SY0-701 Exam Questions
1,057 real SY0-701 exam questions with expert-verified answers and explanations. Page 1 of 22.
- Question #1Security Operations
A security analyst is reviewing alerts in the SIEM related to potential malicious network traffic coming from an employee's corporate laptop. The security analyst has determined th...
- Question #2Security Operations
A cyber operations team informs a security analyst about a new tactic malicious actors are using to compromise networks. SIEM alerts have not yet been configured. Which of the foll...
- Question #3Security program management and oversight
A company purchased cyber insurance to address items listed on the risk register. Which of the following strategies does this represent?
- Question #4Threats, vulnerabilities, and mitigations
A security administrator would like to protect data on employees' laptops. Which of the following encryption techniques should the security administrator use?
- Question #5General security concepts
Which of the following security control types does an acceptable use policy best represent?
- Question #6General security concepts
An IT manager informs the entire help desk staff that only the IT manager and the help desk lead will have access to the administrator console of the help desk software. Which of t...
- Question #7General security concepts
Which of the following roles, according to the shared responsibility model, is responsible for securing the company's database in an IaaS model for a cloud environment?
- Question #8Security program management and oversight
A client asked a security company to provide a document outlining the project, the cost, and the completion time frame. Which of the following documents should the company provide...
- Question #9Threats, vulnerabilities, and mitigations
A security team is reviewing the findings in a report that was delivered after a third party performed a penetration test. One of the findings indicated that a web application form...
- Question #10Security architecture
Which of the following must be considered when designing a high-availability network? (Choose two).
- Question #11Security Operations
A technician needs to apply a high-priority patch to a production system. Which of the following steps should be taken first?
- Question #12Security Operations
Which of the following describes the reason root cause analysis should be conducted as part of incident response?
- Question #13Security program management and oversight
Which of the following is the most likely outcome if a large bank fails an internal PCI DSS compliance assessment?
- Question #14Security program management and oversight
A company is developing a business continuity strategy and needs to determine how many staff members would be required to sustain the business in the case of a disruption. Which of...
- Question #15Security architecture
A company's legal department drafted sensitive documents in a SaaS application and wants to ensure the documents cannot be accessed by individuals in high-risk countries. Which of...
- Question #16Threats, vulnerabilities, and mitigations
Which of the following is a hardware-specific vulnerability?
- Question #17Security operations
While troubleshooting a firewall configuration, a technician determines that a "deny any" policy should be added to the bottom of the ACL. The technician updates the policy, but th...
Firewall managementChange managementPolicy testingOperational best practices - Question #18Security architecture
An organization is building a new backup data center with cost-benefit as the primary requirement and RTO and RPO values around two days. Which of the following types of sites is t...
- Question #19General security concepts
A company requires hard drives to be securely wiped before sending decommissioned systems to recycling. Which of the following best describes this policy?
- Question #20General security concepts
A systems administrator works for a local hospital and needs to ensure patient data is protected and secure. Which of the following data classifications should be used to secure pa...
Data classificationSensitive dataPatient data - Question #21Security program management and oversight
A U.S.-based cloud-hosting provider wants to expand its data centers to new international locations. Which of the following should the hosting provider consider first?
- Question #22Threats, vulnerabilities, and mitigations
Which of the following would be the best way to block unknown programs from executing?
- Question #23Security Operations
A company hired a consultant to perform an offensive security assessment covering penetration testing and social engineering. Which of the following teams will conduct this assessm...
- Question #24Threats, vulnerabilities, and mitigations
A software development manager wants to ensure the authenticity of the code created by the company. Which of the following options is the most appropriate?
- Question #25Threats, vulnerabilities, and mitigations
Which of the following can be used to identify potential attacker activities without affecting production servers?
- Question #26Security Operations
During an investigation, an incident response team attempts to understand the source of an incident. Which of the following incident response activities describes this process?
- Question #27
A security practitioner completes a vulnerability assessment on a company's network and finds several vulnerabilities, which the operations team remediates. Which of the following...
- Question #28Threats, vulnerabilities, and mitigations
An administrator was notified that a user logged in remotely after hours and copied large amounts of data to a personal device. Which of the following best describes the user's act...
- Question #29General security concepts
Which of the following allows for the attribution of messages to individuals?
- Question #30Security operations
Which of the following is the best way to consistently determine on a daily basis whether security settings on servers have been modified?
Security automationConfiguration managementContinuous monitoringOperational security - Question #31Threats, vulnerabilities, and mitigations
Which of the following tools can assist with detecting an employee who has accidentally emailed a file containing a customer's PII?
- Question #32Threats, vulnerabilities, and mitigations
An organization recently updated its security policy to include the following statement: Regular expressions are included in source code to remove special characters such as $, |,...
Input validationWeb application securityRegular expressionsData sanitization - Question #33Threats, vulnerabilities, and mitigations
A security analyst and the management team are reviewing the organizational performance of a recent phishing campaign. The user click-through rate exceeded the acceptable risk thre...
- Question #34General security concepts
Which of the following has been implemented when a host-based firewall on a legacy Linux system allows connections from only specific internal IP addresses?
- Question #35Security Operations
The management team notices that new accounts that are set up manually do not always have correct access or permissions. Which of the following automation techniques should a syste...
- Question #36Security Operations
A company is planning to set up a SIEM system and assign an analyst to review the logs on a weekly basis. Which of the following types of controls is the company setting up?
- Question #37Security architecture
A systems administrator is looking for a low-cost application-hosting solution that is cloud-based. Which of the following meets these requirements?
Cloud servicesServerless architectureApplication hostingCloud cost optimization - Question #38Security Operations
A security operations center determines that the malicious activity detected on a server is normal. Which of the following activities describes the act of ignoring detected activit...
- Question #39Threats, vulnerabilities, and mitigations
A security analyst reviews domain activity logs and notices the following: Which of the following is the best explanation for what the security analyst has discovered?
- Question #40Threats, vulnerabilities, and mitigations
A company is concerned about weather events causing damage to the server room and downtime. Which of the following should the company consider?
- Question #41Threats, vulnerabilities, and mitigations
Which of the following is a primary security concern for a company setting up a BYOD program?
- Question #42Security Program Management and Oversight
A company decided to reduce the cost of its annual cyber insurance policy by removing the coverage for ransomware attacks. Which of the following analysis elements did the company...
Risk ManagementQuantitative Risk AnalysisAROCyber Insurance - Question #43Security program management and oversight
Which of the following is the most likely to be included as an element of communication in a security awareness program?
Security AwarenessCommunicationPhishingSecurity Programs - Question #44Threats, vulnerabilities, and mitigations
Hotspot Question Select the appropriate attack and remediation from each drop-down list to label the corresponding attack with its remediation. INSTRUCTIONS Not all attacks and rem...
Malware classificationDDoS mitigationEndpoint security controlsVulnerability management - Question #45Security Operations
Hotspot Question You are a security administrator investigating a potential infection on a network. INSTRUCTIONS Click on each host and firewall. Review all logs to determine which...
Incident responseLog analysisMalware analysisNetwork forensics - Question #46Threats, vulnerabilities, and mitigations
Which of the following vulnerabilities is exploited when an attacker overwrites a register with a malicious address?
- Question #47Threats, vulnerabilities, and mitigations
Which of the following would be the best way to handle a critical business application that is running on a legacy server?
- Question #48General security concepts
Which of the following describes the process of concealing code or text inside a graphical image?
- Question #49Security program management and oversight
After a company was compromised, customers initiated a lawsuit. The company's attorneys have requested that the security team initiate a legal hold in response to the lawsuit. Whic...
- Question #50General Security Concepts
A network manager wants to protect the company's VPN by implementing multifactor authentication that uses: - Something you know - Something you have - Something you are Which of th...
Multifactor Authentication (MFA)Authentication FactorsIdentity and Access Management (IAM)Biometrics