πŸ”

SY0-701 β€” questions

Page 25 of 31 Β· 603 total questions.

Topic 1 Β· Question 487

A customer has a contract with a CSP and wants to identify which controls should be implemented in the IaaS enclave. Which of the following is most likely to contain this information?

  • AStatement of work
  • BResponsibility matrix (correct answer)
  • CService-level agreement
  • DMaster service agreement
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Responsibility matrix

Topic 1 Β· Question 488

A Chief Information Security Officer is developing procedures to guide detective and corrective activities associated with common threats, including phishing, social engineering, and business email compromise. Which of the following documents would be most relevant to revise as part of this process?

  • ASDLC
  • BIRP (correct answer)
  • CBCP
  • DAUP
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: IRP This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 489

Which of the following testing techniques uses both defensive and offensive testing methodologies with developers to securely build key applications and software?

  • ABlue
  • BYellow (correct answer)
  • CRed
  • DGreen
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Yellow This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 490

An administrator wants to automate an account permissions update for a large number of accounts. Which of the following would best accomplish this task?

  • ASecurity groups (correct answer)
  • BFederation
  • CUser provisioning
  • DVertical scaling
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Security groups

Topic 1 Β· Question 491

Which of the following is the fastest and most cost-effective way to confirm a third-party supplier's compliance with security obligations?

  • AAttestation report (correct answer)
  • BThird-party audit
  • CVulnerability assessment
  • DPenetration testing
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Attestation report This option delivers the requirement at the lowest cost.

Topic 1 Β· Question 492

Various company stakeholders meet to discuss roles and responsibilities in the event of a security breach that would affect offshore offices. Which of the following is this an example of?

  • ATabletop exercise (correct answer)
  • BPenetration test
  • CGeographic dispersion
  • DIncident response
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Tabletop exercise This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 493

Which of the following is an example of a data protection strategy that uses tokenization?

  • AEncrypting databases containing sensitive data
  • BReplacing sensitive data with surrogate values (correct answer)
  • CRemoving sensitive data from production systems
  • DHashing sensitive data in critical systems
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Replacing sensitive data with surrogate values

Topic 1 Β· Question 494

Which of the following is a type of vulnerability that refers to the unauthorized installation of applications on a device through means other than the official application store?

  • ACross-site scripting
  • BBuffer overflow
  • CJailbreaking
  • DSide loading (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Side loading

Topic 1 Β· Question 495

Which of the following types of identification methods can be performed on a deployed application during runtime?

  • ADynamic analysis (correct answer)
  • BCode review
  • CPackage monitoring
  • DBug bounty
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Dynamic analysis

Topic 1 Β· Question 496

Which of the following cryptographic solutions is used to hide the fact that communication is occurring?

  • ASteganography (correct answer)
  • BData masking
  • CTokenization
  • DPrivate key
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Steganography

Topic 1 Β· Question 497

Which of the following steps should be taken before mitigating a vulnerability in a production server?

  • AEscalate the issue to the SDLC team.
  • BUse the IR plan to evaluate the changes.
  • CPerform a risk assessment to classify the vulnerability.
  • DRefer to the change management policy. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Refer to the change management policy.

Topic 1 Β· Question 498

A security engineer needs to quickly identify a signature from a known malicious file. Which of the following analysis methods would the security engineer most likely use?

  • AStatic (correct answer)
  • BSandbox
  • CNetwork traffic
  • DPackage monitoring
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Static This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 499

Which of the following should a company use to provide proof of external network security testing?

  • ABusiness impact analysis
  • BSupply chain analysis
  • CVulnerability assessment
  • DThird-party attestation (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Third-party attestation This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 500 Β· Select all that apply

A security administrator is addressing an issue with a legacy system that communicates data using an unencrypted protocol to transfer sensitive data to a third party. No software updates that use an encrypted protocol are available, so a compensating control is needed. Which of the following are the most appropriate for the administrator to suggest? (Choose two.)

  • ATokenization
  • BCryptographic downgrade
  • CSSH tunneling (correct answer)
  • DSegmentation (correct answer)
  • EPatch installation
  • FData masking
Reveal answer & explanation
Correct answer: C, D

The correct answer is C, D. Option C: SSH tunneling Option D: Segmentation This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 501

Which of the following steps in the risk management process involves establishing the scope and potential risks involved with a project?

  • ARisk assessment
  • BRisk identification (correct answer)
  • CRisk treatment
  • DRisk monitoring and review
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Risk identification

Topic 1 Β· Question 502

A company's website is www.company.com. Attackers purchased the domain www.c0mpany.com. Which of the following types of attacks describes this example?

  • ATyposquatting (correct answer)
  • BBrand impersonation
  • COn-path
  • DWatering-hole
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Typosquatting

Topic 1 Β· Question 503

Which of the following allows a systems administrator to tune permissions for a file?

  • APatching
  • BAccess control list (correct answer)
  • CConfiguration enforcement
  • DLeast privilege
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Access control list

Topic 1 Β· Question 504

Which of the following would be the greatest concern for a company that is aware of the consequences of non-compliance with government regulations?

  • ARight to be forgotten
  • BSanctions (correct answer)
  • CExternal compliance reporting
  • DAttestation
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Sanctions

Topic 1 Β· Question 505

Which of the following security concepts is accomplished when granting access after an individual has logged into a computer network?

  • AAuthorization (correct answer)
  • BIdentification
  • CNon-repudiation
  • DAuthentication
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Authorization This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 506

A growing organization, which hosts an externally accessible application, adds multiple virtual servers to improve application performance and decrease the resource usage on individual servers. Which of the following solutions is the organization most likely to employ to further increase performance and availability?

  • ALoad balancer (correct answer)
  • BJump server
  • CProxy server
  • DSD-WAN
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Load balancer

Explanation

A load balancer distributes requests across healthy backends to improve scale and availability.

Showing questions 481–500 of 603 Β· Page 25 of 31