Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA Security+ SY0-701 Questions and answers with CertsForce

Viewing page 1 out of 14 pages
Viewing questions 1-20 out of questions
Questions # 1:

In an effort to reduce costs, a company is implementing a strategy that gives employees access to internal company resources, including email, from personal devices. Which of the following strategies is the company implementing?

Options:

A.

CYOD


B.

BYOD


C.

COPE


D.

MDM


Expert Solution
Questions # 2:

Which of the following is an example of a certificate that is generated by an internal source?

Options:

A.

Digital signature


B.

Asymmetric key


C.

Self-signed


D.

Symmetric key


Expert Solution
Questions # 3:

Which of the following should a security operations center use to improve its incident response procedure?

Options:

A.

Playbooks


B.

Frameworks


C.

Baselines


D.

Benchmarks


Expert Solution
Questions # 4:

Which of the following is a primary security concern for a company setting up a BYOD program?

Options:

A.

End of life


B.

Buffer overflow


C.

VM escape


D.

Jailbreaking


Expert Solution
Questions # 5:

Which of the following should a security administrator adhere to when setting up a new set of firewall rules?

Options:

A.

Disaster recovery plan


B.

Incident response procedure


C.

Business continuity plan


D.

Change management procedure


Expert Solution
Questions # 6:

Which of the following is the best method to reduce the attack surface of an enterprise network?

Options:

A.

Disable unused network services on servers.


B.

Use port security for wired connections.


C.

Change default passwords for network printers.


D.

Create a guest wireless network for visitors.


Expert Solution
Questions # 7:

An administrator is estimating the cost associated with an attack that could result in the replacement of a physical server. Which of the following processes is the administrator performing?

Options:

A.

Quantitative risk analysis


B.

Disaster recovery test


C.

Physical security controls review


D.

Threat modeling


Expert Solution
Questions # 8:

Which of the following is the most effective way to protect an application server running software that is no longer supported from network threats?

Options:

A.

Air gap


B.

Barricade


C.

Port security


D.

Screen subnet


Expert Solution
Questions # 9:

Which of the following would best allow a company to prevent access to systems from the Internet?

Options:

A.

Containerization


B.

Virtualization


C.

SD-WAN


D.

Air-gapped


Expert Solution
Questions # 10:

A malicious update was distributed to a common software platform and disabled services at many organizations. Which of the following best describes this type of vulnerability?

Options:

A.

DDoS attack


B.

Rogue employee


C.

Insider threat


D.

Supply chain


Expert Solution
Questions # 11:

Which of the following has been implemented when a host-based firewall on a legacy Linux system allows connections from only specific internal IP addresses?

Options:

A.

Compensating control


B.

Network segmentation


C.

Transfer of risk


D.

SNMP traps


Expert Solution
Questions # 12:

An unexpected and out-of-character email message from a Chief Executive Officer’s corporate account asked an employee to provide financial information and to change the recipient ' s contact number. Which of the following attack vectors is most likely being used?

Options:

A.

Business email compromise


B.

Phishing


C.

Brand impersonation


D.

Pretexting


Expert Solution
Questions # 13:

An analyst is evaluating the implementation of Zero Trust principles within the data plane. Which of the following would be most relevant for the analyst to evaluate?

Options:

A.

Secured zones


B.

Subject role


C.

Adaptive identity


D.

Threat scope reduction


Expert Solution
Questions # 14:

Which of the following describes an executive team that is meeting in a board room and testing the company ' s incident response plan?

Options:

A.

Continuity of operations


B.

Capacity planning


C.

Tabletop exercise


D.

Parallel processing


Expert Solution
Questions # 15:

A website user is locked out of an account after clicking an email link and visiting a different website Web server logs show the user ' s password was changed, even though the user did not change the password. Which of the following is the most likely cause?

Options:

A.

Cross-sue request forgery


B.

Directory traversal


C.

ARP poisoning


D.

SQL injection


Expert Solution
Questions # 16:

Which of the following must be considered when designing a high-availability network? (Choose two).

Options:

A.

Ease of recovery


B.

Ability to patch


C.

Physical isolation


D.

Responsiveness


E.

Attack surface


F.

Extensible authentication


Expert Solution
Questions # 17:

Which of the following is used to protect a computer from viruses, malware, and Trojans being installed and moving laterally across the network?

Options:

A.

IDS


B.

ACL


C.

EDR


D.

NAC


Expert Solution
Questions # 18:

An accountant is transferring information to a bank over FTP. Which of the following mitigations should the accountant use to protect the confidentiality of the data?

Options:

A.

Tokenization


B.

Data masking


C.

Encryption


D.

Obfuscation


Expert Solution
Questions # 19:

Which of the following types of identification methods can be performed on a deployed application during runtime?

Options:

A.

Dynamic analysis


B.

Code review


C.

Package monitoring


D.

Bug bounty


Expert Solution
Questions # 20:

The help desk receives multiple calls that machines with an outdated OS version are running slowly. Several users are seeing virus detection alerts. Which of the following mitigation techniques should be reviewed first?

Options:

A.

Patching


B.

Segmentation


C.

Monitoring


D.

Isolation


Expert Solution
Viewing page 1 out of 14 pages
Viewing questions 1-20 out of questions