Comptia

SY0-701 Free Practice Questions — Page 27

Question 261

Which of the following would a security administrator use to comply with a secure baseline during a patch update?

A. Information security policy
B. Service-level expectations
C. Standard operating procedure
D. Test result report
Show Answer
Correct Answer: C
Explanation:
A standard operating procedure (SOP) provides the documented, step-by-step process that administrators follow to perform patch updates consistently and in accordance with an organization's secure baseline. An information security policy defines high-level requirements, service-level expectations define performance targets, and a test result report records validation outcomes rather than guiding the update process.

Question 262

A company discovered its data was advertised for sale on the dark web. During the initial investigation, the company determined the data was proprietary data. Which of the following is the next step the company should take?

A. Identify the attacker’s entry methods.
B. Report the breach to the local authorities.
C. Notify the applicable parties of the breach.
D. Implement vulnerability scanning of the company's systems.
Show Answer
Correct Answer: C
Explanation:
The best next step is to notify the applicable parties of the breach. Once a compromise has been identified, organizations should follow their incident response and breach notification obligations, which may include notifying internal stakeholders, regulators, customers, partners, or other affected parties as applicable. Reporting to local authorities is not universally required, identifying the attacker's entry method is part of the ongoing investigation, and vulnerability scanning is a remediation activity rather than the immediate next step.

Question 263

An IT administrator needs to ensure data retention standards are implemented on an enterprise application. Which of the following describes the administrator’s role?

A. Processor
B. Custodian
C. Privacy officer
D. Owner
Show Answer
Correct Answer: B
Explanation:
A custodian is responsible for implementing and maintaining the organization's data handling controls, including retention, backup, storage, and disposal, based on policies set by the data owner. The owner determines the retention requirements, while the IT administrator, acting as the custodian, implements them. A processor processes data on behalf of a controller, and a privacy officer oversees privacy compliance rather than implementing technical retention controls.

Question 264

An employee who was working remotely lost a mobile device containing company data. Which of the following provides the best solution to prevent future data loss?

A. MDM
B. DLP
C. FDE
D. EDR
Show Answer
Correct Answer: A
Explanation:
MDM (Mobile Device Management) is the best overall solution for preventing future data loss from lost mobile devices because it enables centralized management, policy enforcement, remote lock/wipe, and can require encryption. FDE protects data at rest if a device is lost, but MDM provides broader preventive controls specifically for managed mobile devices. DLP focuses on monitoring and controlling data movement, and EDR detects and responds to endpoint threats rather than addressing lost devices.

Question 265

While reviewing logs, a security administrator identifies the following code: Which of the following best describes the vulnerability being exploited?

A. XSS
B. SQLi
C. DDoS
D. CSRF
Show Answer
Correct Answer: A
Explanation:
A <script> tag containing JavaScript is characteristic of an attempted cross-site scripting (XSS) payload. SQL injection would involve SQL syntax rather than JavaScript, DDoS is a traffic attack, and CSRF relies on forged authenticated requests rather than injected script.

Question 266

A security engineer would like to enhance the use of automation and orchestration within the SIEM. Which of the following would be the primary benefit of this enhancement?

A. It increases complexity.
B. It removes technical debt.
C. It adds additional guard rails.
D. It acts as a workforce multiplier.
Show Answer
Correct Answer: D
Explanation:
Automation and orchestration in a SIEM reduce manual effort by automating repetitive detection, enrichment, and response tasks. This enables security analysts to handle more alerts and incidents with the same staffing, making the team more effective as a workforce multiplier. The other options are not primary benefits: increasing complexity is generally a drawback, removing technical debt is unrelated, and adding guard rails may occur in specific workflows but is not the main benefit.

Question 267

Which of the following would most likely be used by attackers to perform credential harvesting?

A. Social engineering
B. Supply chain compromise
C. Third-party software
D. Rainbow table
Show Answer
Correct Answer: A
Explanation:
Credential harvesting most commonly refers to obtaining valid usernames and passwords by tricking users into revealing them, such as through phishing or other social engineering techniques. Supply chain compromise and third-party software can lead to credential theft but are not the primary credential harvesting method. Rainbow tables are used to crack password hashes after acquisition, not to harvest credentials.

Question 268

A security analyst is reviewing logs and discovers the following: Which of the following should be used to best mitigate this type of attack?

A. Input sanitization
B. Secure cookies
C. Static code analysis
D. Sandboxing
Show Answer
Correct Answer: A
Explanation:
The payload `${/bin/sh/id}` in a User-Agent header is characteristic of an attempted command injection or shell injection attack, where attacker-controlled input may be interpreted by a shell. The best mitigation among the options is input sanitization and, more broadly, strict input validation and avoiding unsafe shell execution. Secure cookies mitigate session risks, static code analysis helps find vulnerabilities during development but does not directly mitigate an active attack, and sandboxing can reduce impact but is not the primary mitigation for command injection.

Question 269

Which of the following activities is included in the post-incident review phase?

A. Determining the root cause of the incident
B. Developing steps to mitigate the risks of the incident
C. Validating the accuracy of the evidence collected during the investigation
D. Reestablishing the compromised system’s configuration and settings
Show Answer
Correct Answer: A
Explanation:
The post-incident review (lessons learned) phase includes analyzing the incident to determine its root cause, identify process improvements, and prevent recurrence. Mitigation planning may result from the review but is not the defining review activity; evidence validation belongs to investigation, and restoring configurations is part of recovery.

Question 270

A malicious actor conducted a brute-force attack on a company's web servers and eventually gained access to the company's customer information database. Which of the following is the most effective way to prevent similar attacks?

A. Regular patching of servers
B. Web application firewalls
C. Multifactor authentication
D. Enabling encryption of customer data
Show Answer
Correct Answer: C
Explanation:
A brute-force attack targets passwords. Multifactor authentication is the most effective control among the options because even if a password is guessed through brute force, the attacker still cannot authenticate without the second factor. Regular patching does not stop password guessing, a WAF can help mitigate or rate-limit brute-force attempts but is not as effective as MFA at preventing successful account compromise, and encryption protects data at rest rather than preventing unauthorized access.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.