Comptia

SY0-701 Free Practice Questions — Page 24

Question 231

A company is concerned about theft of client data from decommissioned laptops. Which of the following is the most cost-effective method to decrease this risk?

A. Wiping
B. Recycling
C. Shredding
D. Deletion
Show Answer
Correct Answer: A
Explanation:
The best answer is A. Wiping. Secure wiping overwrites the storage media to prevent recovery while allowing the laptop to be reused or resold, making it the most cost-effective way to reduce the risk of client data theft. Deletion only removes file references and is not secure. Recycling does not ensure data destruction. Shredding is highly effective but physically destroys the drive, making it more costly and preventing reuse, so it is not the most cost-effective option.

Question 232

Which of the following should a security team do first before a new web server goes live?

A. Harden the virtual host.
B. Create WAF rules.
C. Enable network intrusion detection.
D. Apply patch management.
Show Answer
Correct Answer: A
Explanation:
Hardening the host is the baseline security activity performed before exposing a new web server. It encompasses secure configuration, disabling unnecessary services, least privilege, and typically includes ensuring the system is appropriately patched. WAF rules and NIDS are complementary controls applied around the deployment, while patch management is an ongoing process rather than the broader first pre-production security step.

Question 233

Which of the following provides the best protection against unwanted or insecure communications to and from a device?

A. System hardening
B. Host-based firewall
C. Intrusion detection system
D. Anti-malware software
Show Answer
Correct Answer: B
Explanation:
A host-based firewall provides the best protection against unwanted or insecure communications by filtering and controlling inbound and outbound network traffic on the device according to security rules. System hardening reduces the attack surface but does not directly control communications. An intrusion detection system primarily detects suspicious activity rather than blocking it, and anti-malware software focuses on detecting and removing malicious software rather than filtering network communications.

Question 234

Which of the following is most likely to be used as a just-in-time reference document within a security operations center?

A. Change management policy
B. Risk profile
C. Playbook
D. SIEM profile
Show Answer
Correct Answer: C
Explanation:
A playbook is the document SOC analysts use as a just-in-time operational reference. It contains step-by-step procedures for responding to specific security events and incidents, enabling consistent and efficient real-time actions. A change management policy governs changes, a risk profile summarizes organizational risk, and a SIEM profile is not a standard just-in-time operational reference document.

Question 235

Which of the following attacks exploits a potential vulnerability as a result of using weak cryptographic algorithms?

A. Password cracking
B. On-path
C. Digital signing
D. Side-channel
Show Answer
Correct Answer: A
Explanation:
Weak cryptographic algorithms (such as outdated password hashing algorithms or weak encryption protecting stored credentials) make password cracking significantly easier through brute-force, dictionary, and rainbow table attacks. An on-path attack is an interception technique that may be aided by weak cryptography but does not itself specifically exploit weak cryptographic algorithms. Digital signing is a security mechanism, not an attack, and side-channel attacks exploit implementation leakage rather than weak algorithms.

Question 236

Which of the following is the most relevant reason a DPO would develop a data inventory?

A. To manage data storage requirements better
B. To determine the impact in the event of a breach
C. To extend the length of time data can be retained
D. To automate the reduction of duplicated data
Show Answer
Correct Answer: B
Explanation:
A data inventory documents what data exists, where it is stored, how it flows, and who can access it. For a DPO, this is primarily valuable for understanding the scope and impact of security incidents and meeting breach assessment and notification obligations. The other options are operational data management goals rather than the primary privacy compliance purpose of a data inventory.

Question 237

An employee used a company’s billing system to issue fraudulent checks. The administrator is looking for evidence of other occurrences of this activity. Which of the following should the administrator examine?

A. Application logs
B. Vulnerability scanner logs
C. IDS/IPS logs
D. Firewall logs
Show Answer
Correct Answer: A
Explanation:
Application logs are the most relevant source because they record activity within the billing application, including user actions, transactions, timestamps, and events related to issuing checks. These logs are the best place to identify additional fraudulent check issuance. Vulnerability scanner logs identify security weaknesses, IDS/IPS logs detect suspicious network activity, and firewall logs record network traffic rather than application-level financial transactions.

Question 238

Which of the following would a systems administrator follow when upgrading the firmware of an organization’s router?

A. Software development life cycle
B. Risk tolerance
C. Certificate signing request
D. Maintenance window
Show Answer
Correct Answer: D
Explanation:
Firmware upgrades on production network devices are typically performed during an approved maintenance window to minimize business impact, allow for planned downtime, and provide time for verification or rollback if needed. The other options do not describe the operational process followed for scheduling and performing a router firmware upgrade.

Question 239

Which of the following consequences would a retail chain most likely face from customers in the event the retailer is non-compliant with PCI DSS?

A. Contractual impacts
B. Sanctions
C. Fines
D. Reputational damage
Show Answer
Correct Answer: D
Explanation:
PCI DSS non-compliance can lead to fines, sanctions, and contractual consequences imposed by payment brands, acquiring banks, or regulators—not by customers. The consequence most directly arising from customers is loss of trust and reputational damage, which can reduce sales and customer retention.

Question 240

A systems administrator discovers a system that is no longer receiving support from the vendor. However, this system and its environment are critical to running the business, cannot be modified, and must stay online. Which of the following risk treatments is the most appropriate in this situation?

A. Reject
B. Accept
C. Transfer
D. Avoid
Show Answer
Correct Answer: B
Explanation:
The correct risk treatment is accept. The unsupported system is business-critical, cannot be modified, and must remain online, so the organization cannot avoid the risk by removing the system or reject it as a treatment option. Transfer shifts financial impact (such as via insurance) but does not address the operational risk of continuing to rely on an unsupported system. In this scenario, the organization knowingly accepts the residual risk while typically implementing compensating controls (such as network segmentation, monitoring, or additional security measures) to reduce exposure.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.