Comptia

SY0-701 Free Practice Questions — Page 10

Question 91

A Chief Information Security Officer (CISO) has developed information security policies that relate to the software development methodology. Which of the following would the CISO most likely include in the organization’s documentation?

A. Peer review requirements
B. Multifactor authentication
C. Branch protection tests
D. Secrets management configurations
Show Answer
Correct Answer: A
Explanation:
Peer review requirements are an appropriate policy-level requirement tied to the software development methodology and secure SDLC. A CISO would commonly require code reviews as part of development governance. Multifactor authentication is an access control policy, while branch protection tests and secrets management configurations are implementation or platform configuration details rather than high-level methodology documentation.

Question 92

Which of the following is the stage in an investigating when forensic images are obtained?

A. Acquisition
B. Preservation
C. Reporting
D. E-discovery
Show Answer
Correct Answer: A
Explanation:
The acquisition phase of a digital forensic investigation is where forensic images (bit-for-bit copies) of storage media or other digital evidence are created. Preservation focuses on maintaining the integrity of evidence, reporting documents findings, and e-discovery is a legal process for identifying and producing electronically stored information rather than the forensic imaging stage.

Question 93

A company is considering an expansion of access controls for an application that contractors and internal employees use to reduce costs. Which of the following risk elements should the implementation team understand before granting access to the application?

A. Threshold
B. Appetite
C. Avoidance
D. Register
Show Answer
Correct Answer: B
Explanation:
The correct answer is B. Risk appetite is the amount and type of risk an organization is willing to accept in pursuit of its objectives. Before expanding application access to contractors and employees, the implementation team should understand the organization's risk appetite so access decisions align with acceptable business risk. A risk threshold is a specific limit derived from the broader appetite, risk avoidance is a treatment strategy, and a risk register is simply the documentation of identified risks.

Question 94

Which of the following activities uses OSINT?

A. Social engineering testing
B. Data analysis of logs
C. Collecting evidence of malicious activity
D. Producing IOC for malicious artifacts
Show Answer
Correct Answer: A
Explanation:
OSINT (Open Source Intelligence) is the collection and analysis of publicly available information. A common use is gathering publicly available details about people and organizations to support or simulate social engineering attacks during authorized security testing. Log analysis is not OSINT, collecting evidence of malicious activity typically refers to forensic or internal investigation, and producing IOCs primarily comes from malware/threat analysis, though OSINT can contribute to threat intelligence.

Question 95

A security engineer at a large company needs to enhance IAM in order to ensure that employees can only access corporate systems during their shifts. Which of the following access controls should the security engineer implement?

A. Role-based
B. Time-of-day restrictions
C. Least privilege
D. Biometric authentication
Show Answer
Correct Answer: B
Explanation:
Time-of-day restrictions are an IAM access control that limits authentication or authorization to specified time windows, such as an employee's scheduled shift. Role-based access controls what resources a user can access based on job function, least privilege limits permissions, and biometric authentication verifies identity but does not enforce shift-based access.

Question 96

Which of the following is a reason environmental variables are a concern when reviewing potential system vulnerabilities?

A. The contents of environmental variables could affect the scope and impact of an exploited vulnerability.
B. In-memory environmental variable values can be overwritten and used by attackers to insert malicious code.
C. Environmental variables define cryptographic standards for the system and could create vulnerabilities if deprecated algorithms are used.
D. Environmental variables will determine when updates are run and could mitigate the likelihood of vulnerability exploitation.
Show Answer
Correct Answer: A
Explanation:
Environmental variables can contain sensitive configuration, credentials, paths, and runtime settings that influence application behavior. If a vulnerability is exploited, exposure or manipulation of these variables can increase the attack's scope and impact. The other options are inaccurate: environment variables do not define cryptographic standards, do not generally determine update schedules, and overwriting environment variables is not the primary or general concern described in vulnerability assessment.

Question 97

While conducting a business continuity tabletop exercise, the security team becomes concerned by potential impact if a generator was to develop a fault during failover. Which of the following is the team most likely to consider in regard to risk management activities?

A. RPO
B. ARO
C. BIA
D. MTTR
Show Answer
Correct Answer: C
Explanation:
The scenario focuses on assessing the potential business impact of a generator failing during failover in a business continuity exercise. Business Impact Analysis (BIA) is the risk management activity used to evaluate the effects of disruptions on business operations and prioritize recovery. RPO concerns acceptable data loss, ARO estimates event frequency, and MTTR measures average recovery time after a failure rather than analyzing business impact.

Question 98

An administrator is creating a secure method for a contractor to access a test environment. Which of the following would provide the contractor with the best access to the test environment?

A. Application server
B. Jump server
C. RDP server
D. Proxy server
Show Answer
Correct Answer: B
Explanation:
A jump server (bastion host) is the standard secure method for providing controlled, monitored access to an isolated environment. It serves as a hardened intermediary, allowing contractors to authenticate and then access only the test environment while enabling logging, auditing, and reducing direct exposure. An application server hosts applications, an RDP server only provides remote desktop capability without the security role of a bastion host, and a proxy server forwards network requests rather than providing secure administrative access.

Question 99

Which of the following is a type of vulnerability that refers to the unauthorized installation of applications on a device through means other than the official application store?

A. Cross-site scripting
B. Buffer overflow
C. Jailbreaking
D. Side loading
Show Answer
Correct Answer: D
Explanation:
Side loading is the installation of applications from sources other than the official application store. This practice can bypass the platform's security review process and increase the risk of unauthorized or malicious applications. Jailbreaking removes operating system restrictions and may enable sideloading, but it is a different concept. Cross-site scripting and buffer overflow are unrelated software vulnerabilities.

Question 100

Which of the following should be used to aggregate log data in order to create alerts and detect anomalous activity?

A. SIEM
B. WAF
C. Network taps
D. IDS
Show Answer
Correct Answer: A
Explanation:
A SIEM (Security Information and Event Management) platform is specifically designed to collect, aggregate, correlate, and analyze log data from multiple sources to generate alerts and detect anomalous or suspicious activity. A WAF protects web applications, network taps passively capture network traffic, and an IDS detects intrusions but is not the primary log aggregation and correlation platform.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.