Comptia

SY0-701 Free Practice Questions — Page 29

Question 281

An organization needs to determine how many employees are accessing the building each day in order to configure the proper access controls. Which of the following control types best meets this requirement?

A. Detective
B. Preventive
C. Corrective
D. Directive
Show Answer
Correct Answer: A
Explanation:
The requirement is to determine how many employees are accessing the building each day. Controls that monitor, log, and identify events (such as badge access logs or entry monitoring) are detective controls. Preventive controls stop unauthorized access, corrective controls restore after an issue, and directive controls provide guidance or policy.

Question 282

Which of the following would be the best solution to deploy a low-cost standby site that includes hardware and internet access?

A. Recovery site
B. Cold site
C. Hot site
D. Warm site
Show Answer
Correct Answer: D
Explanation:
A warm site is the lowest-cost standby option that includes preconfigured hardware and network/Internet connectivity. A cold site is cheaper but typically provides only facilities (power, cooling, space, and basic networking) without installed hardware. A hot site is fully operational but significantly more expensive. 'Recovery site' is a generic term rather than a specific tier.

Question 283

Which of the following should an organization focus on the most when making decisions about vulnerability prioritization?

A. Exposure factor
B. CVSS
C. CVE
D. Industry impact
Show Answer
Correct Answer: A
Explanation:
For vulnerability prioritization, organizations should focus primarily on their own exposure and business risk rather than generic severity metrics. CVSS is a useful standardized severity score, but effective prioritization is risk-based and depends on exposure, asset criticality, and organizational impact. CVE is only an identifier, and industry impact is less important than the organization's specific exposure. Sources: https://www.wiz.io/academy/vulnerability-management/vulnerability-management-best-practices

Question 284

A security analyst attempts to start a company's database server. When the server starts, the analyst receives an error message indicating the database server did not pass authentication. After reviewing and testing the system, the analyst receives confirmation that the server has been compromised and that attackers have redirected all outgoing database traffic to a server under their control. Which of the following MITRE ATT&CK techniques did the attacker most likely use to redirect database traffic?

A. Browser extension
B. Process injection
C. Valid accounts
D. Escape to host
Show Answer
Correct Answer: B
Explanation:
Process Injection best matches the described behavior. The key behavior in the scenario is not how the attacker initially gained access, but how they redirected the database server's outgoing traffic. Injecting or modifying the behavior of the database process can enable interception or redirection of its network communications. Valid Accounts explains unauthorized access but does not itself redirect traffic. Browser Extension is unrelated to a database server, and Escape to Host refers to breaking out of a container or VM to the host, which is not described.

Question 285

Which of the following allows an exploit to go undetected by the operating system?

A. Firmware vulnerabilities
B. Side loading
C. Memory injection
D. Encrypted payloads
Show Answer
Correct Answer: C
Explanation:
Memory injection is the technique most directly associated with executing malicious code inside the address space of a legitimate process, helping it evade traditional OS and file-based detection. Firmware vulnerabilities are flaws that can be exploited below the OS but are not themselves a stealth technique. Side loading is loading code through trusted mechanisms, and encrypted payloads conceal content but must be decrypted to execute and do not inherently evade OS detection.

Question 286

Which of the following is a risk of conducting a vulnerability assessment?

A. A disruption of business operations
B. Unauthorized access to the system
C. Reports of false positives
D. Finding security gaps in the system
Show Answer
Correct Answer: A
Explanation:
The primary risk of conducting a vulnerability assessment is that scanning or testing can negatively affect production systems, causing performance degradation, service interruption, or other disruption to business operations. Unauthorized access is not an inherent risk of performing the assessment itself, finding security gaps is the intended outcome, and false positives are a common limitation of scanning tools but are generally considered a characteristic or drawback rather than the primary operational risk.

Question 287

Which of the following activities are associated with vulnerability management? (Choose two.)

A. Reporting
B. Prioritization
C. Exploiting
D. Correlation
E. Containment
F. Tabletop exercise
Show Answer
Correct Answer: A, B
Explanation:
Vulnerability management includes identifying, assessing, prioritizing, remediating, and tracking/reporting vulnerabilities. Reporting communicates findings and remediation status, while prioritization ranks vulnerabilities by risk and exploitability to guide remediation. Exploiting is part of penetration testing or attacker activity, containment is primarily an incident response function, correlation is more associated with SIEM/threat analysis, and tabletop exercises are preparedness activities rather than vulnerability management.

Question 288

A company processes and stores sensitive data on its own systems. Which of the following steps should the company take first to ensure compliance with privacy regulations?

A. Implement access controls and encryption.
B. Develop and provide training on data protection policies.
C. Create incident response and disaster recovery plans.
D. Purchase and install security software.
Show Answer
Correct Answer: B
Explanation:
When the question asks what the company should do first to ensure compliance with privacy regulations, the foundational step is to establish data protection policies and train personnel on them. Administrative controls define the organization's compliance requirements and guide the implementation of technical controls such as access control and encryption. Incident response plans and purchasing security software come later.

Question 289

Which of the following is a benefit of vendor diversity?

A. Patch availability
B. Zero-day resiliency
C. Secure configuration guide applicability
D. Load balancing
Show Answer
Correct Answer: B
Explanation:
Vendor diversity reduces systemic risk by avoiding dependence on a single vendor. If a zero-day vulnerability affects one vendor's product, systems from other vendors are less likely to be affected by the same flaw, improving resilience. Patch availability is not inherently improved by using multiple vendors, secure configuration guides are vendor-specific rather than a benefit of diversity, and load balancing is unrelated.

Question 290

An organization plans to expand its operations internationally and needs to keep data at the new location secure. The organization wants to use the most secure architecture model possible. Which of the following models offers the highest level of security?

A. Cloud-based
B. Peer-to-peer
C. On-premises
D. Hybrid
Show Answer
Correct Answer: C
Explanation:
On-premises is the best answer in the context of a certification-style question asking for the 'most secure architecture model possible.' An on-premises deployment gives the organization the greatest control over physical security, infrastructure, access controls, and data handling. While cloud providers can offer excellent security and hybrid models provide flexibility, they do not inherently offer a higher maximum level of security than a fully controlled on-premises environment.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.