Comptia

SY0-701 Free Practice Questions — Page 26

Question 253

An enterprise security team is researching a new security architecture to better protect the company’s networks and applications against the latest cyberthreats. The company has a fully remote workforce. The solution should be highly redundant and enable users to connect to a VPN with an integrated, software-based firewall. Which of the following solutions meets these requirements?

A. IPS
B. SIEM
C. SASE
D. CASB
Show Answer
Correct Answer: C
Explanation:
SASE (Secure Access Service Edge) is a cloud-native security architecture designed for distributed and remote workforces. It provides highly redundant, globally distributed access with integrated secure connectivity (VPN/Zero Trust access) and software-based security controls such as Firewall-as-a-Service, secure web gateway, and threat protection. The other options are individual security components, not a comprehensive architecture for remote access and networking security.

Question 254

Executives at a company are concerned about employees accessing systems and information about sensitive company projects unrelated to the employees’ normal job duties. Which of the following enterprise security capabilities will the security team most likely deploy to detect that activity?

A. UBA
B. EDR
C. NAC
D. DLP
Show Answer
Correct Answer: A
Explanation:
The goal is to detect employees accessing systems or project information outside their normal job duties. User Behavior Analytics (UBA) establishes a baseline of typical user activity and identifies anomalous behavior, such as unusual access patterns or unauthorized interest in sensitive projects. EDR focuses on endpoint threats, NAC controls network access, and DLP focuses on preventing or detecting data exfiltration rather than inappropriate access. Therefore, UBA is the best fit for detecting this activity.

Question 255

A security engineer configured a remote access VPN. The remote access VPN allows end users to connect to the network by using an agent that is installed on the endpoint, which establishes an encrypted tunnel. Which of the following protocols did the engineer most likely implement?

A. GRE
B. IPSec
C. SD-WAN
D. EAP
Show Answer
Correct Answer: B
Explanation:
A remote access VPN that uses an endpoint agent to establish an encrypted tunnel most commonly relies on IPsec. IPsec provides authentication, integrity, and encryption at the network layer and is widely used for both remote access and site-to-site VPNs. GRE does not provide encryption by itself, SD-WAN is an architecture rather than a VPN protocol, and EAP is an authentication framework, not a tunneling/encryption protocol.

Question 256

Which of the following tasks is typically included in the BIA process?

A. Estimating the recovery time of systems
B. Identifying the communication strategy
C. Evaluating the risk management plan
D. Establishing the backup and recovery procedures
E. Developing the incident response plan
Show Answer
Correct Answer: A
Explanation:
A Business Impact Analysis (BIA) focuses on identifying critical business processes and determining the impact of disruptions, including defining Recovery Time Objectives (RTOs) and often Recovery Point Objectives (RPOs). Estimating how quickly systems must be restored is a core BIA task, while the other options relate to planning and response activities that occur after the BIA.

Question 257

A systems administrator is concerned about vulnerabilities within cloud computing instances. Which of the following is most important for the administrator to consider when architecting a cloud computing environment?

A. SQL injection
B. TOC/TOU
C. VM escape
D. Tokenization
E. Password spraying
Show Answer
Correct Answer: C
Explanation:
In cloud computing, especially multi-tenant environments, virtualization is foundational. VM escape is a critical architectural concern because it allows an attacker to break out of a guest VM and compromise the hypervisor or other VMs on the same host, undermining isolation between tenants. The other options are general application or identity threats, or a mitigation technique, and are not as central to cloud infrastructure architecture.

Question 258

An organization issued new laptops to all employees and wants to provide web filtering both in and out of the office without configuring additional access to the network. Which of the following types of web filtering should a systems administrator configure?

A. Agent-based
B. Centralized proxy
C. URL scanning
D. Content categorization
Show Answer
Correct Answer: A
Explanation:
Agent-based web filtering installs a client on each laptop, allowing policies to be enforced regardless of whether the device is inside or outside the corporate network. It does not require VPNs, proxies, or additional network configuration, unlike centralized proxies. URL scanning and content categorization are techniques, not deployment models that ensure off-network coverage.

Question 259

An organization has recently decided to implement SSO. The requirements are to leverage access tokens and focus on application authorization rather than user authentication. Which of the following solutions would the engineering team most likely configure?

A. LDAP
B. Federation
C. SAML
D. OAuth
Show Answer
Correct Answer: D
Explanation:
The key requirement is to use access tokens and emphasize application authorization rather than user authentication. OAuth is an authorization framework specifically designed to issue access tokens that allow applications to access resources on behalf of a user or service. SAML and federation primarily address authentication and identity assertions, while LDAP is a directory protocol. Therefore, OAuth best fits the stated requirements.

Question 260

Which of the following should a security team use to document persistent vulnerabilities with related recommendations?

A. Audit report
B. Risk register
C. Compliance report
D. Penetration test
Show Answer
Correct Answer: B
Explanation:
A risk register is specifically designed to document ongoing or persistent risks and vulnerabilities, along with their likelihood, impact, ownership, and recommended mitigation actions. It is a living document used for tracking and managing issues over time, unlike audit, compliance, or penetration test reports, which are point-in-time assessments.

Question 261

While investigating a possible incident, a security analyst discovers the following: Which of the following should the analyst do first?

A. Implement a WAF.
B. Disable the query.php script.
C. Block brute-force attempts on temporary users.
D. Check the users table for new accounts.
Show Answer
Correct Answer: D
Explanation:
The evidence indicates a suspected SQL injection attempt targeting the application. The first step in incident response is analysis: determine whether the attack succeeded. Checking the users table for newly created or unauthorized accounts immediately confirms impact and scope. Containment actions like disabling scripts or deploying a WAF come after verifying compromise, to avoid unnecessary service disruption.

Question 262

Which of the following options will provide the lowest RTO and RPO for a database?

A. Snapshots
B. On-site backups
C. Journaling
D. Hot site
Show Answer
Correct Answer: D
Explanation:
The option that provides the lowest combined RTO and RPO is a hot site. A hot site is a fully operational, continuously synchronized replica of the primary environment, allowing near-immediate failover (very low RTO) and minimal to zero data loss (very low RPO). Journaling minimizes RPO but still requires time to replay logs during recovery, resulting in a higher RTO than a hot site. Snapshots and on-site backups have significantly higher RTO and RPO.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.