Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA Security+ SY0-701 Questions and answers with CertsForce

Viewing page 4 out of 14 pages
Viewing questions 61-80 out of questions
Questions # 61:

A security team is reviewing the findings in a report that was delivered after a third party performed a penetration test. One of the findings indicated that a web application form field is vulnerable to cross-site scripting. Which of the following application security techniques should the security analyst recommend the developer implement to prevent this vulnerability?

Options:

A.

Secure cookies


B.

Version control


C.

Input validation


D.

Code signing


Expert Solution
Questions # 62:

Which of the following is a common source of unintentional corporate credential leakage in cloud environments?

Options:

A.

Code repositories


B.

Dark web


C.

Threat feeds


D.

State actors


E.

Vulnerability databases


Expert Solution
Questions # 63:

Which of the following strategies should an organization use to efficiently manage and analyze multiple types of logs?

Options:

A.

Deploy a SIEM solution


B.

Create custom scripts to aggregate and analyze logs


C.

Implement EDR technology


D.

Install a unified threat management appliance


Expert Solution
Questions # 64:

A network manager wants to protect the company ' s VPN by implementing multifactor authentication that uses:

. Something you know

. Something you have

. Something you are

Which of the following would accomplish the manager ' s goal?

Options:

A.

Domain name, PKI, GeolP lookup


B.

VPN IP address, company ID, facial structure


C.

Password, authentication token, thumbprint


D.

Company URL, TLS certificate, home address


Expert Solution
Questions # 65:

A Chief Information Security Officer (CISO) develops information security policies that relate to the software development methodology. Which of the following will the CISO most likely include in the organization ' s documentation?

Options:

A.

Peer review requirements


B.

Multifactor authentication


C.

Branch protection tests


D.

Secrets management configurations


Expert Solution
Questions # 66:

A university employee logged on to the academic server and attempted to guess the system administrators ' log-in credentials. Which of the following security measures should the university have implemented to detect the employee ' s attempts to gain access to the administrators ' accounts?

Options:

A.

Two-factor authentication


B.

Firewall


C.

Intrusion prevention system


D.

User activity logs


Expert Solution
Questions # 67:

A company implements an authentication mechanism using certificates on smart cards. However, former employees are able to use the smart cards to authenticate and gain access to company resources. Which of the following should the company implement to prevent unauthorized access?

Options:

A.

CA


B.

TPM


C.

CRL


D.

CSR


E.

HSM


Expert Solution
Questions # 68:

Which of the following activities should be included as part of passive reconnaissance in a penetration test?

Options:

A.

Domain Name System (DNS) zone transfer


B.

Vulnerability scanning


C.

Social engineering


D.

Google hacking


Expert Solution
Questions # 69:

To which of the following security categories does an EDR solution belong?

Options:

A.

Physical


B.

Operational


C.

Managerial


D.

Technical


Expert Solution
Questions # 70:

A company receives an alert that a widely used network device vendor has been banned by the government. What will general counsel most likely be concerned with during hardware refresh?

Options:

A.

Sanctions


B.

Data sovereignty


C.

Cost of replacement


D.

Loss of license


Expert Solution
Questions # 71:

A company requires hard drives to be securely wiped before sending decommissioned systems to recycling. Which of the following best describes this policy?

Options:

A.

Enumeration


B.

Sanitization


C.

Destruction


D.

Inventory


Expert Solution
Questions # 72:

A company is concerned about the theft of client data from decommissioned laptops. Which of the following is the most cost-effective method to decrease this risk?

Options:

A.

Wiping


B.

Recycling


C.

Shredding


D.

Deletion


Expert Solution
Questions # 73:

An MSSP manages firewalls for hundreds of clients. Which of the following tools would be most helpful to create a standard configuration template in order to improve the efficiency of firewall changes?

Options:

A.

SNMP


B.

Benchmarks


C.

Netflow


D.

SCAP


Expert Solution
Questions # 74:

An employee who was working remotely lost a mobile device containing company data. Which of the following provides the best solution to prevent future data loss?

Options:

A.

MDM


B.

DLP


C.

FDE


D.

EDR


Expert Solution
Questions # 75:

After reviewing the following vulnerability scanning report:

Server:192.168.14.6

Service: Telnet

Port: 23 Protocol: TCP

Status: Open Severity: High

Vulnerability: Use of an insecure network protocol

A security analyst performs the following test:

nmap -p 23 192.168.14.6 —script telnet-encryption

PORT STATE SERVICE REASON

23/tcp open telnet syn-ack

I telnet encryption:

| _ Telnet server supports encryption

Which of the following would the security analyst conclude for this reported vulnerability?

Options:

A.

It is a false positive.


B.

A rescan is required.


C.

It is considered noise.


D.

Compensating controls exist.


Expert Solution
Questions # 76:

Which of the following is the phase in the incident response process when a security analyst reviews roles and responsibilities?

Options:

A.

Preparation


B.

Recovery


C.

Lessons learned


D.

Analysis


Expert Solution
Questions # 77:

A company purchased cyber insurance to address items listed on the risk register. Which of the following strategies does this represent?

Options:

A.

Accept


B.

Transfer


C.

Mitigate


D.

Avoid


Expert Solution
Questions # 78:

An attacker forces an internal company employee to inject malware into corporate systems under threat of publishing the employee ' s sensitive personal files. Which of the following best describes the attacker ' s motivation in this type of attack?

Options:

A.

Financial gain


B.

Revenge


C.

Blackmail


D.

Espionage


Expert Solution
Questions # 79:

A Chief Information Security Officer would like to conduct frequent, detailed reviews of systems and procedures to track compliance objectives. Which of the following is the best method to achieve this objective?

Options:

A.

Third-party attestation


B.

Penetration testing


C.

Internal auditing


D.

Vulnerability scans


Expert Solution
Questions # 80:

Which of the following is the main consideration when a legacy system that is a critical part of a company ' s infrastructure cannot be replaced?

Options:

A.

Resource provisioning


B.

Cost


C.

Single point of failure


D.

Complexity


Expert Solution
Viewing page 4 out of 14 pages
Viewing questions 61-80 out of questions