review. They never change the scoring key automatically.

Full review queue
No community corrections yet

Be the first to flag unclear wording, an answer-key issue, or a source that needs another look.

Propose a correction