SY0-701 Exam Questions
1,057 real SY0-701 exam questions with expert-verified answers and explanations. Page 6 of 22.
- Question #254Threats, vulnerabilities, and mitigations
An administrator is Investigating an incident and discovers several users' computers were Infected with malware after viewing files mat were shared with them. The administrator dis...
- Question #255General security concepts
Which of the following is an algorithm performed to verify that data has not been modified?
- Question #256Security program management and oversight
An employee recently resigned from a company. The employee was responsible for managing and supporting weekly batch jobs over the past five years. A few weeks after the employee re...
- Question #257General security concepts
A security manager is implementing MFA and patch management. Which of the following would best describe the control type and category? (Select two).
- Question #258Security architecture
An organization implemented cloud-managed IP cameras to monitor building entry points and sensitive areas. The service provider enables direct TCP/IP connection to stream live vide...
- Question #259Threats, vulnerabilities, and mitigations
A security analyst discovers that a large number of employee credentials had been stolen and were being sold on the dark web. The analyst investigates and discovers that some hourl...
- Question #260Threats, vulnerabilities, and mitigations
A business uses Wi-Fi with content filleting enabled. An employee noticed a coworker accessed a blocked sue from a work computer and repotted the issue. While Investigating the iss...
- Question #262Security program management and oversight
Two companies are in the process of merging. The companies need to decide how to standardize their information security programs. Which of the following would best align the securi...
- Question #263General security concepts
A network administrator deployed a DNS logging tool that togs suspicious websites that are visited and then sends a daily report based on various weighted metrics. Which of the fol...
- Question #264General security concepts
Which of the following is best used to detect fraud by assigning employees to different roles?
- Question #265Security Operations
A systems administrate wants to implement a backup solution. the solution needs to allow recovery of the entire system, including the operating system, in case of a disaster. Which...
- Question #266Threats, vulnerabilities, and mitigations
A spoofed identity was detected for a digital certificate. Which of the following are the type of unidentified key and the certificate mat could be in use on the company domain?
- Question #267Security program management and oversight
The Chief Information Security Officer wants to put security measures in place to protect PlI. The organization needs to use its existing labeling and classification system to acco...
- Question #268Security Operations
An analyst is reviewing an incident in which a user clicked on a link in a phishing email. Which of the following log sources would the analyst utilize to determine whether the con...
- Question #269Security Operations
The Cruel Information Security Officer (CISO) asks a security analyst to install an OS update to a production VM that has a 99% uptime SLA. The CISO tells me analyst the installati...
- Question #270Security architecture
Sine?a recent upgrade (o a WLAN infrastructure, several mobile users have been unable to access the internet from the lobby. The networking team performs a heat map survey of the b...
- Question #271Threats, vulnerabilities, and mitigations
An employee in the accounting department receives an email containing a demand for payment tot services performed by a vendor However, the vendor is not in the vendor management da...
- Question #272Security architecture
While considering the organization's cloud-adoption strategy, the Chief Information Security Officer sets a goal to outsource patching of firmware, operating systems, and applicati...
- Question #273Security Operations
A security analyst is assessing several company firewalls. Which of the following cools would The analyst most likely use to generate custom packets to use during the assessment?
- Question #274Security Operations
A new vulnerability enables a type of malware that allows the unauthorized movement of data from a system. Which of the following would detect this behavior?
- Question #275Threats, vulnerabilities, and mitigations
Which of the following can a security director use to prioritize vulnerability patching within a company's IT environment?
- Question #276Security architecture
Which of the following is the most effective way to protect an application server running software that is no longer supported from network threats?
- Question #277Threats, vulnerabilities, and mitigations
Which of the following is the best method to reduce the attack surface of an enterprise network?
Attack Surface ReductionHardeningVulnerability ManagementDefault Credentials - Question #278Threats, vulnerabilities, and mitigations
Cadets speaking a foreign language are using company phone numbers to make unsolicited phone calls lo a partner organization. A security analyst validates through phone system logs...
- Question #279Threats, vulnerabilities, and mitigations
An IT security team is concerned about the confidentiality of documents left unattended in MFPs. Which of the following should the security team do to mitigate the situation?
- Question #280Security Operations
A systems administrator is auditing all company servers to ensure. They meet the minimum security baseline While auditing a Linux server, the systems administrator observes the /et...
- Question #281Threats, vulnerabilities, and mitigations
During a recent company safety stand-down, the cyber-awareness team gave a presentation on the importance of cyber hygiene. One topic the team covered was best practices for printi...
- Question #282Threats, vulnerabilities, and mitigations
A software developer would like to ensure. The source code cannot be reverse engineered or debugged. Which of the following should the developer consider?
- Question #284Security architecture
A security audit of an organization revealed that most of the IT staff members have domain administrator credentials and do not change the passwords regularly. Which of the followi...
- Question #285Security Operations
A company wants to get alerts when others are researching and doing reconnaissance on the company One approach would be to host a part of the Infrastructure online with known vulne...
- Question #286Threats, vulnerabilities, and mitigations
Which of the following best describes why me SMS DIP authentication method is more risky to implement than the TOTP method?
- Question #287Threats, vulnerabilities, and mitigations
A website user is locked out of an account after clicking an email link and visiting a different website Web server logs show the user's password was changed, even though the user...
- Question #288Threats, vulnerabilities, and mitigations
A security engineer is working to address the growing risks that shadow IT services are introducing to the organization. The organization has taken a cloud-first approach end does...
- Question #289Security Operations
A cybersecurity incident response team at a large company receives notification that malware is present on several corporate desktops No known Indicators of compromise have been fo...
- Question #290Security Operations
Which of the following is a reason why a forensic specialist would create a plan to preserve data after an modem and prioritize the sequence for performing forensic analysis?
- Question #291Security program management and oversight
A security analyst is creating base for the server team to follow when hardening new devices for deployment. Which of the following beet describes what the analyst is creating?
- Question #292General security concepts
In which of the following scenarios is tokenization the best privacy technique 10 use?
- Question #293Threats, vulnerabilities, and mitigations
A security administrator recently reset local passwords and the following values were recorded in the system: Which of the following in the security administrator most likely prote...
- Question #294General security concepts
A vendor needs to remotely and securely transfer files from one server to another using the command line. Which of the following protocols should be Implemented to allow for this t...
- Question #295Security program management and oversight
Which of the following data roles is responsible for identifying risks and appropriate access to data?
- Question #296Security program management and oversight
Various stakeholders are meeting to discuss their hypothetical roles and responsibilities in a specific situation, such as a security incident or major disaster. Which of the follo...
- Question #297General security concepts
An external vendor recently visited a company's headquarters tor a presentation. Following the visit a member of the hosting team found a file that the external vendor left behind...
- Question #298Security Operations
The security operations center is researching an event concerning a suspicious IP address. A security analyst looks at the following event logs and discovers that a significant por...
- Question #299Threats, vulnerabilities, and mitigations
Which of the following explains why an attacker cannot easily decrypt passwords using a rainbow table attack?
- Question #300Security architecture
A company is currently utilizing usernames and passwords, and it wants to integrate an MFA method that is seamless, can Integrate easily into a user's workflow, and can utilize emp...
- Question #301Security architecture
A financial institution would like to store its customer data m the cloud but still allow the data to be accessed and manipulated while encrypted. Doing so would prevent the cloud...
- Question #302Threats, vulnerabilities, and mitigations
The Chief Information Security Officer of an organization needs to ensure recovery from ransomware would likely occur within the organization's agreed-upon RPOs end RTOs. Which of...
- Question #303General security concepts
Which of the following best describe why a process would require a two-person integrity security control?
- Question #304Security architecture
A company recently decided to allow employees to work remotely. The company wants to protect us data without using a VPN. Which of the following technologies should the company Imp...
- Question #305Security program management and oversight
In a rush to meet an end-of-year business goal, the IT department was told to implement a new business application. The security engineer reviews the attributes of the application...