Comptia

SY0-701 Free Practice Questions — Page 30

Question 291

A company installed cameras and added signs to alert visitors that they are being recorded. Which of the following controls did the company implement? (Choose two.)

A. Directive
B. Deterrent
C. Preventive
D. Detective
E. Corrective
F. Technical
Show Answer
Correct Answer: B, D
Explanation:
Signs warning of surveillance primarily act as a deterrent by discouraging unwanted behavior. Cameras are detective controls because they monitor and record activity to detect events. While signs provide notice, they are not typically classified as directive controls in this context because they do not instruct users on required behavior; they warn of monitoring. Preventive controls stop actions from occurring, which cameras alone do not do.

Question 292

Which of the following is a common, passive reconnaissance technique employed by penetration testers in the early phases of an engagement?

A. Open-source intelligence
B. Port scanning
C. Pivoting
D. Exploit validation
Show Answer
Correct Answer: A
Explanation:
Passive reconnaissance gathers information without directly interacting with the target. Open-source intelligence (OSINT) uses publicly available sources such as websites, social media, public records, and search engines to collect information. Port scanning is active reconnaissance, while pivoting and exploit validation occur later during exploitation or post-exploitation phases.

Question 293

Which of the following would be the best way to test resiliency in the event of a primary power failure?

A. Parallel processing
B. Tabletop exercise
C. Simulation testing
D. Production failover
Show Answer
Correct Answer: D
Explanation:
Production failover provides the most realistic validation of resiliency by intentionally transferring operations from the primary environment to the backup/secondary environment under production conditions. This directly verifies that continuity mechanisms work during a primary power loss. Tabletop exercises are discussion-based, simulation testing is less representative than an actual failover, and parallel processing is unrelated to testing power-failure resiliency.

Question 294

A company's online shopping website became unusable shortly after midnight on January 30, 2023. When a security analyst reviewed the database server, the analyst noticed the following code used for backing up data: Which of the following should the analyst do next?

A. Check for recently terminated DBAs.
B. Review WAF logs for evidence of command injection.
C. Scan the database server for malware.
D. Search the web server for ransomware notes.
Show Answer
Correct Answer: A
Explanation:
The embedded date-triggered destructive SQL in a backup script is characteristic of a logic bomb, indicating code was intentionally planted in a scheduled administrative process. The most appropriate next step is to investigate privileged insider access, such as recently terminated DBAs, rather than focusing first on external attack vectors like WAF logs. No web search results were provided, so there are no supporting URLs.

Question 295

An organization recently started hosting a new service that customers access through a web portal. A security engineer needs to add to the existing security devices a new solution to protect this new service. Which of the following is the engineer most likely to deploy?

A. Layer 4 firewall
B. NGFW
C. WAF
D. UTM
Show Answer
Correct Answer: C
Explanation:
A Web Application Firewall (WAF) is specifically designed to protect web applications and HTTP/HTTPS services. Since the new customer-facing service is accessed through a web portal, a WAF provides targeted protection against web application attacks such as SQL injection, cross-site scripting (XSS), and other application-layer threats. A Layer 4 firewall operates at the transport layer, an NGFW provides broader network security but is not as specialized for web application protection, and a UTM is a general-purpose security appliance rather than the most appropriate dedicated control for a web portal.

Question 296

Which of the following is used to conceal credit card information in a database log file?

A. Tokenization
B. Masking
C. Hashing
D. Obfuscation
Show Answer
Correct Answer: B
Explanation:
Masking is specifically used to conceal sensitive data such as credit card numbers in outputs like logs by obscuring all or part of the value (for example, showing only the last four digits). Tokenization replaces the value with a surrogate token for storage or processing, while hashing is one-way and obfuscation is a broader, less specific term.

Question 297

A security analyst is evaluating a SaaS application that the human resources department would like to implement. The analyst requests a SOC 2 report from the SaaS vendor. Which of the following processes is the analyst most likely conducting?

A. Internal audit
B. Penetration testing
C. Attestation
D. Due diligence
Show Answer
Correct Answer: D
Explanation:
Requesting a SOC 2 report from a prospective SaaS vendor is part of evaluating the vendor's security controls and risk before adoption, which is a due diligence activity. A SOC 2 report is an attestation report produced by an independent auditor, but the analyst's process of requesting and reviewing it is due diligence, not performing the attestation itself. It is also not an internal audit or penetration test.

Question 298

Which of the following would be the most appropriate way to protect data in transit?

A. SHA-256
B. SSL3.0
C. TLS 1.3
D. AES-256
Show Answer
Correct Answer: C
Explanation:
TLS 1.3 is the modern protocol specifically designed to protect data in transit by providing encryption, integrity, and authentication for network communications. SHA-256 is a hashing algorithm, SSL 3.0 is obsolete and insecure, and AES-256 is a symmetric encryption algorithm rather than a complete transport security protocol.

Question 299

SIMULATION - A systems administrator is configuring a site-to-site VPN between two branch offices. Some of the settings have already been configured correctly. The systems administrator has been provided the following requirements as part of completing the configuration: • Most secure algorithms should be selected • All traffic should be encrypted over the VPN • A secret password will be used to authenticate the two VPN concentrators INSTRUCTIONS - Click on the two VPN Concentrators to configure the appropriate settings. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Illustration for SY0-701 question 299 Illustration for SY0-701 question 299 Illustration for SY0-701 question 299 Illustration for SY0-701 question 299 Illustration for SY0-701 question 299
Show Answer
Correct Answer: VPN Concentrator 1 Phase 1: Peer 5.5.5.20, PSK, AES256, SHA256 Phase 2: ESP, AES256, SHA256, Local 192.168.1.0/24, Remote 192.168.2.0/24 VPN Concentrator 2 Phase 1: Peer 5.5.5.10, PSK, AES256, SHA256 Phase 2: ESP, AES256, SHA256, Local 192.168.2.0/24, Remote 192.168.1.0/24
Explanation:
Use PSK because the requirement specifies a shared secret password. Select the strongest available algorithms (AES256 and SHA256), ESP to provide encryption, and configure each concentrator with the opposite peer IP and corresponding local/remote subnets. DH group 14 and Main mode are already set.

Question 300

Which of the following topics would most likely be included within an organization's SDLC?

A. Service-level agreements
B. Information security policy
C. Penetration testing methodology
D. Branch protection requirements
Show Answer
Correct Answer: D
Explanation:
An organization's SDLC documentation commonly includes development-specific requirements and controls. Branch protection requirements are part of secure software development practices, governing how code is reviewed, approved, and merged. Service-level agreements and information security policies are broader governance documents, while a penetration testing methodology is typically a separate security testing standard rather than a core SDLC topic.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.