Which of the following data states applies to data that is being actively processed by a database server?
Answer(s): A
Data "in use" refers to data actively being accessed, processed, or modified by an application or system, such as a database server. This is distinct from data "at rest," which is stored but not actively accessed, and data "in transit," which is being transmitted over a network.
Which of the following architectures is most suitable to provide redundancy for critical business processes?
Answer(s): C
Cloud-native architectures are designed with scalability, redundancy, and resilience in mind. They leverage the distributed nature of cloud infrastructure, allowing for automatic failover, load balancing, and redundancy across multiple geographic regions. This ensures high availability and continuous operation for critical business processes, even in the event of hardware or regional failures.
After a security incident, a systems administrator asks the company to buy a NAC platform. Which of the following attack surfaces is the systems administrator trying to protect?
Answer(s): B
Network Access Control (NAC) platforms are primarily used to secure access to the organization's network, typically focusing on wired and wireless connections. By implementing NAC, the administrator can control which devices are allowed to connect to the network and enforce security policies, reducing the risk of unauthorized access via the wired network.
While reviewing logs, a security administrator identifies the following code:<script>function (send_info)</script>Which of the following best describes the vulnerability being exploited?
The <script> tags in the code suggest a Cross-Site Scripting (XSS) attack, where malicious scripts are injected into web pages viewed by other users. XSS vulnerabilities allow attackers to execute scripts in the context of a user's browser, which can lead to data theft, session hijacking, and other malicious actions.
An organization issued new laptops to all employees and wants to provide web filtering both in and out of the office without configuring additional access to the network. Which of the following types of web filtering should a systems administrator configure?
An agent-based web filtering solution installs a software agent directly on the laptops. This approach allows the filtering to work regardless of the device's location (in or out of the office) without requiring additional network configuration. The agent enforces web filtering policies locally on each laptop, ensuring consistent protection across various network environments.
Which of the following should be used to aggregate log data in order to create alerts and detect anomalous activity?
A SIEM solution collects and aggregates log data from various sources across the network, enabling real-time monitoring, correlation, and alerting on security events. It is designed to detect anomalous activity and provide insights into potential security incidents by analyzing patterns and behaviors across the log data.
Which of the following provides the best protection against unwanted or insecure communications to and from a device?
A host-based firewall monitors and controls incoming and outgoing network traffic on a specific device, based on predetermined security rules. It provides protection by blocking unauthorized or potentially harmful communications, ensuring that only trusted traffic can access the device. This helps prevent both inbound and outbound threats at the device level.
Which of the following is the primary purpose of a service that tracks log-ins and time spent using the service?
Accounting involves tracking and recording user activities, such as log-ins and time spent using a service. This information can be used for auditing, billing, usage analysis, and ensuring compliance with policies. Accounting is one of the components of the AAA model (Authentication, Authorization, and Accounting).
Share your comments for CompTIA SY0-701 exam with other users:
What are incident response processes?Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident. Typical stages are:
Question 142:Correct answer: A — Determining the root cause of the incident The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence. Why the other options are less suitable: