Comptia

SY0-701 Free Practice Questions — Page 2

Question 11

Which of the following should an organization use to ensure that it can review the controls and performance of a service provider or vendor?

A. Service-level agreement
B. Memorandum of agreement
C. Right-to-audit clause
D. Supply chain analysis
Show Answer
Correct Answer: C
Explanation:
A right-to-audit clause contractually grants the organization the ability to inspect, review, and verify a service provider’s controls, compliance, and performance. An SLA defines service expectations, a memorandum of agreement outlines general cooperation terms, and supply chain analysis assesses risk but does not itself grant review rights.

Question 12

An unexpected and out-of-character email message from a Chief Executive Officer's corporate account asked an employee to provide financial information and to change the recipient's contact number. Which of the following attack vectors is most likely being used?

A. Business email compromise
B. Phishing
C. Brand impersonation
D. Pretexting
Show Answer
Correct Answer: A
Explanation:
The scenario describes an unexpected, out-of-character message appearing to come from the CEO’s corporate email account and requesting financial information and changes to contact details. This is characteristic of a Business Email Compromise (BEC) attack, where attackers compromise or convincingly spoof an executive’s email to manipulate employees into disclosing sensitive financial data or redirecting payments.

Question 13

An employee receives a text message from an unrecognized number claiming to be the Chief Executive Officer and asking the employee to purchase gift cards. Which of the following types of attacks describes this example?

A. Watering-hole
B. Disinformation
C. Phishing
D. Impersonation
Show Answer
Correct Answer: D
Explanation:
The attacker pretends to be the CEO to deceive an employee into buying gift cards. This is an impersonation (executive impersonation/CEO fraud) social engineering attack. While it may be delivered via text, the defining characteristic is impersonating a trusted authority, not watering-hole or disinformation.

Question 14

Which of the following phases of the incident response process attempts to minimize disruption?

A. Recovery
B. Containment
C. Preparation
D. Analysis
Show Answer
Correct Answer: B
Explanation:
The Containment phase focuses on limiting the scope and impact of an incident by isolating affected systems and stopping further spread. This directly minimizes disruption to business operations. Recovery restores systems after the incident, Preparation occurs before any incident, and Analysis investigates causes and impact rather than reducing immediate disruption.

Question 15

Which of the following should be used to ensure a user has the permissions needed to effectively do an assigned job role?

A. Changing default passwords
B. Implementing least privilege
C. Enforcing baseline configurations
D. Applying network segmentation
Show Answer
Correct Answer: B
Explanation:
Implementing the principle of least privilege ensures that users are granted only the permissions necessary to perform their assigned job roles. This directly aligns access rights with job responsibilities, enabling effective work while minimizing unnecessary or excessive permissions that could introduce security risks.

Question 16

A security analyst receives an alert that there was an attempt to download known malware. Which of the following actions would allow the best chance to analyze the malware?

A. Review the IPS logs and determine which command-and-control IPs were blocked.
B. Analyze application logs to see how the malware attempted to maintain persistence.
C. Run vulnerability scans to check for systems and applications that are vulnerable to the malware
D. Obtain and execute the malware in a sandbox environment and perform packet captures.
Show Answer
Correct Answer: D
Explanation:
Executing the malware in a sandbox provides the best opportunity for direct malware analysis. A sandbox is an isolated environment that allows safe dynamic analysis of the sample, enabling the analyst to observe runtime behavior, persistence mechanisms, file and registry changes, and network communications through packet captures. This yields actionable indicators of compromise and a deeper understanding of the malware, which the other options do not provide.

Question 17

Which of the following is the first step to secure a newly deployed server?

A. Close unnecessary service ports.
B. Update the current version of the software.
C. Add the device to the ACL.
D. Upgrade the OS version.
Show Answer
Correct Answer: B
Explanation:
The first step in securing a newly deployed server is to bring it to a known secure baseline by applying all available updates and security patches. Newly deployed systems often ship with outdated software containing known vulnerabilities. Updating the current software immediately mitigates these risks. Closing ports, configuring ACLs, or upgrading the OS are important follow-up steps, but they should be done after ensuring the system itself is fully patched and protected against known exploits.

Question 18

During a recent log review, an analyst discovers evidence of successful injection attacks. Which of the following will best address this issue?

A. Authentication
B. Secure cookies
C. Static code analysis
D. Input validation
Show Answer
Correct Answer: D
Explanation:
Injection attacks succeed when untrusted input is not properly handled and is interpreted as commands or code by an application. Input validation directly addresses the root cause by ensuring that all user-supplied data is checked, sanitized, and constrained before processing. Authentication, secure cookies, and static code analysis are valuable controls, but they do not directly prevent malicious input from being injected at runtime.

Question 19

Which of the following would most likely be a hacktivist's motive?

A. Financial gain
B. Espionage
C. Philosophical beliefs
D. Revenge
Show Answer
Correct Answer: C
Explanation:
Hacktivists are primarily motivated by ideological, political, or social causes. Their actions aim to promote, defend, or protest philosophical beliefs rather than to gain money, conduct espionage, or seek personal revenge.

Question 20

The physical security team at a company receives reports that employees are not displaying their badges. The team also observes employees tailgating at controlled entrances. Which of the following topics will the security team most likely emphasize in upcoming security training?

A. Social engineering
B. Situational awareness
C. Phishing
D. Acceptable use policy
Show Answer
Correct Answer: B
Explanation:
The issues described—employees not displaying badges and allowing tailgating—indicate a lack of attention to physical security practices and surroundings. Situational awareness training focuses on being alert to one’s environment, recognizing unauthorized access attempts, properly displaying badges, and challenging or reporting tailgaters. While tailgating can be a social engineering tactic, the primary problem here is employee complacency, best addressed through situational awareness.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.