CompTIA Security+ (SY0-701) Exam

00

hours hour

00

minutes minute

00

seconds second

Question 1 of 50

You are a security administrator for a medium-sized bank. You have discovered a piece of software on your bank’s database server that is not supposed to be there. It appears that the software will begin deleting database files if a specific employee is terminated. What best describes this?

Question 2 of 50

Frank is deeply concerned about attacks to his company’s e-commerce server. He is particularly worried about cross-site scripting and SQL injection. Which of the following would best defend against these two specific attacks?

Question 3 of 50

Mike is concerned about data sovereignty for data that his organization captures and maintains. What best describes his concern?

Question 4 of 50

What is the primary threat model against SMS codes used for multifactor authentication

Question 5 of 50

Bart wants to ensure that the files he encrypts remain secure for as long as possible. What should Bart do to maximize the longevity of his encrypted file’s security?

Question 6 of 50

Nadine’s organization stores and uses sensitive information, including Social Security numbers. After a recent compromise, she has been asked to implement technology that can help prevent this sensitive data from leaving the company’s systems and networks. What type of technology should Nadine implement?

Question 7 of 50

Social login, the ability to use an existing identity from a site like Google, Facebook, or a Microsoft account, is an example of which of the following concepts?

Question 8 of 50

Which of the following is NOT a common part of a cleanup process after a penetration test?

Question 9 of 50

What is the primary difference between active and passive reconnaissance?

Question 10 of 50

During a meeting, you present management with a list of access controls used on your network. Which of the following controls is an example of a corrective control?

Question 11 of 50

James is a security administrator and is attempting to block unauthorized access to the desktop computers within the company’s network. He has configured the computers’ operating systems to lock after 5 minutes of no activity. What type of security control has James implemented?

Question 12 of 50

What term is used to describe a listing of all of an organization’s risks, including information about the risk’s rating, how it is being remediated, remediation status, and who owns or is assigned responsibility for the risk?

Question 13 of 50

Which of the following terms is used to measure how reliable a system or device is?

Question 14 of 50

Ian needs to connect to a system via an encrypted channel so that he can use a command-line shell. What protocol should he use?

Question 15 of 50

Greg is setting up a public key infrastructure (PKI). He creates an offline root certificate authority (CA) and then needs to issue certificates to users and devices. What system or device in a PKI receives certificate signing requests (CSRs) from applications, systems, and users?

Question 16 of 50

Amanda discovers that a member of her organization’s staff has installed a remote access Trojan on their accounting software server and has been accessing it remotely. What type of threat has she discovered?

Question 17 of 50

Elizabeth is investigating a network breach at her company. She discovers a program that was able to execute code within the address space of another process by using the target process to load a specific library. What best describes this attack?

Question 18 of 50

Angela reviews the authentication logs for her website and sees attempts from many different accounts using the same set of passwords. What is this attack technique called?

Question 19 of 50

When investigating breaches and attempting to attribute them to specific threat actors, which of the following is NOT one of the indicators of an APT?

Question 20 of 50

Charles discovers that an attacker has used a vulnerability in a web application that his company runs and has then used that exploit to obtain root privileges on the web server. What type of technique has he discovered?

Question 21 of 50

Which of the following terms describes the process of improving security in an operating system?

Question 22 of 50

Gurvinder’s corporate datacenter is located in an area that FEMA has identified as being part of a 100-year flood plain. He knows that there is a chance in any given year that his datacenter could be completely flooded and underwater, and he wants to ensure that his organization knows what to do if that happens. What type of plan should he write?

Question 23 of 50

Jill has been asked to perform data recovery due to her forensic skills. What should she tell the person asking to perform data recovery to give her the best chance of restoring lost files that were accidentally deleted?

Question 24 of 50

Bart is investigating an incident, and needs to identify the creator of a Microsoft Office document. Where would he find that type of information?

Question 25 of 50

Madhuri has configured a backup that will back up all of the changes to a system since the last time that a full backup occurred. What type of backup has she set up?

Question 26 of 50

What is the point where false acceptance rate and false rejection rate are the same in a biometric system?

Question 27 of 50

Nathaniel wants to improve the fault tolerance of a server in his datacenter. If he wants to ensure that a power outage does not cause the server to lose power, what is the first control he should deploy from the following list?

Question 28 of 50

Which of the following is the best description of a stored procedure?

Question 29 of 50

You are a network security administrator for a bank. You discover that an attacker has exploited a flaw in OpenSSL and forced some connections to move to a weak cipher suite version of TLS, which the attacker could breach. What type of attack was this?

Question 30 of 50

John is running an IDS on his network. Users sometimes report that the IDS flags legitimate traffic as an attack. What describes this?

Question 31 of 50

Mary has discovered that a web application used by her company does not always handle multithreading properly, particularly when multiple threads access the same variable. This could allow an attacker who discovered this vulnerability to exploit it and crash the server. What type of error has Mary discovered?

Question 32 of 50

An OpenVAS scan shows that the database service PostGreSQL has the password "postgres" set. What is this misconfiguration?

Question 33 of 50

What term describes using conversational tactics as part of a social engineering exercise to extract information from targets?

Question 34 of 50

Cheryl is responsible for cybersecurity at a mid-sized insurance company. She has decided to use a different vendor for network antimalware than she uses for host antimalware. Is this a recommended action, and why or why not?

Question 35 of 50

Naomi wants to hire a third-party secure data destruction company. What process is most frequently used to ensure that third parties properly perform data destruction?

Question 36 of 50

Amanda wants to use a digital signature on an email she is sending to Maria. Which key should she use to sign the email?

Question 37 of 50

What cryptographic capability ensures that even if the server’s private key is compromised, the session keys will not be compromised?

Question 38 of 50

Geoff wants to establish a contract with a company to have datacenter space that is equipped and ready to go so that he can bring his data to the location in the event of a disaster. What type of disaster recovery site is he looking for?

Question 39 of 50

Which multifactor authentication can suffer from problems if the system or device’s time is not correct?

Question 40 of 50

What component is most often used as the foundation for a hardware root of trust for a modern PC?

Question 41 of 50

Waleed’s organization uses a combination of internally developed and commercial applications that they deploy to mobile devices used by staff throughout the company. What type of tool can he use to handle a combination of bring-your-own-device phones and corporate tablets that need to have these applications loaded onto them and removed from them when their users are no longer part of the organization?

Question 42 of 50

Sharif uses the chmod command in Linux to set the permissions to a file using the command chmod 700 example.txt. What permission has he set on the file?

Question 43 of 50

Patrick regularly connects to untrusted networks when he travels and is concerned that an on-path attack could be executed against him as he browses websites. He would like to validate certificates against known certificates for those websites. What technique can he use to do this?

Question 44 of 50

Isaac has discovered that his organization’s financial accounting software was misconfigured by the vendor, before the organization started to use it. What type of risk is this?

Question 45 of 50

Kirk’s organization has been experiencing large-scale denial-of-service (DoS) attacks against their primary website. Kirk contracts with his Internet service provider to increase the organization’s bandwidth and expands the server pool for the website to handle significantly more traffic than any of the previous DoS attacks. What type of risk management strategy has he employed?

Question 46 of 50

Chris wants to limit who can use an API that his company provides and be able to log usage of the API uniquely to each organization that they provide access to. What solution is most often used to do this?

Question 47 of 50

Gerard is responsible for secure communications with his company’s e-commerce server. All communications with the server use TLS. What is the most secure option for Gerard to store the private key on the e-commerce server?

Question 48 of 50

Irene wants to use a cloud service for her organization that does not require her to do any coding or system administration, and she wants to do minimal configuration to perform the tasks that her organization needs to accomplish. What type of cloud service is she most likely looking for?

Question 49 of 50

You are responsible for server room security for your company. You are concerned about physical theft of the computers. Which of the following would be best able to detect theft or attempted theft?

Question 50 of 50

Rick believes that Windows systems in his organization are being targeted by fileless viruses. If he wants to capture artifacts of their infection process, which of the following options is most likely to provide him with a view into what they are doing?