Weekend Sale Special Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: CFsave75

Pass the CompTIA CompTIA Security+ SY0-701 Questions and answers with CertsForce

Viewing page 2 out of 14 pages
Viewing questions 21-40 out of questions
Questions # 21:

A systems administrate wants to implement a backup solution. the solution needs to allow recovery of the entire system, including the operating system, in case of a disaster. Which of the following backup types should the administrator consider?

Options:

A.

Incremental


B.

Storage area network


C.

Differential


D.

Image


Expert Solution
Questions # 22:

A service provider wants a cost-effective way to rapidly expand from providing internet links to managing them. Which of the following methods will allow the service provider to best scale its services while maintaining performance consistency?

Options:

A.

Escalation support


B.

Increased workforce


C.

Baseline enforcement


D.

Technical debt


Expert Solution
Questions # 23:

A security engineer is installing an IPS to block signature-based attacks in the environment. Which of the following modes will best accomplish this task?

Options:

A.

Monitor


B.

Sensor


C.

Audit


D.

Active


Expert Solution
Questions # 24:

Which of the following can be used to compromise a system that is running an RTOS?

Options:

A.

Cross-site scripting


B.

Memory injection


C.

Replay attack


D.

Ransomware


Expert Solution
Questions # 25:

A company with a high-availability website is looking to harden its controls at any cost. The company wants to ensure that the site is secure by finding any possible issues. Which of the following would most likely achieve this goal?

Options:

A.

Permission restrictions


B.

Bug bounty program


C.

Vulnerability scan


D.

Reconnaissance


Expert Solution
Questions # 26:

An organization wants a third-party vendor to do a penetration test that targets a specific device. The organization has provided basic information about the device. Which of the following best describes this kind of penetration test?

Options:

A.

Partially known environment


B.

Unknown environment


C.

Integrated


D.

Known environment


Expert Solution
Questions # 27:

Which of the following would be the best way to block unknown programs from executing?

Options:

A.

Access control list


B.

Application allow list.


C.

Host-based firewall


D.

DLP solution


Expert Solution
Questions # 28:

Which of the following is prevented by proper data sanitization?

Options:

A.

Hackers ' ability to obtain data from used hard drives


B.

Devices reaching end-of-life and losing support


C.

Disclosure of sensitive data through incorrect classification


D.

Incorrect inventory data leading to a laptop shortage


Expert Solution
Questions # 29:

Various stakeholders are meeting to discuss their hypothetical roles and responsibilities in a specific situation, such as a security incident or major disaster. Which of the following best describes this meeting?

Options:

A.

Penetration test


B.

Continuity of operations planning


C.

Tabletop exercise


D.

Simulation


Expert Solution
Questions # 30:

An organization has issues with deleted network share data and improper permissions. Which solution helps track and remediate these?

Options:

A.

DLP


B.

EDR


C.

FIM


D.

ACL


Expert Solution
Questions # 31:

Which of the following is die most important security concern when using legacy systems to provide production service?

Options:

A.

Instability


B.

Lack of vendor support


C.

Loss of availability


D.

Use of insecure protocols


Expert Solution
Questions # 32:

Which of the following explains how organizations benefit from SCAP?

Options:

A.

The configurations defined as part of established baselines allow organizations to deploy well-tested security solutions quickly and easily.


B.

The consolidated reporting layout makes it easier for technicians to communicate incident response to senior decision-makers.


C.

The common format for vulnerability scanning and reporting enables greater interoperability between security tools from different vendors.


D.

The strict compliance to international standards reduces overall cost and risk to organizations when a security breach occurs.


Expert Solution
Questions # 33:

The marketing department set up its own project management software without telling the appropriate departments. Which of the following describes this scenario?

Options:

A.

Shadow IT


B.

Insider threat


C.

Data exfiltration


D.

Service disruption


Expert Solution
Questions # 34:

Which of the following would best ensure a controlled version release of a new software application?

Options:

A.

Business continuity planning


B.

Quantified risk analysis


C.

Static code analysis


D.

Change management procedures


Expert Solution
Questions # 35:

When trying to access an internal website, an employee reports that a prompt displays, stating that the site is insecure. Which of the following certificate types is the site most likely using?

Options:

A.

Wildcard


B.

Root of trust


C.

Third-party


D.

Self-signed


Expert Solution
Questions # 36:

An organization plans to expand its operations internationally and needs to keep data at the new location secure. The organization wants to use the most secure architecture model possible. Which of the following models offers the highest level of security?

Options:

A.

Cloud-based


B.

Peer-to-peer


C.

On-premises


D.

Hybrid


Expert Solution
Questions # 37:

A bank insists all of its vendors must prevent data loss on stolen laptops. Which of the following strategies is the bank requiring?

Options:

A.

Encryption at rest


B.

Masking


C.

Data classification


D.

Permission restrictions


Expert Solution
Questions # 38:

Which of the following methods to secure credit card data is best to use when a requirement is to see only the last four numbers on a credit card?

Options:

A.

Encryption


B.

Hashing


C.

Masking


D.

Tokenization


Expert Solution
Questions # 39:

An employee fell for a phishing scam, which allowed an attacker to gain access to a company PC. The attacker scraped the PC’s memory to find other credentials. Without cracking these credentials, the attacker used them to move laterally through the corporate network. Which of the following describes this type of attack?

Options:

A.

Privilege escalation


B.

Buffer overflow


C.

SQL injection


D.

Pass-the-hash


Expert Solution
Questions # 40:

A security operations center determines that the malicious activity detected on a server is normal. Which of the following activities describes the act of ignoring detected activity in the future?

Options:

A.

Tuning


B.

Aggregating


C.

Quarantining


D.

Archiving


Expert Solution
Viewing page 2 out of 14 pages
Viewing questions 21-40 out of questions