SY0-701 Study Guide Questions with Correct
Answers
A security team is reviewing the findings in a report that was delivered after a third
party performed a penetration test. One of the findings indicated that a web application
form field is vulnerable to cross-site scripting. Which of the following application
security techniques should the security analyst recommend the developer implement to
prevent this vulnerability?
A Secure cookies
B Version control
C Input validation
D Code signing
C. Input validation
Which of the following would help ensure a security analyst is able to accurately
measure the overall risk to an organization when a new vulnerability is disclosed?
A. A full inventory of all hardware and software
B. Documentation of system classifications
C. A list of system owners and their departments
D. Third-party risk assessment documentation
A. A full inventory of all hardware and software
An analyst is evaluating the implementation of Zero Trust principles within the data
plane. Which of the following would be most relevant for the analyst to evaluate?
,A. Secured zones
B. Subject role
C. Adaptive identity
D. Threat scope reduction
A. Secured zones
A newly appointed board member with cybersecurity knowledge wants the board of
directors to receive a quarterly report detailing the number of incidents that impacted
the organization. The systems administrator is creating a way to present the data to the
board of directors. Which of the following should the systems administrator use?
A Packet captures
B Vulnerability scans
C Metadata
D Dashboard
d. dashboard
Visitors to a secured facility are required to check in with a photo ID and enter the
facility through an access control vestibule. Which of the following best describes this
form of security control?
A Physical
B Managerial
C Technical
D Operational
A. Physical
,A company is expanding its threat surface program and allowing individuals to security
test the company's internet-facing application. The company will compensate
researchers based on the vulnerabilities discovered. Which of the following best
describes the program the company is setting up?
A. Open-source intelligence
B. Bug bounty
C. Red team
D. Penetration testing
B. Bug bounty
One of a company's vendors sent an analyst a security bulletin that recommends a
BIOS update. Which of the following vulnerability types is being addressed by the
patch?
A. Virtualization
B. Firmware
C. Application
D. Operating system
B. Firmware
Which of the following involves an attempt to take advantage of database
misconfigurations?
A Buffer overflow
B SQL injection
, C VM escape
D Memory injection
B. SQL injection
The management team notices that new accounts that are set up manually do not
always have correct access or permissions.
Which of the following automation techniques should a systems administrator use to
streamline account creation?
A Guard rail script
B Ticketing workflow
C Escalation script
D User provisioning script
D. User provisioning script
The local administrator account for a company's VPN appliance was unexpectedly used
to log in to the remote management interface. Which of the following would have most
likely prevented this from happening?
A Using least privilege
B Changing the default password
C Assigning individual user IDs
D Reviewing logs more frequently
B. Changing the default password
Answers
A security team is reviewing the findings in a report that was delivered after a third
party performed a penetration test. One of the findings indicated that a web application
form field is vulnerable to cross-site scripting. Which of the following application
security techniques should the security analyst recommend the developer implement to
prevent this vulnerability?
A Secure cookies
B Version control
C Input validation
D Code signing
C. Input validation
Which of the following would help ensure a security analyst is able to accurately
measure the overall risk to an organization when a new vulnerability is disclosed?
A. A full inventory of all hardware and software
B. Documentation of system classifications
C. A list of system owners and their departments
D. Third-party risk assessment documentation
A. A full inventory of all hardware and software
An analyst is evaluating the implementation of Zero Trust principles within the data
plane. Which of the following would be most relevant for the analyst to evaluate?
,A. Secured zones
B. Subject role
C. Adaptive identity
D. Threat scope reduction
A. Secured zones
A newly appointed board member with cybersecurity knowledge wants the board of
directors to receive a quarterly report detailing the number of incidents that impacted
the organization. The systems administrator is creating a way to present the data to the
board of directors. Which of the following should the systems administrator use?
A Packet captures
B Vulnerability scans
C Metadata
D Dashboard
d. dashboard
Visitors to a secured facility are required to check in with a photo ID and enter the
facility through an access control vestibule. Which of the following best describes this
form of security control?
A Physical
B Managerial
C Technical
D Operational
A. Physical
,A company is expanding its threat surface program and allowing individuals to security
test the company's internet-facing application. The company will compensate
researchers based on the vulnerabilities discovered. Which of the following best
describes the program the company is setting up?
A. Open-source intelligence
B. Bug bounty
C. Red team
D. Penetration testing
B. Bug bounty
One of a company's vendors sent an analyst a security bulletin that recommends a
BIOS update. Which of the following vulnerability types is being addressed by the
patch?
A. Virtualization
B. Firmware
C. Application
D. Operating system
B. Firmware
Which of the following involves an attempt to take advantage of database
misconfigurations?
A Buffer overflow
B SQL injection
, C VM escape
D Memory injection
B. SQL injection
The management team notices that new accounts that are set up manually do not
always have correct access or permissions.
Which of the following automation techniques should a systems administrator use to
streamline account creation?
A Guard rail script
B Ticketing workflow
C Escalation script
D User provisioning script
D. User provisioning script
The local administrator account for a company's VPN appliance was unexpectedly used
to log in to the remote management interface. Which of the following would have most
likely prevented this from happening?
A Using least privilege
B Changing the default password
C Assigning individual user IDs
D Reviewing logs more frequently
B. Changing the default password