Comptia

SY0-701 Free Practice Questions — Page 22

Question 211

A security analyst is reviewing logs to identify the destination of command-and-control traffic originating from a compromised device within the on-premises network. Which of the following is the best log to review?

A. IDS
B. Antivirus
C. Firewall
D. Application
Show Answer
Correct Answer: C
Explanation:
Firewall logs are the best source for identifying the destination of command-and-control traffic because they record outbound and inbound connections, including destination IP addresses, ports, protocols, and connection details. IDS logs primarily detect suspicious activity, antivirus logs focus on malware detection on endpoints, and application logs record application events rather than network destinations.

Question 212

A customer of a large company receives a phone call from someone claiming to work for the company and asking for the customer’s credit card information. The customer sees the caller ID is the same as the company's main phone number. Which of the following attacks is the customer most likely a target of?

A. Phishing
B. Whaling
C. Smishing
D. Vishing
Show Answer
Correct Answer: D
Explanation:
This is a vishing (voice phishing) attack because the attacker is using a phone call to impersonate a trusted organization and solicit sensitive financial information. The caller ID matching the company's main number indicates caller ID spoofing, but the overall attack type is vishing.

Question 213

Which of the following enables the ability to receive a consolidated report from different devices on the network?

A. IPS
B. DLP
C. SIEM
D. Firewall
Show Answer
Correct Answer: C
Explanation:
A Security Information and Event Management (SIEM) system collects, aggregates, correlates, and reports security logs and events from multiple network devices and systems, providing a consolidated view. IPS, DLP, and firewalls each serve specific security functions but do not primarily provide consolidated reporting across diverse devices.

Question 214

Which of the following best describes the concept of information being stored outside of its country of origin while still being subject to the laws and requirements of the country of origin?

A. Data sovereignty
B. Geolocation
C. Intellectual property
D. Geographic restrictions
Show Answer
Correct Answer: A
Explanation:
Data sovereignty is the principle that data remains subject to the laws and regulatory requirements of its country of origin even when it is stored or processed in another country. The other options do not describe this legal jurisdiction concept.

Question 215

Which of the following is the primary purpose of a service that tracks log-ins and time spent using the service?

A. Availability
B. Accounting
C. Authentication
D. Authorization
Show Answer
Correct Answer: B
Explanation:
The primary purpose of tracking log-ins, session duration, and resource usage is accounting. In the AAA (Authentication, Authorization, Accounting) model, authentication verifies identity, authorization determines permissions, and accounting records and tracks user activity for auditing, reporting, and billing.

Question 216

A company that has a large IT operation is looking to better control, standardize, and lower the time required to build new servers. Which of the following architectures will best achieve the company’s objectives?

A. IoT
B. IaC
C. IaaS
D. ICS
Show Answer
Correct Answer: B
Explanation:
Infrastructure as Code (IaC) automates the provisioning and configuration of servers using declarative or scripted definitions, enabling consistent, standardized, repeatable deployments while reducing build time and manual effort. IaaS provides infrastructure resources but does not by itself standardize or automate server builds. IoT and ICS are unrelated to server provisioning.

Question 217

After a security incident, a systems administrator asks the company to buy a NAC platform. Which of the following attack surfaces is the systems administrator trying to protect?

A. Bluetooth
B. Wired
C. NFC
D. SCADA
Show Answer
Correct Answer: B
Explanation:
A Network Access Control (NAC) platform enforces access policies for endpoints connecting to the enterprise network, most commonly controlling access on wired (and often wireless) networks using technologies such as 802.1X. Among the options, the attack surface it is intended to protect is the wired network. Bluetooth and NFC are short-range wireless technologies rather than the primary NAC focus, and SCADA is an industrial control environment, not an attack surface addressed by NAC.

Question 218

Which of the following architectures is most suitable to provide redundancy for critical business processes?

A. Network-enabled
B. Server-side
C. Cloud-native
D. Multitenant
Show Answer
Correct Answer: C
Explanation:
Cloud-native architectures are designed for resilience through distributed services, automated failover, scaling, and deployment across multiple availability zones or regions. These characteristics make them the most suitable choice for providing redundancy for critical business processes. Network-enabled and server-side describe where connectivity or processing occurs rather than redundancy, while multitenancy is about sharing infrastructure among customers, not ensuring redundancy for a single organization's workloads.

Question 219

Which of the following data states applies to data that is being actively processed by a database server?

A. In use
B. At rest
C. In transit
D. Being hashed
Show Answer
Correct Answer: A
Explanation:
Data that is actively being processed by a database server is considered data 'in use'. 'At rest' refers to stored data, 'in transit' refers to data moving across a network, and 'being hashed' is a cryptographic operation rather than a data state.

Question 220

An accountant is transferring information to a bank over FTP. Which of the following mitigations should the accountant use to protect the confidentiality of the data?

A. Tokenization
B. Data masking
C. Encryption
D. Obfuscation
Show Answer
Correct Answer: C
Explanation:
Encryption protects the confidentiality of data in transit. Standard FTP transmits data in plaintext, so the appropriate mitigation is to encrypt the data (or use an encrypted variant such as FTPS or SFTP). Tokenization, data masking, and obfuscation do not provide confidentiality for data being transmitted over the network.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.