Comptia

SY0-701 Free Practice Questions — Page 11

Question 103

A company relies on open-source software libraries to build the software used by its customers. Which of the following vulnerability types would be the most difficult to remediate due to the company’s reliance on open-source libraries?

A. Buffer overflow
B. SQL injection
C. Cross-site scripting
D. Zero-day
Show Answer
Correct Answer: D
Explanation:
Zero-day vulnerabilities are unknown and unpatched at the time of exploitation. When they exist in open-source libraries, the company typically cannot fix them directly and must wait for maintainers or the community to identify and release a patch, making remediation the most difficult. The other options are well-known vulnerability classes with established detection and remediation practices.

Question 104

To which of the following security categories does an EDR solution belong?

A. Physical
B. Operational
C. Managerial
D. Technical
Show Answer
Correct Answer: D
Explanation:
An Endpoint Detection and Response (EDR) solution is a technical security control. It consists of software and technical mechanisms deployed on endpoints to monitor activity, detect threats, and respond to incidents, which places it squarely in the technical security category.

Question 105

A security analyst notices unusual behavior on the network. The IDS on the network was not able to detect the activities. Which of the following should the security analyst use to help the IDS detect such attacks in the future?

A. Signatures
B. Trends
C. Honeypot
D. Reputation
Show Answer
Correct Answer: A
Explanation:
An IDS primarily detects attacks by matching observed activity against known attack patterns. If unusual behavior was not detected, adding or updating signatures enables the IDS to recognize similar attacks in the future. The other options (trends, honeypot, reputation) do not directly improve an IDS’s detection logic.

Question 106

A company’s gate access logs show multiple entries from an employee’s ID badge within a two-minute period. Which of the following is this an example of?

A. RFID cloning
B. Side-channel attack
C. Shoulder surfing
D. Tailgating
Show Answer
Correct Answer: A
Explanation:
Multiple access log entries from the same ID badge within a very short time window suggest the badge credentials are being used more than once, potentially by more than one person. This is consistent with RFID cloning, where a copied badge is used alongside the original. Tailgating typically does not generate additional log entries because the follower does not present a badge.

Question 107

An administrator must replace an expired SSL certificate. Which of the following does the administrator need to create the new SSL certificate?

A. CSR
B. OCSP
C. Key
D. CRL
Show Answer
Correct Answer: A
Explanation:
To replace an expired SSL certificate, the administrator must generate a Certificate Signing Request (CSR). The CSR contains the public key and identifying information that a Certificate Authority uses to issue a new SSL certificate. OCSP and CRL are used for certificate status checking, and the private key already exists or is generated locally, not submitted to the CA.

Question 108

A company wants to track modifications to the code that is used to build new virtual servers. Which of the following will the company most likely deploy?

A. Change management ticketing system
B. Behavioral analyzer
C. Collaboration platform
D. Version control tool
Show Answer
Correct Answer: D
Explanation:
The goal is to track modifications to code used to build new virtual servers. A version control tool (such as Git) is specifically designed to track changes to source code over time, maintain history, support rollbacks, and manage contributions. Change management ticketing is broader and procedural, a behavioral analyzer is unrelated, and a collaboration platform does not inherently track code changes.

Question 109

A certificate authority needs to post information about expired certificates. Which of the following would accomplish this task?

A. TPM
B. CRL
C. PKI
D. CSR
Show Answer
Correct Answer: B
Explanation:
A Certificate Revocation List (CRL) is published by a certificate authority to provide information about certificates that are no longer valid, including those that are revoked or expired. The other options do not serve the purpose of posting certificate status information.

Question 110

Which of the following is the act of proving to a customer that software developers are trained on secure coding?

A. Assurance
B. Contract
C. Due diligence
D. Attestation
Show Answer
Correct Answer: D
Explanation:
Attestation is the formal act of certifying or providing evidence that a requirement has been met. Proving to a customer that software developers are trained in secure coding involves documented confirmation or certification, which is precisely an attestation. Assurance is broader confidence, a contract is a legal agreement, and due diligence is an internal evaluation process, not customer-facing proof.

Question 111

A security analyst needs to improve the company’s authentication policy following a password audit. Which of the following should be included in the policy? (Choose two.)

A. Length
B. Complexity
C. Least privilege
D. Something you have
E. Security keys
F. Biometrics
Show Answer
Correct Answer: A, B
Explanation:
A password audit focuses on improving password strength. Minimum length and complexity requirements are core elements of a password policy that reduce susceptibility to brute-force and guessing attacks. Least privilege is an authorization concept, and the remaining options relate to MFA rather than password policy.

Question 112

A SOC analyst establishes a remote control session on an end user’s machine and discovers the following in a file: gmail.com[ENT] [ENT]NoOneCanGuessThis123! [ENT]Hello Susan, it was great to see you the other day! Let’s plan a followup[BACKSPACE]follow-up meeting soon. Here is the link to register. [RTN][CTRL]c [CTRL]v [RTN]after[BACKSPACE]After you register give me a call on my cellphone. Which of the following actions should the SOC analyst perform first?

A. Advise the user to change passwords.
B. Reimage the end user’s machine.
C. Check the policy on personal email at work.
D. Check host firewall logs.
Show Answer
Correct Answer: B
Explanation:
The file clearly shows keystroke logging artifacts (e.g., [ENT], [BACKSPACE], [CTRL]c, [CTRL]v) along with captured credentials, indicating the endpoint is compromised by a keylogger or similar malware. The first priority is to eradicate the compromise. Reimaging the machine ensures complete removal of the malware. Advising a password change before reimaging would be ineffective, as new credentials would likely be captured as well. Other actions are secondary and should occur after the system is clean.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.