Comptia

SY0-701 Free Practice Questions — Page 5

Question 42

Which of the following can be used to mitigate attacks from high-risk regions?

A. Obfuscation
B. Data sovereignty
C. IP geolocation
D. Encryption
Show Answer
Correct Answer: C
Explanation:
IP geolocation can identify the geographic origin of incoming traffic and enable geofencing or blocking of requests from high-risk regions. The other options do not control or restrict access based on location.

Question 43

Which of the following activities should be performed first to compile a list of vulnerabilities in an environment?

A. Automated scanning
B. Penetration testing
C. Threat hunting
D. Log aggregation
E. Adversarial emulation
Show Answer
Correct Answer: A
Explanation:
Automated scanning should be performed first because it provides a broad, systematic way to identify known vulnerabilities across systems, networks, and applications. It quickly builds an initial vulnerability baseline, which can then be validated or explored further through more targeted and resource-intensive activities such as penetration testing or adversarial emulation. The other options focus on exploiting, detecting, or monitoring threats rather than initially compiling a vulnerability list.

Question 44

A penetration test identifies that an SMBv1 is enabled on multiple servers across an organization. The organization wants to remediate this vulnerability in the most efficient way possible. Which of the following should the organization use for this purpose?

A. GPO
B. ACL
C. SFTP
D. DLP
Show Answer
Correct Answer: A
Explanation:
Disabling SMBv1 across many servers is best done centrally and at scale. Group Policy Objects allow administrators to enforce configuration changes, such as disabling legacy protocols like SMBv1, across all domain-joined systems efficiently. ACLs manage permissions, SFTP is a file transfer protocol unrelated to SMB, and DLP addresses data leakage rather than protocol configuration.

Question 45

Which of the following best protects sensitive data in transit across a geographically dispersed infrastructure?

A. Encryption
B. Masking
C. Tokenization
D. Obfuscation
Show Answer
Correct Answer: A
Explanation:
Encryption is specifically designed to protect data in transit by transforming it into an unreadable format that can only be decrypted by authorized parties. This ensures confidentiality across networks and geographically dispersed infrastructures. Masking, tokenization, and obfuscation are primarily used for data at rest or non-production use, not for securing data during transmission.

Question 46

A company is concerned about employees unintentionally introducing malware into the network. The company identified fifty employees who clicked on a link embedded in an email sent by the internal IT department. Which of the following should the company implement to best improve its security posture?

A. Social engineering training
B. SPF configuration
C. Simulated phishing campaign
D. Insider threat awareness
Show Answer
Correct Answer: A
Explanation:
The employees already demonstrated susceptibility by clicking a link in an internally sent email. The most effective improvement is targeted social engineering training, which addresses the root cause—user behavior—by teaching employees how to recognize and resist phishing and other manipulation techniques. SPF is a technical email control, simulated phishing has effectively already occurred, and insider threat awareness does not directly address unintentional malware introduction via phishing.

Question 47

Which of the following actions best addresses a vulnerability found on a company's web server?

A. Patching
B. Segmentation
C. Decommissioning
D. Monitoring
Show Answer
Correct Answer: A
Explanation:
Patching directly remediates the identified vulnerability by applying vendor-provided fixes or updates. Segmentation and monitoring are compensating controls that reduce impact or improve detection but do not fix the flaw itself, and decommissioning is only appropriate if the server is no longer needed.

Question 48

A systems administrator needs to encrypt all data on employee laptops. Which of the following encryption levels should be implemented?

A. Volume
B. Partition
C. Full disk
D. File
Show Answer
Correct Answer: C
Explanation:
Full disk encryption encrypts the entire storage device, including the operating system, applications, system files, and user data. This provides comprehensive protection for laptops, especially if they are lost or stolen. Volume, partition, or file encryption only protect subsets of the disk and can leave other data exposed.

Question 50

As part of new compliance audit requirements, multiple servers need to be segmented on different networks and should be reachable only from authorized internal systems. Which of the following would meet the requirements?

A. Configure firewall rules to block external access to Internal resources.
B. Set up a WAP to allow internal access from public networks.
C. Implement a new IPSec tunnel from internal resources.
D. Deploy an internal jump server to access resources.
Show Answer
Correct Answer: D
Explanation:
The requirement is to segment servers onto different networks and ensure they are reachable only from authorized internal systems. An internal jump server (bastion host) provides a controlled access point where authentication, authorization, logging, and monitoring can be enforced before reaching segmented networks. Firewall rules blocking external access alone do not ensure controlled, authorized internal access or proper segmentation, IPSec focuses on encryption rather than access control, and a WAP is inappropriate for secure internal segmentation.

Question 51

A company is changing its mobile device policy. The company has the following requirements: • Company-owned devices • Ability to harden the devices • Reduced security risk • Compatibility with company resources Which of the following would best meet these requirements?

A. BYOD
B. CYOD
C. COPE
D. COBO
Show Answer
Correct Answer: D
Explanation:
The requirements call for company-owned devices, maximum ability to harden them, reduced security risk, and assured compatibility with company resources. COBO (Company-Owned, Business-Only) provides full corporate ownership and exclusive business use, allowing strict configuration, hardening, and policy enforcement while eliminating risks from personal apps or data. BYOD, CYOD, and COPE all permit some level of personal choice or use, which increases risk compared to COBO.

Question 52

Which of the following can best contribute to prioritizing patch applications?

A. CVSS
B. SCAP
C. OSINT
D. CVE
Show Answer
Correct Answer: A
Explanation:
CVSS (Common Vulnerability Scoring System) assigns standardized severity scores to vulnerabilities based on exploitability and impact. These scores directly support risk-based prioritization of patching efforts. SCAP automates vulnerability management, CVE only identifies vulnerabilities without scoring, and OSINT provides contextual threat information but does not prioritize patches.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.