CompTIA Security+ SY0-701 Dumps in PDF

Free CompTIA SY0-701 Real Questions (page: 91)

Which of the following objectives is best achieved by a tabletop exercise?

  1. Familiarizing participants with the incident response process
  2. Deciding red and blue team rules of engagement
  3. Quickly determining the impact of an actual security breach
  4. Conducting multiple security investigations in parallel

Answer(s): A

Explanation:

A tabletop exercise is a discussion-based exercise where participants walk through different scenarios to better understand and familiarize themselves with the incident response process. This type of exercise allows teams to review roles, procedures, and potential responses to various incidents in a low-stress environment, enhancing preparedness and coordination.



The private key for a website was stolen, and a new certificate has been issued.
Which of the following needs to be updated next?

  1. SCEP
  2. CRL
  3. OCSP
  4. CSR

Answer(s): B

Explanation:

The Certificate Revocation List (CRL) should be updated when a private key is compromised. The CRL is a list of certificates that have been revoked by the issuing Certificate Authority (CA) and are no longer trusted. Updating the CRL ensures that clients and systems know the previous certificate is no longer valid, preventing it from being trusted even if the key has been compromised.



Which of the following organizational documents is most often used to establish and communicate expectations associated with integrity and ethical behavior within an organization?

  1. AUP
  2. SLA
  3. EULA
  4. MOA

Answer(s): A

Explanation:

An Acceptable Use Policy (AUP) is commonly used to establish and communicate the organization’s expectations regarding acceptable behavior, integrity, and ethical conduct. It outlines guidelines for appropriate use of company resources and sets standards for employees to follow, promoting a secure and ethical work environment.



Which of the following explains how to determine the global regulations that data is subject to regardless of the country where the data is stored?

  1. Geographic dispersion
  2. Data sovereignty
  3. Geographic restrictions
  4. Data segmentation

Answer(s): B

Explanation:

Data sovereignty refers to the principle that data is subject to the laws and regulations of the country where it originated, regardless of where it is stored. This concept ensures that data complies with the legal requirements of its country of origin, even when stored or processed across borders.



An organization's web servers host an online ordering system. The organization discovers that the servers are vulnerable to a malicious JavaScript injection, which could allow attackers to access customer payment information.
Which of the following mitigation strategies would be most effective for preventing an attack on the organization's web servers? (Choose two.)

  1. Regularly updating server software and patches
  2. Implementing strong password policies
  3. Encrypting sensitive data at rest and in transit
  4. Utilizing a web-application firewall
  5. Performing regular vulnerability scans
  6. Removing payment information from the servers

Answer(s): A,D

Explanation:

Regularly updating server software and applying patches addresses known vulnerabilities, reducing the risk of exploitation through unpatched flaws.
A web-application firewall (WAF) is particularly effective against malicious injections, as it monitors and filters HTTP traffic to block injection attempts, such as JavaScript injections.
Together, these strategies provide robust protection against attacks targeting the web servers.



Which of the following tools is best for logging and monitoring in a cloud environment?

  1. IPS
  2. FIM
  3. NAC
  4. SIEM

Answer(s): D

Explanation:

A Security Information and Event Management (SIEM) system is best suited for logging and monitoring in a cloud environment. SIEM tools collect, aggregate, and analyze log data from multiple sources within the environment, providing real-time monitoring, alerts, and analysis of security events. This centralized approach helps identify potential security incidents across cloud resources effectively.



During a SQL update of a database, a temporary field that was created was replaced by an attacker in order to allow access to the system.
Which of the following best describes this type of vulnerability?

  1. Race condition
  2. Memory injection
  3. Malicious update
  4. Side loading

Answer(s): C



A group of developers has a shared backup account to access the source code repository.
Which of the following is best way to secure the backup account if there is an SSO failure?

  1. RAS
  2. EAP
  3. SAML
  4. PAM

Answer(s): D

Explanation:

Privileged Access Management (PAM) is the best way to secure shared, privileged accounts like a backup account, especially in cases of Single Sign-On (SSO) failure. PAM solutions provide strict controls over access to sensitive accounts, enforce logging and monitoring, and often include features like session recording and access expiration. This approach ensures that access to the backup account remains secure even when other authentication methods, like SSO, are unavailable.



Share your comments for CompTIA SY0-701 exam with other users:

A
AI Tutor Explanation
8/19/2026 12:31:46 PM

What are incident response processes?
Incident response processes are the organized steps an organization follows to identify, manage, and recover from a security incident.
Typical stages are:

  1. Preparation – Create policies, response plans, communication procedures, tools, backups, and training.
  2. Detection and analysis – Identify suspicious activity through alerts, logs, monitoring, or user reports, then determine whether an incident occurred and assess its scope.
  3. Containment – Limit the incident’s impact, such as isolating an affected system or blocking malicious traffic.
  4. Eradication – Remove the root cause, such as malware, compromised accounts, or unauthorized persistence.
  5. Recovery – Restore systems to normal operation, validate that they are secure, and monitor for recurrence.
  6. Lessons learned / post-incident activity – Document what happened, preserve evidence, update controls, and improve the response plan.

For the page’s Question 209, Detection is the first active response stage listed among the choices. However, many formal incident-response frameworks place Preparation before detection as part of the overall lifecycle.

A
AI Tutor Explanation
8/17/2026 10:31:48 AM

Question 142:
Correct answer: A — Determining the root cause of the incident
The post-incident review—also called a lessons-learned review—analyzes what happened and why. Determining the root cause helps the organization fix the underlying weakness and prevent recurrence.
Why the other options are less suitable:

  • B: Developing steps to mitigate risks — May result from the review, but mitigation planning is generally part of remediation and corrective action.
  • C: Validating evidence accuracy — Occurs during the investigation, before the post-incident review.
  • D: Reestablishing system configuration — This is part of recovery and restoration.

A useful sequence is:
  1. Investigate and validate evidence.
  2. Contain and eradicate the threat.
  3. Recover systems.
  4. Conduct a post-incident review, including root-cause analysis.

AI Tutor 👋 I’m here to help!