COMPTIA SECURITY+ SY0-701
CERTIFICATION EXAM – QUESTIONS AND
ANSWERS | VERIFIED AND WELL DETAILED
ANSWERS |
Question 1
Which of the following is the best reason to complete an audit in a banking
environment?
A. Regulatory requirement
B. Organizational change
C. Self-assessment requirement
D. Service-level requirement
Correct Answer
A. Regulatory requirement
Question 2
Which of the following would be the best way to block unknown programs from
executing?
A. Access control list
B. Application allow list.
C. Host-based firewall
D. DLP solution
Correct Answer
B. Application allow list.
Page 1 of 146
,Question 3
A security practitioner completes a vulnerability assessment on a company's network
and finds several vulnerabilities, which the operations team remediates. Which of the
following should be done next?
A. Conduct an audit.
B. Initiate a penetration test.
C. Rescan the network.
D. Submit a report.
Correct Answer
C. Rescan the network.
Question 4
NO.76 An engineer needs to find a solution that creates an added layer of security by
preventing unauthorized access to internal company resources. Which of the
following would be the best solution?
A. RDP server
B. Jump server
C. Proxy server
D. Hypervisor
Correct Answer
B. Jump server
Question 5
A security operations center determines that the malicious activity detected on a
server isnormal. Which of the following activities describes the act of ignoring
detected activity in the future?
A. Tuning
B. Aggregating
C. Quarantining
D. Archiving
Correct Answer
A. Tuning
Page 2 of 146
,Question 6
A company is adding a clause to its AUP that states employees are not allowed to
modify the operating system on mobile devices. Which of the following vulnerabilities
is the organization addressing?
A. Cross-site scripting
B. Buffer overflow
C. Jailbreaking
D. Side loading
Correct Answer
C. Jailbreaking
Page 3 of 146
, Question 7
An administrator is reviewing a single server's security logs and discovers the
following;
Which of the following best describes the action captured in this log file?
A. Brute-force attack
B. Privilege escalation
C. Failed password audit
D. Forgotten password by the user
Correct Answer
A. Brute-force attack
Question 1: A security analyst is reviewing logs from a web application firewall and
notices repeated attempts to inject SQL commands into a login form. The attempts
are coming from multiple IP addresses that appear to be part of a botnet. Which
of the following is the MOST appropriate immediate mitigation to protect the
application while a permanent fix is developed?
A. Disable the login form entirely until the code is rewritten
B. Implement input validation and parameterized queries on the application side
and block the offending IP ranges at the WAF
C. Switch the application to HTTP only to reduce encrypted attack traffic
D. Increase the session timeout values to make brute-force attempts less effective
CORRECT ANSWER: B. Implement input validation and parameterized queries
on the application side and block the offending IP ranges at the WAF
Rationale: Parameterized queries and proper input validation are the definitive
controls against SQL injection. Temporary IP blocking at the WAF provides
immediate protection while the code-level fix is deployed.
Question 2: During a routine vulnerability scan, an organization discovers that
several Windows servers still have SMBv1 enabled. Which of the following
threats is MOST directly associated with this configuration?
A. Pass-the-hash attacks using Kerberos tickets
B. Exploitation via EternalBlue and similar ransomware propagation methods
C. Cross-site scripting against web services running on the servers
Page 4 of 146
CERTIFICATION EXAM – QUESTIONS AND
ANSWERS | VERIFIED AND WELL DETAILED
ANSWERS |
Question 1
Which of the following is the best reason to complete an audit in a banking
environment?
A. Regulatory requirement
B. Organizational change
C. Self-assessment requirement
D. Service-level requirement
Correct Answer
A. Regulatory requirement
Question 2
Which of the following would be the best way to block unknown programs from
executing?
A. Access control list
B. Application allow list.
C. Host-based firewall
D. DLP solution
Correct Answer
B. Application allow list.
Page 1 of 146
,Question 3
A security practitioner completes a vulnerability assessment on a company's network
and finds several vulnerabilities, which the operations team remediates. Which of the
following should be done next?
A. Conduct an audit.
B. Initiate a penetration test.
C. Rescan the network.
D. Submit a report.
Correct Answer
C. Rescan the network.
Question 4
NO.76 An engineer needs to find a solution that creates an added layer of security by
preventing unauthorized access to internal company resources. Which of the
following would be the best solution?
A. RDP server
B. Jump server
C. Proxy server
D. Hypervisor
Correct Answer
B. Jump server
Question 5
A security operations center determines that the malicious activity detected on a
server isnormal. Which of the following activities describes the act of ignoring
detected activity in the future?
A. Tuning
B. Aggregating
C. Quarantining
D. Archiving
Correct Answer
A. Tuning
Page 2 of 146
,Question 6
A company is adding a clause to its AUP that states employees are not allowed to
modify the operating system on mobile devices. Which of the following vulnerabilities
is the organization addressing?
A. Cross-site scripting
B. Buffer overflow
C. Jailbreaking
D. Side loading
Correct Answer
C. Jailbreaking
Page 3 of 146
, Question 7
An administrator is reviewing a single server's security logs and discovers the
following;
Which of the following best describes the action captured in this log file?
A. Brute-force attack
B. Privilege escalation
C. Failed password audit
D. Forgotten password by the user
Correct Answer
A. Brute-force attack
Question 1: A security analyst is reviewing logs from a web application firewall and
notices repeated attempts to inject SQL commands into a login form. The attempts
are coming from multiple IP addresses that appear to be part of a botnet. Which
of the following is the MOST appropriate immediate mitigation to protect the
application while a permanent fix is developed?
A. Disable the login form entirely until the code is rewritten
B. Implement input validation and parameterized queries on the application side
and block the offending IP ranges at the WAF
C. Switch the application to HTTP only to reduce encrypted attack traffic
D. Increase the session timeout values to make brute-force attempts less effective
CORRECT ANSWER: B. Implement input validation and parameterized queries
on the application side and block the offending IP ranges at the WAF
Rationale: Parameterized queries and proper input validation are the definitive
controls against SQL injection. Temporary IP blocking at the WAF provides
immediate protection while the code-level fix is deployed.
Question 2: During a routine vulnerability scan, an organization discovers that
several Windows servers still have SMBv1 enabled. Which of the following
threats is MOST directly associated with this configuration?
A. Pass-the-hash attacks using Kerberos tickets
B. Exploitation via EternalBlue and similar ransomware propagation methods
C. Cross-site scripting against web services running on the servers
Page 4 of 146