A company purchased cyber insurance to address items listed on the risk register. Which of the following strategies does this represent?
Answer(s): B
Which of the following is the most likely to be used to document risks, responsible parties, and thresholds?
Answer(s): C
HOTSPOT (Drag and Drop is not supported)You are a security administrator investigating a potential infection on a network.INSTRUCTIONSClick on each host and firewall. Review all logs to determine which host originated the infection and then identify if each remaining host is clean or infected.If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.Hot Area:
Answer(s): A
A systems administrator notices that the research and development department is not using the company VPN when accessing various company-related services and systems. Which of the following scenarios describes this activity?
Answer(s): D
Which of the following threat vectors is most commonly utilized by insider threat actors attempting data exfiltration?
Which of the following agreement types defines the time frame in which a vendor needs to respond?
Which of the following is a feature of a next-generation SIEM system?
To improve the security at a data center, a security administrator implements a CCTV system and posts several signs about the possibility of being filmed. Which of the following best describe these types of controls? (Choose two.)
Answer(s): B,F
Share your comments for CompTIA SY0-701 exam with other users:
What are incident response processes?Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident. Typical stages are:
Question 142:Correct answer: A — Determining the root cause of the incident The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence. Why the other options are less suitable: