CompTIA SY0-701 Exam Prep
CompTIA Security+ (Page 38 )

Updated On: 31-Aug-2026

A systems administrator successfully configures VPN access to a cloud environment.
Which of the following capabilities should the administrator use to best facilitate remote administration?

  1. A jump host in the shared services security zone
  2. An SSH server within the corporate LAN
  3. A reverse proxy on the firewall
  4. An MDM solution with conditional access

Answer(s): A

Explanation:

A jump host in a shared services security zone is specifically designed to provide secure access to remote environments, such as a cloud environment, while ensuring that access is monitored and controlled. This setup facilitates remote administration by providing a dedicated entry point, allowing administrators to access sensitive network areas through a secure, segmented pathway. This setup minimizes direct exposure to the cloud environment and enhances security.



Which of the following best describes the concept of information being stored outside of its country of origin while still being subject to the laws and requirements of the country of origin?

  1. Data sovereignty
  2. Geolocation
  3. Intellectual property
  4. Geographic restrictions

Answer(s): A

Explanation:

Data sovereignty refers to the concept that data stored outside its country of origin is still subject to the laws and regulations of that original country. This means that, regardless of where the data is physically stored, it remains governed by the legal requirements and privacy standards of its originating country. This concept is essential for ensuring that data complies with national regulations, even in cross-border storage scenarios.



An audit reveals that cardholder database logs are exposing account numbers inappropriately.
Which of the following mechanisms would help limit the impact of this error?

  1. Segmentation
  2. Hashing
  3. Journaling
  4. Masking

Answer(s): D

Explanation:

Masking is a technique used to obscure sensitive data, such as account numbers, in order to prevent unauthorized access to the full details. By applying masking to the cardholder data in the logs, only part of the account number would be visible, limiting the exposure of sensitive information and thus reducing the potential impact of the error. This approach allows for secure handling of data in scenarios where the information needs to be referenced but not fully exposed.



A security analyst attempts to start a company's database server.
When the server starts, the analyst receives an error message indicating the database server did not pass authentication. After reviewing and testing the system, the analyst receives confirmation that the server has been compromised and that attackers have redirected all outgoing database traffic to a server under their control.
Which of the following MITRE ATT&CK techniques did the attacker most likely use to redirect database traffic?

  1. Browser extension
  2. Process injection
  3. Valid accounts
  4. Escape to host

Answer(s): D



A penetration tester enters an office building at the same time as a group of employees despite not having an access badge.
Which of the following attack types is the penetration tester performing?

  1. Tailgating
  2. Shoulder surfing
  3. RFID cloning
  4. Forgery

Answer(s): A

Explanation:

Tailgating is a social engineering technique where an unauthorized person gains access to a restricted area by following closely behind authorized individuals without their knowledge or consent. In this scenario, the penetration tester enters the office building at the same time as a group of employees despite not having an access badge, which exemplifies tailgating.



Viewing page 38 of 198
Viewing questions 186 - 190 out of 985 questions


Post your Comments and Discuss CompTIA SY0-701 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!