Free CompTIA SY0-701 Practice Questions 2026 - Page 16
A company wants to verify that the software the company is deploying came from the vendor the company purchased the software from. Which of the following is the best way for the company to confirm this information?
A. Validate the code signature.
B. Execute the code in a sandbox.
C. Search the executable for ASCII strings.
D. Generate a hash of the files.
Explanation:
A) Validate the code signature is the correct answer.
Code signing is a process where software vendors digitally sign their software using a private key. The corresponding public key is used to verify the signature. By validating the code signature, the company can:
Authenticate the source:
Confirm the software indeed came from the claimed vendor.
Ensure integrity:
Verify that the software has not been tampered with since it was signed by the vendor.
This provides a direct and reliable method to verify both the origin and integrity of the software.
Why the others are incorrect:
B) Execute the code in a sandbox:
Sandboxing is used to observe the behavior of software in an isolated environment (e.g., to detect malware). It does not verify the source of the software—only how it behaves.
C) Search the executable for ASCII strings:
This might reveal metadata or human-readable text (e.g., vendor names) but is easily spoofed and not a secure method for verification. Attackers can embed false information in malicious software.
D) Generate a hash of the files:
Hashing (e.g., SHA-256) can verify integrity (that the file hasn’t changed) if the company has a trusted hash provided by the vendor. However, it does not authenticate the source. If the company obtains the hash from an untrusted location (e.g., a compromised website), it could be misled. Code signing combines authentication and integrity.
Reference:
This question tests knowledge of Domain 3.2: Given a scenario, implement security hardening strategies and Domain 2.8: Summarize the basics of cryptographic concepts. Code signing is a industry-standard practice for verifying software provenance and is emphasized in the SY0-701 objectives for secure software deployment. It leverages public key infrastructure (PKI) to provide trust.
A small business uses kiosks on the sales floor to display product information for customers. A security team discovers the kiosks use end-of-life operating systems. Which of the following is the security team most likely to document as a security implication of the current architecture?
A. Patch availability
B. Product software compatibility
C. Ease of recovery
D. Cost of replacement
Explanation:
An end-of-life (EOL) or end-of-service-life (EOSL) operating system no longer receives security patches, updates, or vulnerability fixes from the vendor. This is the most critical security implication because it means any newly discovered vulnerabilities in the OS will remain unpatched, leaving the kiosks permanently exposed to exploits. Attackers often target EOL systems precisely because they know these vulnerabilities will never be fixed.
Why the others are incorrect:
B) Product software compatibility:
While compatibility might be a concern for functionality, it is not the primary security implication. The question specifically asks for a security implication, and the lack of patches is a direct and severe security risk.
C) Ease of recovery:
This refers to how quickly a system can be restored after a failure. While EOL systems might be harder to recover due to outdated drivers or lack of support, this is an operational concern, not the most direct security implication.
D) Cost of replacement:
This is a financial or business consideration. While upgrading from EOL systems incurs costs, the security team's focus in documentation would be on the risk (e.g., unpatched vulnerabilities), not the financial impact.
Reference:
This aligns with SY0-701 Objective 2.3 ("Explain security implications of embedded and specialized systems"). Kiosks are a type of specialized system, and using EOL software is a major vulnerability. The security implication of missing patches and the inability to remediate vulnerabilities is a core concept in risk management and is emphasized in frameworks like NIST SP 800-40 (Guide to Enterprise Patch Management Planning).
Which of the following exercises should an organization use to improve its incident response process?
A. Tabletop
B. Replication
C. Failover
D. Recovery
Explanation:
A tabletop exercise is a discussion-based session where members of the incident response (IR) team and other key stakeholders (e.g., management, legal, PR) walk through a simulated incident scenario. The goal is to review and validate the incident response plan, identify gaps or ambiguities in procedures, improve communication and coordination among teams, and ensure everyone understands their roles and responsibilities. This type of exercise is specifically designed to improve the process of incident response without the pressure of a real event.
Analysis of Incorrect Options:
B. Replication:
Replication refers to the process of copying data to a secondary location (e.g., for backups or disaster recovery). It is a technical capability for ensuring data availability but is not an exercise designed to improve human-driven processes like incident response.
C. Failover:
Failover is an automated process where operations are switched from a primary system to a redundant or standby system in the event of a failure. Like replication, this is a technical mechanism for maintaining availability and is part of disaster recovery planning, not an IR process improvement exercise.
D. Recovery:
Recovery is a phase within the incident response lifecycle (NIST SP 800-61) where systems are restored and returned to normal operation. It is an action taken during or after an incident, not an exercise used to practice and improve the overall response process.
Reference:
This question falls under Domain 4.0: Security Operations, specifically objective 4.4: Explain key aspects of the incident response process. Tabletop exercises are a core component of the Preparation phase of the incident response lifecycle. They are widely recommended by frameworks like NIST to ensure an organization is ready to handle a real incident effectively. Other exercise types include drills (focused on a specific task) and full-scale simulations, but tabletops are the most common for testing and improving the IR process.
Which of the following would be the best ways to ensure only authorized personnel can access a secure facility? (Select two).
A. Fencing
B. Video surveillance
C. Badge access
D. Access control vestibule
E. Sign-in sheet
F. Sensor
D. Access control vestibule
Explanation:
The question asks for the best ways to ensure only authorized personnel can access a facility. This requires controls that actively verify identity and authorization before granting access, preventing unauthorized "tailgating."
C. Badge access is correct.
This is a form of electronic access control. An ID badge (often with a smart chip or magnetic stripe) is a credential that positively identifies the holder. When scanned at a door, the system checks the credential against an authorization database to determine if the person is allowed entry at that time and location. This is a direct and effective method for ensuring only authorized personnel gain access.
D. Access control vestibule (Mantrap) is correct.
An access control vestibule is a physical security system with two interlocking doors. An individual must authenticate (e.g., with a badge) to enter the first door. Once inside the small vestibule, the first door must close and lock before the individual can be authenticated again to open the second door. This highly effective design ensures only one person can enter at a time and prevents tailgating (unauthorized individuals following an authorized person inside).
Why the other options are less effective for ensuring only authorized access:
A. Fencing:
Fencing is a good deterrent and delay mechanism, but it does not actively identify or authorize individuals. It is a perimeter control, not an access control.
B. Video surveillance:
Surveillance is a detective control. It records who accessed an area but does nothing to prevent unauthorized access in real-time. It is used for after-the-fact investigation.
E. Sign-in sheet:
This is an administrative control that relies on honesty and provides no verification. An unauthorized person can easily write a fake name. It offers no physical barrier to entry.
F. Sensor:
Sensors (e.g., motion, light, temperature) are typically detective or monitoring controls. They might alert to presence or an environmental change but cannot identify or authorize personnel to prevent entry.
Reference:
CompTIA Security+ SY0-701 Objective 2.5: "Explain the purpose of mitigation techniques used to secure the enterprise." This objective includes physical security controls like mantraps (access control vestibules) and electronic access systems (badge access) as key methods for protecting secure areas.
A new vulnerability enables a type of malware that allows the unauthorized movement of data from a system. Which of the following would detect this behavior?
A. Implementing encryption
B. Monitoring outbound traffic
C. Using default settings
D. Closing all open ports
Explanation:
The scenario describes malware that exfiltrates data, meaning it moves data out of the system without authorization. The most direct way to detect this behavior is by monitoring outbound traffic. Security tools like a firewall, intrusion detection system (IDS), or data loss prevention (DLP) system can analyze network traffic leaving the organization. They can detect anomalies such as:
Unusually large data transfers.
Data being sent to suspicious or unauthorized external IP addresses.
Traffic using non-standard ports or protocols for exfiltration.
Why not A?
Implementing encryption: Encryption protects the confidentiality of data by making it unreadable if intercepted. However, it does not detect the movement of data; encrypted data can still be exfiltrated without triggering an alert.
Why not C?
Using default settings: Default settings on systems and applications are often insecure and well-known to attackers. Using them might make a system more vulnerable to infection but does not help detect data exfiltration after the malware is already present.
Why not D?
Closing all open ports: While this is a good hardening practice to reduce the attack surface, it is often impractical (e.g., web servers need port 80/443 open). More importantly, sophisticated malware can use allowed ports (like HTTPS on port 443) to blend in with normal traffic. Closing ports is a preventive measure, not a detective one.
Reference:
Domain 4.3: "Given an incident, utilize appropriate data sources to support an investigation." Monitoring network traffic (especially outbound) is a primary data source for detecting indicators of compromise (IOCs), such as data exfiltration. This aligns with the Security+ objective of using continuous monitoring to identify malicious activity.
A network administrator deployed a DNS logging tool that togs suspicious websites that are visited and then sends a daily report based on various weighted metrics. Which of the following best describes the type of control the administrator put in place?
A. Preventive
B. Deterrent
C. Corrective
D. Detective
Explanation: The tool that the network administrator deployed is described as one that logs suspicious websites and sends a daily report based on various weighted metrics. This fits the description of a detective control. Detective controls are designed to identify and log security events or incidents after they have occurred. By analyzing these logs and generating reports, the tool helps in detecting potential security breaches, thus allowing for further investigation and response.
A systems administrator is working on a defense-in-depth strategy and needs to restrict activity from employees after hours. Which of the following should the systems administrator implement?
A. Role-based restrictions
B. Attribute-based restrictions
C. Mandatory restrictions
D. Time-of-day restrictions
Explanation: To restrict activity from employees after hours, the systems administrator should implement time-of-day restrictions. This method allows access to network resources to be limited to specific times, ensuring that employees can only access systems during approved working hours. This is an effective part of a defense-in-depth strategy to mitigate risks associated with unauthorized access during off-hours, which could be a time when security monitoring might be less stringent. Time-of-day restrictions: These control access based on the time of day, preventing users from logging in or accessing certain systems outside of designated hours. Role-based restrictions: Control access based on a user’s role within the organization. Attribute-based restrictions: Use various attributes (such as location, department, or project) to determine access rights. Mandatory restrictions: Typically refer to non-discretionary access controls, such as those based on government or organizational policy.
Which of the following types of identification methods can be performed on a deployed application during runtime?
A. Dynamic analysis
B. Code review
C. Package monitoring
D. Bug bounty
Explanation:
Dynamic analysis is a security testing method that involves examining an application while it is running (during runtime). This is done in an environment that simulates production, allowing testers to observe the application's behavior, interaction with other systems, and responses to various inputs without needing access to the underlying source code. This makes it ideal for analyzing deployed applications.
Why not B?
Code review is a static analysis technique where the application's source code is examined line by line. This process is performed before the application is compiled and deployed, not during runtime.
Why not C?
Package monitoring typically refers to watching software packages for updates or changes in a repository. While important for security (e.g., detecting vulnerable library versions), it is not a method for identifying vulnerabilities within the application's runtime behavior itself. It is a dependency management activity.
Why not D?
Bug bounty is a program that incentivizes external security researchers to find and report vulnerabilities in an application. While researchers often use dynamic analysis as a technique to find bugs in a deployed application, the bug bounty program itself is the framework or policy, not the specific identification method.
Reference:
Domain 4.2: "Explain the security implications of proper hardware, software, and data asset management." This domain covers concepts like application security testing. The distinction between Static Application Security Testing (SAST - e.g., code review) and Dynamic Application Security Testing (DAST - e.g., dynamic analysis) is a key objective. DAST is explicitly for testing running applications.
A security administrator needs a method to secure data in an environment that includes some form of checks so that the administrator can track any changes. Which of the following should the administrator set up to achieve this goal?
A. SPF
B. GPO
C. NAC
D. FIM
Explanation:
FIM (File Integrity Monitoring) is a security process and technology that continuously monitors and checks files for changes. It creates a cryptographic baseline of files (e.g., system files, configuration files, critical data) and then regularly compares the current state against this baseline to detect any unauthorized modifications. If a change occurs, FIM generates an alert, allowing the security administrator to track and investigate the alteration. This directly meets the requirement to "secure data" and "track any changes."
Why not A?
SPF (Sender Policy Framework): SPF is an email authentication method used to prevent email spoofing by verifying that incoming mail from a domain comes from an authorized IP address. It is unrelated to monitoring file changes or data integrity.
Why not B?
GPO (Group Policy Object): GPOs are used in Windows environments to manage user and computer configurations centrally. While they can enforce security settings (e.g., permissions), they do not inherently monitor or track changes to files over time.
Why not C?
NAC (Network Access Control): NAC solutions enforce security policies on devices attempting to access a network (e.g., checking for antivirus installation). NAC controls network access but does not monitor file integrity or track changes to data.
Reference:
Domain 2.4: "Explain the purpose of mitigation techniques used to secure the enterprise." FIM is a critical control for detecting unauthorized changes, often required by compliance standards (e.g., PCI DSS). It aligns with the SY0-701 focus on implementing monitoring and integrity checks to protect data and systems.
A company tested and validated the effectiveness of network security appliances within the corporate network. The IDS detected a high rate of SQL injection attacks against the company's servers, and the company's perimeter firewall is at capacity. Which of the following would be the best action to maintain security and reduce the traffic to the perimeter firewall?
A. Set the appliance to IPS mode and place it in front of the company firewall.
B. Convert the firewall to a WAF and use IPSec tunnels to increase throughput.
C. Set the firewall to fail open if it is overloaded with traffic and send alerts to the SIEM.
D. Configure the firewall to perform deep packet inspection and monitor TLS traffic.
Explanation: Given the scenario where an Intrusion Detection System (IDS) has detected a high rate of SQL injection attacks and the perimeter firewall is at capacity, the best action would be to set the appliance to Intrusion Prevention System (IPS) mode and place it in front of the company firewall. This approach has several benefits:
Intrusion Prevention System (IPS): Unlike IDS, which only detects and alerts on malicious activity, IPS can actively block and prevent those activities. Placing an IPS in front of the firewall means it can filter out malicious traffic before it reaches the firewall, reducing the load on the firewall and enhancing overall security. Reducing Traffic Load: By blocking SQL injection attacks and other malicious traffic before it reaches the firewall, the IPS helps maintain the firewall's performance and prevents it from becoming a bottleneck. Enhanced Security: The IPS provides an additional layer of defense, identifying and mitigating threats in real-time. Option B (Convert the firewall to a WAF and use IPSec tunnels) would not address the primary issue of reducing traffic to the firewall effectively. Option C (Set the firewall to fail open) would compromise security. Option D (Deep packet inspection) could be resourceintensive and might not alleviate the firewall capacity issue effectively.
| Page 16 out of 91 Pages |