SY0-701 Exam Questions
1,057 real SY0-701 exam questions with expert-verified answers and explanations. Page 8 of 22.
- Question #359Security program management and oversight
After creating a contract for IT contractors, the human resources department changed several clauses. The contract has gone through three revisions. Which of the following processe...
- Question #360Security Program Management and Oversight
The executive management team is mandating the company develop a disaster recovery plan. The cost must be kept to a minimum, and the money to fund additional internet connections i...
Disaster RecoveryCold SiteCost ManagementBusiness Continuity - Question #361General security concepts
Which of the following teams is best suited to determine whether a company has systems that can be exploited by a potential, identified vulnerability?
Red teamVulnerability exploitationSecurity testingOffensive security - Question #362Threats, vulnerabilities, and mitigations
A company is reviewing options to enforce user logins after several account takeovers. The following conditions must be met as part of the solution: - Allow employees to work remot...
- Question #363Security Operations
Which of the following methods can be used to detect attackers who have successfully infiltrated a network? (Choose two.)
- Question #364General security concepts
A company wants to ensure that the software it develops will not be tampered with after the final version is completed. Which of the following should the company most likely use?
- Question #365Security architecture
An organization completed a project to deploy SSO across all business applications last year. Recently, the finance department selected a new cloud-based accounting software vendor...
- Question #366Threats, vulnerabilities, and mitigations
A user, who is waiting for a flight at an airport, logs in to the airline website using the public Wi-Fi, ignores a security warning and purchases an upgraded seat. When the flight...
- Question #367Threats, vulnerabilities, and mitigations
A network engineer deployed a redundant switch stack to increase system availability. However, the budget can only cover the cost of one ISP connection. Which of the following best...
- Question #368General security concepts
A network team segmented a critical, end-of-life server to a VLAN that can only be reached by specific devices but cannot be reached by the perimeter network. Which of the followin...
- Question #369Threats, vulnerabilities, and mitigations
A threat actor was able to use a username and password to log in to a stolen company mobile device. Which of the following provides the best solution to increase mobile data securi...
- Question #370General security concepts
Which of the following best describes the risk present after controls and mitigating factors have been applied?
- Question #371Threats, vulnerabilities, and mitigations
A software development team asked a security administrator to recommend techniques that should be used to reduce the chances of the software being reverse engineered. Which of the...
- Question #372General security concepts
Which of the following is a possible factor for MFA?
MFAAuthentication FactorsAccess Control - Question #373Threats, vulnerabilities, and mitigations
Easy-to-guess passwords led to an account compromise. The current password policy requires at least 12 alphanumeric characters, one uppercase character, one lowercase character, a...
- Question #374Threats, vulnerabilities, and mitigations
A user downloaded software from an online forum. After the user installed the software, the security team observed external network traffic connecting to the user's computer on an...
- Question #375Security architecture
A utility company is designing a new platform that will host all the virtual machines used by business applications. The requirements include: - A starting baseline of 50% memory u...
- Question #376Threats, vulnerabilities, and mitigations
Which of the following best describes a use case for a DNS sinkhole?
- Question #377Security operations
An incident analyst finds several image files on a hard disk. The image files may contain geolocation coordinates. Which of the following best describes the type of information the...
MetadataDigital forensicsGeolocationIncident response - Question #378General security concepts
Which of the following most likely describes why a security engineer would configure all outbound emails to use S/MIME digital signatures?
- Question #379General security concepts
Which of the following considerations is the most important regarding cryptography used in an IoT device?
- Question #380Security architecture
A coffee shop owner wants to restrict internet access to only paying customers by prompting them for a receipt number. Which of the following is the best method to use given this r...
- Question #381Security Operations
While performing digital forensics, which of the following is considered the most volatile and should have the contents collected first?
- Question #382Security program management and oversight
A hosting provider needs to prove that its security controls have been in place over the last six months and have sufficiently protected customer data. Which of the following would...
- Question #383Security program management and oversight
A city municipality lost its primary data center when a tornado hit the facility. Which of the following should the city staff use immediately after the disaster to handle essentia...
- Question #384General security concepts
Which of the following is considered a preventive control?
- Question #385Threats, vulnerabilities, and mitigations
A systems administrator notices that a testing system is down. While investigating, the systems administrator finds that the servers are online and accessible from any device on th...
- Question #386Security Operations
A security team has been alerted to a flood of incoming emails that have various subject lines and are addressed to multiple email inboxes. Each email contains a URL shortener link...
- Question #387Threats, vulnerabilities, and mitigations
A security administrator is working to secure company data on corporate laptops in case the laptops are stolen. Which of the following solutions should the administrator consider?
Data encryptionEndpoint securityData at rest protectionTheft mitigation - Question #388Security program management and oversight
A company needs to keep the fewest records possible, meet compliance needs, and ensure destruction of records that are no longer needed. Which of the following best describes the p...
Data RetentionComplianceData DisposalInformation Governance - Question #390Security program management and oversight
Which of the following is the best reason an organization should enforce a data classification policy to help protect its most sensitive information?
Data classificationSecurity policiesInformation protectionSecurity program management - Question #391Security operations
An analyst is performing a vulnerability scan against the web servers exposed to the internet without a system account. Which of the following is most likely being performed?
Vulnerability scanningNon-credentialed scanSecurity assessmentWeb security - Question #392Threats, vulnerabilities, and mitigations
A security administrator is hardening corporate systems and applying appropriate mitigations by consulting a real-world knowledge base for adversary behavior. Which of the followin...
- Question #393Security architecture
An architect has a request to increase the speed of data transfer using JSON requests externally. Currently, the organization uses SFTP to transfer data files. Which of the followi...
- Question #394Security program management and oversight
Which of the following addresses individual rights such as the right to be informed, the right of access, and the right to be forgotten?
GDPRData PrivacyIndividual RightsRegulatory Compliance - Question #395Security Operations
An administrator is installing an LDAP browser tool in order to view objects in the corporate LDAP directory. Secure connections to the LDAP server are required. When the browser c...
- Question #396Threats, vulnerabilities, and mitigations
Which of the following is the most important security concern when using legacy systems to provide production service?
- Question #397Threats, vulnerabilities, and mitigations
A security investigation revealed that malicious software was installed on a server using a server administrator's credentials. During the investigation, the server administrator e...
- Question #398General security concepts
A user is requesting Telnet access to manage a remote development web server. Insecure protocols are not allowed for use within any environment. Which of the following should be co...
- Question #399Security architecture
A security administrator is working to find a cost-effective solution to implement certificates for a large number of domains and subdomains owned by the company. Which of the foll...
- Question #400Threats, vulnerabilities, and mitigations
An auditor discovered multiple insecure ports on some servers. Other servers were found to have legacy protocols enabled. Which of the following tools did the auditor use to discov...
- Question #401Threats, vulnerabilities, and mitigations
A security analyst received a tip that sensitive proprietary information was leaked to the public. The analyst is reviewing the PCAP and notices traffic between an internal server...
- Question #403Threats, vulnerabilities, and mitigations
A security administrator is performing an audit on a stand-alone UNIX server, and the following message is immediately displayed: (Error 13): /etc/shadow: Permission denied. Which...
- Question #404General security concepts
A security administrator needs to create firewall rules for the following protocols: RTP, SIP, H.323. and SRTP. Which of the following does this rule set support?
- Question #405Threats, vulnerabilities, and mitigations
Which of the following best describes a social engineering attack that uses a targeted electronic messaging campaign aimed at a Chief Executive Officer?
- Question #406Threats, vulnerabilities, and mitigations
During a penetration test, a flaw in the internal PKI was exploited to gain domain administrator rights using specially crafted certificates. Which of the following remediation tas...
- Question #407General security concepts
A company wants to implement MFA. Which of the following enables the additional factor while using a smart card?
- Question #408Security architecture
A company hired an external consultant to assist with required system upgrades to a critical business application. A systems administrator needs to secure the consultant's access w...
- Question #409Threats, vulnerabilities, and mitigations
A newly implemented wireless network is designed so that visitors can connect to the wireless network for business activities. The legal department is concerned that visitors might...
- Question #411General security concepts
Which of the following physical controls can be used to both detect and deter? (Choose two.)