Comptia

SY0-701 Free Practice Questions — Page 7

Question 63

A company has yearly engagements with a service provider. The general terms and conditions are the same for all engagements. The company wants to simplify the process and revisit the general terms every three years. Which of the following documents would provide the best way to set the general terms?

A. MSA
B. NDA
C. MOU
D. SLA
Show Answer
Correct Answer: A
Explanation:
A Master Service Agreement (MSA) sets overarching terms and conditions for an ongoing relationship across multiple engagements, allowing individual projects to be governed by statements of work while revisiting the general terms periodically (e.g., every three years). NDAs cover confidentiality only, MOUs are typically non-binding, and SLAs focus on service performance metrics rather than broad contractual terms.

Question 64

A user needs to complete training at https://comptiatraining.com. After manually entering the URL, the user sees that the accessed website is noticeably different from the standard company website. Which of the following is the most likely explanation for the difference?

A. Cross-site scripting
B. Pretexting
C. Typosquatting
D. Vishing
Show Answer
Correct Answer: C
Explanation:
Manually entering a URL that leads to a site resembling but differing from the legitimate one is characteristic of typosquatting, where attackers register look‑alike or misspelled domains to deceive users. The other options involve social engineering or client-side attacks and do not explain a different website due to a similar domain name.

Question 65

While a school district is performing state testing, a security analyst notices all internet services are unavailable. The analyst discovers that ARP poisoning is occurring on the network and then terminates access for the host. Which of the following is most likely responsible for this malicious activity?

A. Unskilled attacker
B. Shadow IT
C. Insider threat
D. Nation-state
Show Answer
Correct Answer: C
Explanation:
ARP poisoning must be launched from within the same local network segment. During state testing, the attacker clearly had internal network access and intent to disrupt operations. This best aligns with an insider threat (such as a student or staff member) rather than shadow IT, a nation-state, or an external unskilled attacker.

Question 66

Which of the following could potentially be introduced at the time of side loading?

A. User impersonation
B. Rootkit
C. On-path attack
D. Buffer overflow
Show Answer
Correct Answer: B
Explanation:
Side loading installs software from untrusted sources, bypassing platform security controls. This creates an opportunity to introduce malicious software such as a rootkit, which can embed itself deeply in the system with elevated privileges. The other options describe attacks or vulnerabilities that are not directly introduced by the act of side loading itself.

Question 67

A contractor is required to visually inspect the motherboards of all new servers that are purchased to determine whether the servers were tampered with. Which of the following risks is the contractor attempting to mitigate?

A. Embedded rootkit
B. Supply chain
C. Firmware failure
D. RFID keylogger
Show Answer
Correct Answer: B
Explanation:
Visually inspecting motherboards for tampering aims to detect malicious modifications or unauthorized components introduced during manufacturing or shipping. This directly mitigates supply chain risk, where hardware is compromised before it reaches the organization.

Question 68

Which of the following is the most important element when defining effective security governance?

A. Discovering and documenting external considerations
B. Developing procedures for employee onboarding and offboarding
C. Assigning roles and responsibilities for owners, controllers, and custodians
D. Defining and monitoring change management procedures
Show Answer
Correct Answer: C
Explanation:
Effective security governance is built on accountability. Clearly assigning roles and responsibilities—such as data owners, controllers, and custodians—establishes decision authority, accountability, and oversight for security controls. Other options describe important operational or supporting activities, but without defined ownership and responsibility, governance cannot function effectively.

Question 69

An engineer needs to ensure that a script has not been modified before it is launched. Which of the following best provides this functionality?

A. Masking
B. Obfuscation
C. Hashing
D. Encryption
Show Answer
Correct Answer: C
Explanation:
Hashing provides integrity verification. By computing and storing a known-good hash of the script and recomputing the hash before execution, any modification to the script will result in a different hash value, indicating tampering. Masking hides data, obfuscation only makes code harder to read, and encryption focuses on confidentiality rather than detecting modification.

Question 70

An organization designs an inbound firewall with a fail-open configuration while implementing a website. Which of the following would the organization consider to be the highest priority?

A. Confidentiality
B. Non-repudiation
C. Availability
D. Integrity
Show Answer
Correct Answer: C
Explanation:
A fail-open firewall allows traffic to pass if the firewall fails, prioritizing continued access to the service. This design choice emphasizes keeping the website reachable during failures, which aligns with the security objective of availability over confidentiality, integrity, or non-repudiation.

Question 71

For an upcoming product launch, a company hires a marketing agency whose owner is a close relative of the Chief Executive Officer. Which of the following did the company violate?

A. Independent assessments
B. Supply chain analysis
C. Right-to-audit clause
D. Conflict of interest policy
Show Answer
Correct Answer: D
Explanation:
Hiring a vendor owned by a close relative of the CEO creates a situation where personal relationships can improperly influence business decisions. This directly violates a conflict of interest policy, which exists to prevent favoritism or bias. The other options relate to auditing, supply chain evaluation, or independent reviews, none of which address the core issue of personal interest influencing procurement.

Question 72

Which of the following is a use of CVSS?

A. To determine the cost associated with patching systems
B. To identify unused ports and services that should be closed
C. To analyze code for defects that could be exploited
D. To prioritize the remediation of vulnerabilities
Show Answer
Correct Answer: D
Explanation:
CVSS (Common Vulnerability Scoring System) assigns standardized severity scores to vulnerabilities based on impact and exploitability. Organizations use these scores to prioritize which vulnerabilities should be remediated first. It does not calculate patching costs, discover unused ports/services, or perform code analysis.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.