Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA Security+ SY0-701 Questions and answers with CertsForce

Viewing page 3 out of 14 pages
Viewing questions 41-60 out of questions
Questions # 41:

A penetration test identifies that an SMBvl Is enabled on multiple servers across an organization. The organization wants to remediate this vulnerability in the most efficient way possible. Which of the following should the organization use for this purpose?

Options:

A.

GPO


B.

ACL


C.

SFTP


D.

DLP


Expert Solution
Questions # 42:

A company decided to reduce the cost of its annual cyber insurance policy by removing the coverage for ransomware attacks.

Which of the following analysis elements did the company most likely use in making this decision?

Options:

A.

IMTTR


B.

RTO


C.

ARO


D.

MTBF


Expert Solution
Questions # 43:

A software developer released a new application and is distributing the application files through the developer’s website. Which of the following should the developer post on the website to allow users to verify the integrity of the downloaded files?

Options:

A.

Hashes


B.

Certificates


C.

Algorithms


D.

Salting


Expert Solution
Questions # 44:

Which of the following best explains how open service ports increase an organization ' s attack surface?

Options:

A.

They are commonly overlooked by endpoint antivirus tools during scans.


B.

They can make the company’s remote entry point available to the internet.


C.

They enable automatic application updates to reduce vulnerability windows.


D.

They can expose unnecessary services to unauthorized access if not properly restricted.


Expert Solution
Questions # 45:

An end-of-service server cannot be patched, but it still performs as expected for business operations. The team moves the system to a segmented network. Which of the following control types has the team applied?

Options:

A.

Preventive


B.

Deterrent


C.

Corrective


D.

Compensating


Expert Solution
Questions # 46:

A security engineer needs to analyze the implications of moving proprietary company data from a local server to a public cloud storage service. Which of the following actions should the engineer take first?

Options:

A.

Create an architecture diagram of cloud storage solutions.


B.

Migrate sample data to the cloud to run security tests.


C.

Agree on data classification labels with stakeholders.


D.

Make a backup of the data on cloud-neutral storage.


Expert Solution
Questions # 47:

Which of the following is a qualitative approach to risk analysis?

Options:

A.

Including the MTTR and MTBF as part of the risk assessment


B.

Tracking and documenting network risks using a risk register


C.

Assigning a level of high, medium, or low to the risk rating


D.

Using ALE and ARO to help determine whether a risk should be mitigated


Expert Solution
Questions # 48:

Which of the following is the best way to prevent an unauthorized user from plugging a laptop into an employee ' s phone network port and then using tools to scan for database servers?

Options:

A.

MAC filtering


B.

Segmentation


C.

Certification


D.

Isolation


Expert Solution
Questions # 49:

A company processes a large volume of business-to-business transactions and prioritizes data confidentiality over transaction availability. The company’s firewall administrator must configure a new hardware-based firewall to replace the current one. Which of the following should the administrator do to best align with the company requirements in case a security event occurs?

Options:

A.

Ensure the firewall data plane moves to fail-closed mode.


B.

Implement a deny-all rule as the last firewall ACL rule.


C.

Prioritize business-critical application traffic through the firewall.


D.

Configure rate limiting between the firewall interfaces.


Expert Solution
Questions # 50:

Which of the following consequences would a retail chain most likely face from customers in the event the retailer is non-compliant with PCI DSS?

Options:

A.

Contractual impacts


B.

Sanctions


C.

Fines


D.

Reputational damage


Expert Solution
Questions # 51:

A security manager created new documentation to use in response to various types of security incidents. Which of the following is the next step the manager should take?

Options:

A.

Set the maximum data retention policy.


B.

Securely store the documents on an air-gapped network.


C.

Review the documents ' data classification policy.


D.

Conduct a tabletop exercise with the team.


Expert Solution
Questions # 52:

Which of the following is used to validate a certificate when it is presented to a user?

Options:

A.

OCSP


B.

CSR


C.

CA


D.

CRC


Expert Solution
Questions # 53:

Which of the following steps in the incident response process involves developing a hypothesis of possible attack paths and using various sources to confirm or deny the hypothesis?

Options:

A.

Identification


B.

Investigation


C.

Containment


D.

Preparation


Expert Solution
Questions # 54:

A technician needs to apply a high-priority patch to a production system. Which of the following steps should be taken first?

Options:

A.

Air gap the system.


B.

Move the system to a different network segment.


C.

Create a change control request.


D.

Apply the patch to the system.


Expert Solution
Questions # 55:

A security engineer at a large company needs to enhance IAM to ensure that employees can only access corporate systems during their shifts. Which of the following access controls should the security engineer implement?

Options:

A.

Role-based


B.

Time-of-day restrictions


C.

Least privilege


D.

Biometric authentication


Expert Solution
Questions # 56:

In order to cut costs, a company decides to implement a bring-your-own-device policy. The security team wants a solution that will reduce risk to company data, especially in cases in which devices are lost or stolen. Which of the following tools is best to address this concern?

Options:

A.

Mobile device management


B.

Endpoint detection and response


C.

Host-based intrusion detection system


D.

Data loss prevention


Expert Solution
Questions # 57:

A systems administrator is creating a script that would save time and prevent human error when performing account creation for a large number of users. Which of the following would be a good use case for this task?creating a script

Options:

A.

Off-the-shelf software


B.

Orchestration


C.

Baseline


D.

Policy enforcement


Expert Solution
Questions # 58:

A software developer wishes to implement an application security technique that will provide assurance of the application ' s integrity. Which of the following techniques will achieve this?

Options:

A.

Secure cookies


B.

Input validation


C.

Static analysis


D.

Code signing


Expert Solution
Questions # 59:

Which of the following examples would be best mitigated by input sanitization?

Options:

A.

< script > alert ( " Warning! " ) ,- < /script >


B.

nmap - 10.11.1.130


C.

Email message: " Click this link to get your free gift card. "


D.

Browser message: " Your connection is not private. "


Expert Solution
Questions # 60:

An IT security team is concerned about the confidentiality of documents left unattended in MFPs. Which of the following should the security team do to mitigate the situation?

Options:

A.

Educate users about the importance of paper shredder devices.


B.

Deploy an authentication factor that requires ln-person action before printing.


C.

Install a software client m every computer authorized to use the MFPs.


D.

Update the management software to utilize encryption.


Expert Solution
Viewing page 3 out of 14 pages
Viewing questions 41-60 out of questions