Comptia

SY0-701 Free Practice Questions — Page 21

Question 203

An employee emailed a new systems administrator a malicious web link and convinced the administrator to change the email server’s password. The employee used this access to remove the mailboxes of key personnel. Which of the following security awareness concepts would help prevent this threat in the future?

A. Recognizing phishing
B. Providing situational awareness training
C. Using password management
D. Reviewing email policies
Show Answer
Correct Answer: A
Explanation:
The scenario describes a social engineering/phishing attack: a malicious link and deception were used to trick an administrator into changing a critical password. Training focused on recognizing phishing attempts—such as suspicious links, unexpected requests, and verification of credential changes—would directly help prevent this. Situational awareness is broader, but phishing recognition most precisely addresses the threat.

Question 204

An administrator is installing an SSL certificate on a new system. During testing, errors indicate that the certificate is not trusted. The administrator has verified with the issuing CA and has validated the private key. Which of the following should the administrator check for next?

A. If the wildcard certificate is configured
B. If the certificate signing request is valid
C. If the root certificate is installed
D. If the public key is configured
Show Answer
Correct Answer: C
Explanation:
A certificate being reported as "not trusted" most commonly indicates a missing trust chain. Even if the private key and CA issuance are valid, the system must have the issuing CA’s root certificate (and any required intermediate certificates) installed in its trusted store. Without the root certificate, the SSL/TLS certificate cannot be validated as trusted.

Question 205

Several customers want an organization to verify its security controls are operating effectively and have requested an independent opinion. Which of the following is the most efficient way to address these requests?

A. Hire a vendor to perform a penetration test
B. Perform an annual self-assessment.
C. Allow each client the right to audit
D. Provide a third-party attestation report
Show Answer
Correct Answer: D
Explanation:
Providing a third-party attestation report (such as a SOC 2 or ISO 27001 report) is the most efficient way to address multiple customer requests for assurance. It offers an independent, credible evaluation of security controls that can be shared with all customers, avoiding the cost and disruption of multiple client audits, penetration tests, or less-credible self-assessments.

Question 206

A security manager created new documentation to use in response to various types of security incidents. Which of the following is the next step the manager should take?

A. Set the maximum data retention policy.
B. Securely store the documents on an air-gapped network.
C. Review the documents’ data classification policy.
D. Conduct a tabletop exercise with the team.
Show Answer
Correct Answer: D
Explanation:
After creating incident response documentation, the next step is to validate and operationalize it. Conducting a tabletop exercise tests the procedures, ensures team understanding of roles, and identifies gaps before a real incident occurs.

Question 207

A company is redesigning its infrastructure and wants to reduce the number of physical servers in use. Which of the following architectures is best suited for this goal?

A. Isolation
B. Segmentation
C. Virtualization
D. Redundancy
Show Answer
Correct Answer: C
Explanation:
Virtualization allows multiple virtual machines to run on a single physical server, consolidating workloads and significantly reducing the number of physical servers required. This improves hardware utilization, lowers costs, and simplifies infrastructure management compared to isolation, segmentation, or redundancy.

Question 208

For which of the following reasons would a systems administrator leverage a 3DES hash from an installer file that is posted on a vendor’s website?

A. To test the integrity of the file
B. To validate the authenticity of the file
C. To activate the license for the file
D. To calculate the checksum of the file
Show Answer
Correct Answer: A
Explanation:
Comparing a hash value provided by the vendor with a locally calculated value allows the administrator to confirm that the installer file has not been altered or corrupted during download, which verifies file integrity. Hashes do not activate licenses or prove authenticity by themselves, and while a hash is technically a checksum, the security purpose here is integrity verification.

Question 209

The security team has been asked to only enable host A (10.2.2.7) and host B (10.3.9.9) to the new isolated network segment (10.9.8.14) that provides access to legacy devices. Access from all other hosts should be blocked. Which of the following entries would need to be added on the firewall?

A.
B.
C.
D.
Show Answer
Correct Answer: C
Explanation:
Only hosts A (10.2.2.7) and B (10.3.9.9) should be permitted to access the isolated segment, with all others denied. Firewall rules must therefore specify each allowed source as a single host, which is done using a /32 subnet mask. Option C correctly uses host-specific (/32) entries to allow only those two IP addresses, while other options would permit broader address ranges.

Question 210

A company wants to improve the availability of its application with a solution that requires minimal effort in the event a server needs to be replaced or added. Which of the following would be the best solution to meet these objectives?

A. Load balancing
B. Fault tolerance
C. Proxy servers
D. Replication
Show Answer
Correct Answer: A
Explanation:
Load balancing best meets the requirement of improving availability with minimal effort when servers are added or replaced. A load balancer automatically distributes traffic across multiple servers and removes failed ones from service, allowing servers to be added or replaced with little to no manual intervention or downtime. Replication focuses on data synchronization rather than traffic management and is not inherently required for application availability in this scenario.

Question 211

A company is in the process of migrating to cloud-based services. The company’s IT department has limited resources for migration and ongoing support. Which of the following best meets the company’s needs?

A. IPS
B. WAF
C. SASE
D. IAM
Show Answer
Correct Answer: C
Explanation:
SASE is a cloud-native, integrated security and networking model that reduces on‑premises infrastructure, simplifies deployment, and minimizes ongoing management. For an organization migrating to the cloud with limited IT resources, SASE offloads much of the security and access complexity to the provider while delivering scalable, centralized protection. The other options (IPS, WAF, IAM) address specific security functions but do not provide the comprehensive, low‑overhead architecture needed for cloud migration.

Question 212

Which of the following elements of digital forensics should a company use if it needs to ensure the integrity of evidence?

A. Preservation
B. E-discovery
C. Acquisition
D. Containment
Show Answer
Correct Answer: A
Explanation:
Preservation focuses on maintaining the integrity of digital evidence by preventing alteration, damage, or loss from the moment it is identified. This includes using write blockers, creating forensic images, and maintaining a proper chain of custody. These actions directly ensure evidence integrity, unlike e-discovery, acquisition, or containment.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.