Comptia

SY0-701 Free Practice Questions — Page 13

Question 123

A customer has a contract with a CSP and wants to identify which controls should be implemented in the IaaS enclave. Which of the following is most likely to contain this information?

A. Statement of work
B. Responsibility matrix
C. Service-level agreement
D. Master service agreement
Show Answer
Correct Answer: B
Explanation:
In an IaaS model, the document that identifies which security and operational controls are implemented by the customer versus the cloud service provider is the responsibility matrix (also called a shared responsibility matrix). It explicitly maps specific controls to each party. An SLA focuses on service performance and availability, while an SOW and MSA define scope and overarching legal terms, not detailed control ownership.

Question 124

A security manager wants to reduce the number of steps required to identify and contain basic threats. Which of the following will help achieve this goal?

A. SOAR
B. SIEM
C. DMARC
D. NIDS
Show Answer
Correct Answer: A
Explanation:
SOAR automates and orchestrates security workflows using predefined playbooks, reducing manual steps needed to identify, investigate, and contain common threats. SIEM aggregates logs, DMARC is email authentication, and NIDS detects network intrusions but do not streamline response steps.

Question 125

An alert references attacks associated with a zero-day exploit. An analyst places a bastion host in the network to reduce the risk of the exploit. Which of the following types of controls is the analyst implementing?

A. Compensating
B. Detective
C. Operational
D. Physical
Show Answer
Correct Answer: A
Explanation:
A bastion host is introduced to mitigate risk from a zero-day exploit when the primary control (such as patching the vulnerability) is not yet available. This matches the definition of a compensating control, which provides an alternative means of reducing risk when standard preventive controls cannot be implemented.

Question 126

The Chief Information Officer (CIO) asked a vendor to provide documentation detailing the specific objectives within the compliance framework that the vendor's services meet. The vendor provided a report and a signed letter stating that the services meet 17 of the 21 objectives. Which of the following did the vendor provide to the CIO?

A. Penetration test results
B. Self-assessment findings
C. Attestation of compliance
D. Third-party audit report
Show Answer
Correct Answer: C
Explanation:
The vendor provided a report along with a signed letter stating which specific compliance objectives were met. This is characteristic of an Attestation of Compliance (AOC), which is a formal assertion by the vendor regarding compliance status. It is not a third-party audit (independent), a penetration test, or merely internal self-assessment findings.

Question 127

A company is using a legacy FTP server to transfer financial data to a third party. The legacy system does not support SFTP, so a compensating control is needed to protect the sensitive, financial data in transit. Which of the following would be the most appropriate for the company to use?

A. Telnet connection
B. SSH tunneling
C. Patch installation
D. Full disk encryption
Show Answer
Correct Answer: B
Explanation:
The legacy FTP server cannot natively encrypt data in transit, so a compensating control is required. SSH tunneling encrypts the FTP traffic by encapsulating it within an SSH-encrypted channel, protecting sensitive financial data during transmission. Telnet provides no encryption, patch installation does not address the lack of secure transport, and full disk encryption protects data at rest, not in transit.

Question 128

Which of the following should a systems administrator use to decrease the company's hardware attack surface?

A. Replication
B. Isolation
C. Centralization
D. Virtualization
Show Answer
Correct Answer: D
Explanation:
The question specifically asks about reducing the **hardware attack surface**, which refers to the number of physical devices that could be targeted (ports, firmware, physical access, etc.). Virtualization consolidates multiple workloads onto fewer physical machines, directly reducing the amount of hardware that must be protected. Isolation improves security by separation, but it does not inherently reduce the quantity of hardware exposed. Replication and centralization do not reduce—and may even increase—the hardware attack surface.

Question 129

Which of the following is most likely a security concern when installing and using low-cost IoT devices in infrastructure environments?

A. Country of origin
B. Device responsiveness
C. Ease of deployment
D. Storage of data
Show Answer
Correct Answer: D
Explanation:
The most likely security concern with low-cost IoT devices in infrastructure environments is how data is stored and protected. These devices often lack strong encryption, secure storage, and proper access controls, increasing the risk of data leakage, breaches, or misuse of sensitive operational information. Device responsiveness and ease of deployment are not security issues, and while country of origin can be a concern in specific threat models, it is less universally emphasized than data storage in standard security guidance such as CompTIA.

Question 130

An administrator has configured a quarantine subnet for all guest devices that connect to the network. Which of the following would be best for the security team to perform before allowing access to corporate resources?

A. Device fingerprinting
B. Compliance attestation
C. Penetration test
D. Application vulnerability test
Show Answer
Correct Answer: B
Explanation:
Guest devices placed in a quarantine subnet should be validated before accessing corporate resources. Compliance attestation verifies that a device meets required security controls (e.g., up-to-date OS patches, antivirus enabled, firewall on), which is a core Network Access Control step. Device fingerprinting only identifies device characteristics, while penetration testing and application vulnerability testing are inappropriate for onboarding guest devices.

Question 131

A company captures log-in details and reviews them each week to identify conditions such as excessive log-in attempts and frequent lockouts. Which of the following should a security analyst recommend to improve security compliance monitoring?

A. Including the date and person who reviewed the information in a report
B. Adding automated alerting when anomalies occur
C. Requiring a statement each week that no exceptions were noted
D. Masking the username in a report to protect privacy
Show Answer
Correct Answer: B
Explanation:
Automated alerting improves security compliance monitoring by providing real-time detection and notification of suspicious activities such as excessive login attempts or frequent lockouts. This reduces reliance on periodic manual reviews and enables faster response to potential security incidents, strengthening overall monitoring effectiveness.

Question 132

An engineer has ensured that the switches are using the latest OS, the servers have the latest patches, and the endpoints' definitions are up to date. Which of the following will these actions most effectively prevent?

A. Zero-day attacks
B. Insider threats
C. End-of-life support
D. Known exploits
Show Answer
Correct Answer: D
Explanation:
Keeping network devices, servers, and endpoints fully updated applies fixes and signature updates for vulnerabilities and threats that are already known. These actions are most effective at preventing attacks that rely on known exploits, not zero-day attacks, insider threats, or end-of-life issues.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.