πŸ”

SY0-701 β€” questions

Page 22 of 31 Β· 603 total questions.

Topic 1 Β· Question 426

A systems administrator discovers a system that is no longer receiving support from the vendor. However, this system and its environment are critical to running the business, cannot be modified, and must stay online. Which of the following risk treatments is the most appropriate in this situation?

  • AReject
  • BAccept (correct answer)
  • CTransfer
  • DAvoid
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Accept

Topic 1 Β· Question 427

A company discovered its data was advertised for sale on the dark web. During the initial investigation, the company determined the data was proprietary data. Which of the following is the next step the company should take?

  • AIdentify the attacker’s entry methods.
  • BReport the breach to the local authorities.
  • CNotify the applicable parties of the breach. (correct answer)
  • DImplement vulnerability scanning of the company's systems.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Notify the applicable parties of the breach.

Topic 1 Β· Question 428

Which of the following would be the best solution to deploy a low-cost standby site that includes hardware and internet access?

  • ARecovery site
  • BCold site
  • CHot site
  • DWarm site (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Warm site

Topic 1 Β· Question 429

An organization needs to determine how many employees are accessing the building each day in order to configure the proper access controls. Which of the following control types best meets this requirement?

  • ADetective (correct answer)
  • BPreventive
  • CCorrective
  • DDirective
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Detective

Topic 1 Β· Question 430 Β· Select all that apply

An organization wants to implement a secure solution for remote users. The users handle sensitive PHI on a regular basis and need to access an internally developed corporate application. Which of the following best meet the organization's security requirements? (Choose two.)

  • ALocal administrative password
  • BPerimeter network
  • CJump server
  • DWAF
  • EMFA (correct answer)
  • FVPN (correct answer)
Reveal answer & explanation
Correct answer: E, F

The correct answer is E, F. Option E: MFA Option F: VPN

Explanation

Multifactor authentication combines independent authentication factors so one compromised credential is insufficient. A VPN creates an encrypted tunnel across an untrusted network for private remote or site connectivity. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 431

A security officer is implementing a security awareness program and is placing security-themed posters around the building and is assigning online user training. Which of the following would the security officer most likely implement?

  • APassword policy
  • BAccess badges
  • CPhishing campaign (correct answer)
  • DRisk assessment
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Phishing campaign

Explanation

Phishing uses deceptive communication to obtain credentials, money, or execution of malicious content. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 432

A security consultant is working with a client that wants to physically isolate its secure systems. Which of the following best describes this architecture?

  • ASDN
  • BAir gapped (correct answer)
  • CContainerized
  • DHighly available
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Air gapped This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 433

A company is in the process of migrating to cloud-based services. The company’s IT department has limited resources for migration and ongoing support. Which of the following best meets the company’s needs?

  • AIPS
  • BWAF
  • CSASE (correct answer)
  • DIAM
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: SASE

Topic 1 Β· Question 434

An employee clicks a malicious link in an email that appears to be from the company's Chief Executive Officer. The employee's computer is infected with ransomware that encrypts the company's files. Which of the following is the most effective way for the company to prevent similar incidents in the future?

  • ASecurity awareness training (correct answer)
  • BDatabase encryption
  • CSegmentation
  • DReporting suspicious emails
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Security awareness training This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 435

Which of the following types of vulnerabilities is primarily caused by improper use and management of cryptographic certificates?

  • AMisconfiguration (correct answer)
  • BResource reuse
  • CInsecure key storage
  • DWeak cipher suites
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Misconfiguration

Topic 1 Β· Question 436 Β· Select all that apply

Which of the following best describe the benefits of a microservices architecture when compared to a monolithic architecture? (Choose two.)

  • AEasier debugging of the system
  • BReduced cost of ownership of the system
  • CImproved scalability of the system (correct answer)
  • DIncreased compartmentalization of the system (correct answer)
  • EStronger authentication of the system
  • FReduced complexity of the system
Reveal answer & explanation
Correct answer: C, D

The correct answer is C, D. Option C: Improved scalability of the system Option D: Increased compartmentalization of the system

Topic 1 Β· Question 437

A user's workstation becomes unresponsive and displays a ransom note demanding payment to decrypt files. Before the attack, the user opened a resume they received in a message, browsed the company's website, and installed OS updates. Which of the following is the most likely vector of this attack?

  • ASpear-phishing attachment (correct answer)
  • BWatering hole
  • CInfected website
  • DTyposquatting
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Spear-phishing attachment

Explanation

Phishing uses deceptive communication to obtain credentials, money, or execution of malicious content.

Topic 1 Β· Question 438

A penetration tester finds an unused Ethernet port during an on-site penetration test. Upon plugging a device into the unused port, the penetration tester notices that the machine is assigned an IP address, allowing the tester to enumerate the local network. Which of the following should an administrator implement in order to prevent this situation from happening in the future?

  • APort security (correct answer)
  • BTransport Layer Security
  • CProxy server
  • DSecurity zones
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Port security

Topic 1 Β· Question 439

Which of the following should be used to ensure an attacker is unable to read the contents of a mobile device's drive if the device is lost?

  • ATPM
  • BECC
  • CFDE (correct answer)
  • DHSM
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: FDE

Topic 1 Β· Question 440

A security administrator documented the following records during an assessment of network services: Two weeks later, the administrator performed a log review and noticed the records were changed as follows: When consulting the service owner, the administrator validated that the new address was not part of the company network. Which of the following was the company most likely experiencing?

Exhibit 1 for question 440Exhibit 2 for question 440
  • ADDoS attack
  • BDNS poisoning (correct answer)
  • CRansomware compromise
  • DSpyware infection
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: DNS poisoning

Explanation

DNS resolves host names to records such as IP addresses and service locations. DNS poisoning inserts false resolution data so users are redirected to an attacker-controlled destination. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 441

Which of the following is the primary reason why false negatives on a vulnerability scan should be a concern?

  • AThe system has vulnerabilities that are not being detected. (correct answer)
  • BThe time to remediate vulnerabilities that do not exist is excessive.
  • CVulnerabilities with a lower severity will be prioritized over critical vulnerabilities.
  • DThe system has vulnerabilities, and a patch has not yet been released.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: The system has vulnerabilities that are not being detected.

Topic 1 Β· Question 442

A company is concerned about theft of client data from decommissioned laptops. Which of the following is the most cost-effective method to decrease this risk?

  • AWiping (correct answer)
  • BRecycling
  • CShredding
  • DDeletion
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Wiping This option delivers the requirement at the lowest cost.

Topic 1 Β· Question 443

A company that has a large IT operation is looking to better control, standardize, and lower the time required to build new servers. Which of the following architectures will best achieve the company’s objectives?

  • AIoT
  • BIaC (correct answer)
  • CIaaS
  • DICS
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: IaC

Topic 1 Β· Question 444

A government official receives a blank envelope containing photos and a note instructing the official to wire a large sum of money by midnight to prevent the photos from being leaked on the internet. Which of the following best describes the threat actor's intent?

  • AOrganized crime
  • BPhilosophical beliefs
  • CEspionage
  • DBlackmail (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Blackmail

Topic 1 Β· Question 445

Which of the following is the best security reason for closing service ports that are not needed?

  • ATo mitigate risks associated with unencrypted traffic
  • BTo eliminate false positives from a vulnerability scan
  • CTo reduce a system's attack surface (correct answer)
  • DTo improve a system's resource utilization
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: To reduce a system's attack surface This option keeps traffic private / properly secured as required.

Showing questions 421–440 of 603 Β· Page 22 of 31