Comptia

SY0-701 Free Practice Questions — Page 9

Question 83

Which of the following describes the difference between encryption and hashing?

A. Encryption protects data in transit, while hashing protects data at rest.
B. Encryption replaces cleartext with ciphertext, while hashing calculates a checksum.
C. Encryption ensures data integrity, while hashing ensures data confidentiality.
D. Encryption uses a public-key exchange, while hashing uses a private key.
Show Answer
Correct Answer: B
Explanation:
Encryption transforms plaintext into ciphertext using an algorithm and key and is reversible (decryption restores the original data), providing confidentiality. Hashing applies a one-way function to produce a fixed-length digest (checksum) that cannot be reversed, primarily used to verify data integrity.

Question 84

A security report shows that during a two-week test period, 80% of employees unwittingly disclosed their SSO credentials when accessing an external website. The organization purposely created the website to simulate a cost-free password complexity test. Which of the following would best help reduce the number of visits to similar websites in the future?

A. Block all outbound traffic from the intranet.
B. Introduce a campaign to recognize phishing attempts.
C. Restrict internet access for the employees who disclosed credentials.
D. Implement a deny list of websites.
Show Answer
Correct Answer: B
Explanation:
The scenario describes users being tricked into disclosing credentials on a simulated external site, which is a classic social-engineering/phishing-style test. The most effective long-term way to reduce visits to similar malicious sites is user awareness training so employees can recognize and avoid such attempts. Blocking all traffic or restricting users is impractical, and deny lists are reactive and easily bypassed as new sites appear. Therefore, a phishing-recognition awareness campaign best addresses the root cause.

Question 85

A systems administrator just purchased multiple network devices. Which of the following should the systems administrator perform to prevent attackers from accessing the devices by using publicly available information?

A. Install endpoint protection.
B. Disable ports/protocols.
C. Change default passwords.
D. Remove unnecessary software.
Show Answer
Correct Answer: C
Explanation:
Newly purchased network devices commonly ship with well-known default usernames and passwords that are publicly documented. Attackers can easily exploit this information to gain access. Changing default passwords directly mitigates this risk. The other options are good hardening steps but do not specifically address publicly available access credentials.

Question 86

Which of the following is the fastest and most cost-effective way to confirm a third-party supplier's compliance with security obligations?

A. Attestation report
B. Third-party audit
C. Vulnerability assessment
D. Penetration testing
Show Answer
Correct Answer: A
Explanation:
An attestation report (e.g., SOC 1/2, ISO certification) is the fastest and most cost-effective way to confirm a supplier’s compliance because it is already prepared by an independent third party and can be reviewed immediately. It provides documented assurance against defined security obligations without the time, cost, and effort of conducting a new audit, vulnerability assessment, or penetration test, which are slower, more expensive, and assess technical controls rather than overall compliance.

Question 87

Which of the following objectives is best achieved by a tabletop exercise?

A. Familiarizing participants with the incident response process
B. Deciding red and blue team rules of engagement
C. Quickly determining the impact of an actual security breach
D. Conducting multiple security investigations in parallel
Show Answer
Correct Answer: A
Explanation:
Tabletop exercises are discussion-based simulations designed to walk participants through roles, responsibilities, and decision-making during an incident. Their primary objective is to familiarize and train participants on the incident response process, identify gaps, and improve coordination—not to handle real breaches, set team engagement rules, or conduct live investigations.

Question 88

An organization has a new regulatory requirement to implement corrective controls on a financial system. Which of the following is the most likely reason for the new requirement?

A. To defend against insider threats altering banking details
B. To ensure that errors are not passed to other systems
C. To allow for business insurance to be purchased
D. To prevent unauthorized changes to financial data
Show Answer
Correct Answer: B
Explanation:
Corrective controls are designed to fix problems after they have occurred, minimizing impact and restoring systems to a correct state. In a regulated financial system, the primary regulatory driver for corrective controls is to ensure that detected errors or issues are corrected so they do not propagate to downstream systems or reporting. Options A and D describe preventive objectives (stopping threats or unauthorized changes before they occur), while C is unrelated to control objectives.

Question 89

A Chief Information Security Officer (CISO) wants to: • Prevent employees from downloading malicious content. • Establish controls based on departments and users. • Map internet access for business applications to specific service accounts. • Restrict content based on categorization. Which of the following should the CSO implement?

A. Web application firewall
B. Secure DNS server
C. Jump server
D. Next-generation firewall
Show Answer
Correct Answer: D
Explanation:
A next-generation firewall (NGFW) provides all the required capabilities: prevention of malicious downloads through deep packet inspection and malware filtering, enforcement of policies based on users and departments via directory integration, application-aware controls that can map internet access to specific service accounts, and URL/content filtering based on categorization. The other options do not collectively support all these requirements.

Question 90

A company evaluates several options that would allow employees to have remote access to the network. The security team wants to ensure the solution includes AAA to comply with internal security policies. Which of the following should the security team recommend?

A. IPSec with RADIUS
B. RDP connection with LDAPS
C. Web proxy for all remote traffic
D. Jump server with 802.1X
Show Answer
Correct Answer: A
Explanation:
The requirement is a remote access solution that includes AAA (Authentication, Authorization, and Accounting). RADIUS is a protocol explicitly designed to provide AAA services, and when integrated with IPSec it forms a secure VPN solution for remote employees. The other options do not inherently provide full AAA for remote network access.

Question 91

A security analyst learns that an attack vector, which was used as a part of a recent incident, was a well-known IoT device exploit. The analyst needs to review logs to identify the time of initial exploit. Which of the following logs should the analyst review first?

A. Endpoint
B. Application
C. Firewall
D. NAC
Show Answer
Correct Answer: C
Explanation:
The goal is to identify the *time of the initial exploit* of a well-known IoT vulnerability. Such exploits are typically network-based (scanning, inbound connections, exploit attempts). Firewall logs are the most reliable first source because they record inbound and outbound network traffic crossing security boundaries and can show the earliest malicious connection attempt targeting the IoT device. Endpoint logs are often unavailable or minimal on IoT devices, application logs are irrelevant to device-level exploits, and NAC logs focus on authentication and access control rather than exploit activity. Therefore, firewall logs should be reviewed first.

Question 92

A systems administrator creates a script that validates OS version, patch levels, and installed applications when users log in. Which of the following examples best describes the purpose of this script?

A. Resource scaling
B. Policy enumeration
C. Baseline enforcement
D. Guard rails implementation
Show Answer
Correct Answer: C
Explanation:
The script checks systems at login to ensure the OS version, patch levels, and installed applications comply with a predefined standard configuration. This is the definition of baseline enforcement—verifying and enforcing adherence to an established security or configuration baseline. The other options do not involve compliance checking against defined standards.

$19

Get all 609 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.