CompTIA SY0-701 Exam Prep
CompTIA Security+ (Page 34 )

Updated On: 31-Aug-2026

Which of the following data states applies to data that is being actively processed by a database server?

  1. In use
  2. At rest
  3. In transit
  4. Being hashed

Answer(s): A

Explanation:

Data "in use" refers to data actively being accessed, processed, or modified by an application or system, such as a database server. This is distinct from data "at rest," which is stored but not actively accessed, and data "in transit," which is being transmitted over a network.



Which of the following architectures is most suitable to provide redundancy for critical business processes?

  1. Network-enabled
  2. Server-side
  3. Cloud-native
  4. Multitenant

Answer(s): C

Explanation:

Cloud-native architectures are designed with scalability, redundancy, and resilience in mind. They leverage the distributed nature of cloud infrastructure, allowing for automatic failover, load balancing, and redundancy across multiple geographic regions. This ensures high availability and continuous operation for critical business processes, even in the event of hardware or regional failures.



After a security incident, a systems administrator asks the company to buy a NAC platform.
Which of the following attack surfaces is the systems administrator trying to protect?

  1. Bluetooth
  2. Wired
  3. NFC
  4. SCADA

Answer(s): B

Explanation:

Network Access Control (NAC) platforms are primarily used to secure access to the organization's network, typically focusing on wired and wireless connections. By implementing NAC, the administrator can control which devices are allowed to connect to the network and enforce security policies, reducing the risk of unauthorized access via the wired network.



While reviewing logs, a security administrator identifies the following code:
<script>function (send_info)</script>
Which of the following best describes the vulnerability being exploited?

  1. XSS
  2. SQLi
  3. DDoS
  4. CSRF

Answer(s): A

Explanation:

The <script> tags in the code suggest a Cross-Site Scripting (XSS) attack, where malicious scripts are injected into web pages viewed by other users. XSS vulnerabilities allow attackers to execute scripts in the context of a user's browser, which can lead to data theft, session hijacking, and other malicious actions.



An organization issued new laptops to all employees and wants to provide web filtering both in and out of the office without configuring additional access to the network.
Which of the following types of web filtering should a systems administrator configure?

  1. Agent-based
  2. Centralized proxy
  3. URL scanning
  4. Content categorization

Answer(s): A

Explanation:

An agent-based web filtering solution installs a software agent directly on the laptops. This approach allows the filtering to work regardless of the device's location (in or out of the office) without requiring additional network configuration. The agent enforces web filtering policies locally on each laptop, ensuring consistent protection across various network environments.



Viewing page 34 of 198
Viewing questions 166 - 170 out of 985 questions


Post your Comments and Discuss CompTIA SY0-701 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!