SY0-701 Practice Questions with Correct
Answers
Which of the following would be the best way to handle a critical business application
that is running on a legacy server?
Hardening
An organization disabled unneeded services and placed a firewall in front of a business-
critical legacy system. Which of the following best describes the actions taken by the
organization?
Compensating Controls
A hacker gained access to a system via a phishing attempt that was a direct result of a
user clicking a suspicious link. The link laterally deployed ransomware, which laid
dormant for multiple weeks, across the network. Which of the following would have
mitigated the spread?
IPS
An analyst is evaluating the implementation of Zero Trust principles within the data
plane. Which of the following would be mot relevant for the analyst to evaluate?
Secure Zones
A company is planning to set up a SIEM system and assign an analyst to review the logs
on a weekly basis. Which of the following types of controls is the company setting up?
Detective
Which of the following security control types does an acceptable use policy best
represent?
Answers
Which of the following would be the best way to handle a critical business application
that is running on a legacy server?
Hardening
An organization disabled unneeded services and placed a firewall in front of a business-
critical legacy system. Which of the following best describes the actions taken by the
organization?
Compensating Controls
A hacker gained access to a system via a phishing attempt that was a direct result of a
user clicking a suspicious link. The link laterally deployed ransomware, which laid
dormant for multiple weeks, across the network. Which of the following would have
mitigated the spread?
IPS
An analyst is evaluating the implementation of Zero Trust principles within the data
plane. Which of the following would be mot relevant for the analyst to evaluate?
Secure Zones
A company is planning to set up a SIEM system and assign an analyst to review the logs
on a weekly basis. Which of the following types of controls is the company setting up?
Detective
Which of the following security control types does an acceptable use policy best
represent?