Comptia

SY0-701 Free Practice Questions — Page 5

Question 41

Which of the following activities should be performed first to compile a list of vulnerabilities in an environment?

A. Automated scanning
B. Penetration testing
C. Threat hunting
D. Log aggregation
E. Adversarial emulation
Show Answer
Correct Answer: A
Explanation:
Automated vulnerability scanning is the appropriate first activity for compiling a list of vulnerabilities across an environment. It efficiently identifies known weaknesses such as missing patches, insecure configurations, and outdated software. Penetration testing and adversarial emulation are follow-on validation exercises, threat hunting focuses on active threats rather than vulnerability enumeration, and log aggregation supports monitoring rather than discovering vulnerabilities.

Question 42

A penetration test identifies that an SMBv1 is enabled on multiple servers across an organization. The organization wants to remediate this vulnerability in the most efficient way possible. Which of the following should the organization use for this purpose?

A. GPO
B. ACL
C. SFTP
D. DLP
Show Answer
Correct Answer: A
Explanation:
Group Policy Objects (GPOs) allow administrators in a Windows Active Directory environment to centrally configure and enforce settings across multiple servers, including disabling the SMBv1 protocol. This is the most efficient way to remediate the issue organization-wide. ACLs manage permissions, SFTP is a secure file transfer protocol unrelated to disabling SMBv1, and DLP focuses on preventing data exfiltration rather than protocol configuration.

Question 43

Which of the following best protects sensitive data in transit across a geographically dispersed infrastructure?

A. Encryption
B. Masking
C. Tokenization
D. Obfuscation
Show Answer
Correct Answer: A
Explanation:
Encryption is the primary control for protecting sensitive data in transit. It ensures confidentiality by making intercepted data unreadable without the appropriate cryptographic keys. Masking, tokenization, and obfuscation are generally used for protecting stored data, limiting data exposure, or development/testing scenarios rather than securing data during transmission.

Question 44

A company is concerned about employees unintentionally introducing malware into the network. The company identified fifty employees who clicked on a link embedded in an email sent by the internal IT department. Which of the following should the company implement to best improve its security posture?

A. Social engineering training
B. SPF configuration
C. Simulated phishing campaign
D. Insider threat awareness
Show Answer
Correct Answer: A
Explanation:
The internal IT department has already effectively conducted a simulated phishing exercise by sending a test email. The results identified employees susceptible to phishing. The best next step to improve the organization's security posture is to provide social engineering training so employees learn to recognize and resist phishing and other manipulation techniques. SPF is an email authentication control, not a user behavior mitigation, and insider threat awareness focuses on malicious or negligent insiders rather than phishing susceptibility.

Question 45

Which of the following actions best addresses a vulnerability found on a company's web server?

A. Patching
B. Segmentation
C. Decommissioning
D. Monitoring
Show Answer
Correct Answer: A
Explanation:
Patching is the primary remediation for a discovered software vulnerability because it applies vendor fixes that remove or mitigate the underlying flaw. Segmentation and monitoring are compensating or detective controls, and decommissioning is only appropriate if the server is being retired.

Question 46

A systems administrator needs to encrypt all data on employee laptops. Which of the following encryption levels should be implemented?

A. Volume
B. Partition
C. Full disk
D. File
Show Answer
Correct Answer: C
Explanation:
Full disk encryption encrypts the entire storage device, including the operating system, system files, applications, and user data. This provides comprehensive protection for all data on employee laptops. Volume or partition encryption protects only selected logical areas, and file encryption protects only individual files rather than the entire device.

Question 47

After a series of account compromises and credential misuse, a company hires a security manager to develop a security program. Which of the following steps should the security manager take first to increase security awareness?

A. Evaluate tools that identify risky behavior and distribute reports on the findings.
B. Send quarterly newsletters that explain the importance of password management.
C. Develop phishing campaigns and notify the management team of any successes.
D. Update policies and handbooks to ensure all employees are informed of the new procedures.
Show Answer
Correct Answer: D
Explanation:
A security program should begin with governance: establishing or updating security policies and procedures that define expectations and required behaviors. Awareness activities should be aligned with these policies. Evaluating monitoring tools (A) and phishing campaigns (C) are implementation and assessment activities that follow, while newsletters (B) are a limited awareness mechanism rather than the foundational first step.

Question 48

As part of new compliance audit requirements, multiple servers need to be segmented on different networks and should be reachable only from authorized internal systems. Which of the following would meet the requirements?

A. Configure firewall rules to block external access to Internal resources.
B. Set up a WAP to allow internal access from public networks.
C. Implement a new IPSec tunnel from internal resources.
D. Deploy an internal jump server to access resources.
Show Answer
Correct Answer: D
Explanation:
The requirement is not only segmentation but that the segmented servers be reachable only from authorized internal systems. A jump server provides a controlled access point so administrators or authorized internal users must connect through it to reach the protected servers. A firewall blocking external access alone does not ensure only authorized internal systems can reach the segmented networks, while a WAP is unrelated and an IPsec tunnel provides encryption rather than segmentation or access restriction.

Question 49

A company is changing its mobile device policy. The company has the following requirements: • Company-owned devices • Ability to harden the devices • Reduced security risk • Compatibility with company resources Which of the following would best meet these requirements?

A. BYOD
B. CYOD
C. COPE
D. COBO
Show Answer
Correct Answer: D
Explanation:
COBO (Company-Owned, Business-Only) best matches all stated requirements. The devices are company-owned, allowing full administrative control and hardening, they are restricted to business use which minimizes security risk compared with personal-use models, and standardized corporate-managed devices maximize compatibility with company resources.

Question 50

Which of the following can best contribute to prioritizing patch applications?

A. CVSS
B. SCAP
C. OSINT
D. CVE
Show Answer
Correct Answer: A
Explanation:
CVSS (Common Vulnerability Scoring System) assigns standardized severity scores to vulnerabilities, allowing organizations to prioritize patching based on risk. CVE only identifies vulnerabilities, SCAP automates security content and assessment, and OSINT provides publicly available intelligence but is not a patch prioritization framework.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.