Comptia

SY0-701 Free Practice Questions — Page 16

Question 151

A new employee accessed an unauthorized website. An investigation found that the employee violated the company's rules. Which of the following did the employee violate?

A. MOU
B. AUP
C. NDA
D. MOA
Show Answer
Correct Answer: B
Explanation:
An Acceptable Use Policy (AUP) defines the rules for appropriate use of an organization's systems, networks, internet access, and other IT resources. Accessing an unauthorized website violates the AUP. An MOU (Memorandum of Understanding) and MOA (Memorandum of Agreement) define relationships or agreements between parties, while an NDA (Non-Disclosure Agreement) concerns confidentiality, not acceptable system use.

Question 152

A malicious actor is trying to access sensitive financial information from a company's database by intercepting and reusing log-in credentials. Which of the following attacks is the malicious actor attempting?

A. SQL injection
B. On-path
C. Brute-force
D. Password spraying
Show Answer
Correct Answer: B
Explanation:
The key indicators are that the attacker is intercepting communications and then reusing captured login credentials. That describes an on-path (formerly man-in-the-middle) attack. SQL injection targets databases through unsanitized queries, brute-force attempts many password guesses, and password spraying tries a small set of common passwords across many accounts rather than intercepting valid credentials.

Question 153

A company is performing a risk assessment on new software the company plans to use. Which of the following should the company assess during this process?

A. Software vulnerabilities
B. Cost-benefit analysis
C. Ongoing monitoring strategies
D. Network infrastructure compatibility
Show Answer
Correct Answer: A
Explanation:
A risk assessment for new software focuses on identifying and evaluating risks associated with adopting the software, including known and potential software vulnerabilities that could affect confidentiality, integrity, or availability. While cost-benefit analysis, ongoing monitoring, and compatibility may be part of broader evaluation or implementation planning, they are not the primary focus of a security risk assessment.

Question 154

Which of the following describes the procedures a penetration tester must follow while conducting a test?

A. Rules of engagement
B. Rules of acceptance
C. Rules of understanding
D. Rules of execution
Show Answer
Correct Answer: A
Explanation:
The correct answer is A. Rules of Engagement (RoE) define the scope, procedures, constraints, communication methods, authorized targets, timing, and actions a penetration tester must follow during an engagement. They ensure the test is conducted within agreed legal, ethical, and operational boundaries.

Question 155

Which of the following describes the most effective way to address OS vulnerabilities after they are identified?

A. Endpoint protection
B. Removal of unnecessary software
C. Configuration enforcement
D. Patching
Show Answer
Correct Answer: D
Explanation:
Patching is the primary and most effective remediation for identified operating system vulnerabilities because it applies vendor-provided fixes that remove or mitigate the underlying security flaw. Endpoint protection, removing unnecessary software, and configuration enforcement improve security posture but do not generally remediate the specific OS vulnerability itself.

Question 156

A security administrator is addressing an issue with a legacy system that communicates data using an unencrypted protocol to transfer sensitive data to a third party. No software updates that use an encrypted protocol are available, so a compensating control is needed. Which of the following are the most appropriate for the administrator to suggest? (Choose two.)

A. Tokenization
B. Cryptographic downgrade
C. SSH tunneling
D. Segmentation
E. Patch installation
F. Data masking
Show Answer
Correct Answer: C, D
Explanation:
SSH tunneling provides an encrypted channel for the legacy application's otherwise unencrypted protocol, protecting sensitive data in transit without modifying the application. Network segmentation is a compensating control that isolates the legacy system and restricts its communications, reducing exposure and attack surface. Tokenization changes how applications handle sensitive data and is not the most appropriate network compensating control for a legacy protocol; cryptographic downgrade weakens security, patch installation is unavailable, and data masking is intended for obscuring displayed or test data rather than securing transmission.

Question 157

Which of the following types of identification methods can be performed on a deployed application during runtime?

A. Dynamic analysis
B. Code review
C. Package monitoring
D. Bug bounty
Show Answer
Correct Answer: A
Explanation:
Dynamic analysis is performed against a running application, making it suitable for identifying issues during runtime in a deployed environment. Code review is a static pre-deployment activity, package monitoring focuses on dependencies rather than runtime application analysis, and bug bounty programs are a testing program rather than a specific runtime identification method.

Question 158

An administrator wants to automate an account permissions update for a large number of accounts. Which of the following would best accomplish this task?

A. Security groups
B. Federation
C. User provisioning
D. Vertical scaling
Show Answer
Correct Answer: A
Explanation:
Security groups are the best fit for updating permissions across a large number of existing accounts. Permissions are assigned to the group, and changes to the group's permissions automatically apply to all members, avoiding individual account updates. User provisioning focuses on the lifecycle of accounts (creation, modification, and deprovisioning), but for bulk permission management on existing users, security groups are the standard solution.

Question 159

Which of the following testing techniques uses both defensive and offensive testing methodologies with developers to securely build key applications and software?

A. Blue
B. Yellow
C. Red
D. Green
Show Answer
Correct Answer: B
Explanation:
The Yellow Team bridges developers with security by combining offensive (red team) and defensive (blue team) practices to build more secure applications throughout the software development lifecycle. Red is primarily offensive testing, Blue is defensive operations, and Green is not the team that fulfills this combined developer-focused role.

Question 160

The management team reports that employees are missing features on company-provided tablets, which is causing productivity issues. The management team directs the IT team to resolve the issue within 48 hours. Which of the following would be the best solution for the IT team to leverage in this scenario?

A. EDR
B. COPE
C. MDM
D. FDE
Show Answer
Correct Answer: C
Explanation:
MDM (Mobile Device Management) is the best solution because it enables IT administrators to remotely manage, configure, update, and deploy applications and features to company-provided tablets. This allows the missing features to be restored quickly across devices within the required timeframe. EDR focuses on threat detection and response, COPE is a device ownership/deployment model rather than a management tool, and FDE provides storage encryption rather than feature deployment.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.