Comptia

SY0-701 Free Practice Questions — Page 27

Question 263

Which of the following would a security administrator use to comply with a secure baseline during a patch update?

A. Information security policy
B. Service-level expectations
C. Standard operating procedure
D. Test result report
Show Answer
Correct Answer: C
Explanation:
A secure baseline is enforced through documented, repeatable procedures. A Standard Operating Procedure (SOP) provides step-by-step instructions for performing patch updates in a consistent and secure manner, ensuring compliance with the established secure baseline. Policies are high-level, service-level expectations are unrelated to patch execution, and test result reports only document outcomes.

Question 264

A company discovered its data was advertised for sale on the dark web. During the initial investigation, the company determined the data was proprietary data. Which of the following is the next step the company should take?

A. Identify the attacker’s entry methods.
B. Report the breach to the local authorities.
C. Notify the applicable parties of the breach.
D. Implement vulnerability scanning of the company's systems.
Show Answer
Correct Answer: C
Explanation:
Once a company has confirmed that proprietary data has been compromised and is being sold, the next step is to fulfill incident response and legal obligations by notifying applicable parties. This includes internal stakeholders, affected customers or partners, and regulators as required by law. Notification is time‑sensitive and mandated in many jurisdictions. Identifying entry methods and vulnerability scanning are important but occur as part of the broader investigation and remediation after required notifications, while reporting to local authorities is situational rather than universally required.

Question 265

An IT administrator needs to ensure data retention standards are implemented on an enterprise application. Which of the following describes the administrator’s role?

A. Processor
B. Custodian
C. Privacy officer
D. Owner
Show Answer
Correct Answer: B
Explanation:
An IT administrator who ensures data retention standards are implemented is performing day-to-day management and enforcement of data handling policies. This aligns with the role of a data custodian, who implements and maintains controls defined by the data owner. The owner sets retention requirements, the privacy officer oversees compliance, and a processor handles data on behalf of another entity, but the custodian operationalizes retention within systems.

Question 266

An employee who was working remotely lost a mobile device containing company data. Which of the following provides the best solution to prevent future data loss?

A. MDM
B. DLP
C. FDE
D. EDR
Show Answer
Correct Answer: A
Explanation:
The scenario involves a lost mobile device used by a remote employee, and the goal is to prevent future data loss. Mobile Device Management (MDM) is the best solution because it provides centralized control over mobile devices, including enforcing security policies, mandatory encryption, device locking, and—most importantly—remote wipe capabilities if a device is lost or stolen. Full Disk Encryption (FDE) protects data confidentiality but does not allow administrators to take action after loss. DLP and EDR address different threats and do not directly mitigate data loss from lost mobile devices.

Question 267

While reviewing logs, a security administrator identifies the following code: Which of the following best describes the vulnerability being exploited?

A. XSS
B. SQLi
C. DDoS
D. CSRF
Show Answer
Correct Answer: A
Explanation:
The presence of a <script> tag with JavaScript code indicates injected client-side script content. This is characteristic of Cross-Site Scripting (XSS), where attackers inject malicious JavaScript into pages or inputs that may be rendered by users' browsers. The other options (SQLi, DDoS, CSRF) do not involve embedded JavaScript code in this manner.

Question 268

A security engineer would like to enhance the use of automation and orchestration within the SIEM. Which of the following would be the primary benefit of this enhancement?

A. It increases complexity.
B. It removes technical debt.
C. It adds additional guard rails.
D. It acts as a workforce multiplier.
Show Answer
Correct Answer: D
Explanation:
Automation and orchestration in a SIEM streamline repetitive tasks and accelerate incident response, allowing the same security staff to handle more alerts and incidents efficiently. This effectively multiplies the workforce’s capacity, which is the primary benefit.

Question 269

Which of the following would most likely be used by attackers to perform credential harvesting?

A. Social engineering
B. Supply chain compromise
C. Third-party software
D. Rainbow table
Show Answer
Correct Answer: A
Explanation:
Credential harvesting is the act of tricking or persuading users to directly reveal valid usernames and passwords. Social engineering (e.g., phishing emails, fake login pages, phone scams) is the most common and direct technique used for this purpose. Supply chain compromise and third‑party software can facilitate theft but are indirect, while rainbow tables are used for cracking hashed passwords, not harvesting credentials.

Question 270

A security analyst is reviewing logs and discovers the following: Which of the following should be used to best mitigate this type of attack?

A. Input sanitization
B. Secure cookies
C. Static code analysis
D. Sandboxing
Show Answer
Correct Answer: A
Explanation:
The log indicates an attempted command injection via the User-Agent header (e.g., shell metacharacters like ${/bin/sh/id}). The most effective mitigation is input sanitization/validation to properly filter, escape, or reject malicious characters before the input is processed. Secure cookies are unrelated, static code analysis is a detection method rather than a runtime mitigation, and sandboxing does not directly prevent injection at the input level.

Question 271

Which of the following activities is included in the post-incident review phase?

A. Determining the root cause of the incident
B. Developing steps to mitigate the risks of the incident
C. Validating the accuracy of the evidence collected during the investigation
D. Reestablishing the compromised system’s configuration and settings
Show Answer
Correct Answer: A
Explanation:
The post-incident review (lessons learned) phase focuses on analyzing what happened and why. Determining the root cause of the incident is a core activity of this phase, enabling organizations to prevent recurrence. The other options align with mitigation planning, evidence handling during investigation, or recovery activities.

Question 272

A malicious actor conducted a brute-force attack on a company's web servers and eventually gained access to the company's customer information database. Which of the following is the most effective way to prevent similar attacks?

A. Regular patching of servers
B. Web application firewalls
C. Multifactor authentication
D. Enabling encryption of customer data
Show Answer
Correct Answer: C
Explanation:
The attack described is a brute-force attack against authentication. Multifactor authentication (MFA) is the most effective countermeasure because it prevents account compromise even if a password is successfully guessed. An attacker would still need the additional factor (e.g., OTP, token, biometric), which brute-force techniques cannot easily bypass. While web application firewalls and patching help reduce risk, they are indirect controls. Encryption protects data at rest but does not prevent unauthorized access. Therefore, MFA most directly and effectively prevents similar attacks.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.