لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
Which of the following best describes the risk present after controls and mitigating factors have been applied?
A. Residual
B. Avoided
C. Inherent
D. Operational
عرض الإجابة
اجابة صحيحة: A

View The Updated SY0-701 Exam Questions

SPOTO Provides 100% Real SY0-701 Exam Questions for You to Pass Your SY0-701 Exam!

السؤال #2
Which of the following teams is best suited to determine whether a company has systems that can be exploited by a potential, identified vulnerability?
A. Purple team
B. Blue team
C. Red team
D. White team
عرض الإجابة
اجابة صحيحة: C
السؤال #3
An organization maintains intellectual property that it wants to protect. Which of the following concepts would be most beneficial to add to the company's security awareness training program?
A. Insider threat detection
B. Simulated threats
C. Phishing awareness
D. Business continuity planning
عرض الإجابة
اجابة صحيحة: A
السؤال #4
A security administrator needs to create firewall rules for the following protocols: RTP, SIP, H.323. and SRTP.Which of the following does this rule set support?
A. RTOS
B. VoIP
C. SoC
D. HVAC
عرض الإجابة
اجابة صحيحة: B
السؤال #5
A security analyst is evaluating a SaaS application that the human resources department would like to implement. The analyst requests a SOC 2 report from the SaaS vendor. Which of the following processes is the analyst most likely conducting?
A. Internal audit
B. Penetration testing
C. Attestation
D. Due diligence
عرض الإجابة
اجابة صحيحة: D
السؤال #6
Which of the following activities would involve members of the incident response team and other stakeholders simulating an event?
A. Lessons learned
B. Digital forensics
C. Tabletop exercise
D. Root cause analysis
E. Reveal Answer
عرض الإجابة
اجابة صحيحة: C
السؤال #7
A Chief Information Security Officer would like to conduct frequent, detailed reviews of systems and proceduresto track compliance objectives. Which of the following will be the best method to achieve this objective?
A. Third-party attestation
B. Penetration testing
C. Internal auditing
D. Vulnerability scans
عرض الإجابة
اجابة صحيحة: C
السؤال #8
An administrator is installing an LDAP browser tool in order to view objects in the corporate LDAP directory. Secure connections to the LDAP server are required. When the browser connects to the server, certificate errors are being displayed, and then the connection is terminated. Which of the following is the most likely solution?
A. The administrator should allow SAN certificates in the browser configuration
B. The administrator needs to install the server certificate into the local truststore
C. The administrator should request that the secure LDAP port be opened to the server
D. The administrator needs to increase the TLS version on the organization's RA
عرض الإجابة
اجابة صحيحة: B
السؤال #9
Which of the following is the best resource to consult for information on the most common application exploitation methods?
A. OWASP
B. STIX
C. OVAL
D. Threat intelligence feed
E. Common Vulnerabilities and Exposures
عرض الإجابة
اجابة صحيحة: A
السؤال #10
A company is decommissioning its physical servers and replacing them with an architecture that will reduce the number of individual operating systems. Which of the following strategies should the company use to achieve this security requirement?
A. Microservices
B. Containerization
C. Virtualization
D. Infrastructure as code
عرض الإجابة
اجابة صحيحة: B
السؤال #11
After conducting a vulnerability scan, a systems administrator notices that one of the identified vulnerabilities is not present on the systems that were scanned. Which of the following describes this example?
A. False positive
B. False negative
C. True positive
D. True negative
عرض الإجابة
اجابة صحيحة: A
السؤال #12
A security analyst is reviewing the source code of an application in order to identify misconfigurations and vulnerabilities. Which of the following kinds of analysis best describes this review?
A. Dynamic
B. Static
C. Gap
D. Impact
عرض الإجابة
اجابة صحيحة: B
السؤال #13
A company installed cameras and added signs to alert visitors that they are being recorded. Which of the following controls did the company implement? (Choose two.)
A. Directive
B. Deterrent
C. Preventive
D. Detective
E. Corrective
F. Technical
عرض الإجابة
اجابة صحيحة: BD
السؤال #14
Which of the following agreement types defines the time frame in which a vendor needs to respond?
A. SOW
B. SLA
C. MOA
D. MOU
عرض الإجابة
اجابة صحيحة: B
السؤال #15
Which of the following would a systems administrator follow when upgrading the firmware of an organization's router?
A. Software development life cycle
B. Risk tolerance
C. Certificate signing request
D. Maintenance window
عرض الإجابة
اجابة صحيحة: D
السؤال #16
Which of the following concepts protects sensitive information from unauthorized disclosure?
A. vailability
B. ntegrity
C. uthentication
D. onfidentiality
عرض الإجابة
اجابة صحيحة: D
السؤال #17
A U.S.-based cloud-hosting provider wants to expand its data centers to new international locations.
A. Local data protection regulations
B. Risks from hackers residing in other countries
C. Impacts to existing contractual obligations
D. Time zone differences in log correlation
عرض الإجابة
اجابة صحيحة: A
السؤال #18
Which of the following scenarios describes a possible business email compromise attack?
A. An employee receives a gift card request in an email that has an executive’s name in the display field of the email
B. Employees who open an email attachment receive messages demanding payment in order to access files
C. A service desk employee receives an email from the HR director asking for log-in credentials to a cloud administrator account
D. An employee receives an email with a link to a phishing site that is designed to look like the company’s email portal
عرض الإجابة
اجابة صحيحة: C
السؤال #19
An enterprise is trying to limit outbound DNS traffic originating from its internal network. Outbound DNS requests will only be allowed from one device with the IP address 10.50.10.25. Which of the following firewall ACLs will accomplish this goal?
A. Access list outbound permit 0
B. Access list outbound permit 0
C. Access list outbound permit 0
D. Access list outbound permit 10
عرض الإجابة
اجابة صحيحة: D
السؤال #20
After creating a contract for IT contractors, the human resources department changed several clauses. The contract has gone through three revisions. Which of the following processes should the human resources department follow to track revisions?
A. Version validation
B. Version changes
C. Version updates
D. Version control
عرض الإجابة
اجابة صحيحة: D
السؤال #21
During an annual review of the system design, an engineer identified a few issues with the currently released design. Which of the following should be performed next according to best practices?
A. Risk management process
B. Product design process
C. Design review process
D. Change control process
عرض الإجابة
اجابة صحيحة: D
السؤال #22
An organization is adopting cloud services at a rapid pace and now has multiple SaaS applications in use. Each application has a separate log-in, so the security team wants to reduce the number of credentials each employee must maintain. Which of the following is the first step the security team should take?
A. Enable SAML
B. Create OAuth tokens
C. Use password vaulting
D. Select an IdP
عرض الإجابة
اجابة صحيحة: D
السؤال #23
Easy-to-guess passwords led to an account compromise. The current password policy requires at least 12 alphanumeric characters, one uppercase character, one lowercase character, a password history of two passwords, a minimum password age of one day, and a maximum password age of 90 days. Which of the following would reduce the risk of this incident from happening again? (Choose two.)
A. Increasing the minimum password length to 14 characters
B. Upgrading the password hashing algorithm from MD5 to SHA-512
C. Increasing the maximum password age to 120 days
D. Reducing the minimum password length to ten characters
E. Reducing the minimum password age to zero days
F. Including a requirement for at least one special character
عرض الإجابة
اجابة صحيحة: AF
السؤال #24
Which of the following is considered a preventive control?
A. Configuration auditing
B. Log correlation
C. Incident alerts
D. Segregation of duties
عرض الإجابة
اجابة صحيحة: D
السؤال #25
A security team has been alerted to a flood of incoming emails that have various subject lines and are addressed to multiple email inboxes. Each email contains a URL shortener link that is redirecting to a dead domain. Which of the following is the best step for the security team to take?
A. Create a blocklist for all subject lines
B. Send the dead domain to a DNS sinkhole
C. Quarantine all emails received and notify all employees
D. Block the URL shortener domain in the web proxy
عرض الإجابة
اجابة صحيحة: D
السؤال #26
Which of the following is the most important security concern when using legacy systems to provide production service?
A. Instability
B. Lack of vendor support
C. Loss of availability
D. Use of insecure protocols
عرض الإجابة
اجابة صحيحة: B
السؤال #27
A company web server is initiating outbound traffic to a low-reputation, public IP on non-standard pat. The web server is used to present an unauthenticated page to clients who upload images the company. An analyst notices a suspicious process running on the server hat was not created by the company development team. Which of the following is the most likely explanation for his security incident?
A. A web shell has been deployed to the server through the page
B. A vulnerability has been exploited to deploy a worm to the server
C. Malicious insiders are using the server to mine cryptocurrency
D. Attackers have deployed a rootkit Trojan to the server over an exposed RDP port
عرض الإجابة
اجابة صحيحة: A
السؤال #28
A company has a website in a server cluster. One server is experiencing very high usage, while others are nearly unused. Which of the following should the company configure to help distribute traffic quickly?
A. Server multiprocessing
B. Warm site
C. Load balancer
D. Proxy server
E. Reveal Answer
عرض الإجابة
اجابة صحيحة: C
السؤال #29
Which of the following environments utilizes a subset of customer data and is most likely to be used to assess the impacts of major system upgrades and demonstrate system features?
A. Development
B. Test
C. Production
D. Staging
E. Reveal Answer
عرض الإجابة
اجابة صحيحة: D
السؤال #30
A systems administrator deployed a monitoring solution that does not require installation on the endpoints that the solution is monitoring. Which of the following is described in this scenario?
A. Agentless solution
B. Client-based soon
C. Open port
D. File-based solution
عرض الإجابة
اجابة صحيحة: A
السؤال #31
Which of the following data roles is responsible for identifying risks and appropriate access to data?
A. Owner
B. Custodian
C. Steward
D. Controller
عرض الإجابة
اجابة صحيحة: A
السؤال #32
An organization is leveraging a VPN between its headquarters and a branch location. Which of the following is the VPN protecting?
A. Open-source intelligence
B. Penetration testing
C. Red team
D. Bug bounty
عرض الإجابة
اجابة صحيحة: B
السؤال #33
Which of the following examples would be best mitigated by input sanitization?
A.
B. nmap - 10
C. Email message: "Click this link to get your free gift card
D. Browser message: "Your connection is not private
عرض الإجابة
اجابة صحيحة: A
السؤال #34
While analyzing SIEM alerts for a company WAR an incident response analyst observes the following:https://corporate-A.com/loadimage?filename=../../../etc/https://corporate-A.com/loadimage?filename=../../../etc/passwdhttps://corporate-A.com/loadimage?filename=../../../etc/passwdWhich of the following best describes the observed behavior?
A. redential replay
B. irectory traversal
C. esource exhaustion
D. rute-force attack
عرض الإجابة
اجابة صحيحة: B
السؤال #35
Which of the following security concepts is being followed when implementing a product that offers protection against DDoS attacks?
A. Availability
B. Non-repudiation
C. Integrity
D. Confidentiality
عرض الإجابة
اجابة صحيحة: A
السؤال #36
Which of the following best protects sensitive data in transit across a geographically dispersed infrastructure?
A. bfuscation
B. ncryption
C. okenization
D. asking
عرض الإجابة
اجابة صحيحة: B
السؤال #37
Which of the following is a preventive physical security control?
A. Video surveillance system
B. Bollards
C. Alarm system
D. Motion sensors
عرض الإجابة
اجابة صحيحة: B

View The Updated CompTIA Exam Questions

SPOTO Provides 100% Real CompTIA Exam Questions for You to Pass Your CompTIA Exam!

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us