Comptia

SY0-701 Free Practice Questions — Page 3

Question 21

A business provides long-term cold storage services to banks that are required to follow regulator-imposed data retention guidelines. Banks that use these services require that data is disposed of in a specific manner at the conclusion of the regulatory threshold for data retention. Which of the following aspects of data management is the most important to the bank in the destruction of this data?

A. Encryption
B. Classification
C. Certification
D. Procurement
Show Answer
Correct Answer: C
Explanation:
Banks must be able to demonstrate to regulators that data was destroyed in an approved, compliant manner at the end of the retention period. Certification (e.g., certificates of destruction, adherence to standards like NIST 800-88) provides auditable proof of proper disposal. Encryption, classification, and procurement do not address verified destruction.

Question 22

Which of the following is a prerequisite for a DLP solution?

A. Data destruction
B. Data sanitization
C. Data classification
D. Data masking
Show Answer
Correct Answer: C
Explanation:
A Data Loss Prevention (DLP) solution must first know what data is sensitive in order to monitor, control, or prevent its leakage. Data classification identifies and categorizes data based on sensitivity and value, making it a fundamental prerequisite for effective DLP. The other options are data handling techniques that may be applied after sensitive data is identified, not prerequisites.

Question 23

Which of the following is a type of vulnerability that may result from outdated algorithms or keys?

A. Hash collision
B. Cryptographic
C. Buffer overflow
D. Input validation
Show Answer
Correct Answer: B
Explanation:
Outdated or weak algorithms and cryptographic keys lead to cryptographic vulnerabilities, such as broken encryption, compromised confidentiality, or forged signatures. These issues fall under the category of cryptographic vulnerabilities, not buffer overflows or input validation flaws.

Question 24

A company wants to prevent proprietary and confidential company information from being shared to outsiders. Which of the following would this best describe?

A. MOA
B. SLA
C. MSA
D. NDA
Show Answer
Correct Answer: D
Explanation:
An NDA (Non-Disclosure Agreement) is specifically designed to prevent proprietary or confidential company information from being disclosed to unauthorized outsiders. The other options govern broader relationships or service terms rather than confidentiality protection.

Question 25

Which of the following solutions would most likely be used in the financial industry to mask sensitive data?

A. Tokenization
B. Hashing
C. Salting
D. Steganography
Show Answer
Correct Answer: A
Explanation:
Tokenization is widely used in the financial industry to protect sensitive data such as credit card numbers by replacing them with non-sensitive tokens that have no exploitable value. The original data is stored securely and only referenced when necessary, allowing systems to function without exposing real financial information. Hashing and salting are mainly for password storage, and steganography is about hiding data within other data, not masking financial records.

Question 26

Which of the following is used to calculate the impact to an organization per cybersecurity incident?

A. SLE
B. ALE
C. ARO
D. SLA
Show Answer
Correct Answer: A
Explanation:
Single Loss Expectancy (SLE) measures the financial impact of a single cybersecurity incident by estimating the loss from one occurrence (typically AV × EF). ALE measures annual impact, ARO measures frequency, and SLA is unrelated.

Question 27

A security administrator needs to reduce the attack surface in the company's data centers. Which of the following should the security administrator do to complete this task?

A. Implement a honeynet.
B. Define Group Policy on the servers.
C. Configure the servers for high availability.
D. Upgrade end-of-support operating systems.
Show Answer
Correct Answer: D
Explanation:
Reducing the attack surface means eliminating known and unnecessary vulnerabilities. End-of-support operating systems no longer receive security patches, leaving exploitable flaws permanently exposed. Upgrading to supported OS versions restores regular security updates and hardening capabilities, directly reducing exploitable entry points. The other options do not primarily reduce attack surface: honeynets increase exposure for monitoring, high availability focuses on resilience, and Group Policy helps configuration management but does not address inherent unpatched OS vulnerabilities as effectively.

Question 28

A site reliability engineer is designing a recovery strategy that requires quick failover to an identical site if the primary facility goes down. Which of the following types of sites should the engineer consider?

A. Recovery site
B. Hot site
C. Cold site
D. Warm site
Show Answer
Correct Answer: B
Explanation:
A hot site is a fully equipped and operational replica of the primary site with current data, enabling rapid or near-immediate failover. This matches the requirement for quick recovery to an identical site if the primary facility goes down. Cold and warm sites do not provide sufficiently fast failover, and "recovery site" is too generic.

Question 29

Which of the following would an organization most likely use to minimize the loss of data on a file server in the event data needs to be restored?

A. Snapshots
B. Journaling
C. Obfuscation
D. Tokenization
Show Answer
Correct Answer: A
Explanation:
Snapshots provide point-in-time copies of file system data, allowing rapid restoration to a recent state and thereby minimizing data loss after accidental deletion, corruption, or system failure. Journaling focuses on file system consistency rather than recovery, while obfuscation and tokenization are data protection techniques unrelated to backup or restoration.

Question 30

SIMULATION - A security analyst is creating the first draft of a network diagram for the company’s new customer-facing payment application that will be hosted by a third-party cloud service provider. INSTRUCTIONS - Click the ? to select the appropriate icons to create a secure, redundant web application. Then use the dropdown menu to select the appropriate subnet type. Every space in the diagram must be filled. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Illustration for SY0-701 question 30 Illustration for SY0-701 question 30
Show Answer
Correct Answer: Top (Internet-facing): WAF Public Subnet: Load Balancer (redundant) Application tier: Autoscaling Instances Private Subnet: Application Instances (multiple) Private Subnet (lowest): Database Subnet dropdown (middle): Private Subnet
Explanation:
Incoming traffic flows from the Internet Gateway through a WAF, then to redundant public load balancers. Application servers run behind the load balancer using autoscaling for resilience. Backend application instances and the database are placed in private subnets to prevent direct internet access and improve security and availability.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.