CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 22)

An employee who was working remotely lost a mobile device containing company data.
Which of the following provides the best solution to prevent future data loss?

  1. MDM
  2. DLP
  3. FDE
  4. EDR

Answer(s): A

Explanation:

MDM allows an organization to remotely manage, monitor, and secure mobile devices used by employees, especially when they contain company data. With MDM, administrators can enforce security policies, remotely lock or wipe lost or stolen devices, and ensure compliance with data protection policies, thereby mitigating the risk of data loss.



An IT administrator needs to ensure data retention standards are implemented on an enterprise application.
Which of the following describes the administrator’s role?

  1. Processor
  2. Custodian
  3. Privacy officer
  4. Owner

Answer(s): B

Explanation:

A custodian is responsible for the implementation and enforcement of data management policies, including data retention standards, on systems and applications. Custodians manage the technical aspects of data storage and maintenance according to the organization’s policies and standards, supporting the data owner’s requirements.



A company plans to secure its systems by:
-Preventing users from sending sensitive data over corporate email
-Restricting access to potentially harmful websites
Which of the following features should the company set up? (Choose two.)

  1. DLP software
  2. DNS filtering
  3. File integrity monitoring
  4. Stateful firewall
  5. Guardrails
  6. Antivirus signatures

Answer(s): A,B

Explanation:

DLP (Data Loss Prevention) software: DLP helps prevent users from sending sensitive data over corporate email by monitoring and controlling the flow of sensitive information. DNS filtering: DNS filtering restricts access to potentially harmful websites by blocking access to sites based on their domain names, helping to protect users from malicious or inappropriate content.



A company processes and stores sensitive data on its own systems.
Which of the following steps should the company take first to ensure compliance with privacy regulations?

  1. Implement access controls and encryption.
  2. Develop and provide training on data protection policies.
  3. Create incident response and disaster recovery plans.
  4. Purchase and install security software.

Answer(s): A



Which of the following cryptographic methods is preferred for securing communications with limited computing resources?

  1. Hashing algorithm
  2. Public key infrastructure
  3. Symmetric encryption
  4. Elliptic curve cryptography

Answer(s): C



A network administrator wants to ensure that network traffic is highly secure while in transit.
Which of the following actions best describes the actions the network administrator should take?

  1. Ensure that NAC is enforced on all network segments, and confirm that firewalls have updated policies to block unauthorized traffic.
  2. Ensure only TLS and other encrypted protocols are selected for use on the network, and only permit authorized traffic via secure protocols.
  3. Configure the perimeter IPS to block inbound HTTPS directory traversal traffic, and verify that signatures are updated on a daily basis.
    -D. Ensure the EDR software monitors for unauthorized applications that could be used by threat actors, and configure alerts for the security team.
    -

Answer(s): B

Explanation:

Using TLS and other encrypted protocols ensures that data is securely transmitted, protecting it from interception or eavesdropping. By restricting traffic to secure protocols, the administrator can maintain high security for data in transit across the network. This approach directly addresses securing network traffic rather than focusing solely on perimeter or endpoint security.



Which of the following definitions best describes the concept of log correlation?

  1. Combining relevant logs from multiple sources into one location
  2. Searching and processing data to identify patterns of malicious activity
  3. Making a record of the events that occur in the system
  4. Analyzing the log files of the system components

Answer(s): B

Explanation:

Log correlation involves analyzing and linking data from multiple sources to identify patterns, trends, or sequences of events that indicate potential security incidents or malicious activity. This process helps security teams detect complex threats that may not be evident from individual logs alone.



An enterprise security team is researching a new security architecture to better protect the company’s networks and applications against the latest cyberthreats. The company has a fully remote workforce. The solution should be highly redundant and enable users to connect to a VPN with an integrated, software-based firewall.
Which of the following solutions meets these requirements?

  1. IPS
  2. SIEM
  3. SASE
  4. CASB

Answer(s): C

Explanation:

SASE combines network and security functions, including VPN, software-based firewalls, secure web gateways, and more, into a single cloud-delivered service. It is well-suited for a fully remote workforce as it provides secure, scalable, and redundant access to company resources from any location, while protecting networks and applications against the latest cyberthreats.



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!