Comptia

SY0-701 Free Practice Questions — Page 22

Question 213

A security analyst is reviewing logs to identify the destination of command-and-control traffic originating from a compromised device within the on-premises network. Which of the following is the best log to review?

A. IDS
B. Antivirus
C. Firewall
D. Application
Show Answer
Correct Answer: C
Explanation:
Firewall logs are the best source for identifying the destination of command-and-control traffic because they record network-level connections, including source and destination IP addresses, ports, and protocols for outbound and inbound traffic. This visibility allows analysts to see where a compromised internal host is communicating externally. IDS focuses on detecting suspicious patterns, antivirus focuses on malware on endpoints, and application logs do not provide comprehensive network destination details.

Question 214

A customer of a large company receives a phone call from someone claiming to work for the company and asking for the customer’s credit card information. The customer sees the caller ID is the same as the company's main phone number. Which of the following attacks is the customer most likely a target of?

A. Phishing
B. Whaling
C. Smishing
D. Vishing
Show Answer
Correct Answer: D
Explanation:
The attack is conducted via a phone call where the attacker impersonates a legitimate company representative and attempts to obtain credit card information. This is voice-based social engineering, known as vishing (voice phishing). The spoofed caller ID reinforces the deception but does not change the attack category.

Question 215

Which of the following enables the ability to receive a consolidated report from different devices on the network?

A. IPS
B. DLP
C. SIEM
D. Firewall
Show Answer
Correct Answer: C
Explanation:
A SIEM (Security Information and Event Management) system aggregates, correlates, and reports on log and event data collected from multiple devices across the network (e.g., firewalls, servers, IDS/IPS). This enables centralized monitoring and consolidated reporting, which the other options do not provide as their primary function.

Question 216

Which of the following best describes the concept of information being stored outside of its country of origin while still being subject to the laws and requirements of the country of origin?

A. Data sovereignty
B. Geolocation
C. Intellectual property
D. Geographic restrictions
Show Answer
Correct Answer: A
Explanation:
The concept described is data sovereignty, which means that data remains subject to the laws and regulatory requirements of its country of origin even when it is stored or processed in another country. The other options do not address legal jurisdiction over data stored abroad.

Question 217

Which of the following is the primary purpose of a service that tracks log-ins and time spent using the service?

A. Availability
B. Accounting
C. Authentication
D. Authorization
Show Answer
Correct Answer: B
Explanation:
Tracking log-ins and time spent using a service is the function of accounting, which records and audits user activity and resource usage. Authentication verifies identity, authorization controls permissions, and availability concerns uptime.

Question 218

A company that has a large IT operation is looking to better control, standardize, and lower the time required to build new servers. Which of the following architectures will best achieve the company’s objectives?

A. IoT
B. IaC
C. IaaS
D. ICS
Show Answer
Correct Answer: B
Explanation:
The company wants better control, standardization, and faster server builds. Infrastructure as Code (IaC) achieves this by defining server infrastructure through code and automation, enabling consistent, repeatable, and rapid provisioning across a large IT environment. IaaS provides resources but does not inherently standardize or automate builds, while IoT and ICS are unrelated to server provisioning.

Question 219

After a security incident, a systems administrator asks the company to buy a NAC platform. Which of the following attack surfaces is the systems administrator trying to protect?

A. Bluetooth
B. Wired
C. NFC
D. SCADA
Show Answer
Correct Answer: B
Explanation:
A Network Access Control (NAC) platform enforces security policies on devices before they are allowed onto the network, most commonly controlling access to the wired network infrastructure (and often wireless as well). Among the options given, the relevant attack surface is the wired network.

Question 220

Which of the following architectures is most suitable to provide redundancy for critical business processes?

A. Network-enabled
B. Server-side
C. Cloud-native
D. Multitenant
Show Answer
Correct Answer: C
Explanation:
Cloud-native architectures are specifically designed for high availability and redundancy through distributed services, microservices, container orchestration, automated failover, load balancing, and use of multiple availability zones or regions. These features directly support continuity of critical business processes. Network-enabled and server-side describe deployment or processing location, not redundancy, and multitenant focuses on resource sharing across customers rather than ensuring redundancy for a single organization’s critical processes.

Question 221

Which of the following data states applies to data that is being actively processed by a database server?

A. In use
B. At rest
C. In transit
D. Being hashed
Show Answer
Correct Answer: A
Explanation:
Data that is actively processed by a database server—such as during queries, updates, or computations—is considered data "in use." "At rest" is stored data, "in transit" is data moving across networks, and "being hashed" is a security operation rather than a data state.

Question 222

An accountant is transferring information to a bank over FTP. Which of the following mitigations should the accountant use to protect the confidentiality of the data?

A. Tokenization
B. Data masking
C. Encryption
D. Obfuscation
Show Answer
Correct Answer: C
Explanation:
FTP transmits data in cleartext, so protecting confidentiality during transfer requires encrypting the data (or using an encrypted variant such as FTPS/SFTP). Encryption ensures intercepted traffic cannot be read. Tokenization, data masking, and obfuscation are mainly used for data at rest or display and do not secure data in transit.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.