CompTIA SY0-701 Exam Prep
CompTIA Security+ (Page 35 )

Updated On: 31-Aug-2026

Which of the following should be used to aggregate log data in order to create alerts and detect anomalous activity?

  1. SIEM
  2. WAF
  3. Network taps
  4. IDS

Answer(s): A

Explanation:

A SIEM solution collects and aggregates log data from various sources across the network, enabling real-time monitoring, correlation, and alerting on security events. It is designed to detect anomalous activity and provide insights into potential security incidents by analyzing patterns and behaviors across the log data.



Which of the following provides the best protection against unwanted or insecure communications to and from a device?

  1. System hardening
  2. Host-based firewall
  3. Intrusion detection system
  4. Anti-malware software

Answer(s): B

Explanation:

A host-based firewall monitors and controls incoming and outgoing network traffic on a specific device, based on predetermined security rules. It provides protection by blocking unauthorized or potentially harmful communications, ensuring that only trusted traffic can access the device. This helps prevent both inbound and outbound threats at the device level.



Which of the following is the primary purpose of a service that tracks log-ins and time spent using the service?

  1. Availability
  2. Accounting
  3. Authentication
  4. Authorization

Answer(s): B

Explanation:

Accounting involves tracking and recording user activities, such as log-ins and time spent using a service. This information can be used for auditing, billing, usage analysis, and ensuring compliance with policies. Accounting is one of the components of the AAA model (Authentication, Authorization, and Accounting).



An employee who was working remotely lost a mobile device containing company data.
Which of the following provides the best solution to prevent future data loss?

  1. MDM
  2. DLP
  3. FDE
  4. EDR

Answer(s): A

Explanation:

MDM allows an organization to remotely manage, monitor, and secure mobile devices used by employees, especially when they contain company data. With MDM, administrators can enforce security policies, remotely lock or wipe lost or stolen devices, and ensure compliance with data protection policies, thereby mitigating the risk of data loss.



An IT administrator needs to ensure data retention standards are implemented on an enterprise application.
Which of the following describes the administrator’s role?

  1. Processor
  2. Custodian
  3. Privacy officer
  4. Owner

Answer(s): B

Explanation:

A custodian is responsible for the implementation and enforcement of data management policies, including data retention standards, on systems and applications. Custodians manage the technical aspects of data storage and maintenance according to the organization’s policies and standards, supporting the data owner’s requirements.



Viewing page 35 of 198
Viewing questions 171 - 175 out of 985 questions


Post your Comments and Discuss CompTIA SY0-701 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!