πŸ”

SY0-701 β€” questions

Page 16 of 31 Β· 603 total questions.

Topic 1 Β· Question 303

A company web server is initiating outbound traffic to a low-reputation, public IP on non-standard pat. The web server is used to present an unauthenticated page to clients who upload images the company. An analyst notices a suspicious process running on the server hat was not created by the company development team. Which of the following is the most likely explanation for his security incident?

  • AA web shell has been deployed to the server through the page. (correct answer)
  • BA vulnerability has been exploited to deploy a worm to the server.
  • CMalicious insiders are using the server to mine cryptocurrency.
  • DAttackers have deployed a rootkit Trojan to the server over an exposed RDP port.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: A web shell has been deployed to the server through the page. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 304

An organization requests a third-party full-spectrum analysis of its supply chain. Which of the following would the analysis team use to meet this requirement?

  • AVulnerability scanner
  • BPenetration test
  • CSCAP
  • DIllumination tool (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Illumination tool

Explanation

Network address translation maps addresses between networks and commonly lets private hosts share public connectivity.

Topic 1 Β· Question 305

A systems administrator deployed a monitoring solution that does not require installation on the endpoints that the solution is monitoring. Which of the following is described in this scenario?

  • AAgentless solution (correct answer)
  • BClient-based soon
  • COpen port
  • DFile-based solution
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Agentless solution

Topic 1 Β· Question 306

A security analyst is reviewing the source code of an application in order to identify misconfigurations and vulnerabilities. Which of the following kinds of analysis best describes this review?

  • ADynamic
  • BStatic (correct answer)
  • CGap
  • DImpact
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Static This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 307

Which of the following agreement types is used to limit external discussions?

  • ABPA
  • BNDA (correct answer)
  • CSLA
  • DMSA
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: NDA

Topic 1 Β· Question 308

A security analyst is evaluating a SaaS application that the human resources department would like to implement. The analyst requests a SOC 2 report from the SaaS vendor. Which of the following processes is the analyst most likely conducting?

  • AInternal audit
  • BPenetration testing
  • CAttestation
  • DDue diligence (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Due diligence This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 309

Which of the following is used to conceal credit card information in a database log file?

  • ATokenization
  • BMasking (correct answer)
  • CHashing
  • DObfuscation
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Masking

Topic 1 Β· Question 311

An organization recently started hosting a new service that customers access through a web portal. A security engineer needs to add to the existing security devices a new solution to protect this new service. Which of the following is the engineer most likely to deploy?

  • ALayer 4 firewall
  • BNGFW
  • CWAF (correct answer)
  • DUTM
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: WAF This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 312

Which of the following topics would most likely be included within an organization's SDLC?

  • AService-level agreements
  • BInformation security policy
  • CPenetration testing methodology
  • DBranch protection requirements (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Branch protection requirements

Topic 1 Β· Question 313

Which of the following control types is AUP an example of?

  • APhysical
  • BManagerial (correct answer)
  • CTechnical
  • DOperational
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Managerial

Topic 1 Β· Question 314

An organization is adopting cloud services at a rapid pace and now has multiple SaaS applications in use. Each application has a separate log-in, so the security team wants to reduce the number of credentials each employee must maintain. Which of the following is the first step the security team should take?

  • AEnable SAML.
  • BCreate OAuth tokens.
  • CUse password vaulting.
  • DSelect an IdP. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Select an IdP. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 315

A company's online shopping website became unusable shortly after midnight on January 30, 2023. When a security analyst reviewed the database server, the analyst noticed the following code used for backing up data: Which of the following should the analyst do next?

Exhibit 1 for question 315
  • ACheck for recently terminated DBAs. (correct answer)
  • BReview WAF logs for evidence of command injection.
  • CScan the database server for malware.
  • DSearch the web server for ransomware notes.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Check for recently terminated DBAs.

Explanation

Network address translation maps addresses between networks and commonly lets private hosts share public connectivity. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 316

Which of the following would be the best way to test resiliency in the event of a primary power failure?

  • AParallel processing
  • BTabletop exercise
  • CSimulation testing
  • DProduction failover (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Production failover By spanning multiple Availability Zones / adding redundancy, this option provides the high availability and resilience required.

Topic 1 Β· Question 317

Which of the following would be the most appropriate way to protect data in transit?

  • ASHA-256
  • BSSL3.0
  • CTLS 1.3 (correct answer)
  • DAES-256
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: TLS 1.3

Explanation

TLS protects data in transit with authenticated encryption between network endpoints.

Topic 1 Β· Question 318

Which of the following is a common, passive reconnaissance technique employed by penetration testers in the early phases of an engagement?

  • AOpen-source intelligence (correct answer)
  • BPort scanning
  • CPivoting
  • DExploit validation
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Open-source intelligence

Topic 1 Β· Question 319

Which of the following threat actors is the most likely to seek financial gain through the use of ransomware attacks?

  • AOrganized crime (correct answer)
  • BInsider threat
  • CNation-state
  • DHacktivists
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Organized crime

Topic 1 Β· Question 320

Which of the following would a systems administrator follow when upgrading the firmware of an organization’s router?

  • ASoftware development life cycle
  • BRisk tolerance
  • CCertificate signing request
  • DMaintenance window (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Maintenance window

Topic 1 Β· Question 323

A systems administrator needs to ensure the secure communication of sensitive data within the organization’s private cloud. Which of the following is the best choice for the administrator to implement?

  • AIPSec (correct answer)
  • BSHA-1
  • CRSA
  • DTGT
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: IPSec

Explanation

An intrusion prevention system detects and actively blocks malicious traffic inline. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 324

Which of the following should an internal auditor check for first when conducting an audit of the organization’s risk management program?

  • APolicies and procedures (correct answer)
  • BAsset management
  • CVulnerability assessment
  • DBusiness impact analysis
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Policies and procedures

Topic 1 Β· Question 325 Β· Select all that apply

Which of the following activities are associated with vulnerability management? (Choose two.)

  • AReporting (correct answer)
  • BPrioritization (correct answer)
  • CExploiting
  • DCorrelation
  • EContainment
  • FTabletop exercise
Reveal answer & explanation
Correct answer: A, B

The correct answer is A, B. Option A: Reporting Option B: Prioritization

Showing questions 301–320 of 603 Β· Page 16 of 31