Comptia

SY0-701 Free Practice Questions — Page 28

Question 273

Which of the following types of vulnerabilities is primarily caused by improper use and management of cryptographic certificates?

A. Misconfiguration
B. Resource reuse
C. Insecure key storage
D. Weak cipher suites
Show Answer
Correct Answer: A
Explanation:
Improper use and management of cryptographic certificates most commonly results in misconfiguration vulnerabilities, such as expired or improperly chained certificates, incorrect trust relationships, missing revocation checks, or certificates used for the wrong purpose. These issues stem from configuration and lifecycle management errors rather than from key storage alone or cipher selection.

Question 274

Which of the following cryptographic methods is preferred for securing communications with limited computing resources?

A. Hashing algorithm
B. Public key infrastructure
C. Symmetric encryption
D. Elliptic curve cryptography
Show Answer
Correct Answer: C
Explanation:
For environments with limited computing resources, symmetric encryption is preferred because it is computationally efficient, fast, and requires significantly less processing power than asymmetric methods. While elliptic curve cryptography (ECC) is more efficient than other asymmetric algorithms like RSA, it is still more resource-intensive than symmetric encryption and is typically used only for key exchange rather than bulk data protection. Therefore, symmetric encryption is the best choice.

Question 275

During a SQL update of a database, a temporary field that was created was replaced by an attacker in order to allow access to the system. Which of the following best describes this type of vulnerability?

A. Race condition
B. Memory injection
C. Malicious update
D. Side loading
Show Answer
Correct Answer: A
Explanation:
The scenario describes an attacker exploiting a timing window during a SQL update, where a temporary field is created and then replaced before the operation completes. This is a classic race condition, specifically a time-of-check to time-of-use (TOCTOU) issue. The vulnerability arises from improper synchronization or access control over a temporary resource, not from injecting memory, loading side components, or a vaguely defined 'malicious update.'

Question 276

Which of the following organizational documents is most often used to establish and communicate expectations associated with integrity and ethical behavior within an organization?

A. AUP
B. SLA
C. EULA
D. MOA
Show Answer
Correct Answer: A
Explanation:
An Acceptable Use Policy (AUP) is designed to define acceptable and unacceptable behavior, setting expectations for integrity and ethical use of organizational resources. SLAs define service levels, EULAs govern software licensing, and MOAs outline agreements between parties, none of which primarily address ethical conduct.

Question 277

Which of the following would enable a data center to remain operational through a multiday power outage?

A. Generator
B. Uninterruptible power supply
C. Replication
D. Parallel processing
Show Answer
Correct Answer: A
Explanation:
A generator can supply sustained electrical power for days as long as fuel is available, allowing a data center to remain operational during a multiday outage. A UPS is designed for short-term power bridging, while replication and parallel processing do not address power loss.

Question 278

An administrator wants to perform a risk assessment without using proprietary company information. Which of the following methods should the administrator use to gather information?

A. Network scanning
B. Penetration testing
C. Open-source intelligence
D. Configuration auditing
Show Answer
Correct Answer: C
Explanation:
Open-source intelligence (OSINT) gathers information from publicly available sources such as websites, social media, and public reports. It enables a risk assessment without using or accessing proprietary company information, unlike scanning, penetration testing, or configuration auditing, which involve direct interaction with internal systems.

Question 279

Which of the following should an internal auditor check for first when conducting an audit of the organization’s risk management program?

A. Policies and procedures
B. Asset management
C. Vulnerability assessment
D. Business impact analysis
Show Answer
Correct Answer: A
Explanation:
An internal audit of risk management should start with policies and procedures because they establish the formal framework, governance, roles, and methodology for managing risk. Verifying their existence, adequacy, and alignment with standards is prerequisite to evaluating specific activities such as asset management, vulnerability assessments, or business impact analyses.

Question 280

A database administrator is updating the company’s SQL database, which stores credit card information for pending purchases. Which of the following is the best method to secure the data against a potential breach?

A. Hashing
B. Obfuscation
C. Tokenization
D. Masking
Show Answer
Correct Answer: C
Explanation:
Tokenization is the best method for securing stored credit card data in a production database. It replaces the actual card numbers with non-sensitive tokens while keeping the real data in a secure token vault. If the database is breached, the stolen tokens are useless without access to the vault. This approach is standard in payment systems and aligns with PCI DSS requirements. Masking mainly protects data from casual viewing and is more appropriate for non-production or display purposes, not for securing stored sensitive data against breaches.

Question 281

Which of the following threat actors is the most likely to seek financial gain through the use of ransomware attacks?

A. Organized crime
B. Insider threat
C. Nation-state
D. Hacktivists
Show Answer
Correct Answer: A
Explanation:
Organized crime groups commonly deploy ransomware to extort payments for direct financial gain. They operate ransomware-as-a-service models and target victims for profit, unlike nation-states (espionage/sabotage), hacktivists (ideology), or insiders (varied motives).

Question 282

An organization purchased a critical business application containing sensitive data. The organization would like to ensure that the application is not exploited by common data exfiltration attacks. Which of the following approaches would best help to fulfill this requirement?

A. URL scanning
B. WAF
C. Reverse proxy
D. NAC
Show Answer
Correct Answer: B
Explanation:
A Web Application Firewall (WAF) is designed to inspect and control application‑layer traffic and block common attacks that lead to data exfiltration (e.g., SQL injection, XSS, malicious request patterns). Among the options, it directly protects the application itself. URL scanning is passive, a reverse proxy does not inherently prevent exfiltration, and NAC controls network access rather than application‑layer exploitation.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.