SY0-701 Exam Questions
1,057 real SY0-701 exam questions with expert-verified answers and explanations. Page 19 of 22.
- Question #926General security concepts
Which of the following is the most closely associated with confidentiality?
- Question #927Security Operations
During an assessment, an organization provides a penetration tester with a website URL and login credentials. However, the tester does not have access to the source code. Which of...
- Question #928Security Operations
A security analyst learns that an attack vector, which was used as a part of a recent incident, was a well-known IoT device exploit. The analyst needs to review logs to identify th...
- Question #929Threats, vulnerabilities, and mitigations
Which of the following best describes when a user installs an application from an unofficial application store?
- Question #930General security concepts
A security administrator must use a strategy to protect the company's data. The security administrator decides to deploy FDE on the end user devices and TLS for all web connections...
- Question #931Security Operations
An administrator investigating an incident is concerned about the downtime of a critical server due to a failed drive. Which of the following would the administrator use to estimat...
- Question #932Security architecture
A business manager is concerned about the availability of an application running on hardware in the local data center. Which of the following solutions will improve availability wh...
- Question #933Security architecture
A company wants to ensure that a mission-critical database can only be accessed from specific internal IP addresses. Which of the following should the company deploy to meet this r...
- Question #934Security architecture
A store is setting up wireless access for their employees. Management wants to limit the number of access points while ensuring all areas of the store are covered. Which of the fol...
- Question #935Security operations
A security engineer has been assigned to work on a request from outside counsel. The security engineer must provide all email correspondence within a specific date range. Which of...
Litigation holdEvidence preservationeDiscoveryLegal compliance - Question #936Security Operations
A red-team provider tailgates into an organization's facility. Which of the following has occurred?
- Question #937General security concepts
Which of the following describes an agent-based application that detects and blocks malicious behavior on enterprise systems while disconnected from the corporate network?
- Question #938Security Operations
A manager meets with various stakeholders involved with a recently resolved security incident. During the meeting, they discuss potential improvements to the environment in order t...
- Question #939Threats, vulnerabilities, and mitigations
A database engineer needs sample customer data for testing purposes. Which of the following techniques can be used to remove sensitive information from database records while still...
- Question #940Threats, vulnerabilities, and mitigations
Which of the following encryption methods protects data if a user loses their laptop?
- Question #941Security Operations
A security analyst regularly receives emails from users who are concerned that attached files may be malicious. Which of the following should the analyst use to evaluate the suspic...
- Question #942Security Operations
A CIRT team updates their playbooks to include instructions to respond to a ransomware attack. To prepare for a real event, the team performs a simulation and assesses their perfor...
- Question #943Security Operations
Which of the following can automate vulnerability management?
- Question #944Security program management and oversight
Which of the following is a reason to perform a one-time risk assessment?
- Question #945Threats, vulnerabilities, and mitigations
An employee from the accounting department logs in to the website used for processing the company's payments. After logging in, a new desktop application automatically downloads on...
- Question #946Security Operations
An EDR solution recognizes that a specific workstation has outbound traffic to a malicious IP. Which of the following would be the best action to take to contain the threat?
- Question #947Threats, vulnerabilities, and mitigations
Which of the following would most likely prevent exploitation of an end-of-life, business-critical system?
- Question #948General security concepts
Which of the following is the most likely motivation for a hacktivist?
- Question #949Threats, vulnerabilities, and mitigations
Which of the following is the best physical security control to prevent damage from a vehicle?
- Question #950Security architecture
A security team wants to work with the same organization's development team to ensure WAF policies are automatically created when applications are deployed. Which of the following...
- Question #951Security architecture
Which of the following uses proprietary controls and is designed to function in harsh environments over many years with limited remote access management?
- Question #952Security Operations
Which of the following data recovery strategies will result in a quick recovery at low cost?
- Question #953Security architecture
An MSSP manages firewalls for hundreds of clients. Which of the following tools would be most helpful to create a standard configuration template in order to improve the efficiency...
- Question #954Security program management and oversight
After multiple phishing simulations, the Chief Security Officer announces a new program that incentivizes employees to not click phishing links in the upcoming quarter. Which of th...
- Question #955Threats, vulnerabilities, and mitigations
A security analyst sees an increase of vulnerabilities on workstations after a deployment of a company group policy. Which of the following vulnerability types will the analyst mos...
- Question #956Threats, vulnerabilities, and mitigations
Which of the following threat actors would most likely target an organization by using a logic bomb within an internally-developed application?
- Question #957Security architecture
Which of the following is a company addressing when it rolls out MDM on all COPE devices?
- Question #958Security program management and oversight
An organization failed to account for the right-to-be-forgotten regulations. Which of the following impacts might this action have on the company?
- Question #959Threats, vulnerabilities, and mitigations
A company is experiencing issues with employees leaving the company for a competitor and taking customer contact information with them. Which of the following tools will help preve...
- Question #960Security architecture
A company that operates with most of its infrastructure in the cloud had its development environment breached. The attackers gained access via a public-facing development applicati...
- Question #961General security concepts
Which of the following security concepts is being followed when applying encryption to sensitive data?
- Question #962General security concepts
Which of the following cryptographic solutions would allow an organization to recover encrypted data after a key becomes corrupted or is deleted?
- Question #963Security program management and oversight
An organization is evaluating the cost of licensing a new solution to prevent ransomware. Which of the following is the most helpful in making this decision?
- Question #964Security architecture
Which of the following should be used to ensure that a device is inaccessible to a network- connected resource?
- Question #965Security Operations
During the investigation of a webmail log-in using compromised credentials, a security analyst needs to review information about the source IP for the log-in. Which of the followin...
- Question #966General security concepts
Which of the following should be used to select a label for a file based on the file's value, sensitivity, or applicable regulations?
- Question #967Security Operations
A company makes a change during the appropriate change window, but the unsuccessful change extends beyond the scheduled time and impacts customers. Which of the following would pre...
- Question #968Security Operations
A security analyst is collecting evidence in response to an incident. Which of the following must the analyst maintain in order to ensure the admissibility of the evidence in a cou...
- Question #969Threats, vulnerabilities, and mitigations
Which of the following types of vulnerabilities involves attacking a system to access adjacent hosts?
- Question #970Threats, vulnerabilities, and mitigations
While reviewing a recent compromise, a forensics team discovers that there are hard-coded credentials in the database connection strings. Which of the following assessment types sh...
- Question #971Security architecture
Which of the following should be deployed on an externally facing web server in order to establish an encrypted connection?
- Question #972Security Operations
A security administrator receives multiple reports about the same suspicious email. Which of the following is the most likely reason for the malicious email's continued delivery?
- Question #973Threats, vulnerabilities, and mitigations
While browsing a web page, a user receives a pop-up with a link telling them to navigate to another site. To which of the following is the site vulnerable?
- Question #974Threats, vulnerabilities, and mitigations
An administrator must secure several end-of-life SCADA devices in a manufacturing facility on a limited budget. Which of the following should the security administrator do to best...
- Question #975Threats, vulnerabilities, and mitigations
A business is expanding to a new country and must protect customers from accidental disclosure of specific national identity information. Which of the following should the security...