Comptia

SY0-701 Free Practice Questions — Page 19

Question 181

Which of the following is a possible consequence of a VM escape?

A. Malicious instructions can be inserted into memory and give the attacker elevated permissions.
B. An attacker can access the hypervisor and compromise other VMs.
C. Unencrypted data can be read by a user who is in a separate environment.
D. Users can install software that is not on the manufacturer’s approved list.
Show Answer
Correct Answer: B
Explanation:
A VM escape occurs when code running inside a virtual machine breaks isolation and executes on or gains control over the hypervisor/host. This can allow an attacker to compromise the hypervisor and potentially access or control other virtual machines hosted on it.

Question 182

Which of the following is the best security reason for closing service ports that are not needed?

A. To mitigate risks associated with unencrypted traffic
B. To eliminate false positives from a vulnerability scan
C. To reduce a system's attack surface
D. To improve a system's resource utilization
Show Answer
Correct Answer: C
Explanation:
Closing unnecessary service ports removes potential entry points that attackers can probe or exploit, thereby reducing the system's overall attack surface. While it may have secondary benefits, the primary security reason is minimizing opportunities for attack.

Question 183

A penetration tester finds an unused Ethernet port during an on-site penetration test. Upon plugging a device into the unused port, the penetration tester notices that the machine is assigned an IP address, allowing the tester to enumerate the local network. Which of the following should an administrator implement in order to prevent this situation from happening in the future?

A. Port security
B. Transport Layer Security
C. Proxy server
D. Security zones
Show Answer
Correct Answer: A
Explanation:
Port security on managed switches restricts which devices can connect to a switch port (for example by limiting or binding MAC addresses) and allows administrators to disable or shut down unused ports. This prevents unauthorized devices from plugging into an unused Ethernet jack and obtaining network access. TLS secures communications, a proxy server intermediates traffic, and security zones segment networks but do not stop physical port access.

Question 184

Which of the following best describe the benefits of a microservices architecture when compared to a monolithic architecture? (Choose two.)

A. Easier debugging of the system
B. Reduced cost of ownership of the system
C. Improved scalability of the system
D. Increased compartmentalization of the system
E. Stronger authentication of the system
F. Reduced complexity of the system
Show Answer
Correct Answer: C, D
Explanation:
Microservices primarily provide independent scaling of services (improved scalability) and decompose applications into smaller, isolated services (increased compartmentalization/modularity). They generally make distributed debugging more difficult rather than easier, do not inherently reduce total cost of ownership, do not inherently strengthen authentication, and often increase overall system complexity despite reducing per-service complexity.

Question 185

An attacker submits a request containing unexpected characters in an attempt to gain unauthorized access to information within the underlying systems. Which of the following best describes this attack?

A. Side loading
B. Target of evaluation
C. Resource reuse
D. SQL injection
Show Answer
Correct Answer: D
Explanation:
Submitting unexpected characters to manipulate backend queries and gain unauthorized access to underlying data is characteristic of an SQL injection attack. The other options do not describe this type of input-based database attack.

Question 186

A security administrator observed the following in a web server log while investigating an incident: "GET ../../../../etc/passwd" Which of the following attacks did the security administrator most likely see?

A. Privilege escalation
B. Credential replay
C. Brute force
D. Directory traversal
Show Answer
Correct Answer: D
Explanation:
The request path '../../../../etc/passwd' uses repeated '../' sequences to navigate up the directory tree and attempt to access the Unix /etc/passwd file outside the web application's intended directory. This is the classic pattern of a directory traversal (path traversal) attack, not privilege escalation, credential replay, or brute force.

Question 187

Which of the following is a compensating control for providing user access to a high-risk website?

A. Enabling threat prevention features on the firewall
B. Configuring a SIEM tool to capture all web traffic
C. Setting firewall rules to allow traffic from any port to that destination
D. Blocking that website on the endpoint protection software
Show Answer
Correct Answer: A
Explanation:
A compensating control reduces risk when access must still be permitted. If users require access to a high-risk website, enabling threat prevention features on the firewall mitigates the risk by inspecting, filtering, and blocking malicious content while still allowing the necessary access. A SIEM primarily provides detection and logging rather than mitigating the risk directly. Allowing any port weakens security, and blocking the website defeats the requirement to provide access.

Question 188

Which of the following is the main consideration when a legacy system that is a critical part of a company's infrastructure cannot be replaced?

A. Resource provisioning
B. Cost
C. Single point of failure
D. Complexity
Show Answer
Correct Answer: C
Explanation:
When a legacy system is business-critical and cannot be replaced, the primary concern is that it may represent a single point of failure. If that system fails and there is no viable replacement, it can disrupt essential business operations. While cost, complexity, and resource provisioning are important considerations, mitigating the risk of a single point of failure is the key priority.

Question 189

Which of the following can be used to compromise a system that is running an RTOS?

A. Cross-site scripting
B. Memory injection
C. Replay attack
D. Ransomware
Show Answer
Correct Answer: B
Explanation:
Memory injection is a common technique for compromising systems running an RTOS by injecting or modifying code/data in the memory of a running process, potentially gaining code execution or control. Cross-site scripting targets web applications, replay attacks target communication protocols rather than specifically compromising the RTOS itself, and ransomware is not an RTOS-specific compromise technique and is uncommon on typical RTOS deployments.

Question 190

A security analyst wants to better understand the behavior of users and devices in order to gain visibility into potential malicious activities. The analyst needs a control to detect when actions deviate from a common baseline. Which of the following should the analyst use?

A. Intrusion prevention system
B. Sandbox
C. Endpoint detection and response
D. Antivirus
Show Answer
Correct Answer: C
Explanation:
Endpoint detection and response (EDR) is designed to continuously monitor endpoint activity, establish normal behavioral patterns, and detect anomalies or deviations that may indicate malicious activity. An IPS primarily focuses on detecting and blocking network threats using signatures and some anomaly detection, but it is not the primary control for user and device behavior visibility. A sandbox analyzes suspicious files in isolation, and antivirus mainly detects known malware.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.