πŸ”

SY0-701 β€” questions

Page 20 of 31 Β· 603 total questions.

Topic 1 Β· Question 386

A malicious insider from the marketing team alters records and transfers company funds to a personal account. Which of the following methods would be the best way to secure company records in the future?

  • APermission restrictions (correct answer)
  • BHashing
  • CInput validation
  • DAccess control list
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Permission restrictions This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 387

An organization is required to provide assurance that its controls are properly designed and operating effectively. Which of the following reports will best achieve the objective?

  • ARed teaming
  • BPenetration testing
  • CIndependent audit (correct answer)
  • DVulnerability assessment
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Independent audit

Topic 1 Β· Question 388

A systems administrator successfully configures VPN access to a cloud environment. Which of the following capabilities should the administrator use to best facilitate remote administration?

  • AA jump host in the shared services security zone (correct answer)
  • BAn SSH server within the corporate LAN
  • CA reverse proxy on the firewall
  • DAn MDM solution with conditional access
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: A jump host in the shared services security zone

Topic 1 Β· Question 389

Which of the following best describes the concept of information being stored outside of its country of origin while still being subject to the laws and requirements of the country of origin?

  • AData sovereignty (correct answer)
  • BGeolocation
  • CIntellectual property
  • DGeographic restrictions
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Data sovereignty

Topic 1 Β· Question 390

An audit reveals that cardholder database logs are exposing account numbers inappropriately. Which of the following mechanisms would help limit the impact of this error?

  • ASegmentation
  • BHashing
  • CJournaling
  • DMasking (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Masking

Topic 1 Β· Question 391

A security analyst attempts to start a company's database server. When the server starts, the analyst receives an error message indicating the database server did not pass authentication. After reviewing and testing the system, the analyst receives confirmation that the server has been compromised and that attackers have redirected all outgoing database traffic to a server under their control. Which of the following MITRE ATT&CK techniques did the attacker most likely use to redirect database traffic?

  • ABrowser extension
  • BProcess injection (correct answer)
  • CValid accounts
  • DEscape to host
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Process injection This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 392

A penetration tester enters an office building at the same time as a group of employees despite not having an access badge. Which of the following attack types is the penetration tester performing?

  • ATailgating (correct answer)
  • BShoulder surfing
  • CRFID cloning
  • DForgery
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Tailgating

Topic 1 Β· Question 393

Which of the following enables the ability to receive a consolidated report from different devices on the network?

  • AIPS
  • BDLP
  • CSIEM (correct answer)
  • DFirewall
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: SIEM

Explanation

A SIEM centralizes and correlates security events to support detection, investigation, and reporting.

Topic 1 Β· Question 394

Which of the following should an organization focus on the most when making decisions about vulnerability prioritization?

  • AExposure factor
  • BCVSS (correct answer)
  • CCVE
  • DIndustry impact
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: CVSS

Topic 1 Β· Question 395

An organization needs to monitor its users’ activities in order to prevent insider threats. Which of the following solutions would help the organization achieve this goal?

  • ABehavioral analytics (correct answer)
  • BAccess control lists
  • CIdentity and access management
  • DNetwork intrusion detection system
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Behavioral analytics

Topic 1 Β· Question 396

A customer of a large company receives a phone call from someone claiming to work for the company and asking for the customer’s credit card information. The customer sees the caller ID is the same as the company's main phone number. Which of the following attacks is the customer most likely a target of?

  • APhishing
  • BWhaling
  • CSmishing
  • DVishing (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Vishing

Topic 1 Β· Question 397

A security analyst is reviewing logs to identify the destination of command-and-control traffic originating from a compromised device within the on-premises network. Which of the following is the best log to review?

  • AIDS
  • BAntivirus
  • CFirewall (correct answer)
  • DApplication
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Firewall

Explanation

A firewall enforces traffic policy by permitting or blocking connections based on configured rules. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 398

When trying to access an internal website, an employee reports that a prompt displays, stating that the site is insecure. Which of the following certificate types is the site most likely using?

  • AWildcard
  • BRoot of trust
  • CThird-party
  • DSelf-signed (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Self-signed This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 399

Which of the following would most likely be deployed to obtain and analyze attacker activity and techniques?

  • AFirewall
  • BIDS
  • CHoneypot (correct answer)
  • DLayer 3 switch
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Honeypot

Topic 1 Β· Question 400

Which of the following objectives is best achieved by a tabletop exercise?

  • AFamiliarizing participants with the incident response process (correct answer)
  • BDeciding red and blue team rules of engagement
  • CQuickly determining the impact of an actual security breach
  • DConducting multiple security investigations in parallel
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Familiarizing participants with the incident response process

Explanation

Incident response prepares for, detects, contains, eradicates, and recovers from security incidents while preserving evidence.

Topic 1 Β· Question 401

The private key for a website was stolen, and a new certificate has been issued. Which of the following needs to be updated next?

  • ASCEP
  • BCRL (correct answer)
  • COCSP
  • DCSR
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: CRL This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 402

Which of the following organizational documents is most often used to establish and communicate expectations associated with integrity and ethical behavior within an organization?

  • AAUP (correct answer)
  • BSLA
  • CEULA
  • DMOA
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: AUP

Topic 1 Β· Question 403

Which of the following explains how to determine the global regulations that data is subject to regardless of the country where the data is stored?

  • AGeographic dispersion
  • BData sovereignty (correct answer)
  • CGeographic restrictions
  • DData segmentation
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Data sovereignty

Topic 1 Β· Question 404 Β· Select all that apply

An organization's web servers host an online ordering system. The organization discovers that the servers are vulnerable to a malicious JavaScript injection, which could allow attackers to access customer payment information. Which of the following mitigation strategies would be most effective for preventing an attack on the organization's web servers? (Choose two.)

  • ARegularly updating server software and patches (correct answer)
  • BImplementing strong password policies
  • CEncrypting sensitive data at rest and in transit
  • DUtilizing a web-application firewall (correct answer)
  • EPerforming regular vulnerability scans
  • FRemoving payment information from the servers
Reveal answer & explanation
Correct answer: A, D

The correct answer is A, D. Option A: Regularly updating server software and patches Option D: Utilizing a web-application firewall

Explanation

A firewall enforces traffic policy by permitting or blocking connections based on configured rules.

Topic 1 Β· Question 405

Which of the following tools is best for logging and monitoring in a cloud environment?

  • AIPS
  • BFIM
  • CNAC
  • DSIEM (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: SIEM

Explanation

A SIEM centralizes and correlates security events to support detection, investigation, and reporting.

Showing questions 381–400 of 603 Β· Page 20 of 31