Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA Security+ SY0-701 Questions and answers with CertsForce

Viewing page 5 out of 14 pages
Viewing questions 81-100 out of questions
Questions # 81:

Which of the following is the most likely reason a security analyst would review SIEM logs?

Options:

A.

To check for recent password reset attempts


B.

To monitor for potential DDoS attacks


C.

To assess the scope of a privacy breach


D.

To see correlations across multiple hosts


Expert Solution
Questions # 82:

Client files can only be accessed by employees who need to know the information and have specified roles in the company. Which of the following best describes this security concept?

Options:

A.

Availability


B.

Confidentiality


C.

Integrity


D.

Non-repudiation


Expert Solution
Questions # 83:

A company hired a consultant to perform an offensive security assessment covering penetration testing and social engineering.

Which of the following teams will conduct this assessment activity?

Options:

A.

White


B.

Purple


C.

Blue


D.

Red


Expert Solution
Questions # 84:

A security officer is implementing a security awareness program and is placing security-themed posters around the building and is assigning online user training. Which of the following would the security officer most likely implement?

Options:

A.

Password policy


B.

Access badges


C.

Phishing campaign


D.

Risk assessment


Expert Solution
Questions # 85:

Which of the following most accurately describes the order in which a security engineer should implement secure baselines?

Options:

A.

Deploy, maintain, establish


B.

Establish, maintain, deploy


C.

Establish, deploy, maintain


D.

Deploy, establish, maintain


Expert Solution
Questions # 86:

Which of the following outlines the configuration, maintenance, and security roles between a cloud service provider and the customer?

Options:

A.

Service-level agreement


B.

Responsibility matrix


C.

Memorandum of understanding


D.

Non-disclosure agreement


Expert Solution
Questions # 87:

A security analyst is reviewing logs to identify the destination of command-and-control traffic originating from a compromised device within the on-premises network. Which of the following is the best log to review?

Options:

A.

IDS


B.

Antivirus


C.

Firewall


D.

Application


Expert Solution
Questions # 88:

A company requests a collaboration between the infrastructure and security teams to determine the most secure method of deploying applications that saves costs on physical hardware. Which of the following is the best way to achieve this goal?

Options:

A.

Infrastructure as code


B.

Hybrid cloud


C.

Virtualization


D.

Containerization


Expert Solution
Questions # 89:

An employee decides to collect PII data from the company ' s system for personal use. The employee compresses the data into a single encrypted file before sending the file to their personal email. The security department becomes aware of the attempted misuse and blocks the attachment from leaving the corporate environment. Which of the following types of employee training would most likely reduce the occurrence of this type of issue?

(Select two).

Options:

A.

Privacy legislation


B.

Social engineering


C.

Risk management


D.

Company compliance


E.

Phishing


F.

Remote work


Expert Solution
Questions # 90:

A security engineer is working to address the growing risks that shadow IT services are introducing to the organization. The organization has taken a cloud-first approach end does not have an on-premises IT infrastructure. Which of the following would best secure the organization?

Options:

A.

Upgrading to a next-generation firewall


B.

Deploying an appropriate in-line CASB solution


C.

Conducting user training on software policies


D.

Configuring double key encryption in SaaS platforms


Expert Solution
Questions # 91:

Which of the following would best explain why a security analyst is running daily vulnerability scans on all corporate endpoints?

Options:

A.

To track the status of patching installations


B.

To find shadow IT cloud deployments


C.

To continuously the monitor hardware inventory


D.

To hunt for active attackers in the network


Expert Solution
Questions # 92:

Which of the following best practices gives administrators a set period to perform changes to an operational system to ensure availability and minimize business impacts?

Options:

A.

Impact analysis


B.

Scheduled downtime


C.

Backout plan


D.

Change management boards


Expert Solution
Questions # 93:

A company is aware of a given security risk related to a specific market segment. The business chooses not to accept responsibility and target their services to a different market segment. Which of the following describes this risk management strategy?

Options:

A.

Exemption


B.

Exception


C.

Avoid


D.

Transfer


Expert Solution
Questions # 94:

A security analyst locates a potentially malicious video file on a server and needs to identify both the creation date and the file ' s creator. Which of the following actions would most likely give the security analyst the information required?

Options:

A.

Obtain the file ' s SHA-256 hash.


B.

Use hexdump on the file ' s contents.


C.

Check endpoint logs.


D.

Query the file ' s metadata.


Expert Solution
Questions # 95:

Which of the following is the best mitigation for a zero-day vulnerability found in mission-critical production servers that must be highly available?

Options:

A.

Virtualizing and migrating to a containerized instance


B.

Removing and sandboxing to an isolated network


C.

Monitoring and implementing compensating controls


D.

Patching and redeploying to production as quickly as possible


Expert Solution
Questions # 96:

While reviewing logs, a security administrator identifies the following code:

< script > function(send_info) < /script >

Which of the following best describes the vulnerability being exploited?

Options:

A.

XSS


B.

SQLi


C.

DDoS


D.

CSRF


Expert Solution
Questions # 97:

An organization with multiple geographic locations has invested in various internet circuits at each location, including MPLS, 4G/5G, broadband, and dial-up. An architect is configuring a solution that will allow locations to function consistently and leverage links based on specific criteria. Which of the following is the best solution for the architect to configure?

Options:

A.

SD-WAN


B.

UTM


C.

VPN


D.

SASE


Expert Solution
Questions # 98:

Which of the following would most likely be used by attackers to perform credential harvesting?

Options:

A.

Social engineering


B.

Supply chain compromise


C.

Third-party software


D.

Rainbow table


Expert Solution
Questions # 99:

A penetration testing report indicated that an organization should implement controls related to database input validation. Which of the following best identifies the type of vulnerability that was likely discovered during the test?

Options:

A.

XSS


B.

Command injection


C.

Buffer overflow


D.

SQLi


Expert Solution
Questions # 100:

During a SQL update of a database, a temporary field used as part of the update sequence was modified by an attacker before the update completed in order to allow access to the system. Which of the following best describes this type of vulnerability?

Options:

A.

Race condition


B.

Memory injection


C.

Malicious update


D.

Side loading


Expert Solution
Viewing page 5 out of 14 pages
Viewing questions 81-100 out of questions