πŸ”

SY0-701 β€” questions

Page 5 of 31 Β· 603 total questions.

Topic 1 Β· Question 83

A security analyst scans a company's public network and discovers a host is running a remote desktop that can be used to access the production network. Which of the following changes should the security analyst recommend?

  • AChanging the remote desktop port to a non-standard number
  • BSetting up a VPN and placing the jump server inside the firewall (correct answer)
  • CUsing a proxy for web connections from the remote desktop server
  • DConnecting the remote server to the domain and increasing the password length
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Setting up a VPN and placing the jump server inside the firewall

Explanation

A VPN creates an encrypted tunnel across an untrusted network for private remote or site connectivity. A firewall enforces traffic policy by permitting or blocking connections based on configured rules. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 84

An enterprise has been experiencing attacks focused on exploiting vulnerabilities in older browser versions with well-known exploits. Which of the following security solutions should be configured to best provide the ability to monitor and block these known signature-based attacks?

  • AACL
  • BDLP
  • CIDS
  • DIPS (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: IPS

Explanation

An intrusion prevention system detects and actively blocks malicious traffic inline. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 85

Security controls in a data center are being reviewed to ensure data is properly protected and that human life considerations are included. Which of the following best describes how the controls should be set up?

  • ARemote access points should fail closed.
  • BLogging controls should fail open.
  • CSafety controls should fail open. (correct answer)
  • DLogical security controls should fail closed.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Safety controls should fail open. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 86

Which of the following would be best suited for constantly changing environments?

  • ARTOS
  • BContainers (correct answer)
  • CEmbedded systems
  • DSCADA
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Containers

Explanation

A container packages an application and dependencies while sharing the host kernel for lightweight isolation.

Topic 1 Β· Question 87

Which of the following incident response activities ensures evidence is properly handled?

  • AE-discovery
  • BChain of custody (correct answer)
  • CLegal hold
  • DPreservation
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Chain of custody

Explanation

Chain of custody documents every transfer and handler of evidence to preserve integrity and admissibility.

Topic 1 Β· Question 88

An accounting clerk sent money to an attacker's bank account after receiving fraudulent instructions to use a new account. Which of the following would most likely prevent this activity in the future?

  • AStandardizing security incident reporting
  • BExecuting regular phishing campaigns
  • CImplementing insider threat detection measures
  • DUpdating processes for sending wire transfers (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Updating processes for sending wire transfers

Topic 1 Β· Question 89

A systems administrator is creating a script that would save time and prevent human error when performing account creation for a large number of end users. Which of the following would be a good use case for this task?

  • AOff-the-shelf software
  • BOrchestration (correct answer)
  • CBaseline
  • DPolicy enforcement
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Orchestration

Topic 1 Β· Question 90

A company's marketing department collects, modifies, and stores sensitive customer data. The infrastructure team is responsible for securing the data while in transit and at rest. Which of the following data roles describes the customer?

  • AProcessor
  • BCustodian
  • CSubject (correct answer)
  • DOwner
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Subject

Topic 1 Β· Question 91

Which of the following describes the maximum allowance of accepted risk?

  • ARisk indicator
  • BRisk level
  • CRisk score
  • DRisk threshold (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Risk threshold

Topic 1 Β· Question 92

A security analyst receives alerts about an internal system sending a large amount of unusual DNS queries to systems on the internet over short periods of time during non-business hours. Which of the following is most likely occurring?

  • AA worm is propagating across the network.
  • BData is being exfiltrated. (correct answer)
  • CA logic bomb is deleting data.
  • DRansomware is encrypting files.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Data is being exfiltrated. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 93

A technician is opening ports on a firewall for a new system being deployed and supported by a SaaS provider. Which of the following is a risk in the new system?

  • ADefault credentials
  • BNon-segmented network
  • CSupply chain vendor (correct answer)
  • DVulnerable software
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Supply chain vendor

Topic 1 Β· Question 94

A systems administrator is working on a solution with the following requirements: β€’ Provide a secure zone. β€’ Enforce a company-wide access control policy. β€’ Reduce the scope of threats. Which of the following is the systems administrator setting up?

  • AZero Trust (correct answer)
  • BAAA
  • CNon-repudiation
  • DCIA
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Zero Trust

Explanation

Zero trust continuously verifies identity, device, and context instead of trusting traffic based on network location. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 95

Which of the following involves an attempt to take advantage of database misconfigurations?

  • ABuffer overflow
  • BSQL injection (correct answer)
  • CVM escape
  • DMemory injection
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: SQL injection

Explanation

SQL injection manipulates database queries through untrusted input and is mitigated with parameterized statements.

Topic 1 Β· Question 96

Which of the following is used to validate a certificate when it is presented to a user?

  • AOCSP (correct answer)
  • BCSR
  • CCA
  • DCRC
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: OCSP

Topic 1 Β· Question 97

One of a company's vendors sent an analyst a security bulletin that recommends a BIOS update. Which of the following vulnerability types is being addressed by the patch?

  • AVirtualization
  • BFirmware (correct answer)
  • CApplication
  • DOperating system
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Firmware This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 98

Which of the following is used to quantitatively measure the criticality of a vulnerability?

  • ACVE
  • BCVSS (correct answer)
  • CCIA
  • DCERT
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: CVSS

Topic 1 Β· Question 99

Which of the following actions could a security engineer take to ensure workstations and servers are properly monitored for unauthorized changes and software?

  • AConfigure all systems to log scheduled tasks.
  • BCollect and monitor all traffic exiting the network.
  • CBlock traffic based on known malicious signatures.
  • DInstall endpoint management software on all systems (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Install endpoint management software on all systems This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 100

An organization is leveraging a VPN between its headquarters and a branch location. Which of the following is the VPN protecting?

  • AData in use
  • BData in transit (correct answer)
  • CGeographic restrictions
  • DData sovereignty
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Data in transit

Topic 1 Β· Question 101

After reviewing the following vulnerability scanning report: A security analyst performs the following test: Which of the following would the security analyst conclude for this reported vulnerability?

Exhibit 1 for question 101Exhibit 2 for question 101
  • AIt is a false positive. (correct answer)
  • BA rescan is required.
  • CIt is considered noise.
  • DCompensating controls exist.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: It is a false positive. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 102

An organization disabled unneeded services and placed a firewall in front of a business-critical legacy system. Which of the following best describes the actions taken by the organization?

  • AException
  • BSegmentation
  • CRisk transfer
  • DCompensating controls (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Compensating controls

Showing questions 81–100 of 603 Β· Page 5 of 31