Comptia

SY0-701 Free Practice Questions — Page 29

Question 283

An organization needs to determine how many employees are accessing the building each day in order to configure the proper access controls. Which of the following control types best meets this requirement?

A. Detective
B. Preventive
C. Corrective
D. Directive
Show Answer
Correct Answer: A
Explanation:
The requirement is to determine (measure and monitor) how many employees access the building each day. That requires collecting and reviewing information, such as badge logs, access records, or camera footage. Controls that monitor and record events are detective controls. Preventive controls stop access, corrective controls fix issues after they occur, and directive controls provide guidance, none of which primarily determine counts.

Question 284

Which of the following would be the best solution to deploy a low-cost standby site that includes hardware and internet access?

A. Recovery site
B. Cold site
C. Hot site
D. Warm site
Show Answer
Correct Answer: D
Explanation:
A warm site is the best low-cost standby solution that still includes hardware and internet access. It provides preinstalled hardware, network connectivity, and basic system configuration, but does not maintain real-time data replication like a hot site, keeping costs lower. A cold site is cheaper but typically lacks hardware (and often active internet), while a hot site is significantly more expensive.

Question 285

Which of the following should an organization focus on the most when making decisions about vulnerability prioritization?

A. Exposure factor
B. CVSS
C. CVE
D. Industry impact
Show Answer
Correct Answer: A
Explanation:
Vulnerability prioritization should be driven primarily by the organization’s own risk and potential business impact. The exposure factor reflects how a vulnerability affects that specific organization—considering asset value, data sensitivity, likelihood, and potential loss. CVSS provides a useful general severity score, but it is generic and does not account for organizational context. Therefore, exposure factor is the most important focus when making prioritization decisions.

Question 286

A security analyst attempts to start a company's database server. When the server starts, the analyst receives an error message indicating the database server did not pass authentication. After reviewing and testing the system, the analyst receives confirmation that the server has been compromised and that attackers have redirected all outgoing database traffic to a server under their control. Which of the following MITRE ATT&CK techniques did the attacker most likely use to redirect database traffic?

A. Browser extension
B. Process injection
C. Valid accounts
D. Escape to host
Show Answer
Correct Answer: B
Explanation:
Redirecting all outgoing database traffic implies the attacker altered the behavior of the running database service or its network calls. In MITRE ATT&CK, this most closely aligns with Process Injection (T1055), where malicious code is injected into a legitimate process to manipulate execution, intercept, or reroute network communications. Valid Accounts explains access, not traffic manipulation; Browser Extension is irrelevant to a database server; and Escape to Host refers to container/VM breakout, which is not described.

Question 287

Which of the following allows an exploit to go undetected by the operating system?

A. Firmware vulnerabilities
B. Side loading
C. Memory injection
D. Encrypted payloads
Show Answer
Correct Answer: C
Explanation:
Memory injection allows malicious code to execute directly within the memory space of a running process without being written to disk. Because it avoids file-based artifacts and persistence, it can bypass many operating system detection and monitoring mechanisms, making the exploit harder for the OS to detect compared to the other options.

Question 288

Which of the following is a risk of conducting a vulnerability assessment?

A. A disruption of business operations
B. Unauthorized access to the system
C. Reports of false positives
D. Finding security gaps in the system
Show Answer
Correct Answer: A
Explanation:
A key risk of conducting a vulnerability assessment is the potential disruption of business operations. Active or aggressive scanning can consume system resources, trigger crashes, overload networks, or interfere with production services. False positives are a common outcome of assessments but are not inherently a risk to operations, while finding security gaps is the purpose of the assessment, not a risk.

Question 289

Which of the following activities are associated with vulnerability management? (Choose two.)

A. Reporting
B. Prioritization
C. Exploiting
D. Correlation
E. Containment
F. Tabletop exercise
Show Answer
Correct Answer: A, B
Explanation:
Vulnerability management focuses on identifying, assessing, tracking, and remediating vulnerabilities. Reporting is a core activity because vulnerabilities, their risk, and remediation status must be documented and communicated to stakeholders. Prioritization is also essential, as vulnerabilities are ranked based on severity, exploitability, and business impact to ensure limited resources address the most critical issues first. The other options relate to incident response, offensive security, or training rather than vulnerability management.

Question 290

A company processes and stores sensitive data on its own systems. Which of the following steps should the company take first to ensure compliance with privacy regulations?

A. Implement access controls and encryption.
B. Develop and provide training on data protection policies.
C. Create incident response and disaster recovery plans.
D. Purchase and install security software.
Show Answer
Correct Answer: A
Explanation:
The first priority for compliance with privacy regulations is protecting sensitive data through concrete technical safeguards. Access controls ensure only authorized users can view or modify data, and encryption protects data at rest and in transit. Most privacy regulations (e.g., GDPR, HIPAA, CCPA) explicitly require these protections. Policies, training, and plans are important, but they are ineffective without foundational security controls already in place.

Question 291

Which of the following is a benefit of vendor diversity?

A. Patch availability
B. Zero-day resiliency
C. Secure configuration guide applicability
D. Load balancing
Show Answer
Correct Answer: B
Explanation:
Vendor diversity reduces reliance on a single vendor’s technology stack. If a zero-day vulnerability impacts one vendor’s product, systems from other vendors are less likely to be affected by the same exploit, improving overall resiliency. The other options are not inherent benefits of vendor diversity: patch availability and configuration guides vary by vendor, and load balancing is an architectural feature, not a vendor diversity benefit.

Question 292

An organization plans to expand its operations internationally and needs to keep data at the new location secure. The organization wants to use the most secure architecture model possible. Which of the following models offers the highest level of security?

A. Cloud-based
B. Peer-to-peer
C. On-premises
D. Hybrid
Show Answer
Correct Answer: C
Explanation:
The question asks for the most secure architecture model possible, not the most scalable or convenient. An on‑premises model provides the highest level of security because the organization retains full control over data, infrastructure, access controls, and physical security. This minimizes reliance on third parties and allows tailored security policies, which is why it is generally considered the most secure option.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.