πŸ”

SY0-701 β€” questions

Page 29 of 31 Β· 603 total questions.

Topic 1 Β· Question 567

While updating the security awareness training, a security analyst wants to address issues created if vendors' email accounts are compromised. Which of the following recommendations should the security analyst include in the training?

  • ARefrain from clicking on images included in emails from new vendors
  • BDelete emails from unknown service provider partners.
  • CRequire that invoices be sent as attachments
  • DBe alert to unexpected requests from familiar email addresses (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Be alert to unexpected requests from familiar email addresses This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 568 Β· Select all that apply

A new corporate policy requires all staff to use multifactor authentication to access company resources. Which of the following can be utilized to set up this form of identity and access management? (Choose two.)

  • AAuthentication tokens (correct answer)
  • BLeast privilege
  • CBiometrics (correct answer)
  • DLDAP
  • EPassword vaulting
  • FSAML
Reveal answer & explanation
Correct answer: A, C

The correct answer is A, C. Option A: Authentication tokens Option C: Biometrics

Topic 1 Β· Question 569

A help desk employee receives a call from someone impersonating the Chief Executive Officer. The caller asks for assistance with resetting a password. Which of the following best describes this event?

  • AVishing (correct answer)
  • BHacktivism
  • CBlackmail
  • DMisinformation
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Vishing

Topic 1 Β· Question 570

The number of tickets the help desk has been receiving has increased recently due to numerous false-positive phishing reports. Which of the following would be best to help to reduce the false positives?

  • APerforming more phishing simulation campaigns
  • BImproving security awareness training (correct answer)
  • CHiring more help desk staff
  • DImplementing an incident reporting web page
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Improving security awareness training

Topic 1 Β· Question 571

A systems administrator needs to encrypt all data on employee laptops. Which of the following encryption levels should be implemented?

  • AVolume
  • BPartition
  • CFull disk (correct answer)
  • DFile
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Full disk This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 572

Which of the following actions best addresses a vulnerability found on a company's web server?

  • APatching (correct answer)
  • BSegmentation
  • CDecommissioning
  • DMonitoring
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Patching

Topic 1 Β· Question 573

A company is changing its mobile device policy. The company has the following requirements: β€’ Company-owned devices β€’ Ability to harden the devices β€’ Reduced security risk β€’ Compatibility with company resources Which of the following would best meet these requirements?

  • ABYOD
  • BCYOD
  • CCOPE
  • DCOBO (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: COBO This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 574

A company is concerned about employees unintentionally introducing malware into the network. The company identified fifty employees who clicked on a link embedded in an email sent by the internal IT department. Which of the following should the company implement to best improve its security posture?

  • ASocial engineering training (correct answer)
  • BSPF configuration
  • CSimulated phishing campaign
  • DInsider threat awareness
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Social engineering training This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 575

A penetration test identifies that an SMBv1 is enabled on multiple servers across an organization. The organization wants to remediate this vulnerability in the most efficient way possible. Which of the following should the organization use for this purpose?

  • AGPO (correct answer)
  • BACL
  • CSFTP
  • DDLP
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: GPO

Topic 1 Β· Question 576

Which of the following best protects sensitive data in transit across a geographically dispersed infrastructure?

  • AEncryption (correct answer)
  • BMasking
  • CTokenization
  • DObfuscation
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Encryption

Explanation

Encryption protects confidentiality by making data unreadable without the appropriate key.

Topic 1 Β· Question 577

As part of new compliance audit requirements, multiple servers need to be segmented on different networks and should be reachable only from authorized internal systems. Which of the following would meet the requirements?

  • AConfigure firewall rules to block external access to Internal resources.
  • BSet up a WAP to allow internal access from public networks.
  • CImplement a new IPSec tunnel from internal resources.
  • DDeploy an internal jump server to access resources. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Deploy an internal jump server to access resources.

Topic 1 Β· Question 578

Which of the following activities should be performed first to compile a list of vulnerabilities in an environment?

  • AAutomated scanning (correct answer)
  • BPenetration testing
  • CThreat hunting
  • DLog aggregation
  • EAdversarial emulation
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Automated scanning

Topic 1 Β· Question 579

Which of the following can be used to mitigate attacks from high-risk regions?

  • AObfuscation
  • BData sovereignty
  • CIP geolocation (correct answer)
  • DEncryption
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: IP geolocation

Topic 1 Β· Question 580

A program manager wants to ensure contract employees can only access the company's computers Monday through Friday from 9 a m. to 5 p.m. Which of the following would best enforce this access control?

  • ACreating a GPO for all contract employees and setting time-of-day log-in restrictions (correct answer)
  • BCreating a discretionary access policy and setting rule-based access for contract employees
  • CImplementing an OAuth server and then setting least privilege for contract employees
  • DImplementing SAML with federation to the contract employees’ authentication server
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Creating a GPO for all contract employees and setting time-of-day log-in restrictions

Topic 1 Β· Question 581

After a series of account compromises and credential misuse, a company hires a security manager to develop a security program. Which of the following steps should the security manager take first to increase security awareness?

  • AEvaluate tools that identify risky behavior and distribute reports on the findings.
  • BSend quarterly newsletters that explain the importance of password management.
  • CDevelop phishing campaigns and notify the management team of any successes.
  • DUpdate policies and handbooks to ensure all employees are informed of the new procedures. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Update policies and handbooks to ensure all employees are informed of the new procedures. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 582

Which of the following analysis methods allows an organization to measure the exposure factor associated with organizational assets?

  • AHeuristic
  • BQuantitative (correct answer)
  • CUser-driven
  • DTrend-based
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Quantitative

Topic 1 Β· Question 583

A security analyst notices an increase in port scans on the edge of the corporate network. Which of the following logs should the analyst check to obtain the attacker’s source IP address?

  • AOS security
  • BFirewall (correct answer)
  • CApplication
  • DEndpoint
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Firewall

Explanation

A firewall enforces traffic policy by permitting or blocking connections based on configured rules. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 584

A security team receives reports about high latency and complete network unavailability throughout most of the office building. Flow logs from the campus switches show high traffic on TCP 445. Which of the following is most likely the root cause of this incident?

  • ABuffer overflow
  • BNTP amplification attack
  • CWorm (correct answer)
  • DDoS attack
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Worm This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 585

A security analyst is examining a penetration test report and notices that the tester pivoted to critical internal systems with the same local user ID and password. Which of the following would help prevent this in the future?

  • AImplement centralized authentication with proper password policies (correct answer)
  • BAdd password complexity rules and increase password history limits
  • CConnect the systems to an external authentication server
  • DLimit the ability of user accounts to change passwords
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Implement centralized authentication with proper password policies This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 586

When used with an access control vestibule which of the following would provide the best prevention against tailgating?

  • APIN
  • BAccess card
  • CSecurity guard (correct answer)
  • DCCTV
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Security guard

Showing questions 561–580 of 603 Β· Page 29 of 31