nerdexam
CompTIA

SY0-701 · Question #311

A security analyst finds a rogue device during a monthly audit of current endpoint assets that are connected to the network. The corporate network utilizes 002.1X for access control. To be allowed on

Sign in or unlock SY0-701 to reveal the answer and full explanation for question #311. The question stem and answer options stay visible for context.

Submitted by kwame.gh· Mar 6, 2026Threats, vulnerabilities, and mitigations

Question

A security analyst finds a rogue device during a monthly audit of current endpoint assets that are connected to the network. The corporate network utilizes 002.1X for access control. To be allowed on the network, a device must have a Known hardware address, and a valid user name and password must be entered in a captive portal. The following is the audit report:

Which of the following is the most likely way a rogue device was allowed to connect?

Exhibit

SY0-701 question #311 exhibit

Options

  • AA user performed a MAC cloning attack with a personal device.
  • BA DMCP failure caused an incorrect IP address to be distributed
  • CAn administrator bypassed the security controls for testing.
  • DDNS hijacking let an attacker intercept the captive portal traffic.

Unlock SY0-701 to see the answer

You've previewed enough free SY0-701 questions. Unlock SY0-701 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SY0-701 Practice