Comptia

SY0-701 Free Practice Questions — Page 31

Question 301

An organization is adopting cloud services at a rapid pace and now has multiple SaaS applications in use. Each application has a separate log-in, so the security team wants to reduce the number of credentials each employee must maintain. Which of the following is the first step the security team should take?

A. Enable SAML.
B. Create OAuth tokens.
C. Use password vaulting.
D. Select an IdP.
Show Answer
Correct Answer: D
Explanation:
The first step is to select an Identity Provider (IdP) to centralize authentication and enable single sign-on across multiple SaaS applications. After choosing an IdP, the organization can configure federation protocols such as SAML. OAuth is primarily for delegated authorization rather than SSO authentication, and password vaulting stores credentials but does not eliminate the need for multiple accounts or provide centralized identity.

Question 302

Which of the following control types is AUP an example of?

A. Physical
B. Managerial
C. Technical
D. Operational
Show Answer
Correct Answer: B
Explanation:
An Acceptable Use Policy (AUP) is a documented security policy that defines rules and expectations for users. Security policies are classified as managerial (administrative) controls because they provide governance and direction rather than directly implementing technical safeguards or physical protections. Operational controls are the day-to-day procedures used to carry out those policies, while the AUP itself is the policy.

Question 303

Which of the following agreement types is used to limit external discussions?

A. BPA
B. NDA
C. SLA
D. MSA
Show Answer
Correct Answer: B
Explanation:
An NDA (Non-Disclosure Agreement) is specifically designed to restrict the disclosure of confidential information and limit external discussions about protected information. A BPA is not a confidentiality agreement, an SLA defines service performance expectations, and an MSA establishes general contractual terms between parties.

Question 304

A systems administrator deployed a monitoring solution that does not require installation on the endpoints that the solution is monitoring. Which of the following is described in this scenario?

A. Agentless solution
B. Client-based soon
C. Open port
D. File-based solution
Show Answer
Correct Answer: A
Explanation:
An agentless solution monitors endpoints without requiring software to be installed on each endpoint. It typically uses existing remote management protocols to collect data. The other options do not describe this deployment model.

Question 305

A security analyst is reviewing the source code of an application in order to identify misconfigurations and vulnerabilities. Which of the following kinds of analysis best describes this review?

A. Dynamic
B. Static
C. Gap
D. Impact
Show Answer
Correct Answer: B
Explanation:
Reviewing an application's source code without executing it is static analysis. Static analysis is used to identify coding flaws, security vulnerabilities, and certain misconfigurations directly from the source or compiled code. Dynamic analysis requires the application to be running, while gap analysis compares current and desired states, and impact analysis evaluates the consequences of changes or vulnerabilities.

Question 306

The author of a software package is concerned about bad actors repackaging and inserting malware into the software. The software download is hosted on a website, and the author exclusively controls the website's contents. Which of the following techniques would best ensure the software's integrity?

A. Input validation
B. Code signing
C. Secure cookies
D. Fuzzing
Show Answer
Correct Answer: B
Explanation:
Code signing digitally signs the software so recipients can verify both its authenticity (it came from the publisher) and its integrity (it has not been modified). If an attacker repackages the software with malware, the signature verification will fail. Input validation protects applications from invalid input, secure cookies protect web session data, and fuzzing is a testing technique for finding bugs rather than ensuring distributed software integrity.

Question 307

A multinational bank hosts several servers in its data center. These servers run a business-critical application used by customers to access their account information. Which of the following should the bank use to ensure accessibility during peak usage times?

A. Load balancer
B. Cloud backups
C. Geographic dispersal
D. Disk multipathing
Show Answer
Correct Answer: A
Explanation:
A load balancer distributes incoming client requests across multiple servers, preventing any single server from becoming overloaded during peak traffic. This improves application availability, responsiveness, and scalability for a business-critical customer-facing service. Cloud backups are for data recovery, geographic dispersal primarily improves disaster resilience rather than handling peak load, and disk multipathing provides redundant storage paths rather than balancing application traffic.

Question 308

Which of the following is the best reason an organization should enforce a data classification policy to help protect its most sensitive information?

A. End users will be required to consider the classification of data that can be used in documents.
B. The policy will result in the creation of access levels for each level of classification.
C. The organization will have the ability to create security requirements based on classification levels.
D. Security analysts will be able to see the classification of data within a document before opening it.
Show Answer
Correct Answer: C
Explanation:
A data classification policy enables an organization to categorize information by sensitivity and then define and enforce appropriate security controls for each classification level. This is the primary purpose of data classification. The other options describe possible side effects or implementation details, but they are not the fundamental reason to enforce the policy.

Question 309

Which of the following best describes a social engineering attack that uses a targeted electronic messaging campaign aimed at a Chief Executive Officer?

A. Whaling
B. Spear phishing
C. Impersonation
D. Identity fraud
Show Answer
Correct Answer: A
Explanation:
Whaling is a specialized form of spear phishing that targets high-profile executives such as CEOs, CFOs, or other senior leaders using highly tailored electronic messages. While spear phishing is targeted phishing in general, attacks specifically aimed at a CEO are best described as whaling.

Question 310

A user is requesting Telnet access to manage a remote development web server. Insecure protocols are not allowed for use within any environment. Which of the following should be configured to allow remote access to this server?

A. HTTPS
B. SNMPv3
C. SSH
D. RDP
E. SMTP
Show Answer
Correct Answer: C
Explanation:
SSH is the secure replacement for Telnet, providing encrypted remote command-line access for server administration. HTTPS secures web traffic rather than shell management, SNMPv3 is for network device management/monitoring, RDP is for remote graphical desktop access (primarily Windows), and SMTP is for email transport.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.