Comptia

SY0-701 Free Practice Questions — Page 21

Question 201

An employee emailed a new systems administrator a malicious web link and convinced the administrator to change the email server’s password. The employee used this access to remove the mailboxes of key personnel. Which of the following security awareness concepts would help prevent this threat in the future?

A. Recognizing phishing
B. Providing situational awareness training
C. Using password management
D. Reviewing email policies
Show Answer
Correct Answer: B
Explanation:
The attack relied on social engineering to convince a systems administrator to perform a sensitive action (changing the email server password), which then enabled an insider to abuse access. Situational awareness training teaches personnel to recognize manipulation, verify unusual requests, and consider the security implications before making privileged changes. While recognizing phishing is valuable, the key failure was being persuaded into an unauthorized administrative action rather than simply identifying a malicious email. Sources: https://www.mycenturybank.com/security-resources

Question 202

An administrator is installing an SSL certificate on a new system. During testing, errors indicate that the certificate is not trusted. The administrator has verified with the issuing CA and has validated the private key. Which of the following should the administrator check for next?

A. If the wildcard certificate is configured
B. If the certificate signing request is valid
C. If the root certificate is installed
D. If the public key is configured
Show Answer
Correct Answer: C
Explanation:
A certificate trust error after verifying the issuing CA and private key most commonly indicates that the trust chain cannot be validated. The next thing to check is whether the root CA certificate (and, in practice, any required intermediate certificates) is installed in the trusted certificate store. A wildcard certificate is unrelated to trust, the CSR is only used during certificate issuance, and the public key is contained in the certificate itself.

Question 203

Several customers want an organization to verify its security controls are operating effectively and have requested an independent opinion. Which of the following is the most efficient way to address these requests?

A. Hire a vendor to perform a penetration test
B. Perform an annual self-assessment.
C. Allow each client the right to audit
D. Provide a third-party attestation report
Show Answer
Correct Answer: D
Explanation:
A third-party attestation report (such as a SOC 2 report) provides an independent assessment of the effectiveness of an organization's security controls and can be shared with many customers, making it the most efficient way to satisfy multiple requests. A penetration test is narrower in scope, a self-assessment lacks independent assurance, and allowing each client to audit is the least efficient approach.

Question 204

A security manager created new documentation to use in response to various types of security incidents. Which of the following is the next step the manager should take?

A. Set the maximum data retention policy.
B. Securely store the documents on an air-gapped network.
C. Review the documents’ data classification policy.
D. Conduct a tabletop exercise with the team.
Show Answer
Correct Answer: D
Explanation:
After creating incident response documentation, the next step is to validate and socialize it through testing. A tabletop exercise allows the team to walk through incident scenarios, verify roles and procedures, and identify gaps before a real incident. The other options are unrelated or secondary: data retention and classification concern information governance, and storing documents on an air-gapped network is not standard practice for incident response documentation, which must be accessible during an incident.

Question 205

A company is redesigning its infrastructure and wants to reduce the number of physical servers in use. Which of the following architectures is best suited for this goal?

A. Isolation
B. Segmentation
C. Virtualization
D. Redundancy
Show Answer
Correct Answer: C
Explanation:
Virtualization enables multiple virtual machines to run on a single physical host, consolidating workloads and reducing the number of physical servers required while improving hardware utilization. Isolation, segmentation, and redundancy serve different infrastructure or security purposes and do not primarily reduce physical server count.

Question 206

For which of the following reasons would a systems administrator leverage a 3DES hash from an installer file that is posted on a vendor’s website?

A. To test the integrity of the file
B. To validate the authenticity of the file
C. To activate the license for the file
D. To calculate the checksum of the file
Show Answer
Correct Answer: A
Explanation:
The intended purpose of a vendor-posted hash is to verify file integrity by comparing the hash of the downloaded file to the published value. If they match, the file has not been altered or corrupted in transit. The question incorrectly refers to a '3DES hash'; 3DES is a symmetric encryption algorithm, not a hash function, but the expected exam answer is integrity verification.

Question 207

The security team has been asked to only enable host A (10.2.2.7) and host B (10.3.9.9) to the new isolated network segment (10.9.8.14) that provides access to legacy devices. Access from all other hosts should be blocked. Which of the following entries would need to be added on the firewall?

A.
B.
C.
D.
Show Answer
Correct Answer: C
Explanation:
To permit only two specific source hosts to access a single destination host, the firewall entries must match the individual source IP addresses using /32 host masks and the destination host as a /32 as well. The correct option is the one that creates allow rules for 10.2.2.7/32 and 10.3.9.9/32 to 10.9.8.14/32, with all other traffic implicitly or explicitly denied.

Question 208

A company wants to improve the availability of its application with a solution that requires minimal effort in the event a server needs to be replaced or added. Which of the following would be the best solution to meet these objectives?

A. Load balancing
B. Fault tolerance
C. Proxy servers
D. Replication
Show Answer
Correct Answer: A
Explanation:
Load balancing is the best fit because it improves application availability by distributing traffic across multiple servers and automatically routing requests away from failed or removed servers. It also makes adding or replacing servers straightforward with minimal operational effort. Fault tolerance is a broader design goal rather than a specific solution here, proxy servers do not primarily provide high availability, and replication focuses on copying data rather than transparently handling application server replacement or scaling.

Question 209

A company is in the process of migrating to cloud-based services. The company’s IT department has limited resources for migration and ongoing support. Which of the following best meets the company’s needs?

A. IPS
B. WAF
C. SASE
D. IAM
Show Answer
Correct Answer: C
Explanation:
SASE (Secure Access Service Edge) is designed for cloud-first environments and delivers networking and security as a cloud-managed service. For an organization migrating to cloud services with limited IT resources, it reduces deployment and operational overhead by consolidating multiple security functions into a managed, scalable platform. IPS, WAF, and IAM each address narrower security needs and do not provide the same comprehensive, low-maintenance cloud security architecture.

Question 210

Which of the following elements of digital forensics should a company use if it needs to ensure the integrity of evidence?

A. Preservation
B. E-discovery
C. Acquisition
D. Containment
Show Answer
Correct Answer: A
Explanation:
Preservation is the digital forensics phase focused on maintaining the integrity of evidence by preventing alteration, documenting chain of custody, and ensuring evidence remains admissible. Acquisition is the collection of evidence, e-discovery is the legal process of identifying and producing electronically stored information, and containment is an incident response activity.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.