Comptia

SY0-701 Free Practice Questions — Page 23

Question 221

A new security regulation was announced that will take effect in the coming year. A company must comply with it to remain in business. Which of the following activities should the company perform next?

A. Gap analysis
B. Policy review
C. Security procedure evaluation
D. Threat scope reduction
Show Answer
Correct Answer: A
Explanation:
A gap analysis is the appropriate next step after a new regulation is announced because it compares the organization's current controls, processes, and compliance posture against the new regulatory requirements. This identifies deficiencies that must be addressed before updating policies, procedures, or implementing remediation. Policy reviews and procedure evaluations may follow based on the identified gaps, while threat scope reduction is not the primary compliance activity.

Question 222

Which of the following strategies should an organization use to efficiently manage and analyze multiple types of logs?

A. Deploy a SIEM solution
B. Create custom scripts to aggregate and analyze logs.
C. Implement EDR technology.
D. Install a unified threat management appliance.
Show Answer
Correct Answer: A
Explanation:
A SIEM (Security Information and Event Management) solution is purpose-built to collect, normalize, correlate, store, and analyze logs from many different sources efficiently. Custom scripts are less scalable and harder to maintain, EDR focuses on endpoint detection and response rather than centralized multi-source log management, and a UTM appliance consolidates security functions but is not designed for enterprise-wide log aggregation and analysis across diverse systems.

Question 223

A company suffered a critical incident where 30GB of data was exfiltrated from the corporate network. Which of the following actions is the most efficient way to identify where the system data was exfiltrated from and what location the attacker sent the data to?

A. Analyze firewall and network logs for large amounts of outbound traffic to external IP addresses or domains.
B. Analyze IPS and IDS logs to find the IP addresses used by the attacker for reconnaissance scans.
C. Analyze endpoint and application logs to see whether file-sharing programs were running on the company systems.
D. Analyze external vulnerability scans and automated reports to identify the systems the attacker could have exploited a remote code vulnerability.
Show Answer
Correct Answer: A
Explanation:
Firewall and network logs are the most efficient source for identifying large outbound data transfers, the internal host that initiated the transfer, and the external IP address or domain that received the data. IDS/IPS logs focus on detection events rather than complete exfiltration paths, endpoint logs may show applications but not the network destination, and vulnerability scan reports do not identify actual exfiltration activity.

Question 224

A group of developers has a shared backup account to access the source code repository. Which of the following is best way to secure the backup account if there is an SSO failure?

A. RAS
B. EAP
C. SAML
D. PAM
Show Answer
Correct Answer: D
Explanation:
Privileged Access Management (PAM) is designed to secure and control privileged or shared accounts through credential vaulting, access approval, auditing, session monitoring, and credential rotation. For a shared backup account used when SSO is unavailable, PAM is the appropriate control. RAS provides remote access, EAP is a network authentication framework, and SAML is an SSO/federation protocol rather than a mechanism for securing a shared fallback account.

Question 225

An organization's web servers host an online ordering system. The organization discovers that the servers are vulnerable to a malicious JavaScript injection, which could allow attackers to access customer payment information. Which of the following mitigation strategies would be most effective for preventing an attack on the organization's web servers? (Choose two.)

A. Regularly updating server software and patches
B. Implementing strong password policies
C. Encrypting sensitive data at rest and in transit
D. Utilizing a web-application firewall
E. Performing regular vulnerability scans
F. Removing payment information from the servers
Show Answer
Correct Answer: A, D
Explanation:
Regularly updating server software and applying patches addresses known vulnerabilities that could be exploited for JavaScript injection. A web application firewall (WAF) provides runtime protection by detecting and blocking malicious requests, including many injection and cross-site scripting attacks. Other options improve security posture or reduce impact but do not most effectively prevent exploitation of the vulnerable web application.

Question 226

Which of the following security concepts is being followed when implementing a product that offers protection against DDoS attacks?

A. Availability
B. Non-repudiation
C. Integrity
D. Confidentiality
Show Answer
Correct Answer: A
Explanation:
DDoS attacks are designed to overwhelm a service and prevent legitimate users from accessing it. Implementing DDoS protection helps ensure systems and services remain accessible, which is the security principle of availability. Non-repudiation concerns proof of actions, integrity protects against unauthorized modification, and confidentiality protects against unauthorized disclosure.

Question 227

Which of the following is the best way to securely store an encryption key for a data set in a manner that allows multiple entities to access the key when needed?

A. Public key infrastructure
B. Open public ledger
C. Public key encryption
D. Key escrow
Show Answer
Correct Answer: D
Explanation:
Key escrow is specifically designed to securely store encryption keys with a trusted repository or service so that authorized multiple entities can retrieve the key when needed. The other options involve key management or encryption concepts but are not mechanisms for shared secure key storage.

Question 228

Which of the following should an organization use to protect its environment from external attacks conducted by an unauthorized hacker?

A. ACL
B. IDS
C. HIDS
D. NIPS
Show Answer
Correct Answer: D
Explanation:
A Network Intrusion Prevention System (NIPS) monitors network traffic inline and can detect and actively block malicious traffic from external attackers before it reaches internal systems. An ACL provides filtering rules but is not a comprehensive intrusion prevention solution. An IDS/HIDS detects suspicious activity but does not prevent attacks; HIDS is also limited to individual hosts.

Question 229

An organization maintains intellectual property that it wants to protect. Which of the following concepts would be most beneficial to add to the company’s security awareness training program?

A. Insider threat detection
B. Simulated threats
C. Phishing awareness
D. Business continuity planning
Show Answer
Correct Answer: A
Explanation:
Protecting intellectual property is strongly tied to reducing the risk of theft or misuse by people who already have authorized access. Including insider threat detection in security awareness training helps employees recognize suspicious behaviors, understand proper handling of sensitive information, and report potential insider risks. Phishing awareness is valuable generally, but the question specifically emphasizes protecting intellectual property, making insider threat awareness the most directly applicable choice.

Question 230

A systems administrator needs to ensure the secure communication of sensitive data within the organization’s private cloud. Which of the following is the best choice for the administrator to implement?

A. IPSec
B. SHA-1
C. RSA
D. TGT
Show Answer
Correct Answer: A
Explanation:
IPSec is the appropriate choice because it is a suite of protocols that provides encryption, integrity protection, and authentication for IP communications, making it well suited to securing sensitive data in transit within a private cloud. SHA-1 is a hash function (and deprecated for security), RSA is a public-key cryptographic algorithm rather than a complete communication security protocol, and a TGT is a Kerberos authentication ticket, not a mechanism for securing network traffic.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.