Comptia

SY0-701 Free Practice Questions — Page 28

Question 271

Which of the following types of vulnerabilities is primarily caused by improper use and management of cryptographic certificates?

A. Misconfiguration
B. Resource reuse
C. Insecure key storage
D. Weak cipher suites
Show Answer
Correct Answer: A
Explanation:
Improper use and management of cryptographic certificates is primarily a certificate management/configuration issue. Examples include expired certificates, incorrect certificate chains, improper trust configuration, missing revocation checking, and incorrect certificate deployment. Insecure key storage is related to protecting private keys, but it is a distinct vulnerability category rather than the primary classification for certificate misuse and management.

Question 272

Which of the following cryptographic methods is preferred for securing communications with limited computing resources?

A. Hashing algorithm
B. Public key infrastructure
C. Symmetric encryption
D. Elliptic curve cryptography
Show Answer
Correct Answer: C
Explanation:
Symmetric encryption is the most computationally efficient option for protecting communications because it uses a shared secret key and has much lower processing overhead than asymmetric cryptography. Although elliptic curve cryptography (ECC) is the preferred asymmetric algorithm for constrained devices due to its smaller key sizes and improved efficiency over RSA, it is still more computationally expensive than symmetric encryption and is typically used for key exchange or digital signatures rather than bulk data encryption. Hashing does not provide confidential communications, and PKI is an infrastructure rather than an encryption method.

Question 273

During a SQL update of a database, a temporary field that was created was replaced by an attacker in order to allow access to the system. Which of the following best describes this type of vulnerability?

A. Race condition
B. Memory injection
C. Malicious update
D. Side loading
Show Answer
Correct Answer: A
Explanation:
This describes exploiting a timing window during an update in which a temporary object/field exists and is replaced before the operation completes. That is a race condition (specifically a TOCTOU-style issue). 'Memory injection' is unrelated, 'side loading' refers to loading unauthorized libraries/apps, and 'malicious update' is not the established vulnerability class for this timing-based attack.

Question 274

Which of the following organizational documents is most often used to establish and communicate expectations associated with integrity and ethical behavior within an organization?

A. AUP
B. SLA
C. EULA
D. MOA
Show Answer
Correct Answer: A
Explanation:
An Acceptable Use Policy (AUP) is an internal organizational policy that defines acceptable and unacceptable behavior when using company systems and resources, reinforcing expectations for ethical conduct and integrity. An SLA defines service levels, a EULA is a software licensing agreement, and an MOA documents cooperation between parties rather than employee ethical expectations.

Question 275

Which of the following would enable a data center to remain operational through a multiday power outage?

A. Generator
B. Uninterruptible power supply
C. Replication
D. Parallel processing
Show Answer
Correct Answer: A
Explanation:
A generator is designed to provide sustained backup power for extended outages, including multiday events, as long as fuel is available. An uninterruptible power supply (UPS) provides short-term power to bridge the gap until a generator starts or systems shut down safely. Replication and parallel processing improve availability or performance but do not supply electrical power.

Question 276

An administrator wants to perform a risk assessment without using proprietary company information. Which of the following methods should the administrator use to gather information?

A. Network scanning
B. Penetration testing
C. Open-source intelligence
D. Configuration auditing
Show Answer
Correct Answer: C
Explanation:
Open-source intelligence (OSINT) gathers information from publicly available sources, making it appropriate for conducting a risk assessment without using proprietary company information. Network scanning, penetration testing, and configuration auditing all involve interacting with or assessing the organization's own systems and configurations rather than relying solely on public information.

Question 277

Which of the following should an internal auditor check for first when conducting an audit of the organization’s risk management program?

A. Policies and procedures
B. Asset management
C. Vulnerability assessment
D. Business impact analysis
Show Answer
Correct Answer: A
Explanation:
An internal auditor should first verify that the organization's risk management program is governed by documented policies and procedures. These establish the framework, roles, responsibilities, and processes against which the rest of the program (such as asset management, vulnerability assessments, and business impact analyses) can be evaluated. Without this foundation, it is difficult to assess whether other risk management activities are appropriate or compliant.

Question 278

A database administrator is updating the company’s SQL database, which stores credit card information for pending purchases. Which of the following is the best method to secure the data against a potential breach?

A. Hashing
B. Obfuscation
C. Tokenization
D. Masking
Show Answer
Correct Answer: C
Explanation:
Tokenization is the best choice for protecting stored credit card data against a database breach. It replaces the card number with a non-sensitive token while the real value is kept separately in a secure token vault. If the SQL database is compromised, the attacker obtains only tokens, not usable card numbers. Hashing is not appropriate when the original value must be retrieved for payment processing, masking is primarily for limiting what users see rather than securing production storage, and obfuscation is not a strong protection for sensitive payment data.

Question 279

Which of the following threat actors is the most likely to seek financial gain through the use of ransomware attacks?

A. Organized crime
B. Insider threat
C. Nation-state
D. Hacktivists
Show Answer
Correct Answer: A
Explanation:
Organized crime groups are primarily motivated by financial profit and commonly use ransomware attacks to extort victims for payment. Insider threats may have varied motives, nation-states are typically focused on espionage or strategic objectives, and hacktivists are generally motivated by ideology rather than financial gain.

Question 280

An organization purchased a critical business application containing sensitive data. The organization would like to ensure that the application is not exploited by common data exfiltration attacks. Which of the following approaches would best help to fulfill this requirement?

A. URL scanning
B. WAF
C. Reverse proxy
D. NAC
Show Answer
Correct Answer: B
Explanation:
A Web Application Firewall (WAF) is the best fit among the options because it is designed to inspect and filter application-layer HTTP/HTTPS traffic, blocking common attacks such as SQL injection and other exploits that can lead to unauthorized data access and exfiltration. A reverse proxy primarily forwards and can hide backend servers but does not inherently provide application attack protection. URL scanning focuses on malicious URLs rather than protecting an application's sensitive data. NAC controls which devices/users can access the network but does not prevent application-layer exploitation once access exists.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.