Comptia

SY0-701 Free Practice Questions — Page 8

Question 71

Which of the following is the best reason to perform a tabletop exercise?

A. To address audit findings
B. To collect remediation response times
C. To update the IRP
D. To calculate the ROI
Show Answer
Correct Answer: C
Explanation:
A tabletop exercise is primarily used to validate and improve the incident response process by identifying gaps, clarifying roles, and updating the Incident Response Plan (IRP). It is discussion-based rather than performance-metric driven, so it is not intended to collect remediation response times, address audit findings directly, or calculate ROI.

Question 72

Which of the following should be used to ensure a device is inaccessible to a network-connected resource?

A. Disablement of unused services
B. Web application firewall
C. Host isolation
D. Network-based IDS
Show Answer
Correct Answer: C
Explanation:
Host isolation is specifically used to quarantine a device by preventing network communication to and from other network-connected resources, making it inaccessible. Disabling unused services reduces attack surface but does not isolate the device. A web application firewall protects web applications, and a network-based IDS only detects suspicious activity rather than blocking access.

Question 73

An organization is preparing to export proprietary software to a customer. Which of the following would be the best way to prevent the loss of intellectual property?

A. Code signing
B. Obfuscation
C. Tokenization
D. Blockchain
Show Answer
Correct Answer: B
Explanation:
Obfuscation is the best choice because it makes software code significantly harder to understand and reverse-engineer while preserving functionality, helping protect proprietary algorithms and intellectual property when distributing software. Code signing verifies authenticity and integrity but does not hide implementation details. Tokenization protects sensitive data, not software logic. Blockchain does not prevent reverse engineering of distributed software.

Question 74

Which of the following is used to improve security and overall functionality without losing critical application data?

A. Reformatting
B. Decommissioning
C. Patching
D. Encryption
Show Answer
Correct Answer: C
Explanation:
Patching applies software or firmware updates that fix security vulnerabilities, correct bugs, and often improve functionality while preserving existing application data. Reformatting erases data, decommissioning retires a system, and encryption protects data confidentiality but does not improve application functionality or remediate software flaws.

Question 75

Which of the following are the first steps an analyst should perform when developing a heat map? (Choose two.)

A. Methodically walk around the office noting Wi-Fi signal strength.
B. Log in to each access point and check the settings.
C. Create or obtain a layout of the office.
D. Measure cable lengths between access points.
E. Review access logs to determine the most active devices.
F. Remove possible impediments to radio transmissions.
Show Answer
Correct Answer: A, C
Explanation:
Developing a Wi-Fi heat map begins by obtaining a floor plan or office layout to use as the map baseline, then collecting RF signal measurements throughout the space by walking the area with a Wi-Fi survey tool. Checking AP settings, measuring cable lengths, reviewing logs, or removing obstacles are not the initial steps in creating the heat map.

Question 76

Prior to implementing a design change, the change must go through multiple steps to ensure that it does not cause any security issues. Which of the following is most likely to be one of those steps?

A. Board review
B. Service restart
C. Backout planning
D. Maintenance
Show Answer
Correct Answer: C
Explanation:
Backout planning is a standard step in change management before implementing changes. It ensures there is a documented rollback procedure if the design change introduces operational or security problems. While a Change Advisory Board may review significant changes, 'board review' is not a universal required step, whereas backout planning is a core element of controlled change implementation.

Question 77

An organization wants to deploy software in a container environment to increase security. Which of the following would limit the organization's ability to achieve this goal?

A. Regulatory compliance
B. Patch availability
C. Kernel version
D. Monolithic code
Show Answer
Correct Answer: D
Explanation:
Monolithic applications can run in containers, but their tightly coupled architecture limits the ability to realize many of the security and operational benefits of containerization, such as isolating components into separate containers with least privilege. Regulatory compliance does not inherently prevent container deployment, patch availability is not a defining limitation, and while containers share the host kernel, the kernel version is an operational consideration rather than the primary architectural factor limiting adoption.

Question 78

Which of the following is an example of a treatment strategy for a continuous risk?

A. Email gateway to block phishing attempts
B. Background checks for new employees
C. Dual control requirements for wire transfers
D. Branch protection as part of the CI/CD pipeline
Show Answer
Correct Answer: A
Explanation:
The best answer is the email gateway to block phishing attempts. A continuous risk is an ongoing threat that requires persistent mitigation. Phishing is a continuous threat, and an email security gateway continuously filters and blocks malicious messages. Background checks are primarily point-in-time, dual control is transaction-specific, and branch protection is a CI/CD security control but is not the clearest general example of treating a continuous risk in risk management.

Question 79

The internal audit team determines a software application is no longer in scope for external reporting requirements. Which of the following will confirm that the application is no longer applicable?

A. Data inventory and retention
B. Right to be forgotten
C. Due care and due diligence
D. Acknowledgement and attestation
Show Answer
Correct Answer: A
Explanation:
An application's scope for external reporting is determined by whether it stores, processes, or transmits data subject to those reporting requirements. Reviewing the data inventory and retention records confirms whether the application still contains in-scope data. Acknowledgement and attestation may document the decision, but they do not establish that the application is actually out of scope. Due care/due diligence and the right to be forgotten are unrelated to confirming reporting scope. Sources: https://nmehelp.getnerdio.com/hc/en-us/articles/19837802929677-Release-Notes

Question 80

A security analyst created a fake account and saved the password in a non-readily accessible directory in a spreadsheet. An alert was also configured to notify the security team if the spreadsheet is opened. Which of the following best describes the deception method being deployed?

A. Honeypot
B. Honeyfile
C. Honeytoken
D. Honeynet
Show Answer
Correct Answer: B
Explanation:
The deception mechanism being monitored is the spreadsheet itself. A honeyfile is a decoy file placed where an attacker might find it, with monitoring to alert defenders when it is opened or accessed. Although the spreadsheet contains fake credentials (which are honeytoken-like data), the detection trigger is based on opening the decoy file, making the primary deception method a honeyfile. A honeypot is a decoy system, and a honeynet is a collection of honeypots.

$19

Get all 608 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.