` into a public forum signature field. Later, other users who view that…","url":"https://courseiva.com/questions/comptia/security-plus/a-customer-enters-alert-test-into-a-public-forum-signature-field"},{"@type":"ListItem","position":484,"name":"To discourage unauthorized entry into a records room, facilities installs a large warning sign, a visible camera over th…","url":"https://courseiva.com/questions/comptia/security-plus/to-discourage-unauthorized-entry-into-a-records-room-facilities"},{"@type":"ListItem","position":485,"name":"Based on the exhibit, which principle is most directly being violated by the current share permissions?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-principle-is-most-directly-being"},{"@type":"ListItem","position":486,"name":"A SIEM alert shows a workstation connecting to the same unknown internet address every 15 minutes, even after business h…","url":"https://courseiva.com/questions/comptia/security-plus/a-siem-alert-shows-a-workstation-connecting-to-the-same-unknown"},{"@type":"ListItem","position":487,"name":"An employee receives an email that appears to come from payroll and asks them to open a link to \"confirm direct deposit …","url":"https://courseiva.com/questions/comptia/security-plus/an-employee-receives-an-email-that-appears-to-come-from-payroll"},{"@type":"ListItem","position":488,"name":"A web application must be reachable from the internet, but its database should be isolated from direct internet access. …","url":"https://courseiva.com/questions/comptia/security-plus/a-web-application-must-be-reachable-from-the-internet-but-its"},{"@type":"ListItem","position":489,"name":"A help desk technician receives an email that appears to come from the payroll provider. The message says the employee's…","url":"https://courseiva.com/questions/comptia/security-plus/a-help-desk-technician-receives-an-email-that-appears-to-come"},{"@type":"ListItem","position":490,"name":"Based on the exhibit, which indicator should defenders prioritize for detecting future activity from this campaign?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-indicator-should-defenders-prioritize"},{"@type":"ListItem","position":491,"name":"A security manager wants one document that states employees must protect company laptops and another that defines exact …","url":"https://courseiva.com/questions/comptia/security-plus/a-security-manager-wants-one-document-that-states-employees-must"},{"@type":"ListItem","position":492,"name":"Match each requirement or instruction to the correct governance document type. Use each document type once.","url":"https://courseiva.com/questions/comptia/security-plus/match-each-requirement-or-instruction-to-the-correct-governance"},{"@type":"ListItem","position":493,"name":"An office wants finance workstations separated from general user PCs, but employees still need to print to a shared prin…","url":"https://courseiva.com/questions/comptia/security-plus/an-office-wants-finance-workstations-separated-from-general-user"},{"@type":"ListItem","position":494,"name":"Based on the exhibit, which control option provides the greatest net annual financial benefit for the organization?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-control-option-provides-the-greatest"},{"@type":"ListItem","position":495,"name":"Users on the same VLAN report that their browser occasionally reaches a fake internal portal, and packet captures show o…","url":"https://courseiva.com/questions/comptia/security-plus/users-on-the-same-vlan-report-that-their-browser-occasionally"},{"@type":"ListItem","position":496,"name":"Facilities sees occasional water droplets forming above the cable trays in a data room during humid afternoons. The team…","url":"https://courseiva.com/questions/comptia/security-plus/facilities-sees-occasional-water-droplets-forming-above-the"},{"@type":"ListItem","position":497,"name":"An enterprise is moving from on-prem identity to a SaaS HR platform. Employees should sign in with corporate credentials…","url":"https://courseiva.com/questions/comptia/security-plus/moving-from-on-prem-identity-to-a-saas-hr-platform-employees"},{"@type":"ListItem","position":498,"name":"A Linux operations team has a standing need to restart services and edit protected configuration files on production ser…","url":"https://courseiva.com/questions/comptia/security-plus/a-linux-operations-team-has-a-standing-need-to-restart-services"},{"@type":"ListItem","position":499,"name":"A SIEM correlates the following: 17 failed logons against the same VPN account from one IP in 9 minutes, a successful lo…","url":"https://courseiva.com/questions/comptia/security-plus/a-siem-correlates-the-following-17-failed-logons-against-the"},{"@type":"ListItem","position":500,"name":"A developer requests a 45-day exception to use an unsupported browser plug-in on two engineering workstations so a legac…","url":"https://courseiva.com/questions/comptia/security-plus/a-developer-requests-a-45-day-exception-to-use-an-unsupported"},{"@type":"ListItem","position":501,"name":"The help desk needs a document that tells analysts exactly how to verify a caller, reset a password, and record the tick…","url":"https://courseiva.com/questions/comptia/security-plus/the-help-desk-needs-a-document-that-tells-analysts-exactly-how"},{"@type":"ListItem","position":502,"name":"Several company laptops were found to boot from a removable drive containing an untrusted pre-boot utility before the op…","url":"https://courseiva.com/questions/comptia/security-plus/several-company-laptops-were-found-to-boot-from-a-removable"},{"@type":"ListItem","position":503,"name":"A project team must share a spreadsheet containing customer names, account numbers, and purchase history with an externa…","url":"https://courseiva.com/questions/comptia/security-plus/a-project-team-must-share-a-spreadsheet-containing-customer"},{"@type":"ListItem","position":504,"name":"A company wants guest Wi-Fi to reach only the internet, employee laptops to reach internal apps, and payment servers to …","url":"https://courseiva.com/questions/comptia/security-plus/a-company-wants-guest-wi-fi-to-reach-only-the-internet-employee"},{"@type":"ListItem","position":505,"name":"A payment processor stores full card numbers in its transaction database, but developers and analysts should never see t…","url":"https://courseiva.com/questions/comptia/security-plus/a-payment-processor-stores-full-card-numbers-in-its-transaction"},{"@type":"ListItem","position":506,"name":"An organization is placing its public-facing website behind a new security design. The site must be reachable from the i…","url":"https://courseiva.com/questions/comptia/security-plus/placing-its-public-facing-website-behind-a-new-security-design"},{"@type":"ListItem","position":507,"name":"A development team needs to release an urgent fix for a customer portal on Friday evening. The business wants the change…","url":"https://courseiva.com/questions/comptia/security-plus/a-development-team-needs-to-release-an-urgent-fix-for-a-customer"},{"@type":"ListItem","position":508,"name":"An accounts payable specialist receives a reply inside an existing vendor email thread. The message uses the real invoic…","url":"https://courseiva.com/questions/comptia/security-plus/an-accounts-payable-specialist-receives-a-reply-inside-an"},{"@type":"ListItem","position":509,"name":"A scan reports a critical remote code execution vulnerability on an internet-facing VPN appliance with public proof-of-c…","url":"https://courseiva.com/questions/comptia/security-plus/a-scan-reports-a-critical-remote-code-execution-vulnerability-on"},{"@type":"ListItem","position":510,"name":"Based on the exhibit, what is the best next step before the marketing SaaS platform goes live?","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-what-is-the-best-next-step-before-the-2"},{"@type":"ListItem","position":511,"name":"Based on the exhibit, which key management improvement best preserves recoverability if the primary backup server is los…","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-key-management-improvement-best"},{"@type":"ListItem","position":512,"name":"An EDR alert shows winword.exe launching powershell.exe with an encoded command after a user opened an invoice attachmen…","url":"https://courseiva.com/questions/comptia/security-plus/an-edr-alert-shows-winword-exe-launching-powershell-exe-with-an"},{"@type":"ListItem","position":513,"name":"Drag and drop the steps for the TLS 1.3 handshake process into the correct order.","url":"https://courseiva.com/questions/comptia/security-plus/drag-and-drop-the-steps-for-the-tls-1-3-handshake-process-in-pcrjd"},{"@type":"ListItem","position":514,"name":"An HR analyst must send a salary file to an external auditor. The auditor only needs names, departments, and salary tota…","url":"https://courseiva.com/questions/comptia/security-plus/an-hr-analyst-must-send-a-salary-file-to-an-external-auditor-the"},{"@type":"ListItem","position":515,"name":"Match each procurement or oversight need to the best vendor due diligence artifact or clause. Use each item once.","url":"https://courseiva.com/questions/comptia/security-plus/match-each-procurement-or-oversight-need-to-the-best-vendor-due"},{"@type":"ListItem","position":516,"name":"A legacy production scanner cannot support MFA, but it must remain available for six months until replacement hardware a…","url":"https://courseiva.com/questions/comptia/security-plus/a-legacy-production-scanner-cannot-support-mfa-but-it-must"},{"@type":"ListItem","position":517,"name":"At 10:15, a file server begins renaming documents and creating payment notes. The SOC confirms the server is also making…","url":"https://courseiva.com/questions/comptia/security-plus/at-10-15-a-file-server-begins-renaming-documents-and-creating"},{"@type":"ListItem","position":518,"name":"An organization is implementing a Security Information and Event Management (SIEM) system to enhance its security monito…","url":"https://courseiva.com/questions/comptia/security-plus/an-organization-is-implementing-a-security-information-and-event-management-siem-ul9s45jh"},{"@type":"ListItem","position":519,"name":"A contractor connects a personal tablet to a lobby Ethernet jack. The network team wants the device blocked from interna…","url":"https://courseiva.com/questions/comptia/security-plus/a-contractor-connects-a-personal-tablet-to-a-lobby-ethernet-jack"},{"@type":"ListItem","position":520,"name":"Based on the exhibit, which data protection control best allows analysts to work with the records without exposing full …","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-data-protection-control-best-allows"},{"@type":"ListItem","position":521,"name":"Based on the exhibit, which artifact is the strongest evidence that the firewall change was reviewed and approved before…","url":"https://courseiva.com/questions/comptia/security-plus/based-on-the-exhibit-which-artifact-is-the-strongest-evidence"},{"@type":"ListItem","position":522,"name":"A customer portal must keep operating if one application server fails and also remain available if an entire site goes o…","url":"https://courseiva.com/questions/comptia/security-plus/a-customer-portal-must-keep-operating-if-one-application-server"},{"@type":"ListItem","position":523,"name":"A company wants to make sure only approved administrators can view and rotate a shared encryption secret used by several…","url":"https://courseiva.com/questions/comptia/security-plus/make-sure-only-approved-administrators-can-view-and-rotate-a"},{"@type":"ListItem","position":524,"name":"A manager can access the HR portal normally from a managed laptop, but if they sign in from an unmanaged tablet, the sys…","url":"https://courseiva.com/questions/comptia/security-plus/a-manager-can-access-the-hr-portal-normally-from-a-managed"},{"@type":"ListItem","position":525,"name":"Which four of the following are essential considerations when designing a secure cloud architecture in a hybrid environm…","url":"https://courseiva.com/questions/comptia/security-plus/which-four-of-the-following-are-essential-considerations-when-designing-a-secure-a48vyx65"}]}
Security+ SY0-701 (SY0-701) — Questions 451–525
1030 questions total · 14pages · All types, answers revealed
A security analyst detects unusual outbound traffic from a workstation to an external IP address known for command and control. The analyst has verified the alert and wants to contain the threat. According to the NIST SP 800-61 incident response process, which of the following steps should the analyst take FIRST?
A.Disconnect the workstation from the network
B.Perform a forensic analysis of the workstation
C.Reimage the workstation
D.Alert the system administrator
AnswerA
Disconnecting the workstation from the network cable or disabling its virtual NIC is the immediate containment action that stops active command-and-control beaconing and prevents further data exfiltration to the threat actor. Per NIST SP 800-61, this is the first priority once an incident is confirmed, as it isolates the compromised host and blocks lateral movement while preserving the current system state for later forensic acquisition. Do not delay this step for analysis or notification.
Why this answer
According to NIST SP 800-61, the first step in containment during incident response is to prevent further damage by isolating the compromised system. Disconnecting the workstation from the network immediately stops the outbound command-and-control traffic, preventing data exfiltration and further compromise. This aligns with the 'containment' phase before any analysis or remediation occurs.
Exam trap
The trap here is that candidates often confuse the order of incident response phases, choosing forensic analysis (Option B) first instead of containment, because they mistakenly believe evidence preservation must precede network isolation.
Why the other options are wrong
B
Per NIST SP 800-61, containment is the immediate priority after verification. Forensic analysis occurs after containment to preserve evidence and avoid altering the system state.
C
Reimaging the workstation is a recovery step, not a containment step. According to NIST SP 800-61, containment should occur before eradication or recovery to prevent further damage.
D
Alerting the system administrator is not the first containment step; NIST SP 800-61 prioritizes immediate containment actions like disconnecting the workstation to prevent further C2 communication.
When would these options actually be correct?
B
If the question asked 'After containing the threat, which step should the analyst take next?' or 'Which step is part of the eradication and recovery phase?', then forensic analysis would be correct to determine the root cause and scope.
C
A question asks: 'After containing a compromised workstation and completing forensic analysis, which step should be taken to ensure the system is clean and can be returned to production?' In that scenario, reimaging would be correct as part of eradication and recovery.
D
This would be correct if the question asked for the first step after containment is complete, or if the incident requires notification before any technical actions due to policy (e.g., legal or regulatory requirements).
Why candidates pick the wrong answer
B
Candidates may think forensic analysis is needed first to understand the threat, but NIST emphasizes containment before investigation to prevent further damage.
C
Candidates may confuse containment with eradication, thinking that removing the malware immediately via reimage is the first step, but containment (disconnecting) must come first to stop the threat from spreading.
D
Candidates may think notifying a supervisor or administrator is always the first step in incident response, confusing communication protocols with technical containment priorities.
Based on the exhibit, which document should be created or updated to make these settings mandatory and measurable?
Endpoint baseline draft:
- Full-disk encryption should be enabled on all corporate laptops.
- Screen lock should activate after 15 minutes of inactivity.
- Users should choose strong passwords.
Related documents:
Policy: Acceptable Use Policy
Standard: none
Procedure: Laptop imaging steps
Guideline: Suggested hardening tips
A.Update the policy because policies are always the most detailed technical documents.
B.Create or update a standard because it defines mandatory, specific minimum requirements.
C.Update the procedure because procedures are the best place for corporate requirements.
D.Update the guideline because guidelines are the strongest way to enforce compliance.
AnswerB
A standard is the correct document type because it operationalizes a policy's high-level intent into explicit, mandatory technical requirements and baseline configurations that can be tested and audited consistently. Unlike a policy, a standard uses normative language (e.g., 'must,' 'shall') to define specific minimum thresholds, such as password length, encryption algorithms, or patch intervals. This makes the standard the authoritative reference for compliance verification and for enforcing uniform security controls across the enterprise.
Why this answer
A standard defines mandatory, specific minimum requirements that must be met, such as 'full-disk encryption enabled' and 'screen lock after 15 minutes.' Unlike policies (high-level intent) or guidelines (suggestions), a standard provides measurable criteria that can be audited and enforced. Creating or updating a standard makes the endpoint baseline settings mandatory and measurable.
Exam trap
The trap here is confusing the role of a policy (broad intent) with a standard (specific, mandatory requirements), leading candidates to choose 'Update the policy' because they assume policies are the most authoritative document for technical settings.
How to eliminate wrong answers
Option A is wrong because policies are high-level statements of intent, not detailed technical requirements; they lack the specificity needed for measurable enforcement. Option C is wrong because procedures describe step-by-step instructions for tasks (e.g., laptop imaging), not mandatory requirements that apply to all endpoints. Option D is wrong because guidelines are advisory recommendations, not enforceable mandates, and thus cannot make settings mandatory or measurable.
Based on the exhibit, what type of malware is most likely present?
A.Ransomware, because the files are being renamed and recovery copies are being deleted.
B.Adware, because documents are no longer opening correctly.
C.Rootkit, because the system is using a command-line utility.
D.Spyware, because the attacker wants to read user documents.
AnswerA
The combination of shadow copy deletion, mass file renaming, and a ransom note is a strong match for ransomware. The attacker is attempting to prevent recovery while demanding payment or coercing the victim, which is exactly the pattern shown in the exhibit.
Why this answer
The exhibit shows files being renamed with a new extension and recovery copies (shadow copies) being deleted via vssadmin.exe. This is a classic ransomware behavior: encrypting user files and removing Volume Shadow Copy backups to prevent recovery without the attacker's key. Ransomware specifically targets document files and system restore points to maximize extortion leverage.
Exam trap
The trap here is that candidates see 'command-line utility' and think rootkit, but vssadmin deletion is a hallmark of ransomware, not a rootkit's stealth or persistence mechanism.
How to eliminate wrong answers
Option B is wrong because adware typically displays unwanted advertisements or redirects browser traffic, not renames files or deletes shadow copies; document opening issues here are a symptom of encryption, not adware. Option C is wrong because a rootkit hides its presence and provides privileged access, but using a command-line utility like vssadmin is a common ransomware action, not indicative of rootkit functionality. Option D is wrong because spyware covertly collects user data (keystrokes, browsing habits) without altering files; the attacker renaming and deleting backups points to encryption for ransom, not passive data theft.
A help desk technician receives an SMS claiming to be from the mobile carrier. The message says the user's corporate number will be suspended unless they open a link and confirm an MFA code. The user has not reported any account issues. What attack is this?
A.Spear phishing
B.Smishing
C.Vishing
D.Baiting
AnswerB
Smishing is a form of phishing that uses Short Message Service (SMS) text messages as the attack vector, often impersonating trusted entities like mobile carriers to claim account suspension or unusual activity. The fraudulent link directs victims to a credential harvesting page or prompts them to provide one-time passcodes, compromising MFA protections. The urgency and carrier impersonation align precisely with smishing tactics.
Why this answer
Smishing is a phishing attack conducted via SMS (Short Message Service). The message impersonates the mobile carrier, creates urgency by threatening suspension, and lures the user to a malicious link to capture MFA codes or credentials. Since the attack vector is SMS, not email or voice, this is smishing.
Exam trap
The trap here is confusing the delivery method (SMS vs. email vs. voice) — candidates often pick 'spear phishing' because the message is personalized, but the defining characteristic is the SMS channel, which makes it smishing.
How to eliminate wrong answers
Option A is wrong because spear phishing is a targeted email-based attack that uses personalized information to trick a specific individual, not an SMS message. Option C is wrong because vishing (voice phishing) is conducted over phone calls, not text messages.
A development team wants to deploy a new internal application without managing operating system patching, runtime updates, or automatic scaling. The security team still wants the company to control the application code and its data access settings. Which cloud service model best fits this need?
A.Infrastructure as a Service, because the company can ignore guest OS patching entirely.
B.Platform as a Service, because the provider manages the platform and the company manages the application and data.
C.Software as a Service, because the team can deploy custom application code inside the vendor portal.
D.On-premises hosting, because the company can still use the provider's patching tools.
AnswerB
Platform as a Service (PaaS) provides a managed runtime environment where the provider automatically handles the underlying servers, operating system, runtime engine, and often scaling and patching, while the company retains control over the application source code, its configuration, and the data stored by the application. This division of responsibility lets the development team focus on building the internal app and stops them from manually maintaining the platform, making it the correct choice for the stated deployment goal.
Why this answer
Platform as a Service (PaaS) is the correct choice because the provider manages the underlying platform—including OS patching, runtime updates, and automatic scaling—while the company retains control over the application code and data access settings. This aligns with the shared responsibility model where the customer is responsible for the application and data, not the infrastructure.
Exam trap
The trap here is that candidates confuse PaaS with IaaS, assuming 'no patching' means IaaS, but IaaS still requires the customer to patch the guest OS and runtime, whereas PaaS fully offloads that responsibility.
How to eliminate wrong answers
Option A is wrong because Infrastructure as a Service (IaaS) requires the customer to manage guest OS patching and runtime updates, contradicting the team's desire to avoid those tasks. Option C is wrong because Software as a Service (SaaS) does not allow the customer to deploy custom application code; it only provides pre-built applications accessed via a vendor portal. Option D is wrong because on-premises hosting places full responsibility for patching and scaling on the company, not the provider, and does not eliminate the need for OS management.
After several employees clicked on phishing emails, management wants to reduce future click rates and show measurable improvement across finance, HR, and executive assistants. Which control best meets that goal?
A.Send a one-time company-wide memo reminding users not to click suspicious links.
B.Use role-based security awareness training with phishing simulations and metrics tracking.
C.Disable all external email attachments for every department indefinitely.
D.Require employees to complete annual policy acknowledgment without testing.
AnswerB
Role-based awareness training with phishing simulations is the best fit because it directly targets user behavior and lets the security team measure results. Different job roles face different lures, so tailoring content to finance, HR, and executive assistants improves relevance. Tracking click rates, report rates, and repeat offenders also shows whether the program is working and supports continuous improvement.
Why this answer
Role-based security awareness training with phishing simulations and metrics tracking directly addresses the human factor by tailoring content to specific job roles (finance, HR, executive assistants) and provides measurable improvement through simulation click-rate data. This approach aligns with the NIST SP 800-50 framework for continuous security awareness, enabling management to track reduction in click rates over time.
Exam trap
The trap here is that candidates often choose Option A or D because they equate 'training' with a one-time communication or annual sign-off, failing to recognize that measurable improvement requires simulation, role-specific content, and ongoing metrics tracking as specified in the CompTIA SY0-701 objectives for security awareness programs.
How to eliminate wrong answers
Option A is wrong because a one-time memo lacks reinforcement, metrics, and simulation, so it cannot provide measurable improvement or change long-term behavior. Option C is wrong because disabling all external email attachments for every department indefinitely is overly restrictive, breaks legitimate business workflows (e.g., finance receiving invoices, HR receiving resumes), and does not train users to recognize phishing. Option D is wrong because annual policy acknowledgment without testing or simulation does not measure actual user behavior or reduce click rates; it only confirms policy receipt, not comprehension or application.
An engineering tool runs on an unsupported operating system, but the tool is used only occasionally and can be replaced by a supported cloud service with little workflow impact. Which risk treatment is best?
A.Accept the risk because the tool is old and still functions
B.Transfer the risk to the cloud provider without making changes
C.Avoid the risk by retiring the unsupported system and replacing it with the supported service
D.Compensate for the risk by adding more user passwords
AnswerC
Avoiding the risk is the best treatment because the organization has a practical replacement that does not significantly disrupt the workflow. Retiring the unsupported system removes the vulnerability source instead of merely reducing exposure. When a lower-risk alternative is available and business impact is manageable, elimination of the risk is often better than accepting or compensating for it.
Why this answer
The best risk treatment for an unsupported operating system that is only used occasionally and can be replaced with minimal workflow impact is to avoid the risk entirely. By retiring the unsupported system and migrating to the supported cloud service, the organization eliminates the security vulnerabilities and compliance issues associated with the outdated OS. This aligns with the risk avoidance strategy, which is preferred when the cost of mitigation is low and the risk is high.
Exam trap
The trap here is that candidates may confuse risk acceptance with a viable option when the tool 'still functions,' failing to recognize that unsupported systems pose an active security threat that cannot be safely accepted without compensating controls.
How to eliminate wrong answers
Option A is wrong because accepting the risk for an unsupported operating system ignores the lack of security patches, leaving the system vulnerable to exploits that could compromise the entire network. Option B is wrong because transferring the risk to a cloud provider without making changes implies that the unsupported system remains in place, and risk transfer typically involves insurance or contracts, not simply using a cloud service without migration. Option D is wrong because compensating with more user passwords does not address the core issue of an unsupported OS; password policies cannot patch kernel vulnerabilities or missing security updates.
A finance application has a known vulnerability in a third-party reporting component. The vendor says a patch will not be available for six months, but the business cannot stop using the application. What is the BEST risk treatment for the organization to pursue next?
A.Avoid the risk by shutting down the finance application immediately.
B.Mitigate the risk by adding compensating controls and tracking residual risk until the patch is available.
C.Transfer the risk by asking the vendor to guarantee that no incident will occur.
D.Accept the risk because any delay in patching is automatically low priority.
AnswerB
This approach reduces the likelihood or impact of exploitation while keeping the business service running. Compensating controls such as increased monitoring, segmentation, additional access restrictions, and temporary workarounds are appropriate when a patch is unavailable. The organization can then document the remaining risk, assign an owner, and revisit the issue when the vendor releases the fix.
Why this answer
When a known vulnerability exists in a third-party component and patching is delayed, the best risk treatment is to implement compensating controls (such as network segmentation, WAF rules, or input validation) to reduce the likelihood or impact of exploitation. This approach allows the business to continue operations while actively tracking residual risk until the vendor releases the patch. It aligns with the NIST risk management framework, which prioritizes mitigation when avoidance is not feasible.
Exam trap
The trap here is that candidates confuse 'accepting risk' with 'doing nothing,' but in CompTIA's framework, risk acceptance requires a formal decision by management after evaluating the risk level, not an automatic deferral due to a delayed patch.
How to eliminate wrong answers
Option A is wrong because shutting down the finance application immediately would avoid the risk but is not feasible as the business cannot stop using the application, making this an impractical business decision. Option C is wrong because risk transfer requires a third party to accept financial liability (e.g., through insurance or outsourcing), and asking a vendor to 'guarantee no incident' is not a valid risk transfer mechanism—vendors typically do not assume operational risk for unpatched vulnerabilities. Option D is wrong because accepting risk without analysis or compensating controls is negligent; the vulnerability is known and the application is critical, so acceptance should only be considered after a formal risk assessment and only if the residual risk is within the organization's appetite, not automatically due to a delayed patch.
A manufacturer needs to grant a partner company access to a procurement portal. Partner users should authenticate with their own identity provider, and the manufacturer does not want to create local passwords for each partner employee. Which design best supports this?
A.Create local accounts for every partner user and reset passwords manually when staff changes occur.
B.Share one VPN credential with the partner organization and let them manage access internally.
C.Use NTLM pass-through authentication to avoid setting up trust relationships.
D.Establish federation with SAML or OIDC and support just-in-time provisioning for partner users.
AnswerD
Federation with SAML or OIDC is the correct approach because it lets partner users authenticate against their own identity provider while the manufacturer's portal trusts the signed assertion and creates a local account on demand via just-in-time provisioning. This decouples identity lifecycle management from the manufacturer, reduces credential storage, and supports fine-grained authorization based on claims. It also enables seamless SSO, automatic account deactivation when the partner revokes access, and strong compliance through per-user auditable assertions.
Why this answer
Federation with SAML or OIDC allows the partner company to use its own identity provider for authentication, eliminating the need for local passwords. Just-in-time provisioning automatically creates user accounts in the manufacturer's procurement portal upon first successful authentication, ensuring access is granted without manual account management. This design supports secure cross-organization trust without sharing credentials or maintaining duplicate user stores.
Exam trap
The trap here is that candidates may confuse NTLM pass-through authentication (Option C) as a viable cross-org solution, not realizing it requires a direct Active Directory trust and cannot work without establishing a federation relationship, whereas federation with SAML/OIDC is the correct modern approach for external identity provider integration.
How to eliminate wrong answers
Option A is wrong because creating local accounts for every partner user and manually resetting passwords on staff changes is operationally unsustainable, violates the principle of least privilege, and introduces password management overhead that federation avoids. Option B is wrong because sharing one VPN credential violates the principle of non-repudiation and accountability, as it cannot distinguish individual users, and the partner cannot securely manage internal access without per-user authentication. Option C is wrong because NTLM pass-through authentication is a legacy Windows protocol that requires direct trust relationships between domains, does not support modern identity federation standards like SAML or OIDC, and is unsuitable for cross-organizational access without establishing a trust.
A security analyst notices unusual outbound traffic from a server that normally only communicates with internal clients. The traffic is encrypted and goes to an external IP address not on any blocklists. The analyst also finds a new scheduled task on the server that runs a PowerShell script. Which of the following best describes the analyst's immediate next step in the incident response process?
A.Disconnect the server from the network to contain the potential breach.
B.Wipe the server and restore from a known good backup.
C.Run a full antivirus scan on the server to identify malware.
D.Inform the legal department and law enforcement.
AnswerA
This is correct because containment is the immediate priority in incident response to stop the threat from spreading or causing more harm. Disconnecting the network cable or disabling the network interface is a simple and effective containment action.
Why this answer
According to standard incident response frameworks such as NIST SP 800-61, containment is one of the first and most critical steps after detecting a potential compromise. The unusual encrypted outbound traffic and the unauthorized scheduled task are strong indicators of compromise (IOCs). Disconnecting the server from the network immediately helps prevent further data exfiltration, lateral movement, or additional damage.
Other actions, such as running a scan, wiping the server, or notifying legal, are performed later in the process after containment and evidence preservation.
Why the other options are wrong
B
Wiping and restoring from backup is a recovery step, not an immediate containment step. The incident response process requires containment first to prevent further damage or data exfiltration.
C
Running a full antivirus scan is a detection step, but the immediate priority in incident response is containment. The unusual outbound encrypted traffic and scheduled task indicate a potential compromise that must be isolated first to prevent data exfiltration or lateral movement.
D
Informing legal and law enforcement is not the immediate next step during incident response; containment (disconnecting the network) takes priority to prevent further damage or data exfiltration.
When would these options actually be correct?
B
This would be correct if the question asked for the final step after containment and eradication, or if the server is confirmed to be compromised beyond repair and a clean restoration is the approved recovery method.
C
This option would be correct if the question asked for the next step after containment, or if the scenario described no active threat and the goal was to identify the cause of a non-critical anomaly (e.g., a false positive alert).
D
This would be correct as an immediate next step if the question stated that the incident has already been contained, evidence has been preserved, and the organization's policy requires mandatory reporting to legal and law enforcement before any further analysis or remediation.
Why candidates pick the wrong answer
B
Candidates may confuse recovery actions with immediate response steps, or believe that restoring from backup is the fastest way to eliminate the threat without considering the need to preserve evidence and contain the incident first.
C
Candidates often default to scanning for malware as a first response, especially when the symptom suggests malicious code, without recognizing that containment takes precedence to stop ongoing damage.
D
Candidates may think that involving legal and law enforcement early is necessary due to legal obligations or fear of liability, but they overlook the immediate need to contain the threat first.
A customer portal team must keep an unsupported Linux appliance online for 60 days while a replacement is built. The appliance processes payment tokens and cannot be patched until the vendor certifies the new image. Which two actions best reduce the residual risk during the 60-day window? Select two.
Select 2 answers
A.Move the appliance onto the flat user VLAN so the team can monitor it with standard workstation tools.
B.Restrict network paths to only the required upstream and downstream systems through firewall allow-lists.
C.Declare the risk fully accepted and make no configuration changes until the replacement is ready.
D.Add compensating controls such as application allow-listing, enhanced logging, and SIEM alerting.
E.Disable logging because the appliance is already at capacity and logs can slow it down.
AnswersB, D
Enforcing firewall allow-lists to permit only the specific upstream and downstream systems and required ports creates a strict micro-perimeter around the appliance. Because the unsupported OS cannot be patched, this drastically reduces the attack surface by blocking all other network traffic, including opportunistic scans and malware command-and-control attempts. If the appliance is compromised, the blast radius is limited to those allowed paths, making containment easier and providing an additional layer of defense in depth.
Why this answer
Restricting network paths to only required upstream and downstream systems via firewall allow-lists reduces the attack surface by limiting the appliance's exposure to unnecessary network traffic. This is a classic network segmentation compensating control that mitigates the risk of lateral movement from an unpatched, vulnerable system. By enforcing strict ingress/egress rules, the team can prevent unauthorized access and contain potential exploits during the 60-day window.
Exam trap
The trap here is that candidates may think 'accepting the risk' (Option C) is the only valid response when a patch cannot be applied, but CompTIA expects you to recognize that compensating controls must still be implemented to reduce residual risk to an acceptable level.
A laptop is suspected of being compromised, and the responder wants to preserve useful evidence before shutting it down. What should be done first?
A.Power off the laptop immediately to stop all attacker activity.
B.Capture volatile data such as memory and running processes if possible.
C.Install a new antivirus product before collecting evidence.
D.Reimage the laptop so the user can return to work quickly.
AnswerB
Capturing volatile data is the best first step when preserving evidence matters. Memory can contain malware code, encryption keys, active network sessions, and signs of lateral movement that disappear after shutdown. In incident response, responders try to preserve the most time-sensitive evidence before disrupting the system, as long as doing so is safe and approved.
Why this answer
Volatile data (e.g., RAM contents, running processes, network connections) is lost when the laptop is powered off. Capturing this data first preserves critical evidence of the attacker's current activity, such as malware in memory or active network connections, which is essential for forensic analysis. This aligns with the forensic principle of order of volatility, where the most volatile data is collected first.
Exam trap
The trap here is that candidates often think immediate shutdown stops the attack, but CompTIA tests the forensic principle that volatile data must be captured first to preserve evidence that disappears on power loss.
How to eliminate wrong answers
Option A is wrong because immediately powering off the laptop destroys volatile data (e.g., memory, running processes, network connections) that may contain critical evidence of the compromise, such as active malware or attacker commands. Option C is wrong because installing a new antivirus product modifies the system state (e.g., writes files, changes registry entries), potentially overwriting or destroying existing evidence, and is not a forensic best practice. Option D is wrong because reimaging the laptop completely wipes all data, including evidence of the compromise, making forensic analysis impossible and violating evidence preservation protocols.
A SIEM rule flags a Linux server because it makes outbound HTTPS connections to the same cloud IP every 15 minutes. The server runs an approved patch agent that should check in on a regular schedule. Which two checks best validate whether the alert is a false positive? Select two.
Select 2 answers
A.Compare the process name, parent process, and digital signature to the approved agent baseline.
B.Verify the destination domain and certificate chain against vendor documentation.
C.Assume the traffic is benign because it happens on a fixed schedule.
D.Suppress all alerts from the host permanently after this one event.
E.Stop collecting logs from the server so the same alert does not recur.
AnswersA, B
When a SIEM flags outbound traffic, examining the process name and parent process establishes the execution context; a patch agent like SCCM or WSUS will run from an expected parent and have a valid digital signature from the vendor. Matching these attributes against an approved baseline provides high-confidence evidence that the alert is a false positive, because unsigned or anomalous process trees are a common malware indicator.
Why this answer
Comparing the process name, parent process, and digital signature against the approved agent baseline directly validates that the traffic originates from the legitimate patch agent and not from malware masquerading as the agent. This is a standard host-based validation technique to confirm the source process integrity before investigating network alerts.
Exam trap
The trap here is that candidates may think a fixed schedule alone is sufficient to dismiss the alert (Option C), but CompTIA expects you to validate both the source process integrity and the destination legitimacy before concluding a false positive.
Before applying a critical patch to a production application server, which action best reduces the risk of extended downtime if the patch fails?
A.Apply the patch immediately without testing so the system is protected sooner.
B.Create a verified backup or rollback plan before making the change.
C.Disable logging so the patch process uses fewer resources.
D.Postpone the patch indefinitely until all business users request it.
AnswerB
A verified backup or rollback plan is the best safeguard because it gives the team a way to recover quickly if the patch causes instability. In patch management, resilience matters as much as speed. Planning for restoration before the change reduces downtime, supports change control, and helps the business continue operating if the update introduces problems.
Why this answer
Creating a verified backup or rollback plan before applying a critical patch ensures that if the patch causes unexpected failures or incompatibilities, the system can be restored to its previous stable state quickly. This directly reduces the risk of extended downtime by providing a reliable recovery path, which is a fundamental principle of change management and risk mitigation in production environments.
Exam trap
The trap here is that candidates may think immediate patching (Option A) is always the best security practice, but the question specifically asks about reducing the risk of extended downtime if the patch fails, not about security speed, so the correct answer focuses on recovery preparedness.
How to eliminate wrong answers
Option A is wrong because applying the patch immediately without testing bypasses validation and increases the likelihood of a failure that could cause extended downtime, as there is no rollback plan or backup to recover from. Option C is wrong because disabling logging does not reduce downtime risk; it actually hinders troubleshooting by removing forensic evidence needed to diagnose patch failures, and resource savings are negligible compared to the risk of extended outage. Option D is wrong because postponing the patch indefinitely leaves the system vulnerable to known exploits, and waiting for all business users to request it is impractical and violates security best practices for timely patch management.
A support portal has a search field that accepts customer last names. After a tester enters a single quote, the application returns a database syntax error. Which attack is the tester most likely trying to verify?
A.Cross-site scripting (XSS)
B.SQL injection
C.CSRF
D.SSRF
AnswerB
SQL injection happens when user input is inserted into a database query without proper validation or parameterization. A single quote causing a syntax error is a common sign that the input is affecting the SQL statement.
Why this answer
The tester is most likely trying to verify a SQL injection vulnerability. Entering a single quote into a search field that interacts with a database can break the SQL query syntax if user input is improperly sanitized, causing the database to return a syntax error. This error indicates that the input is being directly concatenated into a SQL statement, confirming the presence of a SQL injection flaw.
Exam trap
The trap here is that candidates may confuse the database syntax error with a client-side script execution indicator, leading them to choose XSS, but the error is a direct result of SQL syntax breakage, not script injection.
How to eliminate wrong answers
Option A is wrong because cross-site scripting (XSS) involves injecting client-side scripts into web pages viewed by other users, and a database syntax error is not a typical indicator of XSS; XSS would manifest as script execution in the browser, not a backend database error. Option C is wrong because Cross-Site Request Forgery (CSRF) exploits the trust a site has in a user's browser by tricking the user into making unintended requests, and a single quote in a search field does not trigger a CSRF attack or produce a database syntax error. Option D is wrong because Server-Side Request Forgery (SSRF) involves manipulating the server to make requests to internal or external resources, and a database syntax error from a single quote is not related to SSRF; SSRF would typically involve URL manipulation or protocol-based attacks.
A help desk technician reports that a user's account was locked out three times overnight. The security team reviews the authentication logs and discovers that the lockouts resulted from failed login attempts originating from a single external IP address, each attempt using a slightly different variation of the user's password. Which of the following should the security analyst do FIRST?
A.Block the external IP address at the perimeter firewall.
B.Disable the user account and require a password reset.
C.Investigate the user's recent activity for signs of compromise.
D.Increase the account lockout threshold to prevent future lockouts.
AnswerC
Correct. The analyst should first gather contextual information about the user's account, recent successful logins, and any other anomalous behavior. This investigation determines whether the account was actually breached and informs subsequent containment and remediation steps.
Why this answer
The pattern of failed login attempts from a single external IP using password variations suggests a brute-force or password-spraying attack. The security analyst must first investigate the user's recent activity to determine if the account was successfully compromised or if the attacker gained access via a successful login attempt before the lockouts occurred. This aligns with the incident response process, where identification and analysis precede containment actions like blocking IPs or resetting passwords.
Exam trap
The trap here is that candidates may jump to immediate containment (blocking the IP or disabling the account) without first verifying whether the attack succeeded, which violates the incident response principle of 'identify before contain' and could disrupt legitimate access or miss evidence of a breach.
Why the other options are wrong
A
Blocking the external IP address is premature because the lockouts could be a symptom of a compromised account being used by an attacker, and the priority is to investigate the user's account for compromise first.
B
Disabling the user account and requiring a password reset is premature because the lockouts are from an external IP with password variations, suggesting a brute-force attack, not necessarily that the user's account is compromised. The first step should be to investigate the user's activity to determine if the account was actually breached.
When would these options actually be correct?
A
If the question stated that the failed attempts were from a known malicious IP and the account was not compromised (e.g., no successful logins), then blocking the IP at the firewall would be an appropriate immediate action to prevent further attacks.
B
This option would be correct if the authentication logs showed successful logins from unusual locations or times, indicating the account was compromised. In such a scenario, immediate account disablement and password reset are necessary to prevent further unauthorized access.
Why candidates pick the wrong answer
A
Candidates may think that stopping the source of the attack is the most urgent step, but they overlook the possibility that the account is already compromised and needs investigation first.
B
Candidates may think that any account lockout indicates compromise and that disabling the account is a standard security response, overlooking the need to first investigate the nature of the failed attempts.
After an endpoint cleanup, an EDR agent shows inconsistent results: a suspicious process does not appear in normal task listings, a file in System32 is hidden from user-mode tools, and some security logs stop recording events at the same time. Which malware type best matches these symptoms?
A.Rootkit, because it hides processes, files, or activity from standard system tools.
B.Spyware, because it secretly collects user information and browser data.
C.Worm, because it spreads quickly through network shares and email attachments.
D.Trojan, because it masquerades as legitimate software to trick the user.
AnswerA
Rootkits operate by intercepting or modifying system calls, kernel objects, or process lists so that malware artifacts are omitted from standard enumeration tools like Task Manager, netstat, or Get-Process. They can run in kernel mode (e.g., a malicious driver) or user mode (via API hooking), and they actively subvert the operating system's visibility mechanisms. The EDR agent showing inconsistent data after cleanup aligns with a rootkit removing itself from the agent's view or masking residual artifacts, which is exactly the concealment signature described.
Why this answer
A rootkit is designed to hide its presence and the presence of associated processes, files, and system activities from standard operating system tools and user-mode APIs. The symptoms described—a process invisible to task listings, a hidden file in System32, and security logs ceasing to record events—are classic indicators of kernel-mode or user-mode rootkit behavior that intercepts system calls to filter out its own artifacts.
Exam trap
The trap here is that candidates confuse the 'hiding' behavior of a rootkit with the 'deception' of a trojan or the 'collection' of spyware, but only a rootkit specifically subverts the OS's own APIs to conceal its presence from standard administrative tools.
How to eliminate wrong answers
Option B is wrong because spyware focuses on covert data collection (e.g., keystrokes, browsing habits) and does not inherently hide processes, files, or disable security logging. Option C is wrong because a worm's primary characteristic is self-replication and network propagation, not stealth mechanisms to evade detection by task manager or hide files in System32. Option D is wrong because a trojan relies on social engineering to appear legitimate, but its core behavior does not include the systematic hiding of processes and files from system tools or the suppression of security event logs.
A finance workstation is suspected of running malware. It is still powered on, the user is logged in, and the network cable is connected. Which two actions best preserve volatile evidence before shutdown? Select two.
Select 2 answers
A.Capture RAM or a volatile memory image before the system is powered off
B.Record running processes, open network connections, and logged-on users
C.Shut the workstation down immediately and restart it cleanly
D.Run a disk defragmentation utility to prepare for imaging
E.Uninstall the suspected malware before collecting any evidence
AnswersA, B
RAM and other volatile memory hold a live snapshot of the compromise: running processes, loaded kernel modules, open sockets, active network sessions, decrypted payloads, and plaintext encryption keys often exist nowhere on disk. Once the workstation is powered off, this data vanishes instantaneously and cannot be recovered by any forensic technique, so a memory capture with a tool like WinPmem or FTK Imager must be acquired first. Malware frequently operates entirely in memory—fileless variants or injected code—making the RAM image the only source of evidence of their execution. This is the foundational step in the Order of Volatility and the first action to take during live response.
Why this answer
Capturing RAM or a volatile memory image preserves data that is lost when the system is powered off, such as running processes, encryption keys, and network connections. This is a fundamental step in forensic incident response to ensure volatile evidence is not destroyed before analysis.
Exam trap
The trap here is that candidates may think immediate shutdown is safe or that disk defragmentation is a valid preparation step, but both destroy or alter evidence, violating forensic preservation principles.
After installing a free PDF-to-Word utility from an unofficial website, a user's laptop starts sending data to an unknown server and the security agent is disabled. Which malware type best fits?
A.Trojan
B.Worm
C.Spyware
D.Rootkit
AnswerA
A trojan is malware that disguises itself as a benign or desirable program—here, a free PDF-to-Word utility from an unofficial source—while secretly performing malicious actions upon execution. The user's deliberate installation and the subsequent security tampering (such as disabling antivirus, modifying system settings, or dropping additional payloads) fit the trojan lifecycle directly. Unlike viruses or worms, a trojan does not self-replicate or auto-propagate; it relies on the victim's voluntary action, which is exactly what the scenario describes.
Why this answer
A Trojan is malware disguised as legitimate software, such as a free PDF-to-Word utility, that performs malicious actions without the user's knowledge. In this scenario, the Trojan exfiltrates data to an unknown server and disables the security agent, which are classic Trojan behaviors—unlike self-replicating worms or passive spyware. The user's intentional download from an unofficial website is the typical infection vector for Trojans.
Exam trap
The trap here is that candidates may confuse 'spyware' with 'Trojan' because both can steal data, but the key distinction is that a Trojan actively performs multiple malicious actions (including disabling security) and requires user execution, whereas spyware is typically passive and does not disable defenses.
How to eliminate wrong answers
Option B (Worm) is wrong because worms self-replicate and spread across networks without user interaction, whereas this malware required the user to download and execute the utility. Option C (Spyware) is wrong because spyware primarily passively monitors and collects data without actively disabling security agents or performing destructive actions. Option D (Rootkit) is wrong because rootkits specifically hide their presence by modifying the operating system kernel or drivers, and while disabling a security agent could be a rootkit behavior, the initial infection vector (a downloaded utility) and data exfiltration are more characteristic of a Trojan.
Based on the exhibit, which attack is the developer most likely observing?
A.Cross-site scripting (XSS)
B.Server-side request forgery (SSRF)
C.SQL injection
D.CSRF
AnswerB
The application is being tricked into making a request to an internal metadata endpoint using a user-controlled URL parameter. That is server-side request forgery. SSRF is common in cloud environments because it can expose instance metadata, credentials, or internal services that should not be reachable from the outside.
Why this answer
The developer is most likely observing a server-side request forgery (SSRF) attack because the log shows the application making an outbound HTTP request to an internal IP address (10.0.0.1) initiated by user-supplied input (the 'url' parameter). SSRF occurs when an attacker manipulates the server to send crafted requests to internal or external resources, bypassing access controls. The exhibit's pattern of a server-side request to a private IP range directly indicates SSRF, not client-side or database attacks.
Exam trap
The trap here is that candidates confuse SSRF with CSRF because both involve requests, but SSRF is server-initiated while CSRF is client-initiated; the key clue is the server making a request to a private IP, not the user's browser.
How to eliminate wrong answers
Option A is wrong because cross-site scripting (XSS) involves injecting malicious scripts into web pages viewed by other users, not server-side requests to internal IPs; the log shows no script execution or client-side payload. Option C is wrong because SQL injection targets database queries via input fields, but the log shows an HTTP request to an internal IP, not a database error or query manipulation. Option D is wrong because CSRF (Cross-Site Request Forgery) tricks a user's browser into performing unintended actions on an authenticated site, whereas the exhibit shows the server itself making the request, not the client's browser.
An EDR console alerts that powershell.exe launched with an encoded command on a finance workstation, and a minute later the host begins making repeated outbound connections to an unfamiliar IP address. What is the best initial response?
A.Run a full antivirus scan first and leave the workstation online so the user can keep working.
B.Isolate the workstation through the EDR platform and preserve logs and volatile evidence for investigation.
C.Power off the workstation immediately to ensure the malicious process stops.
D.Create a permanent firewall rule that allows the unfamiliar IP address so you can observe more traffic.
AnswerB
Encoded PowerShell combined with outbound beaconing is a strong indicator of active malicious behavior. Isolating the endpoint through EDR contains the incident while preserving the host’s state for analysis. This approach is better than pulling the plug because it reduces attacker activity without unnecessarily destroying volatile evidence. The analyst can then collect logs, memory, and process details before remediation or reimaging.
Why this answer
Isolating the workstation via the EDR platform stops the immediate threat (the malicious outbound connections) while preserving volatile evidence (e.g., running processes, network connections, memory contents) and logs for forensic analysis. This aligns with the incident response principle of containment before eradication, and EDR isolation typically uses a host-based firewall rule to block all traffic except to the EDR management server, ensuring the host remains accessible for investigation.
Exam trap
The trap here is that candidates confuse immediate containment (isolation) with eradication (antivirus scan) or evidence preservation (shutdown), but the SY0-701 emphasizes that isolation via EDR is the best initial response because it stops the threat without destroying volatile data.
How to eliminate wrong answers
Option A is wrong because running a full antivirus scan while the host remains online allows the attacker to continue exfiltration or lateral movement, and antivirus may miss fileless or encoded PowerShell attacks that never touch disk. Option C is wrong because powering off the workstation destroys volatile evidence (e.g., memory-resident malware, active network connections, process trees) and may prevent forensic analysis of the attack chain. Option D is wrong because creating a permanent firewall rule to allow the unfamiliar IP address would actively assist the attacker by ensuring uninterrupted command-and-control communication, violating the containment principle.
A file-sharing portal uses a download URL like /download?file=12345. A tester changes the value to 12346 and can access another department's document without logging in again. Which control most directly prevents this issue?
A.Implement server-side authorization checks for every object request.
B.Make the identifier longer so users cannot guess nearby values.
C.Move the portal to HTTPS so request parameters cannot be intercepted.
D.Store the document name in a hidden field and validate it in JavaScript.
AnswerA
Server-side authorization ensures the application verifies that the current user is allowed to access the specific object requested. This directly stops insecure direct object reference issues because changing the identifier alone no longer grants access. The check must happen on the server for every request, not in the browser.
Why this answer
The issue is that the server trusts the file identifier in the URL without verifying that the authenticated user is authorized to access the requested resource. Implementing server-side authorization checks for every object request ensures that before serving any file, the server validates whether the current session or user has explicit permission to access that specific document. This directly prevents the IDOR (Insecure Direct Object Reference) vulnerability demonstrated by the tester.
Exam trap
The trap here is that candidates often confuse confidentiality controls (like HTTPS or longer identifiers) with authorization controls, failing to recognize that the core flaw is the lack of server-side permission verification for each object request.
How to eliminate wrong answers
Option B is wrong because making the identifier longer (e.g., using a UUID) only makes guessing harder but does not eliminate the authorization gap; if the server still trusts any identifier without checking permissions, a user who obtains or guesses a valid identifier can still access unauthorized documents. Option C is wrong because HTTPS encrypts the request in transit to prevent interception, but it does not address the server-side authorization flaw; the tester in this scenario is already authenticated and simply changes the parameter value in their own browser. Option D is wrong because storing the document name in a hidden field and validating it in JavaScript is client-side validation, which can be easily bypassed by disabling JavaScript or manipulating the hidden field value using browser developer tools; server-side authorization is required.
A records manager discovers 18-month-old paper onboarding forms stored in a cabinet. The retention schedule says the forms must be destroyed after 12 months unless legal hold applies, and no hold has been issued. What is the best next step?
A.Keep the forms indefinitely in case a future audit asks for them.
B.Scan the forms into a shared folder and then throw away the paper.
C.Destroy the forms using an approved secure disposal method and document the action.
D.Return the forms to HR so they can be reused for new hires.
AnswerC
Once the retention period expires and no legal hold is in force, the correct action is secure destruction using an approved method such as cross-cut shredding, burning, or pulping to prevent reconstruction of PII. Documenting the destruction with a certificate of destruction or equivalent log provides an audit trail that demonstrates compliance with the records schedule. This ensures the information is permanently unrecoverable while satisfying accountability requirements.
Why this answer
The retention schedule explicitly requires destruction after 12 months with no legal hold. An approved secure disposal method (e.g., cross-cut shredding or incineration) ensures the sensitive PII on onboarding forms is irrecoverable, and documenting the action provides an audit trail for compliance with data protection regulations like GDPR or HIPAA.
Exam trap
The trap here is that candidates may choose Option B (scanning) thinking digital preservation is safer, but the question tests the principle that retention schedules mandate destruction—not conversion—and that scanning without secure disposal still leaves the paper intact, violating policy.
How to eliminate wrong answers
Option A is wrong because indefinite retention violates the defined retention schedule and could expose the organization to non-compliance penalties for holding data longer than permitted. Option B is wrong because scanning into a shared folder without access controls or encryption creates a security risk and does not constitute destruction; the paper must still be securely disposed of, and the digital copy may itself require deletion per the schedule. Option D is wrong because reusing forms for new hires would mix old personal data with new, causing data integrity issues and violating privacy principles like data minimization.
The SOC is writing step-by-step instructions for responding to a suspected malware infection on a laptop. The document should tell analysts exactly what to do first, second, and third during triage and containment. Which governance artifact should they create?
A.Policy, because it states the organization's broad security intent.
B.Procedure, because it gives a repeatable sequence of actions for a specific task.
C.Guideline, because it offers optional advice that analysts may choose to follow.
D.Standard, because it defines the organization's security goals at a high level.
AnswerB
A procedure is the right artifact when the team needs exact, repeatable instructions. In incident response, analysts need a consistent sequence for triage, containment, escalation, and evidence handling so that actions are predictable and auditable. Procedures support operational consistency and reduce confusion during stressful events, which is why they fit this scenario better than policies or guidelines.
Why this answer
A procedure is the correct governance artifact because it provides a detailed, step-by-step sequence of actions for a specific task—in this case, triaging and containing a suspected malware infection on a laptop. Unlike policies or standards, which set high-level intent or goals, a procedure ensures repeatable and consistent execution by analysts during incident response.
Exam trap
The SY0-701 exam often tests the distinction between high-level governance documents (policies, standards) and operational documents (procedures, guidelines), and the trap here is that candidates confuse a procedure with a guideline because both provide instructions, but a procedure is mandatory and ordered, while a guideline is advisory and flexible.
How to eliminate wrong answers
Option A is wrong because a policy states the organization's broad security intent (e.g., 'All endpoints must be protected from malware'), not the specific step-by-step instructions needed for triage and containment. Option C is wrong because a guideline offers optional advice or best practices that analysts may choose to follow, but the question requires mandatory, ordered steps for a repeatable process. Option D is wrong because a standard defines mandatory security goals or requirements at a high level (e.g., 'All laptops must have antivirus software'), not the precise sequence of actions for a specific incident response task.
A SOC analyst reviews an EDR alert showing powershell.exe launched with an encoded command, then immediately connected to an unfamiliar IP address and spawned rundll32.exe. The user is still logged in and the machine may still contain evidence needed for investigation. Which two actions should the analyst take first to contain the incident while preserving evidence? Select two.
Select 2 answers
A.Isolate the endpoint using EDR network containment or a quarantine policy.
B.Disable the user account and revoke active sessions or tokens for that identity.
C.Reboot the workstation immediately to clear any malicious process from memory.
D.Run a full vulnerability scan before taking any other action.
E.Delete the suspicious email from the mailbox to remove the original payload.
AnswersA, B
EDR network containment or a quarantine policy is the appropriate first response because it immediately blocks network-level communication from the endpoint to any external C2 server or internal hosts, thereby preventing lateral movement while the endpoint remains in a forensically sound state. By keeping the process and disk intact, the SOC analyst can later extract memory dumps, review active network connections, and perform threat hunting without contaminating volatile evidence. This action aligns with the containment phase of incident response, prioritizing the preservation of evidence over immediate eradication.
Why this answer
Isolating the endpoint via EDR network containment or quarantine policy immediately stops the malicious process from communicating with the command-and-control (C2) server at the unfamiliar IP address, preventing data exfiltration and lateral movement. This action preserves the volatile evidence in memory (e.g., the spawned rundll32.exe process) and on disk, allowing forensic analysis without the risk of the attacker destroying evidence remotely.
Exam trap
The trap here is that candidates often choose to reboot the workstation (Option C) thinking it will 'clean' the system, but this destroys volatile evidence and does not contain the incident, whereas disabling the user account (Option B) is a valid containment step to prevent further access via that identity.
A legacy application server has a critical vulnerability, but the vendor will not release a fix for 30 days. Which two compensating controls are the best short-term risk reduction steps? Select two.
Select 2 answers
A.Restrict access to the server to known admin IPs or a jump host.
B.Place a web application firewall or IPS rule in front of the exposed service.
C.Document the issue and wait for the vendor patch without making any changes.
D.Open the service to more networks so monitoring tools can see it better.
E.Disable logging to reduce the performance overhead caused by the vulnerability.
AnswersA, B
Restricting access to the server via network ACLs, security groups, or firewall rules to only known administrative IPs or a hardened jump host directly shrinks the attack surface. This effectively filters out the vast majority of potential exploit attempts from untrusted networks while the vulnerability remains unpatched. A jump host also centralizes access, enabling stronger authentication, session logging, and audit trails, which further reduces the likelihood and impact of an attacker reaching the vulnerable application.
Why this answer
Restricting access to the server to known admin IPs or a jump host reduces the attack surface by limiting who can reach the vulnerable service. This network-layer control (e.g., using ACLs or firewall rules) prevents exploitation from untrusted sources while the vendor patch is pending. It is a classic compensating control that buys time without modifying the application itself.
Exam trap
The trap here is that candidates may think documenting the issue (Option C) is sufficient or that increasing monitoring (Option D) is a control, but CompTIA expects active risk reduction measures like access restriction and virtual patching, not passive or counterproductive actions.
An IDS raises an alert for a possible SQL injection attack against an internal reporting portal. The web server logs show the source IP belongs to the company's vulnerability scanner, and the requests match the scanner's normal test pattern. What is the most appropriate analyst action?
A.Treat the alert as a confirmed breach and begin password resets for all portal users.
B.Mark the alert as a likely false positive after verifying the scanner schedule and source IP.
C.Block the scanner IP permanently to prevent future alerts from the same host.
D.Quarantine the reporting server because IDS alerts always indicate active exploitation.
AnswerB
The source IP and request pattern match the vulnerability scanner's authorised schedule, confirming benign activity rather than a real SQL injection attempt, so closing the alert as a likely false positive is proportionate and avoids unnecessary escalation.
Why this answer
The IDS alert matches the known behavior of the company's vulnerability scanner, which is a legitimate and scheduled security tool. Verifying the scanner schedule and source IP confirms the traffic is authorized, making the alert a false positive. Analysts should correlate IDS alerts with asset inventories and change management records to avoid unnecessary incident response actions.
Exam trap
The trap here is that candidates may assume any SQL injection pattern in IDS logs is malicious, overlooking the possibility that the traffic originates from an authorized internal security tool.
How to eliminate wrong answers
Option A is wrong because treating the alert as a confirmed breach without verification wastes resources and causes unnecessary user disruption; IDS alerts require validation before escalation. Option C is wrong because permanently blocking the scanner IP would disrupt legitimate security testing and vulnerability management processes. Option D is wrong because quarantining the server based solely on an IDS alert ignores the context that the traffic is from an authorized scanner; IDS alerts can be false positives and do not always indicate active exploitation.
A company wants guest laptops on Wi-Fi to reach the internet but not internal printers or servers. Which two changes best support this design? Select two.
Select 2 answers
A.Assign guest access points to a separate VLAN with its own subnet.
B.Allow guests on the same VLAN as employee devices for simpler routing.
C.Use firewall rules to deny guest traffic to internal RFC1918 address ranges.
D.Enable WPA2-Enterprise on employee wireless only, and reuse that on guest devices.
E.Put printers on the guest VLAN so guests can print directly.
AnswersA, C
A separate VLAN and subnet keep guest devices logically isolated from corporate systems. This is a common first step in segmentation because it limits what guest traffic can reach and makes firewall policy easier to enforce.
Why this answer
Assigning guest access points to a separate VLAN with its own subnet isolates guest traffic at Layer 2, preventing direct communication with internal devices like printers and servers. This segmentation is a foundational step for enforcing access control policies without relying solely on higher-layer filtering.
Exam trap
The trap here is that candidates often think VLAN separation alone is sufficient, forgetting that a Layer 3 gateway (router/firewall) can still route between VLANs unless explicit ACLs or firewall rules block RFC1918 destinations.
Based on the exhibit, which tool should the security team use to safely observe the attachment's behavior before delivery to users?
A.Sandboxing, so the file can execute in a controlled environment before release.
B.DLP, so the gateway can block sensitive data from leaving the organization.
C.NAC, so the sender's device can be checked before the message is accepted.
D.SIEM, so the team can store the attachment and review alerts later.
AnswerA
Sandboxing is designed to detonate suspicious files safely and observe their behavior. Because the attachment is a macro-enabled spreadsheet and static scanning did not find a known signature, dynamic analysis is the right next step. This helps confirm whether the file tries to drop malware, contact an external server, or modify the system.
Why this answer
Sandboxing allows the security team to execute the attachment in a controlled, isolated environment to observe its behavior (e.g., network connections, file modifications) without risking the production network. This is the correct approach because it safely detonates the file before delivery, enabling detection of malicious activity such as ransomware or trojans. Other tools like DLP, NAC, or SIEM do not provide the dynamic analysis needed to assess the attachment's runtime behavior.
Exam trap
The trap here is that candidates may confuse sandboxing with DLP or SIEM, thinking that blocking data exfiltration or reviewing logs after delivery is sufficient, when the question specifically requires observing behavior before delivery.
How to eliminate wrong answers
Option B (DLP) is wrong because Data Loss Prevention focuses on monitoring and blocking sensitive data exfiltration, not on analyzing the behavior of an attachment for malware. Option C (NAC) is wrong because Network Access Control checks the security posture of a device before granting network access, not the content or behavior of an attachment in an email. Option D (SIEM) is wrong because a Security Information and Event Management system aggregates and correlates logs for analysis, but it cannot safely execute or observe the runtime behavior of an attachment before delivery.
The service desk needs a document that tells analysts exactly how to verify a caller and reset a password for a locked account. Which document type should they use?
A.Policy, because it states the organization's high-level security expectations
B.Guideline, because it offers helpful suggestions that staff may choose to follow
C.Procedure, because it provides exact steps staff must follow in order
D.Standard, because it defines a general topic without operational detail
AnswerC
A procedure is the correct document type because it specifies a mandatory, repeatable sequence of detailed actions—such as 'verify two identity attributes, then reset the password, then log the incident ticket.' Procedures remove ambiguity, ensure every analyst performs the task in the same secure order, and support auditability and accountability. This makes a procedure far more actionable than a policy, standard, or guideline for service desk workflows.
Why this answer
A procedure is the correct document type because it provides a step-by-step sequence of actions that staff must follow to complete a specific operational task, such as verifying a caller's identity and resetting a password. Unlike policies or standards, procedures are mandatory and detail the exact commands, verification checks, and escalation paths required to ensure consistent and secure execution of the task.
Exam trap
The trap here is confusing a procedure with a policy or standard, as candidates often think a high-level policy is sufficient for operational tasks, but the exam requires recognizing that procedures are the only document type that mandates exact, ordered steps for a specific task.
How to eliminate wrong answers
Option A is wrong because a policy states high-level security expectations and principles (e.g., 'passwords must be reset securely'), but does not provide the specific steps for verifying a caller or performing the reset. Option B is wrong because a guideline offers suggestions or best practices that staff may choose to follow, not the exact mandatory steps required for a consistent and secure password reset process. Option D is wrong because a standard defines a general topic or baseline requirement (e.g., 'passwords must be at least 8 characters') without the operational detail needed to execute a specific procedure.
Based on the exhibit, what is the best next step before onboarding the vendor?
A.Approve the vendor because it already passed a penetration test.
B.Require a security addendum with breach-notification timing, subprocessor approval, and audit rights.
C.Ask the vendor to provide source code so developers can review it.
D.Move the workload to an internal shared drive until the vendor is ready.
AnswerB
Requiring a security addendum addresses the governance gaps highlighted in the exhibit by forcing the vendor to agree to enforceable breach-notification deadlines, prior approval for subprocessors, and independent audit rights. These contractual controls create accountability and give the organization ongoing visibility into the vendor’s security posture, including downstream subprocessor risks, before the workload is onboarded. This is the best next step because it closes the missing due-diligence and contractual gaps identified.
Why this answer
The exhibit indicates the vendor has not yet provided a security addendum, which is a critical contractual document that defines security obligations such as breach-notification timing, subprocessor approval, and audit rights. Without this addendum, the organization lacks enforceable guarantees for data protection and incident response, making onboarding premature. Option B directly addresses this gap by requiring the addendum before proceeding.
Exam trap
The trap here is that candidates may assume a penetration test is sufficient due diligence, overlooking that contractual security terms are legally binding and address ongoing compliance, not just a one-time technical check.
How to eliminate wrong answers
Option A is wrong because passing a penetration test does not replace the need for contractual security terms; a pen test is a point-in-time assessment, not a binding agreement for ongoing compliance. Option C is wrong because requesting source code is impractical and unnecessary for most vendor relationships—developers cannot realistically review proprietary code, and this does not address legal or operational security requirements. Option D is wrong because moving the workload to an internal shared drive introduces data exposure risks and does not resolve the missing vendor security addendum; it bypasses proper governance.
A hardening script is pushed to a production web server and, within minutes, the application stops accepting secure connections. The team discovers the script disabled a required TLS setting that the legacy application still needs. What should have been in place to reduce the impact of this change?
A.A documented change window with testing in a staging environment and a rollback plan.
B.A longer password policy for administrators so they can log in after the outage.
C.Disabling all logging during the change so the application can restart faster.
D.Replacing the web server hardware to ensure the TLS settings are applied correctly.
AnswerA
A documented change window with staging validation and a rollback plan directly satisfies the stem's impact-reduction constraint: staging testing would have exposed the legacy application's TLS dependency before production, and the rollback plan would have restored the disabled TLS setting immediately, cutting outage duration. Change windows alone do not prevent misconfiguration; the rollback capability is what limits blast radius.
Why this answer
A documented change window with testing in a staging environment and a rollback plan ensures that changes are validated before production deployment. In this scenario, the hardening script disabled a required TLS setting (e.g., TLS 1.0 or a specific cipher suite) that the legacy application depended on. Testing in staging would have caught the incompatibility, and a rollback plan would allow reverting the change quickly, minimizing downtime.
Exam trap
The trap here is that candidates might think the issue is about authentication (Option B) or hardware (Option D), but the core problem is a configuration change that broke TLS compatibility, which requires proper change management and testing, not hardware or password policies.
How to eliminate wrong answers
Option B is wrong because a longer password policy for administrators does not address the technical issue of a misconfigured TLS setting; it only affects authentication, not the secure connection failure. Option C is wrong because disabling logging during the change does not help the application restart faster or prevent the TLS misconfiguration; logging is unrelated to the TLS stack or service recovery. Option D is wrong because replacing the web server hardware does not affect TLS settings; TLS configuration is software-based (e.g., in the web server's config files or registry), and hardware replacement would not resolve a misapplied script.
A customer enters `<script>alert('test')</script>` into a public forum signature field. Later, other users who view that signature see the script execute in their browsers. What attack is this?
A.SQL injection
B.Cross-site scripting
C.Session replay
D.Directory traversal
AnswerB
This is a textbook stored cross-site scripting (XSS) attack: the attacker submits JavaScript (such as an 'alert' popup) into a public forum, the server persists it, and when another user views the page, the browser executes the unsanitized script. Because the script runs in the context of the victim's session, it can steal cookies, deface the page, or perform actions on behalf of the user. The 'alert test' is the classic proof-of-concept payload for confirming XSS vulnerabilities.
Why this answer
This is a classic stored cross-site scripting (XSS) attack. The malicious script is injected into a persistent data store (the forum signature field) and later served to other users without proper sanitization, causing the browser to execute the script in the context of the trusted site.
Exam trap
The trap here is confusing client-side injection (XSS) with server-side injection (SQL injection) because both involve untrusted input, but XSS targets the browser's rendering engine while SQL injection targets the database query parser.
How to eliminate wrong answers
Option A is wrong because SQL injection targets database queries by manipulating input to alter SQL commands, not client-side script execution in a user's browser. Option C is wrong because session replay attacks involve capturing and reusing session tokens (e.g., via packet sniffing or XSS), not injecting scripts into a forum signature. Option D is wrong because directory traversal exploits file system paths to access restricted files (e.g., using '../' sequences), not injecting client-side code into web pages.
To discourage unauthorized entry into a records room, facilities installs a large warning sign, a visible camera over the door, and a turnstile staffed by a guard during business hours. Which control category is the warning sign intended to support most directly?
A.Deterrent
B.Detective
C.Preventive
D.Corrective
AnswerA
A deterrent control aims to discourage a would-be attacker by signaling that unauthorized entry will be detected and punished. The warning sign serves this purpose by altering the perceived cost–benefit of the intrusion before any attempt occurs. Unlike a lock or turnstile, it does not physically prevent access; it relies on psychological influence to stop the action at the intention stage.
Why this answer
The warning sign is a physical security control designed to discourage unauthorized entry by making potential intruders aware of the risks and consequences. This directly supports the deterrent control category, which aims to reduce the likelihood of a security incident by influencing behavior through fear of detection or punishment. Unlike detective controls that identify incidents after they occur, or preventive controls that physically block access, the sign's primary function is psychological deterrence.
Exam trap
The trap here is that candidates confuse the warning sign's purpose with a preventive control, mistakenly thinking that any security measure that stops entry must be preventive, when in fact the sign only discourages rather than physically or logically blocks access.
How to eliminate wrong answers
Option B is wrong because detective controls, such as motion sensors or audit logs, are designed to identify and record security events after they happen, not to discourage entry beforehand. Option C is wrong because preventive controls, like locks or access control systems, physically or logically block unauthorized access, whereas a sign only warns without enforcing a barrier. Option D is wrong because corrective controls, such as backup restoration or incident response procedures, are applied after a security incident to mitigate damage or restore operations, not to prevent or deter initial unauthorized entry.
Based on the exhibit, which principle is most directly being violated by the current share permissions?
A.Least privilege, because the broad Finance Dept access exceeds what many users require.
B.Need-to-know, because only the people working on valuation models should access them.
C.Zero trust, because the share should refuse access until every file request is reauthenticated.
D.Defense in depth, because the folder should have several separate layers of encryption.
AnswerB
Need-to-know applies because the exhibit says only three deal leads require the valuation models, while other finance staff only need unrelated invoice-tracking files. The principle focuses on restricting access to information based on necessity, even when users are part of a broader trusted group.
Why this answer
The exhibit shows share permissions granting 'Finance Dept' full control over a folder containing valuation models. The need-to-know principle restricts access to only those individuals who require the information to perform their job functions. Since not all Finance Dept members work on valuation models, granting the entire department access violates need-to-know, as only the specific users building those models should have access.
Exam trap
The trap here is confusing least privilege (which limits permission levels) with need-to-know (which limits data access based on job function), leading candidates to choose A when the real violation is granting access to users who have no business need for the data.
How to eliminate wrong answers
Option A is wrong because least privilege focuses on granting the minimum rights (e.g., Read vs. Full Control) to perform a task, not on restricting access based on job role necessity; the violation here is about who gets access, not the level of permissions. Option C is wrong because zero trust requires continuous verification of every access request, but the share permissions are static and do not involve reauthentication per file request; the question is about permission scope, not authentication architecture.
Option D is wrong because defense in depth involves multiple layers of security controls (e.g., firewalls, encryption, IDS), not the granularity of share permissions; the folder lacks encryption layers, but the core violation is unauthorized access to sensitive data, not insufficient encryption depth.
A SIEM alert shows a workstation connecting to the same unknown internet address every 15 minutes, even after business hours. The device belongs to an employee who is on vacation. What is the best next step for the analyst?
A.Dismiss the alert because periodic connections are always normal for workstations.
B.Treat the alert as potentially malicious and check endpoint and proxy logs for more context.
C.Immediately delete the workstation account from the directory service.
D.Shut down the entire office network until the analyst can review the alert.
AnswerB
Treating the alert as potentially malicious is the appropriate first response because an unknown destination contacted at regular intervals is a classic beaconing signature used by command-and-control (C2) malware. Checking endpoint logs can reveal the executable or script initiating the connection, while proxy logs provide the full URL, TLS SNI, and destination categorization needed to assess reputation. This non-destructive correlation gives the analyst the context required to determine whether the traffic is a true positive or a benign service, and it preserves forensic data for later investigation.
Why this answer
The alert describes a persistent outbound connection to an unknown external IP address at regular intervals, which is a classic indicator of beaconing behavior often associated with malware command-and-control (C2) traffic. The fact that the connection occurs after business hours and the workstation's user is on vacation increases suspicion, as legitimate scheduled tasks or updates would typically not run under those conditions. Checking endpoint and proxy logs provides the necessary context to determine if the traffic is benign (e.g., a misconfigured service) or malicious (e.g., C2 communication).
Exam trap
The trap here is that candidates may assume periodic connections are always benign (e.g., Windows Update or NTP sync) and dismiss the alert, failing to recognize that the regularity, unknown destination, and user-on-vacation context are red flags for malicious C2 activity.
How to eliminate wrong answers
Option A is wrong because periodic connections are not always normal; beaconing at fixed intervals to an unknown external address is a well-known indicator of compromise (IoC) in security monitoring, and dismissing it outright violates standard incident response procedures. Option C is wrong because immediately deleting the workstation account from the directory service is a drastic, irreversible action that could disrupt legitimate operations and destroy forensic evidence; the proper first step is to gather additional context before taking containment actions.
An employee receives an email that appears to come from payroll and asks them to open a link to "confirm direct deposit details". The link goes to a site with a slightly misspelled company name. What should the employee do first?
A.Click the link and sign in quickly before the account is locked
B.Reply to the email and ask payroll whether the message is real
C.Use the company's known payroll portal or help desk contact to verify the request
D.Forward the message to co-workers so they can compare it with similar emails
AnswerC
Verifying through the company's known payroll portal or help desk contact is the correct, secure response because it uses a trusted, out-of-band channel that bypasses every component of the suspicious email—its links, its reply address, and its embedded payload. By navigating directly to the official portal or calling a verified number, you confirm the legitimacy of the request without ever exposing your credentials or confirming your address to a potential attacker.
Why this answer
The safest first step when receiving a suspicious email is to verify its legitimacy through a trusted, independent channel—such as the company's known payroll portal or the help desk. This avoids interacting with the potentially malicious link or sender, which could lead to credential theft or malware installation. The email exhibits classic phishing indicators: a spoofed sender, a request for sensitive action, and a URL with a misspelled domain.
Exam trap
The trap here is that candidates may think replying to the email (Option B) is a safe verification method, but in reality, it engages the attacker and confirms the email address as active, which is a common social engineering tactic.
How to eliminate wrong answers
Option A is wrong because clicking the link and signing in would directly submit credentials to a phishing site, compromising the employee's account. Option B is wrong because replying to the email confirms the employee's address as active and may reach the attacker, not the legitimate payroll department, increasing the risk of targeted follow-up attacks. Option D is wrong because forwarding the message to co-workers could spread the phishing attempt and potentially expose others to the same threat, violating security best practices that require reporting to the security team instead.
A web application must be reachable from the internet, but its database should be isolated from direct internet access. Which two placements or controls are most appropriate? Select two.
Select 2 answers
A.Place the web server in a DMZ.
B.Keep the database on an internal network segment and restrict access to the web server only.
C.Place both the web server and the database on the same internet-facing subnet.
D.Expose the database port to the internet so administrators can connect faster.
E.Use the guest wireless VLAN for both systems.
AnswersA, B
A DMZ is a separate network segment that sits between the internet and the internal LAN. It is designed to host public-facing services like web servers, with firewall rules that allow inbound traffic only to the web server, while preventing direct access to internal resources. This containment limits compromise impact.
Why this answer
Placing the web server in a DMZ (Option A) allows it to be reachable from the internet while the internal firewall restricts inbound traffic to only necessary ports (e.g., TCP 80/443). Keeping the database on an internal network segment (Option B) and configuring firewall rules to allow traffic only from the web server’s IP address ensures the database is isolated from direct internet access, preventing external attacks on the database service.
Exam trap
The trap here is that candidates often think placing both systems in the DMZ is acceptable, but they overlook that the database must be on an internal segment with strict access controls, not just any segment with internet exposure.
A help desk technician receives an email that appears to come from the payroll provider. The message says the employee's direct deposit will be suspended unless they verify their account through a link. What type of attack is this?
A.Phishing
B.Baiting
C.Vishing
D.Pretexting
AnswerA
Correct because the message uses a fake urgent request to steal credentials through a link. It impersonates a trusted organization and pressures the user to act quickly. That combination is a classic phishing pattern, even if the wording seems professional and the logo looks real.
Why this answer
This is a classic phishing attack because the email impersonates a trusted entity (the payroll provider) and uses social engineering to trick the recipient into clicking a malicious link. Phishing specifically involves fraudulent electronic communications, such as email, to deceive victims into revealing sensitive information or installing malware. The attack vector here is email-based, which aligns directly with the definition of phishing in the SY0-701 domain of threats and vulnerabilities.
Exam trap
The trap here is that candidates may confuse phishing with pretexting because both involve deception, but phishing is specifically electronic (email, SMS, or instant message), while pretexting relies on a fabricated story delivered through any medium, often requiring direct interaction.
How to eliminate wrong answers
Option B (Baiting) is wrong because baiting involves offering something enticing (e.g., a free USB drive or download) to lure a victim into a trap, not sending a deceptive email requesting verification. Option C (Vishing) is wrong because vishing uses voice communication (e.g., phone calls or VoIP) to extract information, not email. Option D (Pretexting) is wrong because pretexting involves fabricating a scenario or identity to gain trust and obtain information, often through direct interaction (e.g., a phone call or in-person), not through an unsolicited email with a link.
Based on the exhibit, which indicator should defenders prioritize for detecting future activity from this campaign?
A.The daily-changing domain names used by the campaign.
B.The executable file hash that remains constant across samples.
C.The TLS certificate fingerprint that remains constant across samples.
D.The changing user agent string seen on each host.
AnswerC
A stable TLS certificate fingerprint is a strong indicator because it can survive daily domain changes and still identify the same infrastructure or campaign. It is especially useful for network detection when other indicators rotate frequently, as shown in the exhibit.
Why this answer
A TLS certificate fingerprint that remains constant across samples provides a stable, attacker-controlled indicator that is difficult for adversaries to change without incurring cost or operational friction. Unlike domain names or user agents, which can be rotated easily, TLS certificates require the attacker to generate or compromise a new private key and certificate, making the fingerprint a persistent and reliable detection signature for defenders.
Exam trap
The trap here is that candidates mistakenly prioritize easily changed artifacts like file hashes or domain names, overlooking the operational friction that makes TLS certificate fingerprints a more stable and attacker-resistant indicator.
How to eliminate wrong answers
Option A is wrong because daily-changing domain names are designed to evade domain-based blocklists and are inherently unstable as indicators; defenders would struggle to keep up with the rapid rotation. Option B is wrong because while an executable file hash may remain constant across samples, it can be trivially altered by recompiling or appending junk data to the binary, making it a weak long-term indicator. Option D is wrong because user agent strings are easily spoofed or randomized by the malware, and they often vary per host or session, providing no reliable consistency for detection.
A security manager wants one document that states employees must protect company laptops and another that defines exact required settings such as disk encryption and a 10-minute screen lock. Which two document types are the best fit? Select two.
Select 2 answers
A.Policy
B.Standard
C.Guideline
D.Procedure
E.Exception
AnswersA, B
A policy is a formal, board-approved statement of management intent that establishes mandatory, high-level expectations for security behavior. It explains the "what" and "why"—for example, employees must protect laptops and company data—without dictating specific technical implementations. As the foundational governance document, it sets the legal and compliance boundary for all lower-level documentation.
Why this answer
A policy is a high-level statement of management intent, such as requiring employees to protect company laptops. A standard defines mandatory, specific technical settings, like requiring disk encryption (e.g., AES-256) and a 10-minute screen lock timeout. Together, they provide the overarching directive (policy) and the enforceable configuration baseline (standard).
Exam trap
The trap here is confusing 'policy' with 'guideline' or 'procedure'—candidates often pick 'guideline' for the technical settings because they think it's a recommendation, but standards are the only document type that mandates exact technical configurations.
Match each requirement or instruction to the correct governance document type. Use each document type once.
Drag a concept onto its matching description — or click a concept then click the description.
Concepts
Matches
Policy
Standard
Procedure
Guideline
Why these pairings
These matches align with common governance document types in IT security frameworks: policy provides high-level direction, standard sets mandatory rules, procedure gives step-by-step instructions, guideline offers non-mandatory recommendations, baseline defines minimum configurations, and framework provides a structured approach.
An office wants finance workstations separated from general user PCs, but employees still need to print to a shared printer and access one accounting application. Which change best supports this?
A.Place all systems on one VLAN and rely on strong passwords.
B.Move finance systems to a separate VLAN or subnet and allow only required traffic through filtering rules.
C.Put the printer in a different building to make it more secure.
D.Enable screen lock timers on the finance PCs and keep the network flat.
AnswerB
This is the best choice because it separates finance systems from general users while still allowing approved services like printing and application access. VLANs or subnets reduce lateral movement, and firewall or ACL rules limit communication to only what is needed. That supports least privilege at the network layer.
Why this answer
Placing finance systems on a separate VLAN or subnet with a Layer 3 boundary enforces network segmentation, which limits broadcast domains and restricts lateral movement. By configuring access control lists (ACLs) or firewall rules to permit only the required traffic (e.g., SMB/CIFS for printer sharing and specific TCP/UDP ports for the accounting application), the organization achieves a least-privilege network architecture. This approach aligns with the principle of defense-in-depth, reducing the attack surface while maintaining necessary business functionality.
Exam trap
The trap here is that candidates often confuse physical separation (Option C) with logical network segmentation, or assume that strong passwords (Option A) or endpoint controls (Option D) are sufficient substitutes for network-layer isolation, when in fact VLANs and ACLs are required to enforce least-privilege access between different security zones.
How to eliminate wrong answers
Option A is wrong because placing all systems on one VLAN with strong passwords only provides authentication security but fails to segment traffic; a single VLAN allows any compromised general user PC to directly communicate with finance workstations via Layer 2, bypassing any network-level controls. Option C is wrong because moving the printer to a different building does not change the logical network topology—if the printer remains on the same flat network, it still exposes a shared resource without addressing segmentation, and physical relocation adds no security benefit against network-based attacks. Option D is wrong because enabling screen lock timers on finance PCs only addresses local physical access risks, while keeping the network flat (no VLANs or subnets) means all devices share the same broadcast domain, allowing potential attackers on general user PCs to perform ARP spoofing or sniff traffic destined for the printer or accounting application.
Based on the exhibit, which control option provides the greatest net annual financial benefit for the organization?
A.Option A, because it reduces loss enough to justify the control cost better than the smaller controls.
B.Option B, because its large reduction in annual loss outweighs the higher implementation cost.
C.Option C, because transferring the risk is always cheaper than engineering a technical fix.
D.Option D, because low upfront cost makes it the most economical option regardless of residual loss.
AnswerB
Reduces annual loss expectancy from $260,000 to $40,000, creating $220,000 in annual savings before cost. After subtracting the $120,000 control cost, it still delivers the highest net benefit among the choices. Quantitative risk decisions should compare expected loss reduction against implementation cost, and this option provides the strongest financial return.
Why this answer
It provides the greatest net annual financial benefit. With a loss reduction of $220,000 and an implementation cost of $120,000, the net benefit is $100,000, which is higher than any other option. This demonstrates that a larger upfront investment can be justified when the reduction in annualized loss expectancy (ALE) significantly outweighs the control cost.
Exam trap
The trap here is that candidates often choose the option with the lowest implementation cost or the highest loss reduction without calculating the net benefit, failing to recognize that the greatest net financial benefit comes from the optimal balance between cost and loss reduction. For example, Option B's loss reduction of $220,000 minus cost of $120,000 yields $100,000 net benefit, surpassing other options.
How to eliminate wrong answers
Option A is wrong because although it reduces loss, its net benefit ($50,000 reduction - $25,000 cost = $25,000) is lower than Option B's net benefit of $75,000, so it does not provide the greatest net annual financial benefit. Option C is wrong because transferring risk (e.g., cyber insurance) is not always cheaper; in this scenario, the net benefit of Option C ($100,000 reduction - $60,000 cost = $40,000) is still less than Option B's net benefit, and risk transfer often involves premiums, deductibles, and residual risk that can make it less economical than a technical control. Option D is wrong because low upfront cost does not guarantee the greatest net benefit; its net benefit ($30,000 reduction - $10,000 cost = $20,000) is the lowest among all options, and ignoring residual loss can lead to underestimating long-term financial impact.
Users on the same VLAN report that their browser occasionally reaches a fake internal portal, and packet captures show one host sending forged ARP replies that claim to be the default gateway. Traffic from nearby systems begins flowing through that host. Which attack is occurring?
A.DNS poisoning
B.ARP spoofing
C.MAC flooding
D.SYN flood
AnswerB
ARP spoofing (also called ARP poisoning) works by sending unsolicited ARP replies—or replying to ARP requests—on the local Ethernet segment, falsely claiming that the attacker's MAC address corresponds to the default gateway or another host's IP. The victim's ARP cache is then poisoned, so unicast traffic intended for the gateway is forwarded to the attacker instead, enabling man-in-the-middle interception, tampering, or sniffing. This perfectly explains intermittent browser misbehavior on the same VLAN, since the poisoned ARP entries expire and the attack can be replayed. The forged gateway ARP replies are the definitive indicator that separates ARP spoofing from the other options.
Why this answer
B is correct because the scenario describes ARP spoofing (also known as ARP poisoning). The attacker sends forged ARP replies to associate their MAC address with the default gateway's IP address, causing traffic from other hosts on the same VLAN to be redirected through the attacker's machine. This allows the attacker to intercept, modify, or redirect traffic to a fake internal portal, which is a classic man-in-the-middle (MITM) attack leveraging the stateless nature of ARP.
Exam trap
The trap here is that candidates confuse ARP spoofing with DNS poisoning because both can redirect traffic to a fake portal, but the key differentiator is the protocol layer: ARP operates at Layer 2 (MAC address manipulation) while DNS operates at Layer 7 (name resolution).
How to eliminate wrong answers
Option A is wrong because DNS poisoning involves corrupting DNS resolver caches or zone data to redirect domain names to malicious IPs, but the packet captures show forged ARP replies, not DNS queries or responses. Option C is wrong because MAC flooding overwhelms a switch's CAM table with fake MAC addresses to force it into fail-open mode (hub-like behavior), but the attack here is targeted and uses spoofed ARP replies, not flooding. Option D is wrong because a SYN flood is a denial-of-service (DoS) attack that exhausts server resources by sending incomplete TCP handshake requests; it does not involve ARP manipulation or traffic redirection.
Facilities sees occasional water droplets forming above the cable trays in a data room during humid afternoons. The team wants the earliest possible warning before equipment is damaged. Which control should be added?
A.Motion detectors connected to the alarm panel.
B.Water leak sensors tied to environmental monitoring.
C.Badge readers on the room entrance only.
D.Fire suppression tests scheduled more frequently.
AnswerB
Water leak sensors are purpose-built to detect the presence of moisture or abnormal humidity levels, often using conductive pads or capacitive probes that trigger an alert when water contacts the sensor. When integrated into an environmental monitoring system, they provide continuous, real-time visibility of conditions such as condensation on ductwork or plumbing leaks, allowing facility staff to respond before water reaches sensitive electrical equipment. This makes them the correct, targeted solution for the described scenario, as they directly address the risk of water intrusion rather than relying on indirect indicators.
Why this answer
Water leak sensors tied to environmental monitoring provide the earliest possible warning by detecting moisture directly on or near the cable trays. Unlike motion detectors or badge readers, these sensors are specifically designed to alert before water reaches sensitive equipment, enabling proactive remediation.
Exam trap
The trap here is that candidates may confuse physical security controls (motion detectors, badge readers) with environmental monitoring controls, overlooking that water damage requires specific moisture detection rather than access or motion sensing.
How to eliminate wrong answers
Option A is wrong because motion detectors detect movement, not water, and would not provide any warning about condensation or leaks. Option C is wrong because badge readers control physical access to the room but cannot detect environmental conditions like humidity or water. Option D is wrong because fire suppression tests are unrelated to water detection and do not address the condensation issue; they focus on fire safety, not moisture monitoring.
An enterprise is moving from on-prem identity to a SaaS HR platform. Employees should sign in with corporate credentials, and terminated users must lose access quickly without manually creating or deleting SaaS passwords. Which solution best fits?
A.Create a shared HR password for all employees and change it quarterly.
B.Use LDAP bind accounts directly against the SaaS platform for every login.
C.Implement federated SSO with the corporate identity provider and automated provisioning and deprovisioning.
D.Require each user to create a separate local SaaS account and store the credentials in a vault.
AnswerC
Federated SSO delegates authentication to the corporate identity provider, allowing users to sign in with existing enterprise credentials via standards like SAML or OIDC, while eliminating the need for separate SaaS passwords. Coupled with SCIM-based automated provisioning and deprovisioning, the platform's user accounts are created, updated, and removed synchronously with HR records, ensuring that departing employees lose access immediately. This architectural pattern enhances security, simplifies compliance, and reduces identity sprawl.
Why this answer
Federated SSO with the corporate identity provider (IdP) allows employees to sign in using their existing corporate credentials via standards like SAML 2.0 or OIDC, eliminating the need for separate SaaS passwords. Automated provisioning and deprovisioning (e.g., via SCIM) ensures that when a user is terminated in the HR platform, their access to the SaaS application is revoked immediately without manual intervention, meeting the requirement for rapid access removal.
Exam trap
The trap here is that candidates often confuse LDAP bind (Option B) with federated SSO, thinking that LDAP can directly authenticate against SaaS platforms, but LDAP is a directory access protocol that requires a gateway or federation service to work with cloud apps, and it lacks automated provisioning capabilities.
How to eliminate wrong answers
Option A is wrong because a shared HR password violates the principle of non-repudiation and individual accountability, and changing it quarterly does not provide immediate revocation of access for terminated users. Option B is wrong because LDAP bind accounts are designed for on-premises directory authentication and are not natively supported by most modern SaaS platforms; they would require a complex LDAP-to-SAML bridge and do not support automated deprovisioning. Option D is wrong because requiring each user to create a separate local SaaS account and store credentials in a vault introduces manual password management, contradicts the goal of using corporate credentials, and does not enable automated deprovisioning upon termination.
A Linux operations team has a standing need to restart services and edit protected configuration files on production servers, but administrators should not keep root privileges all day. Every elevation must be approved through a ticket and logged centrally. Which solution best meets this requirement?
A.Create one shared root password and rotate it weekly
B.Use privileged access management with just-in-time elevation and session logging
C.Assign each administrator the server local administrator role permanently
D.Use single sign-on so administrators only authenticate once each morning
AnswerB
PAM with just-in-time elevation is the best match because it grants administrative rights only when needed and only after approval. Central session logging provides accountability, and the regular user account remains the default for normal work. This reduces standing privilege, limits misuse, and gives auditors a clear record of who elevated, when, and why.
Why this answer
Privileged Access Management (PAM) with just-in-time (JIT) elevation and session logging meets the requirement because it grants temporary, request-based root privileges that are automatically revoked after the task, and it centrally logs all commands executed during the elevated session. This ensures every elevation is approved via a ticket and auditable, without administrators retaining permanent root access.
Exam trap
The trap here is that candidates often confuse 'single sign-on' (SSO) with 'privilege elevation control,' assuming SSO's convenience implies security control, when in fact SSO only handles authentication, not authorization or session auditing.
How to eliminate wrong answers
Option A is wrong because a shared root password rotated weekly violates the principle of non-repudiation (no individual accountability) and does not enforce per-elevation approval or logging. Option C is wrong because permanently assigning the local administrator role (e.g., sudoers membership) gives continuous root-equivalent privileges, contradicting the requirement that administrators should not keep root privileges all day. Option D is wrong because single sign-on (SSO) only simplifies initial authentication; it does not control or log privilege elevation events, nor does it enforce ticket-based approval for each root action.
A SIEM correlates the following: 17 failed logons against the same VPN account from one IP in 9 minutes, a successful login from that IP, creation of a new API token in the SaaS tenant, and a large export job started two minutes later. Which two interpretations are best supported? Select two.
Select 2 answers
A.The attacker is likely performing a brute-force password attack against a single account.
B.The pattern is most consistent with password spraying across many accounts.
C.The account is likely compromised and being used for token abuse or persistence.
D.The events primarily indicate a volumetric denial-of-service attack.
E.Token creation proves the account password was never exposed.
AnswersA, C
Seventeen failed logons all targeting the same account from a single source is the hallmark of a brute-force attack, where the attacker systematically submits many password guesses against one username. Unlike spraying, which spreads a few attempts across many identities, this concentrated burst aims to eventually crack the one credential. The subsequent successful logon and token creation are consistent with a brute-force attempt that finally succeeded and then moved to post-exploitation.
Why this answer
A is correct because 17 failed logons against a single VPN account from one IP in 9 minutes is a classic brute-force pattern—repeated authentication attempts targeting one username. The subsequent successful login, API token creation, and data export indicate the attacker gained access and then established persistence (via the token) to exfiltrate data, confirming the account was compromised.
Exam trap
The trap here is confusing a single-account brute-force with password spraying—candidates often misidentify the pattern because they see multiple failed logons and assume many accounts are targeted, but the key is the same account and same IP over a short window.
A developer requests a 45-day exception to use an unsupported browser plug-in on two engineering workstations so a legacy design tool can finish a customer deliverable. Which three conditions should be required before approving the exception? Select three.
Select 3 answers
A.Document a business justification that explains why the plug-in is required for the deliverable.
B.Convert the exception into a permanent waiver to avoid repeated review overhead.
C.Set a defined end date and require review before the exception expires.
D.Apply compensating controls, such as host isolation, restricted user access, or limiting use to named workstations.
E.Allow the requestor to self-approve the exception if the project deadline is urgent.
AnswersA, C, D
Documenting a business justification is correct because it ties the use of an unsupported plug-in directly to a concrete deliverable, proving that the accepted risk serves a legitimate operational need rather than administrative convenience. This artifact gives the risk owner clear evidence to make an informed decision and creates an audit trail explaining why the standard security baseline could not be met. The justification should name the deliverable, the plug-in's required function, and the impact of not using it, making the exception defensible during review.
Why this answer
Documenting a business justification provides a formal record of why the exception is necessary, ensuring that the risk of using an unsupported browser plug-in is understood and accepted by management. This aligns with the principle of risk acceptance, where the business need outweighs the security risk for a limited time. Without a clear justification, the exception could be granted without proper oversight, potentially leading to unchecked vulnerabilities.
Exam trap
The trap here is that candidates may mistakenly think converting an exception to a permanent waiver reduces administrative overhead, but CompTIA emphasizes that exceptions must remain temporary and reviewed, as permanent waivers bypass the risk management process and can lead to unmanaged security gaps.
The help desk needs a document that tells analysts exactly how to verify a caller, reset a password, and record the ticket when a user is locked out. What type of document is this?
A.Procedure
B.Policy
C.Standard
D.Guideline
AnswerA
A procedure is the right document when staff need exact step-by-step instructions. In this situation, the help desk needs a repeatable process for identity verification, password reset actions, and documentation requirements. Procedures reduce mistakes because they tell employees what to do in sequence rather than leaving the process open to interpretation.
Why this answer
A procedure is the correct type of document because it provides step-by-step instructions for performing a specific task, such as verifying a caller's identity, resetting a password, and recording a ticket. Unlike a policy, which states high-level rules, a procedure details the exact actions to take in a given scenario, making it ideal for help desk operations.
Exam trap
The trap here is that candidates often confuse 'procedure' with 'policy' because both are security documents, but a policy sets the 'what' and 'why' (e.g., 'passwords must be reset securely'), while a procedure defines the 'how' (e.g., 'call the user back at their verified phone number before resetting').
How to eliminate wrong answers
Option B is wrong because a policy defines high-level rules and objectives (e.g., 'passwords must be reset securely') but does not provide the step-by-step instructions needed for the help desk to execute the task. Option C is wrong because a standard specifies mandatory technical requirements or baselines (e.g., 'passwords must be at least 12 characters') but does not describe the process of verification, reset, and ticket recording. Option D is wrong because a guideline offers general advice or best practices (e.g., 'consider using multi-factor authentication') but lacks the precise, mandatory steps required for consistent execution in a help desk workflow.
Several company laptops were found to boot from a removable drive containing an untrusted pre-boot utility before the operating system loaded. The security team wants to prevent unsigned or tampered boot code from starting. Which control is the best fit?
A.Enable Secure Boot in firmware and block external boot devices where possible.
B.Turn on screen lock after ten minutes of inactivity.
C.Increase the password complexity policy for user accounts.
D.Disable Windows Defender notifications on the endpoints.
AnswerA
Secure Boot checks boot components against trusted signatures before they are allowed to run, which directly addresses tampered or untrusted pre-boot code. Disabling external boot adds another layer by reducing the chance of unauthorized removable media being used to bypass protections.
Why this answer
Secure Boot is a UEFI firmware feature that verifies the digital signature of boot code against a trusted database before execution. By enabling Secure Boot and blocking external boot devices, the security team ensures that only signed, trusted bootloaders and drivers can run, preventing untrusted pre-boot utilities from loading. This directly addresses the scenario where laptops boot from a removable drive containing unsigned or tampered boot code.
Exam trap
The trap here is that candidates may confuse endpoint security controls (like screen lock or password policies) with boot-time integrity mechanisms, failing to recognize that Secure Boot is the only option that validates code before the OS loads.
How to eliminate wrong answers
Option B is wrong because screen lock after inactivity addresses unauthorized physical access to an already-booted OS, not the pre-boot execution of untrusted code. Option C is wrong because password complexity policies protect user account credentials but have no effect on boot-time code integrity or device boot order. Option D is wrong because disabling Windows Defender notifications only suppresses security alerts; it does not prevent unsigned boot code from executing.
A project team must share a spreadsheet containing customer names, account numbers, and purchase history with an external auditor. The auditor only needs account numbers and totals. What is the best privacy control?
A.Send the full spreadsheet through regular email to avoid delaying the audit
B.Redact unneeded personal data and transfer only the minimum necessary information through an approved encrypted channel
C.Upload the spreadsheet to a public file-sharing site and protect it with a password
D.Compress the file with a password and reuse the same password for all auditors
AnswerB
This is the best privacy control because it applies data minimization and secure transmission together. The auditor receives only what is needed to complete the review, which reduces exposure of personal information and limits the blast radius if the file is mishandled. Using an approved encrypted channel also helps protect the data in transit and supports governance requirements.
Why this answer
It applies the principle of data minimization and secure transmission. Redacting unneeded personal data (customer names) ensures only the minimum necessary information (account numbers and totals) is shared, reducing exposure. Transferring via an approved encrypted channel (e.g., SFTP, HTTPS, or encrypted email) protects data in transit from interception, which is required for compliance with regulations like GDPR or PCI DSS.
Exam trap
The trap here is that candidates may think password-protecting a file or using a public sharing site is sufficient, but the exam tests the understanding that data minimization and approved encrypted channels are required for privacy compliance, not just any form of access control.
How to eliminate wrong answers
Option A is wrong because sending the full spreadsheet through regular email exposes all customer personal data in transit and at rest, violating data minimization and encryption requirements (email is often unencrypted or uses opportunistic TLS). Option C is wrong because uploading to a public file-sharing site, even with a password, relies on the security of the third-party service and the password alone, which does not guarantee encryption at rest or proper access controls, and the file may be cached or indexed. Option D is wrong because compressing with a password and reusing the same password for all auditors violates the principle of unique credentials per user, lacks audit trails, and does not ensure encryption of the file in transit or at rest (ZIP encryption is weak and can be cracked).
A company wants guest Wi-Fi to reach only the internet, employee laptops to reach internal apps, and payment servers to remain isolated from both. What is the best design approach?
A.Place all systems on one flat network and rely on antivirus.
B.Use separate network segments with firewall rules between guest, employee, and payment zones.
C.Put all systems behind a single VPN so every device is treated the same.
D.Use a larger internet circuit so the payment servers are harder to attack.
AnswerB
This is the best choice because segmentation limits what each group can reach and reduces the impact of a compromise. Guest users are confined to internet access, employee systems can be limited to approved internal services, and payment servers can be placed in a tightly controlled zone with only required ports open. That design supports least privilege at the network layer and makes monitoring and containment easier.
Why this answer
Network segmentation using separate VLANs or subnets with firewall rules enforces isolation between guest Wi-Fi, employee laptops, and payment servers. This design ensures that guest traffic can only reach the internet, employee traffic can access internal apps, and payment servers are completely isolated from both, meeting the principle of least privilege and reducing the attack surface.
Exam trap
The trap here is that candidates may think a VPN provides isolation, but a VPN only encrypts traffic and does not inherently segment networks; without separate firewall rules, all VPN clients share the same network access.
How to eliminate wrong answers
Option A is wrong because placing all systems on one flat network with antivirus only provides endpoint protection and does not prevent lateral movement; an attacker on the guest Wi-Fi could directly access payment servers or internal apps. Option C is wrong because putting all systems behind a single VPN treats every device identically, removing the ability to enforce different access policies; it would allow guest devices to reach internal apps and payment servers, violating isolation requirements.
A payment processor stores full card numbers in its transaction database, but developers and analysts should never see the real numbers in nonproduction reports or troubleshooting tools. The business still needs to correlate the same card across multiple records. Which technique is the best fit?
A.Tokenization, because it replaces the real value with a surrogate token for business use.
B.Hashing, because the output can always be reversed by the application later.
C.Data masking, because it permanently deletes the sensitive record from the database.
D.Compression, because reducing file size also hides the payment information from users.
AnswerA
Tokenization replaces the real primary account number (PAN) with a randomly generated surrogate token that retains the same length and format, enabling the payment processor to perform transactions, lookups, and analytics without exposing the original card data. The actual PAN resides in a highly restricted token vault, so even if application databases or reports are compromised, the sensitive value remains secured.
Why this answer
Tokenization is the best fit because it replaces the full card number with a unique, non-reversible surrogate token that retains the ability to correlate records (the same card always produces the same token). This allows the business to perform analytics and troubleshooting without exposing the actual sensitive data, as the token has no mathematical relationship to the original PAN and cannot be reversed.
Exam trap
The trap here is that candidates confuse tokenization with hashing, assuming both are irreversible, but hashing is reversible for small input spaces like credit card numbers and does not provide a controlled surrogate for business correlation without exposing the original data.
How to eliminate wrong answers
Option B is wrong because hashing, while one-way, is deterministic and can be reversed via brute-force or rainbow tables if the input space is small (e.g., credit card numbers); it also does not provide a controlled surrogate for business use and may expose the original value if the hash is cracked. Option C is wrong because data masking dynamically obscures data (e.g., showing only last four digits) but does not permanently delete records; it still allows the real value to exist in the database and can be bypassed in nonproduction tools. Option D is wrong because compression reduces file size for storage or transmission but does not hide or protect sensitive data; the original card numbers remain fully visible after decompression.
An organization is placing its public-facing website behind a new security design. The site must be reachable from the internet, but the database and file servers must stay isolated from direct external access. What design should the architect use?
A.Place the web server on the internal user subnet so it can reach the database directly.
B.Create a demilitarized zone (DMZ) for the public web server.
C.Use a VPN concentrator so the website can be accessed securely from outside.
D.Use network address translation (NAT) on the web server to hide its IP address.
AnswerB
A demilitarized zone (DMZ) is a physically or logically isolated network segment that sits between the untrusted internet and the trusted internal network. It enforces firewall rules that allow only inbound traffic to the public web server while blocking direct access to internal hosts, ensuring that a breach of the web server does not automatically compromise internal systems.
Why this answer
A demilitarized zone (DMZ) is a network segment that isolates public-facing services, such as a web server, from the internal network. By placing the web server in the DMZ, the organization allows internet traffic to reach the website while keeping the database and file servers on the internal network, which are not directly accessible from the internet. This design enforces a security boundary where only necessary traffic (e.g., HTTP/HTTPS) is permitted through firewall rules, preventing direct external access to sensitive backend systems.
Exam trap
The trap here is that candidates often confuse NAT or VPN as security controls for isolation, when in fact they do not provide network segmentation; the DMZ is the only design that creates a physical or logical boundary to isolate public-facing servers from internal resources.
How to eliminate wrong answers
Option A is wrong because placing the web server on the internal user subnet would expose the internal network to direct internet traffic, violating the isolation requirement for the database and file servers. Option C is wrong because a VPN concentrator is designed for secure remote access by authenticated users, not for hosting a public website that must be reachable by anonymous internet clients. Option D is wrong because network address translation (NAT) on the web server only hides its IP address but does not isolate the database and file servers from direct external access; NAT alone provides no security boundary or segmentation.
A development team needs to release an urgent fix for a customer portal on Friday evening. The business wants the change to be reversible if something breaks, and security does not want the team to skip release controls. Which requirement should be part of the change process?
A.Deploy directly to production as soon as the patch compiles successfully.
B.Require a documented test in a lower environment and a rollback plan before production approval.
C.Turn off logging during deployment to avoid filling the disk with change records.
D.Allow the release only if the developer verbally confirms the code is safe.
AnswerB
Testing in a lower environment and documenting a rollback plan are core secure change-management practices. They reduce the chance of introducing an outage and make recovery faster if the fix has unexpected side effects. This approach supports controlled release, accountability, and operational resilience while still allowing urgent changes to move forward in a safe way.
Why this answer
It enforces a documented test in a lower environment and a rollback plan, which satisfies both the business requirement for reversibility and the security requirement to maintain release controls. This aligns with the change management process in the SY0-701 domain of Security Program Management and Oversight, ensuring that changes are validated before production deployment and can be undone if issues arise.
Exam trap
The trap here is that candidates may think an urgent fix justifies skipping controls (Option A) or that disabling logging is acceptable to avoid disk issues (Option C), but the exam emphasizes that security controls and reversibility must be maintained even for emergency changes.
How to eliminate wrong answers
Option A is wrong because deploying directly to production as soon as the patch compiles skips all release controls, such as testing and approval, which violates security policy and increases risk of unplanned downtime. Option C is wrong because turning off logging during deployment would disable audit trails and monitoring, making it impossible to detect or investigate security incidents or deployment failures, which contradicts security best practices and compliance requirements.
An accounts payable specialist receives a reply inside an existing vendor email thread. The message uses the real invoice number, matches the vendor's usual tone, and asks the specialist to change payment instructions to a new bank account before the end of the day. The vendor later confirms its mailbox was compromised. What type of attack is most likely?
A.Spear phishing, because the attacker targeted one employee with a convincing message.
B.Business email compromise through conversation hijacking, because the attacker used a compromised mailbox to alter a trusted thread.
C.Baiting, because the attacker tried to tempt the user with urgency and financial pressure.
D.Vishing, because the attacker is trying to persuade the user to change banking details.
AnswerB
This is best described as business email compromise via conversation hijacking. The attacker did not just spoof a sender; they gained access to a real vendor mailbox and inserted fraudulent payment instructions into an existing thread. That makes the message much more believable, often bypassing simple awareness checks. The key clues are the real invoice number, familiar tone, and later confirmation of mailbox compromise.
Why this answer
This is a business email compromise (BEC) attack specifically using conversation hijacking. The attacker gained access to the vendor's legitimate email account and inserted a fraudulent reply into an existing, trusted email thread, leveraging the compromised mailbox to bypass the specialist's suspicion. This differs from standard spear phishing because the attacker did not craft a new email from a spoofed address but instead hijacked an ongoing, authenticated conversation.
Exam trap
CompTIA often tests the distinction between spear phishing (a crafted email from a fake sender) and BEC conversation hijacking (using a compromised legitimate account to reply within an existing thread), where candidates mistakenly choose spear phishing because they focus on the targeted nature of the attack rather than the method of compromise.
How to eliminate wrong answers
Option A is wrong because spear phishing involves sending a crafted email from a spoofed or lookalike domain to a specific target, not hijacking an existing thread from a compromised legitimate mailbox. Option C is wrong because baiting relies on offering something enticing (e.g., a free USB drive) to trick the user, not on urgency or financial pressure within a compromised email thread. Option D is wrong because vishing (voice phishing) uses phone calls or voice messages to deceive the target, not email-based manipulation of a trusted conversation.
A scan reports a critical remote code execution vulnerability on an internet-facing VPN appliance with public proof-of-concept exploit code available. It also reports a critical local privilege escalation on an isolated lab workstation. Patch windows are limited this week. Which should be remediated first?
A.The internet-facing VPN appliance because it has higher exposure and exploitability.
B.The isolated lab workstation because all critical findings must be patched in numerical order.
C.The internal printer because peripheral devices are often overlooked and therefore most dangerous.
D.The lab workstation because local privilege escalation is always more dangerous than remote code execution.
AnswerA
An externally reachable device with a known exploit and remote code execution risk presents a much larger immediate threat than an isolated lab workstation. Prioritization should consider exposure, exploit maturity, and business impact, not severity score alone. Because the VPN appliance is publicly reachable, compromise could lead directly to remote access into the environment and broader organizational impact.
Why this answer
The internet-facing VPN appliance presents a higher risk because it is exposed to the public internet and has a known remote code execution vulnerability with public exploit code. This combination of high exposure (attack surface) and high exploitability (availability of proof-of-concept code) significantly increases the likelihood of a successful attack, making it the priority for remediation despite limited patch windows.
Exam trap
The trap here is that candidates may assume all critical vulnerabilities are equal and must be patched in order of severity score, ignoring the critical factor of asset exposure and the presence of public exploit code, which dramatically increases the real-world risk.
How to eliminate wrong answers
Option B is wrong because patching in numerical order is not a valid security prioritization method; risk-based prioritization (e.g., CVSS score combined with environmental factors like exposure) is the correct approach. Option C is wrong because the internal printer is not mentioned in the scan report, and introducing an unlisted asset distracts from the actual findings; peripheral devices are not inherently more dangerous than a critical RCE on an internet-facing system. Option D is wrong because local privilege escalation is not always more dangerous than remote code execution; RCE on an internet-facing device allows an attacker to gain initial access from anywhere, while local privilege escalation requires existing access to the isolated lab workstation, which is already low risk due to network isolation.
Based on the exhibit, what is the best next step before the marketing SaaS platform goes live?
A.Proceed only after the business owner formally accepts the remaining risk in writing.
B.Ignore the residual risk because the vendor has a current SOC report.
C.Require the security team to approve the launch verbally so the project does not slow down.
D.Cancel the contract immediately because any medium risk rating is unacceptable.
AnswerA
The exhibit already shows compensating controls and a measured residual risk rating. When the remaining risk is understood and the business impact of delay is significant, the proper next step is a formal acceptance by the appropriate risk owner. That creates accountability and preserves an auditable record of the decision.
Why this answer
The exhibit shows a residual risk rating of 'Medium' after the vendor's SOC report was reviewed. In the SY0-701 risk management framework, the business owner is the risk owner who must formally accept any residual risk before a system goes live, as they are accountable for the business impact. Proceeding without documented acceptance violates the principle of risk acceptance and could lead to unapproved exposure.
Exam trap
The trap here is that candidates assume a vendor SOC report fully transfers risk to the vendor, but CompTIA emphasizes that residual risk always remains and must be formally accepted by the business owner, not just the security team.
How to eliminate wrong answers
Option B is wrong because a current SOC report only provides a point-in-time assurance of the vendor's controls; it does not eliminate residual risk, which must still be formally accepted by the business owner. Option C is wrong because verbal approval bypasses the required documented risk acceptance process and audit trail, violating governance and compliance requirements. Option D is wrong because a 'Medium' risk rating is not automatically unacceptable; risk acceptance decisions are based on the organization's risk appetite, and cancellation is an extreme response without considering mitigation or acceptance.
Based on the exhibit, which key management improvement best preserves recoverability if the primary backup server is lost?
A.Store the private key on the same backup server so recovery is faster.
B.Replace AES with hashing so the archive no longer needs a key.
C.Keep the private key in an HSM or secure escrow with tested recovery procedures.
D.Send the private key to backup operators by email so they can restore data quickly.
AnswerC
The private key must be protected separately from the primary backup server so the encrypted AES key can still be recovered if the server is lost. An HSM or secure escrow improves key protection while preserving recoverability, especially when paired with tested restoration procedures and restricted access controls.
Why this answer
Storing the private key in a Hardware Security Module (HSM) or secure escrow ensures it remains available even if the primary backup server is lost. HSMs provide tamper-resistant key storage and support tested recovery procedures, which is critical for decrypting backups and maintaining recoverability. This approach separates the key from the backup data, preventing a single point of failure.
Exam trap
The trap here is that candidates may assume storing the key with the backup data (Option A) is efficient, but they overlook that it destroys recoverability when the server is lost, which is the exact failure scenario the question describes.
How to eliminate wrong answers
Option A is wrong because storing the private key on the same backup server creates a single point of failure; if the server is lost, both the backup data and the key are gone, making recovery impossible. Option B is wrong because hashing is a one-way function that cannot be reversed to recover original data, so replacing AES with hashing would make the archive permanently unreadable and unrecoverable. Option D is wrong because sending the private key by email exposes it to interception, violates security best practices (e.g., NIST SP 800-57), and does not guarantee tested, reliable recovery procedures.
An EDR alert shows winword.exe launching powershell.exe with an encoded command after a user opened an invoice attachment. No new executable file was written to disk, and the host is still online. Which two actions should the SOC analyst take first to validate the alert and collect usable evidence? Select two.
Select 2 answers
A.Review the parent-child process chain and the full PowerShell command line in EDR.
B.Compare the endpoint's outbound connections with its normal baseline and approved destinations.
C.Reimage the workstation immediately to eliminate any possible persistence.
D.Ask the user to delete the suspicious email and clear the recycle bin.
E.Check PowerShell script block logs, AMSI detections, and related event records on the endpoint.
AnswersA, E
Reviewing the parent-child process chain in EDR confirms that winword.exe actually spawned powershell.exe, validating the suspicious macro-to-PowerShell execution path rather than assuming a false positive. The full PowerShell command line is essential because it reveals whether an encoded payload, download cradle, or malicious script was passed, and it often exposes obfuscation techniques that would otherwise be invisible. This direct process and script evidence is the fastest and most reliable way to triage the alert before taking broader defensive action.
Why this answer
Reviewing the parent-child process chain (winword.exe → powershell.exe) and the full PowerShell command line in the EDR allows the analyst to immediately validate whether the alert is a true positive by confirming the process lineage and decoding the encoded command. This step is critical for understanding the attacker's intent without relying on disk artifacts, as the attack is fileless and memory-resident.
Exam trap
The trap here is that candidates may think reimaging or deleting the email is a valid containment step, but the question specifically asks for actions to validate the alert and collect usable evidence, not to contain or remediate.
An HR analyst must send a salary file to an external auditor. The auditor only needs names, departments, and salary totals, not Social Security numbers or bank account details. Which two actions should the analyst take first? Select two.
Select 2 answers
A.Remove unnecessary sensitive fields before sharing
B.Use an approved encrypted transfer method
C.Upload the file to a public link and send the URL by email
D.Rename the file to a less obvious name and send it normally
E.Save the file locally on a USB drive and hand-deliver it
AnswersA, B
Data minimization is a core privacy control: by stripping out personally identifiable information (PII) such as Social Security numbers, bank account numbers, or performance ratings that the auditor does not need, you reduce the potential impact of any unauthorised access. This aligns with the least-privilege principle and with regulations like GDPR or CCPA that mandate processing only the minimum necessary data. Even if encryption were to fail, the exposed data is far less sensitive, making this a critical first line of defense.
Why this answer
Removing unnecessary sensitive fields (like Social Security numbers and bank account details) before sharing the file reduces the risk of exposing personally identifiable information (PII) and aligns with the principle of data minimization. This step ensures that only the required data (names, departments, salary totals) is transmitted, which is a foundational security control before any data transfer occurs.
Exam trap
The trap here is that candidates may think renaming a file (Option D) or using a USB drive (Option E) provides sufficient security, when in fact these methods lack encryption and proper access controls, which are essential for protecting sensitive data in transit.
Match each procurement or oversight need to the best vendor due diligence artifact or clause. Use each item once.
Drag a concept onto its matching description — or click a concept then click the description.
Concepts
Matches
SOC 2 Type II report
Data processing agreement (DPA)
Software bill of materials (SBOM)
Right-to-audit clause
Disaster recovery test report
Why these pairings
These artifacts support vendor due diligence: questionnaires assess controls, SOC 2 reports provide independent assurance, audit clauses enable customer verification, DPAs govern data handling, BCPs ensure resilience, and pen tests validate security.
A legacy production scanner cannot support MFA, but it must remain available for six months until replacement hardware arrives. What is the best security response?
A.Permanently waive MFA for the scanner and leave the exception open-ended.
B.Approve a time-bound exception with compensating controls and a review date.
C.Shut down the scanner immediately until MFA can be enabled.
D.Create a shared administrator account so operators can sign in more easily.
AnswerB
A time-bound exception allows the business to keep operating while security reduces risk through other controls such as network restriction, monitoring, or limited access. Adding a review date keeps the exception temporary and accountable, which is the best governance practice.
Why this answer
It balances security with operational necessity by implementing a time-bound exception with compensating controls (e.g., network segmentation, strict access logging, or IP whitelisting) and a mandatory review date. This ensures the legacy scanner remains available for six months while mitigating the risk of unauthorized access, aligning with the principle of least privilege and security program oversight.
Exam trap
The trap here is that candidates may choose Option C (immediate shutdown) thinking it is the only secure choice, but the question explicitly states the scanner must remain available, making a risk-accepted, time-bound exception with compensating controls the correct security program management response.
How to eliminate wrong answers
Option A is wrong because permanently waiving MFA for the scanner leaves an open-ended exception with no expiration or review, violating security policy and increasing long-term risk. Option C is wrong because immediately shutting down the scanner disrupts production operations unnecessarily, as a time-bound exception with compensating controls can safely bridge the six-month gap. Option D is wrong because creating a shared administrator account bypasses accountability and audit trails, directly contradicting MFA's purpose of ensuring non-repudiation and secure authentication.
At 10:15, a file server begins renaming documents and creating payment notes. The SOC confirms the server is also making SMB connections to other internal hosts, but users can still access shared folders. What should the incident handler do FIRST?
A.Disconnect the server from the network or isolate it through EDR containment while preserving power
B.Shut down the server immediately to stop all malicious activity
C.Restore the server from backup before taking any other action
D.Wait for users to report more symptoms before responding
AnswerA
Network isolation or EDR containment is the correct immediate step because it halts ransomware's further encryption and lateral movement while keeping the system powered on. Preserving power retains volatile evidence—RAM, active network connections, and running processes—which incident responders need for forensic analysis and recovery. This approach balances rapid containment with the integrity of digital evidence, unlike destructive shutdowns or premature restoration.
Why this answer
The correct first step is to contain the incident by disconnecting the server from the network or using EDR containment while preserving power. This stops the spread of malicious SMB connections and prevents further damage, while keeping the system powered on to preserve volatile evidence (e.g., memory, running processes) for forensic analysis. Immediate containment aligns with the NIST incident response framework's containment phase, prioritizing isolation over eradication or recovery.
Exam trap
The trap here is that candidates may choose to shut down the server (Option B) thinking it stops the attack, but CompTIA emphasizes preserving power and evidence for forensic analysis, making isolation the correct first step.
How to eliminate wrong answers
Option B is wrong because shutting down the server destroys volatile evidence (e.g., memory contents, active network connections) and may allow malware to persist or trigger destructive payloads on reboot. Option C is wrong because restoring from backup before containment could re-infect the network if the backup is compromised, and it skips the critical step of preserving evidence. Option D is wrong because waiting for more symptoms allows the attacker to move laterally via SMB, encrypt more files, or exfiltrate data, violating the principle of rapid containment.
An organization is implementing a Security Information and Event Management (SIEM) system to enhance its security monitoring capabilities. Which four of the following are primary functions of a SIEM? (Choose four.)
Select 4 answers
.Correlation of log data from multiple sources
.Real-time alerting on security events
.Centralized log storage and retention
.Automated threat intelligence feed integration
.Vulnerability scanning and patch management
.In-line network traffic blocking
Why this answer
A SIEM's primary functions include correlation of log data from multiple sources to identify patterns and anomalies, real-time alerting on security events to enable immediate response, centralized log storage and retention for compliance and forensic analysis, and automated threat intelligence feed integration to enrich event data with known indicators of compromise (IOCs). These capabilities collectively provide comprehensive security monitoring and incident detection.
Exam trap
The SY0-701 exam often tests the misconception that a SIEM can actively block traffic or perform vulnerability scanning, but in reality, a SIEM is a passive monitoring and analysis tool that does not execute remediation actions or network-level blocking.
A contractor connects a personal tablet to a lobby Ethernet jack. The network team wants the device blocked from internal resources until it passes posture checks and only guest access is allowed meanwhile. Which control best fits?
A.A data loss prevention platform that inspects file transfers.
B.Network access control that verifies the device before granting access.
C.A network intrusion detection system placed inline at the switch.
D.A VPN concentrator that encrypts remote traffic back to headquarters.
AnswerB
Network access control (NAC) provides exactly this capability by using protocols like 802.1X and RADIUS to authenticate the device and evaluate its security posture before the switch port is opened. Depending on the policy, the tablet may be allowed onto a guest VLAN, denied entirely, or placed in quarantine if it lacks required patches or antivirus. This pre-admission enforcement prevents the unverified contractor device from reaching internal resources, fulfilling the requirement.
Why this answer
Network Access Control (NAC) is the correct solution because it enforces security policies by checking a device's compliance (e.g., antivirus, patch level) before granting access to internal resources. In this scenario, the contractor's tablet is initially placed on a guest VLAN with internet-only access until posture checks pass, which is a core NAC function (e.g., using 802.1X or MAC authentication bypass).
Exam trap
The trap here is confusing NAC with a NIDS or DLP, because candidates often think 'blocking' requires an inline security appliance, but NAC uses switch-level VLAN assignment and 802.1X to enforce policy without inspecting content.
How to eliminate wrong answers
Option A is wrong because a Data Loss Prevention (DLP) platform inspects data in motion or at rest to prevent leaks, not to enforce pre-admission posture checks or VLAN assignment. Option C is wrong because a Network Intrusion Detection System (NIDS) monitors traffic for malicious patterns but does not block or quarantine devices based on compliance status; it is passive and cannot enforce guest-only access. Option D is wrong because a VPN concentrator encrypts remote traffic but does not perform device posture assessment or control local network segmentation before access is granted.
Based on the exhibit, which data protection control best allows analysts to work with the records without exposing full card numbers?
A.Encrypt the entire analytics database and give the team the decryption key.
B.Tokenize the card numbers and keep the token mapping in a secured vault.
C.Hash the card numbers with SHA-256 so the analytics team can reverse them later if needed.
D.Delete all but the last four digits from the production database immediately.
AnswerB
Tokenization replaces sensitive card numbers with non-sensitive substitutes that can still support joins and repeated reporting without revealing the original values. Keeping the mapping in a secured vault protects the real numbers while allowing the analytics team to work with consistent placeholders. This fits the business need much better than simple encryption or masking alone.
Why this answer
Tokenization replaces sensitive card numbers with non-sensitive placeholders (tokens) that retain the format and length of the original data but have no exploitable value. The analytics team can work with the tokens for reporting and analysis, while the actual card numbers remain securely stored in a separate token vault, preventing exposure even if the analytics database is compromised.
Exam trap
CompTIA often tests the misconception that encryption is always the best data protection control, but the trap here is that encryption still exposes the data to anyone with the key, whereas tokenization removes the sensitive data from the working environment entirely, making it the correct choice for analytics without exposure.
How to eliminate wrong answers
Option A is wrong because encrypting the entire database and giving the team the decryption key would expose the full card numbers to anyone with the key, defeating the purpose of protecting the data during analysis. Option C is wrong because SHA-256 is a one-way hash function that cannot be reversed; the claim that the team can 'reverse them later' is technically impossible, and hashing does not preserve the format needed for analytics. Option D is wrong because deleting all but the last four digits from the production database is a destructive action that permanently loses data and does not allow the team to work with the full card numbers for any legitimate analysis that requires the complete value.
Based on the exhibit, which artifact is the strongest evidence that the firewall change was reviewed and approved before implementation?
A.The engineer's post-implementation email, because it confirms someone checked the change.
B.The firewall logs, because they show the rule was applied successfully on the device.
C.The change request record with CAB approval timestamp and implementation time.
D.The vendor's maintenance notice, because it explains why the rule was needed.
AnswerC
This is the best evidence because it shows formal review and approval occurred before the change was implemented. Auditors want controlled, time-stamped proof of authorization, not just technical confirmation that the firewall rule changed or an informal email afterward. The change record directly supports compliance with change management requirements.
Why this answer
The change request record with a CAB approval timestamp and implementation time provides a clear, auditable trail that the firewall change was formally reviewed and authorized by the Change Advisory Board before it was executed. This aligns with the change management process required for security program oversight, ensuring that changes are not implemented without proper governance.
Exam trap
The trap here is that candidates often confuse post-implementation verification (Option A) or technical success logs (Option B) with the governance requirement for pre-approval, which is the core of change management oversight.
How to eliminate wrong answers
Option A is wrong because a post-implementation email only confirms that someone checked the change after it was made, not that it was reviewed and approved before implementation. Option B is wrong because firewall logs show the rule was applied successfully on the device, but they do not provide any evidence of pre-approval or review by a change board. Option D is wrong because a vendor's maintenance notice explains the technical need for the rule but does not document any internal review or approval process.
A customer portal must keep operating if one application server fails and also remain available if an entire site goes offline. Management is willing to pay more for automatic failover and the shortest possible interruption. Which design is best?
A.An active-active deployment across two sites with load balancing and replicated data.
B.A cold site that restores from nightly backups after a failure.
C.A single active site with one standby server in the same rack.
D.RAID 1 on the database server with no additional redundancy.
AnswerA
An active-active deployment across two sites uses load balancers to distribute traffic to both locations, with data continuously replicated between sites. If one site fails, the load balancer instantly shifts all traffic to the surviving site, and because both are actively serving, failover requires no startup time. This architecture achieves near-zero RPO and RTO, but demands careful session management (e.g., sticky sessions or distributed caching) and conflict resolution for replicated writes, adding complexity and cost.
Why this answer
An active-active deployment across two sites with load balancing and replicated data ensures continuous operation if one application server fails and also if an entire site goes offline. Load balancers distribute traffic to healthy servers, and synchronous data replication keeps both sites consistent, enabling automatic failover with minimal interruption. This design meets the requirement for the shortest possible interruption because failover is instantaneous and does not require manual intervention or data restoration.
Exam trap
The trap here is that candidates often confuse high availability within a single site (like a standby server in the same rack) with disaster recovery across sites, failing to recognize that site-level failures require geographic redundancy, not just server-level redundancy.
How to eliminate wrong answers
Option B is wrong because a cold site that restores from nightly backups after a failure introduces significant downtime (hours or days) for restoration and does not provide automatic failover or the shortest possible interruption. Option C is wrong because a single active site with one standby server in the same rack cannot survive an entire site outage, as both servers are in the same physical location and share the same site-level risks (e.g., power failure, natural disaster). Option D is wrong because RAID 1 on the database server provides only local disk redundancy within a single server, not application-level failover or site-level availability, and does not address server or site failures.
A company wants to make sure only approved administrators can view and rotate a shared encryption secret used by several applications. What is the best way to manage that secret?
A.Store it in a shared spreadsheet
B.Put it directly in application source code
C.Use a centralized secrets vault or key management system
D.Email the secret only to trusted administrators
AnswerC
A centralized secrets vault or key management system is the best choice because it stores sensitive keys in a controlled place with restricted access, auditing, and rotation support. That makes it easier to limit who can view the secret, track use, and update it safely across multiple applications. It is far more secure than embedding the secret in code or sharing it manually.
Why this answer
A centralized secrets vault or key management system (KMS) like HashiCorp Vault or AWS KMS provides role-based access control (RBAC), audit logging, and automatic rotation of secrets. This ensures only approved administrators can view and rotate the shared encryption secret, while applications retrieve it via secure APIs without exposing it in code or files.
Exam trap
The trap here is that candidates may think a spreadsheet or source code is acceptable for small teams, but CompTIA emphasizes that any secret shared across applications must be centrally managed with access controls and rotation capabilities to meet security best practices.
How to eliminate wrong answers
Option A is wrong because storing a shared encryption secret in a shared spreadsheet offers no access controls, no audit trail, and no rotation mechanism, making it vulnerable to unauthorized access and leakage. Option B is wrong because putting the secret directly in application source code exposes it to anyone with code access, violates the principle of least privilege, and makes rotation impossible without redeploying the application.
A manager can access the HR portal normally from a managed laptop, but if they sign in from an unmanaged tablet, the system should require extra verification before granting access. Which control best fits?
A.Conditional access based on device trust or risk.
B.A longer password expiration interval.
C.A separate VLAN for each manager.
D.Data encryption at rest on the HR database.
AnswerA
This is the best answer because conditional access can change authentication requirements depending on the device or sign-in context. A managed laptop can be allowed normally, while an unmanaged tablet can trigger extra verification such as MFA or access restrictions. That lets the organization balance usability and security instead of using the same rule for every login.
Why this answer
Conditional access policies evaluate device trust (e.g., compliance with security baselines, domain membership) and risk signals (e.g., location, sign-in behavior) to enforce step-up authentication. This directly matches the requirement: allow normal access from a managed laptop, but require extra verification from an unmanaged tablet. Other options like password expiration, VLAN segmentation, or encryption do not dynamically adjust authentication requirements based on device trust.
Exam trap
The trap here is that candidates often confuse data protection controls (encryption, VLANs) with access control mechanisms, failing to recognize that conditional access is the only option that dynamically adjusts authentication requirements based on device trust or risk.
How to eliminate wrong answers
Option B is wrong because a longer password expiration interval does not differentiate between managed and unmanaged devices; it applies uniformly to all users regardless of device trust. Option C is wrong because a separate VLAN for each manager provides network segmentation but does not enforce extra verification based on device trust or risk at the authentication layer. Option D is wrong because data encryption at rest protects stored data on the HR database but does not control access decisions or require additional authentication based on the device used to sign in.
Which four of the following are essential considerations when designing a secure cloud architecture in a hybrid environment? (Choose four.)
Select 4 answers
.Ensuring data encryption both at rest and in transit between cloud and on-premises resources
.Using a shared secret key for all API authentication to simplify integration
.Implementing a cloud access security broker (CASB) to enforce security policies
.Configuring identity federation with single sign-on (SSO) for centralized access control
.Placing all cloud resources in a single availability zone to reduce latency
.Applying least privilege principles to IAM roles and policies
Why this answer
Ensuring data encryption both at rest and in transit is critical in a hybrid environment to protect sensitive data from exposure during movement between cloud and on-premises resources and while stored. This includes using TLS 1.2/1.3 for data in transit and AES-256 for data at rest, addressing compliance requirements and mitigating interception risks.
Exam trap
The trap here is that candidates may think a shared secret key simplifies integration and is secure, but the SY0-701 exam emphasizes that shared secrets lack granularity and rotation capabilities, making them a security risk in hybrid environments.