πŸ”

SY0-701 β€” questions

Page 28 of 31 Β· 603 total questions.

Topic 1 Β· Question 547

Which of the following is an example of a treatment strategy for a continuous risk?

  • AEmail gateway to block phishing attempts (correct answer)
  • BBackground checks for new employees
  • CDual control requirements for wire transfers
  • DBranch protection as part of the CI/CD pipeline
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Email gateway to block phishing attempts

Explanation

Phishing uses deceptive communication to obtain credentials, money, or execution of malicious content.

Topic 1 Β· Question 548

An organization wants to deploy software in a container environment to increase security. Which of the following would limit the organization's ability to achieve this goal?

  • ARegulatory compliance
  • BPatch availability
  • CKernel version
  • DMonolithic code (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Monolithic code This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 549

Prior to implementing a design change, the change must go through multiple steps to ensure that it does not cause any security issues. Which of the following is most likely to be one of those steps?

  • ABoard review
  • BService restart
  • CBackout planning (correct answer)
  • DMaintenance
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Backout planning This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 550

The internal audit team determines a software application is no longer in scope for external reporting requirements. Which of the following will confirm that the application is no longer applicable?

  • AData inventory and retention
  • BRight to be forgotten
  • CDue care and due diligence
  • DAcknowledgement and attestation (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Acknowledgement and attestation

Topic 1 Β· Question 551 Β· Select all that apply

Which of the following are the first steps an analyst should perform when developing a heat map? (Choose two.)

  • AMethodically walk around the office noting Wi-Fi signal strength. (correct answer)
  • BLog in to each access point and check the settings.
  • CCreate or obtain a layout of the office. (correct answer)
  • DMeasure cable lengths between access points.
  • EReview access logs to determine the most active devices.
  • FRemove possible impediments to radio transmissions.
Reveal answer & explanation
Correct answer: A, C

The correct answer is A, C. Option A: Methodically walk around the office noting Wi-Fi signal strength. Option C: Create or obtain a layout of the office.

Topic 1 Β· Question 552

Which of the following is used to improve security and overall functionality without losing critical application data?

  • AReformatting
  • BDecommissioning
  • CPatching (correct answer)
  • DEncryption
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Patching This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 553

An organization is preparing to export proprietary software to a customer. Which of the following would be the best way to prevent the loss of intellectual property?

  • ACode signing
  • BObfuscation (correct answer)
  • CTokenization
  • DBlockchain
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Obfuscation

Topic 1 Β· Question 554

Which of the following should be used to ensure a device is inaccessible to a network-connected resource?

  • ADisablement of unused services
  • BWeb application firewall
  • CHost isolation (correct answer)
  • DNetwork-based IDS
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Host isolation

Topic 1 Β· Question 555

In which of the following will unencrypted network traffic most likely be found?

  • ASDN
  • BIoT (correct answer)
  • CVPN
  • DSCADA
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: IoT This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 556

Which of the following is the best reason to perform a tabletop exercise?

  • ATo address audit findings
  • BTo collect remediation response times
  • CTo update the IRP (correct answer)
  • DTo calculate the ROI
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: To update the IRP

Topic 1 Β· Question 557

Which of the following is a use of CVSS?

  • ATo determine the cost associated with patching systems
  • BTo identify unused ports and services that should be closed
  • CTo analyze code for defects that could be exploited
  • DTo prioritize the remediation of vulnerabilities (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: To prioritize the remediation of vulnerabilities

Topic 1 Β· Question 558

For an upcoming product launch, a company hires a marketing agency whose owner is a close relative of the Chief Executive Officer. Which of the following did the company violate?

  • AIndependent assessments
  • BSupply chain analysis
  • CRight-to-audit clause
  • DConflict of interest policy (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Conflict of interest policy

Topic 1 Β· Question 559

An organization designs an inbound firewall with a fail-open configuration while implementing a website. Which of the following would the organization consider to be the highest priority?

  • AConfidentiality
  • BNon-repudiation
  • CAvailability (correct answer)
  • DIntegrity
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Availability

Topic 1 Β· Question 560

An engineer needs to ensure that a script has not been modified before it is launched. Which of the following best provides this functionality?

  • AMasking
  • BObfuscation
  • CHashing (correct answer)
  • DEncryption
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Hashing

Explanation

Hashing produces a one-way digest used to verify integrity without exposing the original value.

Topic 1 Β· Question 561

Which of the following is the most important element when defining effective security governance?

  • ADiscovering and documenting external considerations
  • BDeveloping procedures for employee onboarding and offboarding
  • CAssigning roles and responsibilities for owners, controllers, and custodians (correct answer)
  • DDefining and monitoring change management procedures
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Assigning roles and responsibilities for owners, controllers, and custodians This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 562

A contractor is required to visually inspect the motherboards of all new servers that are purchased to determine whether the servers were tampered with. Which of the following risks is the contractor attempting to mitigate?

  • AEmbedded rootkit
  • BSupply chain (correct answer)
  • CFirmware failure
  • DRFID keylogger
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Supply chain

Topic 1 Β· Question 563

Which of the following could potentially be introduced at the time of side loading?

  • AUser impersonation
  • BRootkit (correct answer)
  • COn-path attack
  • DBuffer overflow
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Rootkit

Topic 1 Β· Question 564

While a school district is performing state testing, a security analyst notices all internet services are unavailable. The analyst discovers that ARP poisoning is occurring on the network and then terminates access for the host. Which of the following is most likely responsible for this malicious activity?

  • AUnskilled attacker
  • BShadow IT
  • CInsider threat (correct answer)
  • DNation-state
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Insider threat This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 565

A user needs to complete training at https://comptiatraining.com. After manually entering the URL, the user sees that the accessed website is noticeably different from the standard company website. Which of the following is the most likely explanation for the difference?

  • ACross-site scripting
  • BPretexting
  • CTyposquatting (correct answer)
  • DVishing
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Typosquatting

Topic 1 Β· Question 566

A company has yearly engagements with a service provider. The general terms and conditions are the same for all engagements. The company wants to simplify the process and revisit the general terms every three years. Which of the following documents would provide the best way to set the general terms?

  • AMSA (correct answer)
  • BNDA
  • CMOU
  • DSLA
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: MSA

Showing questions 541–560 of 603 Β· Page 28 of 31