Comptia

SY0-701 Free Practice Questions — Page 20

Question 193

Which of the following tools is best for logging and monitoring in a cloud environment?

A. IPS
B. FIM
C. NAC
D. SIEM
Show Answer
Correct Answer: D
Explanation:
SIEM platforms are specifically designed to aggregate, correlate, and analyze logs and security events from multiple sources, making them the most suitable tool for centralized logging and continuous monitoring in cloud environments.

Question 194

When trying to access an internal website, an employee reports that a prompt displays, stating that the site is insecure. Which of the following certificate types is the site most likely using?

A. Wildcard
B. Root of trust
C. Third-party
D. Self-signed
Show Answer
Correct Answer: D
Explanation:
Browsers warn that a site is insecure when they cannot validate the site's SSL/TLS certificate against a trusted Certificate Authority. Internal websites commonly use self-signed certificates, which are not trusted by default, triggering such warnings. Wildcard, root of trust, and third-party certificates are typically trusted when properly configured.

Question 195

An audit reveals that cardholder database logs are exposing account numbers inappropriately. Which of the following mechanisms would help limit the impact of this error?

A. Segmentation
B. Hashing
C. Journaling
D. Masking
Show Answer
Correct Answer: D
Explanation:
Masking obscures sensitive portions of account numbers (for example, showing only the last few digits) when data is logged or displayed. This directly limits the impact of logs exposing cardholder data by preventing full account numbers from being readable. Segmentation, hashing, and journaling do not address exposure in logs as effectively.

Question 196

A systems administrator successfully configures VPN access to a cloud environment. Which of the following capabilities should the administrator use to best facilitate remote administration?

A. A jump host in the shared services security zone
B. An SSH server within the corporate LAN
C. A reverse proxy on the firewall
D. An MDM solution with conditional access
Show Answer
Correct Answer: A
Explanation:
After VPN connectivity is established, the best practice for remote administration of a cloud environment is to use a jump host (bastion host) placed in a shared services or security zone. Administrators authenticate to this hardened, tightly monitored system and then access internal cloud resources from there. This minimizes the attack surface, centralizes logging and access control, and aligns with cloud security architecture patterns. The other options do not primarily facilitate secure administrative access to cloud resources.

Question 197

An organization is required to provide assurance that its controls are properly designed and operating effectively. Which of the following reports will best achieve the objective?

A. Red teaming
B. Penetration testing
C. Independent audit
D. Vulnerability assessment
Show Answer
Correct Answer: C
Explanation:
An independent audit provides formal assurance that controls are appropriately designed and operating effectively, typically through objective testing by qualified third parties. The other options focus on identifying technical weaknesses rather than providing comprehensive assurance over control design and effectiveness.

Question 198

A malicious insider from the marketing team alters records and transfers company funds to a personal account. Which of the following methods would be the best way to secure company records in the future?

A. Permission restrictions
B. Hashing
C. Input validation
D. Access control list
Show Answer
Correct Answer: D
Explanation:
The core issue is an insider having excessive privileges. The most effective control is enforcing least privilege through an Access Control List (ACL), which explicitly defines which users or groups can read, modify, or transfer sensitive records. Hashing only detects changes after the fact, and input validation addresses malformed input rather than unauthorized actions. "Permission restrictions" is a vague concept, whereas ACLs are the concrete, standard mechanism used to implement those restrictions.

Question 199

Which of the following definitions best describes the concept of log correlation?

A. Combining relevant logs from multiple sources into one location
B. Searching and processing data to identify patterns of malicious activity
C. Making a record of the events that occur in the system
D. Analyzing the log files of the system components
Show Answer
Correct Answer: B
Explanation:
Log correlation refers to analyzing and relating events across logs—often from multiple systems—to identify meaningful patterns, relationships, or indicators of malicious or abnormal activity. Option A describes log aggregation (collecting logs in one place), while C and D describe logging or basic log analysis rather than correlating events.

Question 200

A network administrator wants to ensure that network traffic is highly secure while in transit. Which of the following actions best describes the actions the network administrator should take?

A. Ensure that NAC is enforced on all network segments, and confirm that firewalls have updated policies to block unauthorized traffic.
B. Ensure only TLS and other encrypted protocols are selected for use on the network, and only permit authorized traffic via secure protocols.
C. Configure the perimeter IPS to block inbound HTTPS directory traversal traffic, and verify that signatures are updated on a daily basis.
D. Ensure the EDR software monitors for unauthorized applications that could be used by threat actors, and configure alerts for the security team.
Show Answer
Correct Answer: B
Explanation:
The question focuses on securing network traffic while it is in transit. The most effective control for this is encryption. Ensuring that TLS and other encrypted protocols are used protects data from eavesdropping and tampering as it traverses the network. The other options focus on access control, intrusion prevention, or endpoint protection, which are important security measures but do not directly ensure confidentiality and integrity of data in transit.

Question 201

Which of the following threat actors would most likely deface the website of a high-profile music group?

A. Unskilled attacker
B. Organized crime
C. Nation-state
D. Insider threat
Show Answer
Correct Answer: A
Explanation:
Website defacement of a high-profile music group is most commonly associated with unskilled attackers (often called script kiddies) seeking notoriety or attention using readily available tools. Organized crime typically targets financial gain, nation-states focus on espionage or strategic objectives, and insider threats involve misuse of internal access, which is less likely in this scenario.

Question 202

A legal department must maintain a backup from all devices that have been shredded and recycled by a third party. Which of the following best describes this requirement?

A. Data retention
B. Certification
C. Sanitization
D. Destruction
Show Answer
Correct Answer: A
Explanation:
The key requirement is to **maintain a backup** of data even after the physical devices have been shredded and recycled. Maintaining copies of data for legal, regulatory, or business purposes is the definition of **data retention**. Certification would be proof of destruction, while sanitization and destruction describe how data is removed, not the obligation to keep a backup.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.