SY0-701 Exam Questions
1,057 real SY0-701 exam questions with expert-verified answers and explanations. Page 21 of 22.
- Question #1026Security architecture
A company wants to protect a specialized legacy platform that controls the physical flow of gas inside of pipes. Which of the following environments does the company need to secure...
- Question #1027Security program management and oversight
Which of the following would a security analyst need to consider when prioritizing remediation efforts against known vulnerabilities?
- Question #1028Security program management and oversight
A company receives an alert that a network device vendor, which is widely used in the enterprise, has been banned by the government. Which of the following will the company's gener...
- Question #1029Threats, vulnerabilities, and mitigations
A security analyst receives an alert from a web server that contains the following logs: Which of the following attacks is being attempted?
- Question #1030Security program management and oversight
An organization knows its single loss expectancy. Which of the following does the organization need in order to determine its annualized loss expectancy?
- Question #1031Security Operations
A Chief Security Officer signs off on a request to allow inbound SMB and RDP from the internet to a single VLAN. Which of the following is the most likely explanation for this acti...
- Question #1032Threats, vulnerabilities, and mitigations
Which of the following vulnerabilities would likely be mitigated by setting up an MDM platform?
- Question #1033Threats, vulnerabilities, and mitigations
During a routine audit, an analyst discovers that a department at a high school uses a simulation program that was not properly vetted before deployment. Which of the following thr...
- Question #1034Security program management and oversight
A new employee can select a particular make and model of an employee workstation from a preapproved list. Which of the following is this an example of?
- Question #1036Security architecture
Which of the following technologies must be used in an organization that intends to automate infrastructure deployment?
- Question #1037Security Operations
A company has experienced a large data breach. The external investigators want to make sure that any evidence related to the breach is preserved. Which of the following incident re...
- Question #1038General security concepts
Which of the following technologies assists in passively verifying the expired status of a dig tal certificate?
- Question #1039Security architecture
A technician is setting up a public-facing web server and needs to ensure traffic is secure. Which of the following steps should the technician take to begin this process?
- Question #1040Security architecture
A school administrator wants to limit access to certain web pages to ensure that only age- appropriate material is available to students. Which of the following tools would best me...
- Question #1041Security program management and oversight
Which of the following is an internal audit team's function within risk management?
- Question #1042Threats, vulnerabilities, and mitigations
A software engineer is developing a new business application and needs to check for errors and security flaws before the software engineer compiles and sends it for testing. Which...
- Question #1043Threats, vulnerabilities, and mitigations
Which of the following should be used to prevent changes to system-level data?
- Question #1044Threats, vulnerabilities, and mitigations
Which of the following best describes why a company would erase a newly purchased device and install its own image with an operating system and applications?
- Question #1045Threats, vulnerabilities, and mitigations
Which of the following factors must a systems administrator take into consideration first when reviewing options to remediate a vulnerability on an end-of-life software system in p...
- Question #1046Security program management and oversight
Which of the following metrics are used to calculate the risk rating in a matrix format? (Choose two.)
- Question #1047Security Operations
An analyst wants to move data from production to the UAT server to test the latest release. Which of the following strategies to protect data should the analyst use?
- Question #1048Security architecture
A company wants to restrict uploads to a popular file-sharing website but allow downloads from the same website. Which of the following technologies would best accomplish this goal...
- Question #1049General security concepts
Which of the following cryptographic solutions best protects the confidentiality and integrity of data?
- Question #1050Security Operations
A security analyst is concerned malicious actors are lurking in an environment but has not received any alerts regarding suspicious activity. Which of the following should the anal...
- Question #1051Threats, vulnerabilities, and mitigations
A software engineer is downloading a third-party application from a public repository and wants to ensure the application has not been maliciously altered. Which of the following t...
- Question #1052Threats, vulnerabilities, and mitigations
Which of the following risk management strategies describes applying a compensating control to a device rather than patching?
- Question #1053General security concepts
Which of the following technologies assists in passively verifying the expired status of a digital certificate?
- Question #1054Threats, vulnerabilities, and mitigations
Which of the following security measures should database servers containing passwords utilize? (Choose two.)
- Question #1055Threats, vulnerabilities, and mitigations
Remote users report that they are unable to log in to the VPN. The help desk confirms that each employee has a stable internet connection and correct permissions for VPN use but al...
- Question #1057Security Operations
Which of the following are examples of operational controls that would be appropriate to implement in an environment where financial processing activities occur? (Choose two.)
- Question #1058Threats, vulnerabilities, and mitigations
A penetration tester gained access to a server room by dressing as an engineer from a known third-party vendor. Which of the following types of penetration tests was performed?
- Question #1059Security Operations
The help desk receives multiple calls indicating that machines are running slowly when running enterprise applications. The help desk notes that the affected machines are out of co...
- Question #1060General security concepts
An organization needs to block certain information from view. Which of the following should the organization use to accomplish this task?
- Question #1061Threats, vulnerabilities, and mitigations
A company phone with proprietary data used by an employee has been stolen. Which of the following can be used to remotely wipe the device?
- Question #1062Threats, vulnerabilities, and mitigations
Visitors to a company's facilities are connecting to the company's corporate network Wi-Fi and open network ports. Which of the following should the security engineer implement to...
- Question #1063Security program management and oversight
A Chief Information Security Officer has decided that purchasing insurance when the ALE of expected incidents exceeds $1 million is the most cost-effective approach. Which of the f...
- Question #1064Threats, vulnerabilities, and mitigations
Which of the following vulnerabilities would a nation-state attacker most likely exploit?
- Question #1065Threats, vulnerabilities, and mitigations
Car vandalism repeatedly occurs near a specific part of a company's ungated facility. Which of the following would provide the best physical deterrent? (Choose two.)
- Question #1067Security architecture
An organization with multiple geographic locations has invested in various internet circuits at each location, including MPLS, 4G/5G, broadband, and dial-up. An architect is config...
- Question #1068Security architecture
A Chief Information Officer wants to ensure that network devices cannot connect to the public internet and the local network to directly perform firmware updates. The IT team must...
- Question #1069General security concepts
Which of the following scenarios will proper application of the least privilege principle prevent?
- Question #1070Implementation - Implementing secure protocols and authentication mechanisms (CompTIA Security+ Domain 3: Implementation / CompTIA Linux+ / LPIC-1 SSH Configuration)
Drag and Drop Question A security engineer is setting up passwordless authentication for the first time. INSTRUCTIONS Drag and drop the MINIMUM set of commands to set this up and v...
SSHPasswordless AuthenticationPublic Key InfrastructureLinux Security - Question #1071Security Operations
While troubleshooting an internal resource's poor performance for an end user, a network engineer performs a traceroute on the end device and receives the following output: The eng...
- Question #1072Security program management and oversight
The management team wants to assess the cybersecurity team's readiness to respond to a threat scenario. Which of the following will adequately assess and formalize a response withi...
- Question #1073General security concepts
A network administrator deploys an FDE solution on all end user workstations. Which of the following data protection strategies does this describe?
- Question #1074Threats, vulnerabilities, and mitigations
A network security analyst monitors the network's IDS. which has flagged unusual activity. The IDS has detected multiple login attempts to a database server within a short period....
- Question #1075Security program management and oversight
A company performs a risk assessment on the information security program each year. Which of the following best describes this risk assessment?
- Question #1076Threats, vulnerabilities, and mitigations
Which of the following threat actors will most likely use multiple zero-day vulnerabilities to target government research organizations to steal IPs?
- Question #1077Threats, vulnerabilities, and mitigations
While accessing a banking website, a user notices that the cursor keeps disappearing and there seems to be a lag when entering login information. Which of the following best descri...
- Question #1078Security program management and oversight
Which of the following will best ensure a controlled version release of a new software application?