{"id":11403,"date":"2026-09-14T08:09:08","date_gmt":"2026-09-14T08:09:08","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11403"},"modified":"2026-09-14T08:46:35","modified_gmt":"2026-09-14T08:46:35","slug":"comptia-sy0-701-practice-test-questions-and-exam-dumps-part-1-q1-20","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-sy0-701-practice-test-questions-and-exam-dumps-part-1-q1-20\/","title":{"rendered":"CompTIA SY0-701 Practice Test Questions and Exam Dumps \u2014 Part 1 (Q1\u201320)"},"content":{"rendered":"<h3>View Full <a href=\"https:\/\/www.examlabs.com\/sy0-701-exam-dumps\">CompTIA SY0-701 Exam Dumps<\/a> and Practice Test Dumps.<\/h3>\n<p>&nbsp;<\/p>\n<h3><b>Question 1<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A security administrator wants to prevent unauthorized users from accessing sensitive company resources even if a user&#8217;s password has been compromised. Which of the following would BEST address this requirement?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Multifactor authentication (MFA) adds an additional verification factor beyond a password, such as a security token, authenticator application, or biometric characteristic. If an attacker obtains a user&#8217;s password, they still need the additional authentication factor to gain access. Network segmentation separates networks, data masking hides sensitive information, and load balancing distributes network traffic. Although these technologies can improve security or performance, they do not directly provide the additional identity verification required when credentials are compromised.<\/span><\/p>\n<h3><b>Question 2<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Which security concept ensures that a user is given only the permissions necessary to perform their assigned duties?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory vacation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The principle of least privilege requires users, applications, and systems to receive only the minimum permissions necessary to complete their required tasks. This limits the potential damage if an account becomes compromised or is misused. Separation of duties divides sensitive responsibilities among multiple individuals, while job rotation changes employee responsibilities periodically. Mandatory vacation can help uncover fraudulent activity. However, none of these directly defines the restriction of permissions to the minimum required level, making least privilege the correct choice.<\/span><\/p>\n<h3><b>Question 3<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A company wants to ensure that employees cannot access internal servers directly from an untrusted external network. Which security control would BEST accomplish this?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A firewall controls network traffic based on predefined security rules and can block unauthorized connections between trusted internal networks and untrusted external networks. It can restrict traffic by source address, destination address, port, protocol, and other criteria. File compression reduces file size, RAID provides storage redundancy, and printer encryption protects information associated with printing. These controls do not directly regulate network connections between external and internal environments. Therefore, a properly configured firewall is the best choice for controlling this type of network access.<\/span><\/p>\n<h3><b>Question 4<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Which type of malware can replicate itself across a network without requiring a user to execute an infected file?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trojan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A worm is malware capable of self-replication and can spread from one system to another, often by exploiting vulnerabilities in operating systems, applications, or network services. Unlike a worm, a Trojan typically disguises itself as legitimate software and depends on a user or process to execute it. Spyware is primarily designed to monitor or collect information, while a rootkit attempts to hide malicious activity and maintain privileged access. Worms can spread rapidly because they do not necessarily require users to manually execute infected files.<\/span><\/p>\n<h3><b>Question 5<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A security analyst receives an email that appears to come from the company&#8217;s CEO. The message urgently requests a wire transfer to an external account. Which attack is MOST likely occurring?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business email compromise<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Business email compromise (BEC) involves attackers impersonating executives, employees, or trusted business partners to manipulate victims into performing unauthorized actions, such as transferring money or revealing sensitive information. In this scenario, the attacker is using the identity of the CEO to create urgency and convince an employee to transfer funds. Phishing is a broader category involving deceptive communications, but the specific financial impersonation scenario is characteristic of BEC. DDoS targets availability, while password spraying attempts authentication using common passwords against multiple accounts.<\/span><\/p>\n<h3><b>Question 6<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Which security control is MOST appropriate for detecting suspicious activity by examining network traffic?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> An intrusion detection system (IDS) monitors network or system activity and generates alerts when it identifies potentially malicious or suspicious behavior. A network-based IDS can inspect traffic for known attack patterns, unusual activity, or policy violations. A UPS provides backup electrical power, an HSM securely manages cryptographic keys and operations, and RAID provides storage redundancy. An IDS is therefore the control specifically designed to detect suspicious network activity. Detection does not necessarily mean the system automatically blocks the traffic; prevention is typically associated with an IPS.<\/span><\/p>\n<h3><b>Question 7<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Which technology is designed to actively block malicious network traffic after detecting an attack?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet sniffer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> An intrusion prevention system (IPS) can detect malicious or suspicious traffic and take automated action to prevent the activity, such as dropping packets or blocking connections. An IDS primarily detects and alerts on suspicious activity without necessarily blocking it. A SIEM collects and correlates security logs and events from multiple sources for analysis. A packet sniffer captures and examines network traffic but is not inherently designed to prevent attacks. Therefore, an IPS is the best answer when the requirement specifically calls for active blocking of malicious traffic.<\/span><\/p>\n<h3><b>Question 8<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An organization wants to collect security logs from firewalls, servers, applications, and endpoints and correlate the events to identify potential attacks. Which solution should be implemented?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A Security Information and Event Management (SIEM) system collects logs and security events from multiple sources and can correlate that information to identify suspicious patterns. For example, a SIEM might detect repeated failed logins followed by successful authentication and unusual access to sensitive resources. A VPN provides encrypted remote connectivity, NAC controls network access based on device or user conditions, and DLP helps prevent sensitive information from leaving an organization. SIEM is therefore the most appropriate technology for centralized security event collection, correlation, monitoring, and analysis.<\/span><\/p>\n<h3><b>Question 9<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Which type of attack attempts to make a service unavailable by overwhelming it with traffic from many compromised systems?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Distributed denial-of-service attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A distributed denial-of-service (DDoS) attack uses many compromised systems, commonly called a botnet, to generate large volumes of requests or traffic toward a target. The objective is to consume network bandwidth, processing resources, memory, or application capacity so legitimate users cannot access the service normally. A brute-force attack attempts to guess credentials, SQL injection targets vulnerable database queries, and credential stuffing uses previously stolen username and password combinations. Because the scenario involves many systems overwhelming a service, DDoS is the correct answer.<\/span><\/p>\n<h3><b>Question 10<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Which authentication factor is represented by a fingerprint?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you have<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you are<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Somewhere you are<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A fingerprint is a biometric characteristic and therefore represents the authentication factor &#8220;something you are.&#8221; Authentication factors are commonly categorized as something you know, something you have, and something you are. Passwords and PINs are examples of something you know, while smart cards and security tokens represent something you have. Fingerprints, facial recognition, and iris scans represent something you are. Using multiple different factor categories provides stronger authentication because compromising one factor does not necessarily give an attacker access to the others.<\/span><\/p>\n<h3><b>Question 11<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A company wants to prevent sensitive customer information from being transmitted outside the organization through email and cloud services. Which security solution is MOST appropriate?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Data Loss Prevention (DLP) technologies are designed to identify, monitor, and protect sensitive information from unauthorized disclosure or transmission. DLP can inspect data in use, in motion, and at rest and may block or alert when sensitive information is being sent through email, uploaded to cloud services, or copied to unauthorized locations. DHCP automatically assigns network configuration information, NAT translates network addresses, and RAID provides storage redundancy. Since the requirement focuses on preventing sensitive data from leaving the organization, DLP is the most appropriate solution.<\/span><\/p>\n<h3><b>Question 12<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Which cryptographic method uses the same key to encrypt and decrypt data?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asymmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Symmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Symmetric encryption uses the same secret key for both encryption and decryption. Because the same key must be shared securely between authorized parties, key management is an important consideration. Asymmetric encryption uses a mathematically related public and private key pair. Hashing is a one-way process normally used for integrity verification or password storage rather than reversible encryption. Digital signatures typically use asymmetric cryptography to provide authenticity and integrity. Therefore, when the same key is used for both encryption and decryption, the method is symmetric encryption.<\/span><\/p>\n<h3><b>Question 13<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A security professional needs to verify that a downloaded file has not been modified during transmission. Which method is MOST appropriate?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Steganography<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Hashing generates a fixed-length value based on the contents of a file. If the file changes, even slightly, its resulting hash value should normally change. By comparing the downloaded file&#8217;s hash with a trusted hash published by the original source, a user can determine whether the file was altered or corrupted. Tokenization replaces sensitive data with tokens, steganography hides information within other media, and data masking obscures sensitive information. Hashing is therefore the appropriate method for verifying file integrity.<\/span><\/p>\n<h3><b>Question 14<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An attacker sends a specially crafted input to an application in an attempt to manipulate database queries. Which attack is this?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP poisoning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS tunneling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> SQL injection occurs when an attacker provides malicious SQL-related input to an application that improperly handles user-supplied data. If the application constructs database queries insecurely, the attacker may manipulate those queries to access, modify, or delete database information. Secure coding practices, parameterized queries, input validation, and proper database permissions can reduce the risk. ARP poisoning targets local network address resolution, DNS tunneling abuses DNS communications, and shoulder surfing involves visually observing sensitive information. The database-query manipulation described here is SQL injection.<\/span><\/p>\n<h3><b>Question 15<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Which type of vulnerability occurs when an application accepts more data than the allocated memory space can hold?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Race condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A buffer overflow occurs when an application writes more data into a memory buffer than the space allocated for that buffer. Excess data may overwrite adjacent memory areas and potentially cause application crashes or, in some cases, allow attackers to execute malicious code. A race condition occurs when the outcome depends on the timing of concurrent operations. Privilege escalation involves obtaining higher permissions than authorized, while directory traversal attempts to access files or directories outside the intended location. Therefore, excessive data written beyond a buffer&#8217;s capacity describes a buffer overflow.<\/span><\/p>\n<h3><b>Question 16<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A company separates its accounting systems from general employee systems so that a compromise in one network does not easily spread to the other. Which security technique is being used?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Network segmentation divides a larger network into separate logical or physical segments with controlled communication between them. Organizations commonly use segmentation to isolate sensitive systems, limit attack propagation, and reduce the potential impact of a compromise. For example, accounting systems can be placed on a restricted network segment that only authorized users and services can access. Data aggregation combines information from multiple sources, password spraying attempts common passwords against multiple accounts, and port mirroring copies network traffic for monitoring. Therefore, network segmentation best matches the scenario.<\/span><\/p>\n<h3><b>Question 17<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Which security principle requires two or more individuals to participate in a sensitive process to reduce the risk of fraud?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Separation of duties divides critical responsibilities among multiple individuals so that one person cannot independently complete a sensitive or potentially fraudulent process. For example, one employee might create a purchase order while another approves it. This reduces the opportunity for unauthorized actions or fraud because multiple people must participate. Least privilege limits permissions, zero trust requires continuous verification rather than automatic trust, and defense in depth uses multiple layers of security controls. Since the scenario specifically requires multiple people to participate in a sensitive process, separation of duties is correct.<\/span><\/p>\n<h3><b>Question 18<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Which security model assumes that no user or device should be automatically trusted, even when the device is connected to the internal corporate network?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter trust<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Zero trust is a security approach based on the principle that users and devices should not receive automatic trust simply because they are inside an organization&#8217;s network. Access should be continuously evaluated using factors such as identity, device security, location, risk, and requested resources. Zero trust commonly follows principles such as verifying explicitly, using least privilege, and assuming breach. Traditional perimeter-based security often treated internal networks as more trusted than external networks. Zero trust reduces this assumption by requiring appropriate verification and authorization for access.<\/span><\/p>\n<h3><b>Question 19<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A security analyst discovers that an employee&#8217;s account has successfully authenticated from two geographically distant locations within a few minutes. What type of suspicious activity is this MOST likely to indicate?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Impossible travel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Impossible travel is a security analytics concept used when authentication events indicate that a user appears to have traveled between geographically distant locations faster than physically possible. For example, a successful login from Pakistan followed by another successful login from the United States only a few minutes later may indicate that credentials have been compromised. Security monitoring systems can use location and authentication timestamps to detect this anomaly. Data masking and tokenization protect information, while load balancing distributes workloads. Therefore, impossible travel is the appropriate answer.<\/span><\/p>\n<h3><b>Question 20<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A company wants to ensure that a user cannot deny having digitally approved an important transaction. Which security mechanism is MOST appropriate?<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen lock<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A digital signature can provide authentication, integrity, and non-repudiation for digitally signed information. A properly implemented digital signature allows recipients to verify that the signature was created using the signer&#8217;s private key and that the signed data has not been altered. This can provide evidence that the signer approved or signed the transaction, subject to the organization&#8217;s legal and technical framework. Data compression reduces file size, NAT translates network addresses, and screen locks protect unattended devices. Therefore, a digital signature is the best choice for non-repudiation.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA SY0-701 Exam Dumps and Practice Test Dumps. &nbsp; Question 1 A security administrator wants to prevent unauthorized users from accessing sensitive company resources even if a user&#8217;s password has been compromised. Which of the following would BEST address this requirement? Multifactor authentication Network segmentation Data masking Load balancing Correct Answer: 1 Explanation: [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11403"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11403"}],"version-history":[{"count":2,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11403\/revisions"}],"predecessor-version":[{"id":11449,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11403\/revisions\/11449"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11403"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11403"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}