CompTIA SY0-701 Exam Prep
CompTIA Security+ (Page 37 )

Updated On: 31-Aug-2026

An enterprise security team is researching a new security architecture to better protect the company’s networks and applications against the latest cyberthreats. The company has a fully remote workforce. The solution should be highly redundant and enable users to connect to a VPN with an integrated, software-based firewall.
Which of the following solutions meets these requirements?

  1. IPS
  2. SIEM
  3. SASE
  4. CASB

Answer(s): C

Explanation:

SASE combines network and security functions, including VPN, software-based firewalls, secure web gateways, and more, into a single cloud-delivered service. It is well-suited for a fully remote workforce as it provides secure, scalable, and redundant access to company resources from any location, while protecting networks and applications against the latest cyberthreats.



Which of the following is the best way to validate the integrity and availability of a disaster recovery site?

  1. Lead a simulated failover.
  2. Conduct a tabletop exercise.
  3. Periodically test the generators.
  4. Develop requirements for database encryption.

Answer(s): A

Explanation:

A simulated failover involves switching operations from the primary site to the disaster recovery site, testing the systems, applications, and processes in a real-world scenario. This approach validates that the disaster recovery site can support operations effectively, ensuring both integrity and availability in the event of an actual disaster.



Which of the following allows an exploit to go undetected by the operating system?

  1. Firmware vulnerabilities
  2. Side loading
  3. Memory injection
  4. Encrypted payloads

Answer(s): C

Explanation:

Memory injection techniques allow attackers to inject malicious code directly into a process's memory space, often bypassing traditional file-based detection methods. By operating in-memory, these exploits can evade detection by the operating system and avoid leaving traces on disk, making them harder for antivirus and other security software to identify.



A malicious insider from the marketing team alters records and transfers company funds to a personal account.
Which of the following methods would be the best way to secure company records in the future?

  1. Permission restrictions
  2. Hashing
  3. Input validation
  4. Access control list

Answer(s): A

Explanation:

Implementing strict permission restrictions ensures that users can only access the data and functions necessary for their specific roles. By limiting access rights, the company can reduce the risk of unauthorized modifications by restricting sensitive financial records to only those who absolutely need access. Additionally, permission restrictions allow for better monitoring and control over sensitive data, making it harder for malicious insiders to perform unauthorized actions.



An organization is required to provide assurance that its controls are properly designed and operating effectively.
Which of the following reports will best achieve the objective?

  1. Red teaming
  2. Penetration testing
  3. Independent audit
  4. Vulnerability assessment

Answer(s): C

Explanation:

An independent audit provides an unbiased assessment of the organization’s controls, verifying that they are properly designed and operating effectively. Such audits often result in formal reports, such as SOC (Service Organization Control) reports, which are specifically designed to give assurance to stakeholders regarding the effectiveness of controls.



Viewing page 37 of 198
Viewing questions 181 - 185 out of 985 questions


Post your Comments and Discuss CompTIA SY0-701 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!