Comptia

SY0-701 Free Practice Questions — Page 30

Question 293

A company installed cameras and added signs to alert visitors that they are being recorded. Which of the following controls did the company implement? (Choose two.)

A. Directive
B. Deterrent
C. Preventive
D. Detective
E. Corrective
F. Technical
Show Answer
Correct Answer: B, D
Explanation:
The company implemented two types of controls. The warning signs act as a **deterrent control** because they discourage inappropriate or malicious behavior by informing people they are being recorded. The cameras act as a **detective control** because they are used to monitor and identify incidents after or as they occur. The controls do not prevent actions outright, nor are they corrective or directive in nature.

Question 294

Which of the following is a common, passive reconnaissance technique employed by penetration testers in the early phases of an engagement?

A. Open-source intelligence
B. Port scanning
C. Pivoting
D. Exploit validation
Show Answer
Correct Answer: A
Explanation:
Passive reconnaissance involves collecting information without directly interacting with the target systems. Open-source intelligence (OSINT) fits this definition because it relies on publicly available sources such as websites, social media, DNS records, and public databases. Port scanning is active, pivoting occurs after compromise, and exploit validation is an active testing phase.

Question 295

Which of the following would be the best way to test resiliency in the event of a primary power failure?

A. Parallel processing
B. Tabletop exercise
C. Simulation testing
D. Production failover
Show Answer
Correct Answer: D
Explanation:
The most effective way to test resiliency to a primary power failure is to perform a production failover. This approach validates that systems, infrastructure, and procedures can actually switch from the primary environment to backup resources under real operating conditions. Unlike tabletop exercises or simulations, production failover directly tests real-world behavior and dependencies, providing the most accurate assessment of true resiliency.

Question 296

A company's online shopping website became unusable shortly after midnight on January 30, 2023. When a security analyst reviewed the database server, the analyst noticed the following code used for backing up data: Which of the following should the analyst do next?

A. Check for recently terminated DBAs.
B. Review WAF logs for evidence of command injection.
C. Scan the database server for malware.
D. Search the web server for ransomware notes.
Show Answer
Correct Answer: A
Explanation:
The code shows a deliberate, time-based destructive action (dropping the database on a specific date), which is characteristic of a logic bomb rather than an external attack. This implies someone with privileged, internal access intentionally embedded the command into a scheduled backup or maintenance job. That points to an insider threat, such as a DBA, making it most appropriate to check for recently terminated or disgruntled DBAs rather than focusing first on WAF logs, malware scans, or ransomware indicators.

Question 297

An organization recently started hosting a new service that customers access through a web portal. A security engineer needs to add to the existing security devices a new solution to protect this new service. Which of the following is the engineer most likely to deploy?

A. Layer 4 firewall
B. NGFW
C. WAF
D. UTM
Show Answer
Correct Answer: C
Explanation:
The new service is accessed through a web portal, making it a web application. A Web Application Firewall (WAF) is specifically designed to protect web applications by inspecting HTTP/HTTPS traffic and defending against application-layer attacks such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 threats. The other options are broader or lower-layer controls and do not provide the same level of targeted web application protection.

Question 298

Which of the following is used to conceal credit card information in a database log file?

A. Tokenization
B. Masking
C. Hashing
D. Obfuscation
Show Answer
Correct Answer: B
Explanation:
For database log files, sensitive fields such as credit card numbers are typically **masked** so they are partially or fully hidden (e.g., **** **** **** 1234) while preserving format for troubleshooting and auditing. Tokenization is mainly used for secure storage or transaction processing, hashing is one-way and unsuitable for readable logs, and obfuscation is a generic term rather than a standard control. Therefore, masking best fits the purpose of concealing credit card data in logs.

Question 299

A security analyst is evaluating a SaaS application that the human resources department would like to implement. The analyst requests a SOC 2 report from the SaaS vendor. Which of the following processes is the analyst most likely conducting?

A. Internal audit
B. Penetration testing
C. Attestation
D. Due diligence
Show Answer
Correct Answer: D
Explanation:
Requesting a SOC 2 report from a SaaS vendor is part of evaluating a third party’s security controls, compliance posture, and risk before adoption. This activity is vendor risk assessment, commonly referred to as due diligence, not an internal audit, penetration test, or the attestation itself.

Question 300

Which of the following would be the most appropriate way to protect data in transit?

A. SHA-256
B. SSL3.0
C. TLS 1.3
D. AES-256
Show Answer
Correct Answer: C
Explanation:
The goal is to protect data in transit using a secure communication protocol. TLS 1.3 provides encryption, integrity, and authentication for data transmitted between endpoints and is the current best practice. SHA-256 is a hashing algorithm, SSL 3.0 is obsolete and insecure, and AES-256 is an encryption algorithm typically used within protocols (like TLS) or for data at rest rather than as a standalone transit protection.

Question 301

SIMULATION - A systems administrator is configuring a site-to-site VPN between two branch offices. Some of the settings have already been configured correctly. The systems administrator has been provided the following requirements as part of completing the configuration: • Most secure algorithms should be selected • All traffic should be encrypted over the VPN • A secret password will be used to authenticate the two VPN concentrators INSTRUCTIONS - Click on the two VPN Concentrators to configure the appropriate settings. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Illustration for SY0-701 question 301 Illustration for SY0-701 question 301 Illustration for SY0-701 question 301 Illustration for SY0-701 question 301 Illustration for SY0-701 question 301
Show Answer
Correct Answer: VPN Concentrator 1 Phase 1: Peer IP: 5.5.5.20 Auth: PSK Encryption: AES256 Hash: SHA256 DH group: 14 Phase 2: Mode: Tunnel Protocol: ESP Encryption: AES256 Hash: SHA256 Local: 192.168.1.0/24 Remote: 192.168.2.0/24 VPN Concentrator 2 Phase 1: Peer IP: 5.5.5.10 Auth: PSK Encryption: AES256 Hash: SHA256 DH group: 14 Phase 2: Mode: Tunnel Protocol: ESP Encryption: AES256 Hash: SHA256 Local: 192.168.2.0/24 Remote: 192.168.1.0/24
Explanation:
The requirements call for the most secure options and a shared secret. PSK satisfies the 'secret password' requirement. AES‑256 and SHA‑256 are the strongest available algorithms. ESP in tunnel mode encrypts all traffic between the two private networks, with matching local/remote subnets on each concentrator.

Question 302

Which of the following topics would most likely be included within an organization's SDLC?

A. Service-level agreements
B. Information security policy
C. Penetration testing methodology
D. Branch protection requirements
Show Answer
Correct Answer: C
Explanation:
The SDLC encompasses the phases and activities used to design, build, test, deploy, and maintain software. Testing activities—including security testing such as penetration testing—are commonly integrated into the SDLC (often referred to as a secure SDLC). Service-level agreements and information security policies are governance artifacts, not SDLC components, and branch protection requirements are repository/version-control controls rather than core SDLC topics. Therefore, penetration testing methodology best fits within an organization’s SDLC.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.