Comptia

SY0-701 Free Practice Questions — Page 4

Question 31

A growing organization, which hosts an externally accessible application, adds multiple virtual servers to improve application performance and decrease the resource usage on individual servers. Which of the following solutions is the organization most likely to employ to further increase performance and availability?

A. Load balancer
B. Jump server
C. Proxy server
D. SD-WAN
Show Answer
Correct Answer: A
Explanation:
A load balancer distributes incoming client requests across multiple virtual servers, improving performance by balancing resource utilization and increasing availability by routing traffic away from failed or overloaded servers. A jump server is for administrative access, a proxy server intermediates client requests but does not primarily provide server load distribution, and SD-WAN optimizes WAN connectivity rather than balancing application traffic.

Question 32

Which of the following would most likely be deployed to obtain and analyze attacker activity and techniques?

A. Firewall
B. IDS
C. Honeypot
D. Layer 3 switch
Show Answer
Correct Answer: C
Explanation:
A honeypot is specifically deployed as a decoy system to attract attackers so defenders can observe, collect, and analyze their behavior, tools, and techniques. A firewall filters traffic, an IDS detects suspicious activity but is not primarily designed to lure and study attackers, and a Layer 3 switch performs network routing/switching functions.

Question 33

Employees sign an agreement that restricts specific activities when leaving the company. Violating the agreement can result in legal consequences. Which of the following agreements does this best describe?

A. SLA
B. BPA
C. NDA
D. MOA
Show Answer
Correct Answer: C
Explanation:
The agreement described is a Non-Disclosure Agreement (NDA). Employees commonly sign an NDA to protect confidential or proprietary information during and after employment. If they disclose protected information after leaving the company, they may face legal consequences. An SLA defines service levels, a BPA is a business partnership/process agreement depending on context, and an MOA is a memorandum of agreement.

Question 34

Which of the following is prevented by proper data sanitization?

A. Hackers’ ability to obtain data from used hard drives
B. Devices reaching end-of-life and losing support
C. Disclosure of sensitive data through incorrect classification
D. Incorrect inventory data leading to a laptop shortage
Show Answer
Correct Answer: A
Explanation:
Proper data sanitization securely removes or destroys data on storage media so it cannot be recovered after reuse or disposal. This prevents unauthorized parties from obtaining data from used hard drives. The other options relate to lifecycle management, data classification, or asset inventory rather than sanitization.

Question 35

The number of tickets the help desk has been receiving has increased recently due to numerous false-positive phishing reports. Which of the following would be best to help to reduce the false positives?

A. Performing more phishing simulation campaigns
B. Improving security awareness training
C. Hiring more help desk staff
D. Implementing an incident reporting web page
Show Answer
Correct Answer: B
Explanation:
Improving security awareness training is the best way to reduce false-positive phishing reports because it helps users better distinguish legitimate emails from actual phishing attempts. More simulations primarily assess and reinforce behavior but are less directly targeted at correcting widespread misclassification. Hiring staff addresses capacity rather than the cause, and a reporting web page changes the reporting mechanism without reducing false positives.

Question 36

A systems administrator receives a text message from an unknown number claiming to be the Chief Executive Officer of the company. The message states an emergency situation requires a password reset. Which of the following threat vectors is being used?

A. Typosquatting
B. Smishing
C. Pretexting
D. Impersonation
Show Answer
Correct Answer: B
Explanation:
The threat vector is smishing, which is phishing conducted via SMS/text messages. The attacker uses a text message to create urgency and trick the administrator into performing a password reset. Although the message includes impersonation of the CEO and a fabricated emergency (pretext), the primary threat vector described is SMS-based phishing (smishing).

Question 37

Which of the following most accurately describes the order in which a security engineer should implement secure baselines?

A. Deploy, maintain, establish
B. Establish, maintain, deploy
C. Establish, deploy, maintain
D. Deploy, establish, maintain
Show Answer
Correct Answer: C
Explanation:
The correct implementation lifecycle for secure baselines is to first establish the baseline by defining secure configuration standards, then deploy those configurations across systems, and finally maintain them through ongoing monitoring, updates, patching, and periodic review. This aligns with standard security configuration management practices.

Question 38

A CVE in a key back-end component of an application has been disclosed. The systems administrator is identifying all of the systems in the environment that are susceptible to this risk. Which of the following should the systems administrator perform?

A. Packet capture
B. Vulnerability scan
C. Metadata analysis
D. Automated reporting
Show Answer
Correct Answer: B
Explanation:
A vulnerability scan is the appropriate action to identify systems affected by a disclosed CVE. Vulnerability scanners compare installed software, versions, and configurations against databases of known vulnerabilities to determine which hosts are susceptible. Packet captures analyze network traffic, metadata analysis does not identify software exposure to CVEs, and automated reporting summarizes findings rather than discovering vulnerable systems.

Question 39

Which of the following would be the greatest concern for a company that is aware of the consequences of non-compliance with government regulations?

A. Right to be forgotten
B. Sanctions
C. External compliance reporting
D. Attestation
Show Answer
Correct Answer: B
Explanation:
Sanctions are the direct consequences imposed by governments for regulatory non-compliance, including fines, legal penalties, operational restrictions, or loss of licenses. External compliance reporting and attestation are compliance mechanisms or obligations, while the right to be forgotten is a specific privacy right rather than the overarching consequence of non-compliance.

Question 40

Which of the following can be used to mitigate attacks from high-risk regions?

A. Obfuscation
B. Data sovereignty
C. IP geolocation
D. Encryption
Show Answer
Correct Answer: C
Explanation:
IP geolocation enables organizations to identify the geographic origin of incoming connections and apply geofencing or access controls to block or restrict traffic from high-risk regions. Obfuscation, data sovereignty, and encryption do not directly mitigate attacks based on geographic source.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.