CompTIA SY0-701 Exam Prep
CompTIA Security+ (Page 32 )

Updated On: 31-Aug-2026

A security analyst is reviewing logs and discovers the following:

Which of the following should be used to best mitigate this type of attack?

  1. Input sanitization
  2. Secure cookies
  3. Static code analysis
  4. Sandboxing

Answer(s): A

Explanation:

Input sanitization ensures that any user-supplied data is properly filtered and cleaned before being processed by the application. By sanitizing inputs, the system can prevent malicious command injection attempts like the one shown in the log entry.



An administrator is installing an SSL certificate on a new system. During testing, errors indicate that the certificate is not trusted. The administrator has verified with the issuing CA and has validated the private key.
Which of the following should the administrator check for next?

  1. If the wildcard certificate is configured
  2. If the certificate signing request is valid
  3. If the root certificate is installed
  4. If the public key is configured

Answer(s): C

Explanation:

If the certificate is not trusted, it’s often because the root certificate (or intermediate certificate) from the issuing Certificate Authority (CA) is not installed or not recognized by the system. The root certificate verifies the chain of trust, and without it, the SSL certificate may not be trusted by the system or browser. Installing the root and any necessary intermediate certificates should resolve the trust issue.



An employee emailed a new systems administrator a malicious web link and convinced the administrator to change the email server’s password. The employee used this access to remove the mailboxes of key personnel.
Which of the following security awareness concepts would help prevent this threat in the future?

  1. Recognizing phishing
  2. Providing situational awareness training
  3. Using password management
  4. Reviewing email policies

Answer(s): A

Explanation:

In this scenario, the employee used a form of social engineering by sending a malicious link and persuading the administrator to take unauthorized actions. Training employees to recognize phishing attempts and other social engineering tactics would help them identify and avoid suspicious requests, reducing the likelihood of falling victim to similar threats in the future.



Which of the following strategies should an organization use to efficiently manage and analyze multiple types of logs?

  1. Deploy a SIEM solution
  2. Create custom scripts to aggregate and analyze logs.
  3. Implement EDR technology.
  4. Install a unified threat management appliance.

Answer(s): A

Explanation:

A Security Information and Event Management (SIEM) solution centralizes log collection, aggregation, and analysis from various sources. SIEMs provide real-time monitoring, correlation, and alerting on security events, enabling organizations to efficiently manage and analyze logs from diverse systems in a single platform. This approach is highly effective for identifying security incidents and ensuring compliance.



A new security regulation was announced that will take effect in the coming year. A company must comply with it to remain in business.
Which of the following activities should the company perform next?

  1. Gap analysis
  2. Policy review
  3. Security procedure evaluation
  4. Threat scope reduction

Answer(s): A

Explanation:

A gap analysis will help the company identify the differences between its current security practices and the requirements of the new regulation. This analysis provides a clear understanding of what needs to be addressed to achieve compliance, allowing the company to prioritize and implement necessary changes before the regulation takes effect.



Viewing page 32 of 198
Viewing questions 156 - 160 out of 985 questions


Post your Comments and Discuss CompTIA SY0-701 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!