Comptia

SY0-701 Free Practice Questions — Page 25

Question 243

A university employee logged on to the academic server and attempted to guess the system administrators’ log-in credentials. Which of the following security measures should the university have implemented to detect the employee’s attempts to gain access to the administrators’ accounts?

A. Two-factor authentication
B. Firewall
C. Intrusion prevention system
D. User activity logs
Show Answer
Correct Answer: D
Explanation:
The question asks which control would **detect** attempts to guess administrator credentials. User activity logs record authentication events such as failed log-in attempts and account access, allowing security staff to identify and investigate suspicious behavior. Two-factor authentication and firewalls are preventive controls, and an intrusion prevention system focuses on blocking attacks rather than logging user credential guessing. Therefore, user activity logs are the correct detection mechanism.

Question 244

Which of the following is a preventive physical security control?

A. Video surveillance system
B. Bollards
C. Alarm system
D. Motion sensors
Show Answer
Correct Answer: B
Explanation:
Preventive physical security controls are intended to stop or block unauthorized actions before they occur. Bollards are fixed physical barriers designed to prevent vehicles from entering restricted areas or ramming into structures, making them a clear preventive control. The other options (video surveillance, alarm systems, and motion sensors) primarily detect or alert after or during an incident, classifying them as detective rather than preventive controls.

Question 245

Which of the following is the primary reason why false negatives on a vulnerability scan should be a concern?

A. The system has vulnerabilities that are not being detected.
B. The time to remediate vulnerabilities that do not exist is excessive.
C. Vulnerabilities with a lower severity will be prioritized over critical vulnerabilities.
D. The system has vulnerabilities, and a patch has not yet been released.
Show Answer
Correct Answer: A
Explanation:
A false negative means the scan fails to identify an existing vulnerability. This is a primary concern because undetected vulnerabilities remain unpatched and exploitable, leaving the system exposed to attack without the organization's knowledge.

Question 246

A security administrator documented the following records during an assessment of network services: Two weeks later, the administrator performed a log review and noticed the records were changed as follows: When consulting the service owner, the administrator validated that the new address was not part of the company network. Which of the following was the company most likely experiencing?

A. DDoS attack
B. DNS poisoning
C. Ransomware compromise
D. Spyware infection
Show Answer
Correct Answer: B
Explanation:
The records for network services were altered to point to an IP address outside the company network without authorization. This behavior is characteristic of DNS poisoning (DNS spoofing), where DNS records are maliciously modified to redirect traffic to attacker-controlled systems. A DDoS attack overwhelms services but does not change records, ransomware focuses on encrypting data, and spyware covertly collects information rather than altering DNS mappings.

Question 247

Which of the following should be used to ensure an attacker is unable to read the contents of a mobile device's drive if the device is lost?

A. TPM
B. ECC
C. FDE
D. HSM
Show Answer
Correct Answer: C
Explanation:
Full Disk Encryption (FDE) encrypts all data stored on the device’s drive, ensuring that if the mobile device is lost or stolen, an attacker cannot read the contents without the proper authentication. TPM and HSM are hardware key management components not typically used or available in mobile devices for this purpose, and ECC is for error correction, not data confidentiality.

Question 248

A user's workstation becomes unresponsive and displays a ransom note demanding payment to decrypt files. Before the attack, the user opened a resume they received in a message, browsed the company's website, and installed OS updates. Which of the following is the most likely vector of this attack?

A. Spear-phishing attachment
B. Watering hole
C. Infected website
D. Typosquatting
Show Answer
Correct Answer: A
Explanation:
The most likely attack vector is a spear-phishing attachment. The user explicitly opened a resume received in a message, which is a classic scenario for targeted phishing delivering malicious attachments that execute ransomware when opened. The other activities mentioned (browsing the company website and installing OS updates) are common and not described as compromised, making them less likely vectors.

Question 249

A security consultant is working with a client that wants to physically isolate its secure systems. Which of the following best describes this architecture?

A. SDN
B. Air gapped
C. Containerized
D. Highly available
Show Answer
Correct Answer: B
Explanation:
Physically isolating secure systems means there is no network or logical connectivity to other systems or networks. This architecture is known as an air gap, where systems are completely separated to prevent unauthorized access or data leakage. The other options do not imply physical isolation.

Question 250

A security analyst has determined that a security breach would have a financial impact of $15,000 and is expected to occur twice within a three-year period. Which of the following is the ALE for this risk?

A. $7,500
B. $10,000
C. $15,000
D. $30,000
Show Answer
Correct Answer: B
Explanation:
ALE = SLE × ARO. The loss is $15,000 per incident (SLE). It is expected to occur twice in three years, so the annualized rate of occurrence is 2/3 ≈ 0.67. ALE = $15,000 × 0.67 ≈ $10,000.

Question 251

Which of the following activities is the first stage in the incident response process?

A. Detection
B. Declaration
C. Containment
D. Verification
Show Answer
Correct Answer: A
Explanation:
In standard incident response lifecycles, the process begins with identifying that an incident has occurred. This initial stage is commonly referred to as detection (or identification), which precedes containment, eradication, and recovery.

Question 252

The private key for a website was stolen, and a new certificate has been issued. Which of the following needs to be updated next?

A. SCEP
B. CRL
C. OCSP
D. CSR
Show Answer
Correct Answer: B
Explanation:
If a website’s private key is stolen, the existing certificate is compromised and must be revoked. After issuing a new certificate, the Certificate Authority must update the Certificate Revocation List (CRL) to mark the old certificate as invalid so clients know not to trust it. OCSP relies on revocation data, SCEP is for enrollment, and a CSR is used before issuing a new certificate, not after compromise.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.