{"id":11575,"date":"2026-09-14T10:31:48","date_gmt":"2026-09-14T10:31:48","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11575"},"modified":"2026-09-14T11:08:24","modified_gmt":"2026-09-14T11:08:24","slug":"comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-12-q221-240\/","title":{"rendered":"CompTIA Security+ SY0-701 Practice Test Questions and Exam Dumps \u2014 Part 12 (Q221\u2013240)"},"content":{"rendered":"<h3>View Full\u00a0<a href=\"https:\/\/www.examlabs.com\/sy0-701-exam-dumps\">CompTIA SY0-701 Exam Dumps<\/a>\u00a0and Practice Test Dumps.<\/h3>\n<p>&nbsp;<\/p>\n<h3><b>Question 221<\/b><\/h3>\n<p><b>Which security control is designed to prevent unauthorized software from executing on an endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Application allowlisting permits only approved applications to execute. This can prevent unknown or unauthorized software, including many types of malware, from running on an endpoint.<\/span><\/p>\n<h3><b>Question 222<\/b><\/h3>\n<p><b>Which type of attack uses fraudulent phone calls to convince victims to reveal sensitive information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Smishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pharming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Vishing, or voice phishing, uses phone calls or voice communications to manipulate victims into providing credentials, financial information, or other sensitive data.<\/span><\/p>\n<h3><b>Question 223<\/b><\/h3>\n<p><b>Which security technology can analyze large volumes of log data from servers, endpoints, and network devices in one centralized platform?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A Security Information and Event Management (SIEM) platform collects and correlates logs from multiple sources. It helps security teams identify suspicious activity and investigate incidents.<\/span><\/p>\n<h3><b>Question 224<\/b><\/h3>\n<p><b>Which security control is specifically designed to protect web applications from attacks such as SQL injection and cross-site scripting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A Web Application Firewall (WAF) filters and monitors HTTP\/HTTPS traffic to protect web applications from common application-layer attacks.<\/span><\/p>\n<h3><b>Question 225<\/b><\/h3>\n<p><b>An attacker attempts to gain higher permissions after compromising a standard user account. What type of attack is this?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reconnaissance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data exfiltration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Privilege escalation occurs when an attacker attempts to obtain permissions beyond those originally assigned to the compromised account.<\/span><\/p>\n<h3><b>Question 226<\/b><\/h3>\n<p><b>Which technique protects sensitive information by replacing it with a value that cannot be used to directly identify the original data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Tokenization substitutes sensitive information with a token. The token itself does not contain the original sensitive value and can be mapped back to it only through an appropriate system.<\/span><\/p>\n<h3><b>Question 227<\/b><\/h3>\n<p><b>Which security control can prevent a compromised endpoint from communicating with other systems on the network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File hashing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Network isolation separates a compromised endpoint from other systems. This can limit lateral movement and help contain an active security incident.<\/span><\/p>\n<h3><b>Question 228<\/b><\/h3>\n<p><b>Which type of malware executes when a specific condition or event occurs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Logic bomb<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A logic bomb contains malicious code that activates when a predefined condition is met, such as a particular date, event, or system state.<\/span><\/p>\n<h3><b>Question 229<\/b><\/h3>\n<p><b>Which security mechanism provides proof that a message or document was created or approved by a particular party?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password hash<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN tunnel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A digital signature uses asymmetric cryptography to provide integrity and authentication of the signer. It can also support non-repudiation.<\/span><\/p>\n<h3><b>Question 230<\/b><\/h3>\n<p><b>Which method is most effective for reducing the risk associated with users reusing the same password across multiple systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password managers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing account lockout<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sharing credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Password managers can generate and securely store unique passwords for different services. This reduces password reuse and helps users maintain stronger credentials.<\/span><\/p>\n<h3><b>Question 231<\/b><\/h3>\n<p><b>Which attack attempts to discover valid usernames by observing differences in application responses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account enumeration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS poisoning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Account enumeration occurs when an attacker determines whether specific usernames or accounts exist. Applications should avoid revealing noticeably different responses for valid and invalid accounts.<\/span><\/p>\n<h3><b>Question 232<\/b><\/h3>\n<p><b>Which technology can enforce security policies by controlling what devices are allowed to connect to a network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Network Access Control (NAC) evaluates connecting devices and can enforce requirements such as authentication, security software status, and compliance before granting network access.<\/span><\/p>\n<h3><b>Question 233<\/b><\/h3>\n<p><b>Which type of attack attempts to access files outside the intended web application directory by manipulating a file path?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replay attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Directory traversal manipulates file paths to access files or directories outside the application&#8217;s intended location. Proper input validation and access controls can help prevent it.<\/span><\/p>\n<h3><b>Question 234<\/b><\/h3>\n<p><b>Which security measure helps protect against unauthorized physical access by requiring a visitor to be accompanied by an authorized employee?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Escort policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> An escort policy requires visitors to remain with an authorized employee while inside restricted areas. This reduces the risk of unauthorized physical access.<\/span><\/p>\n<h3><b>Question 235<\/b><\/h3>\n<p><b>Which security approach uses multiple controls such as authentication, segmentation, encryption, and monitoring to protect an environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Defense in depth combines multiple independent security controls. If one layer fails, additional layers can still protect systems and information.<\/span><\/p>\n<h3><b>Question 236<\/b><\/h3>\n<p><b>Which type of backup contains all changes made since the last full backup?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Differential<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incremental<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Snapshot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mirror<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> A differential backup stores changes made since the most recent full backup. Restoring generally requires the latest full backup and the latest differential backup.<\/span><\/p>\n<h3><b>Question 237<\/b><\/h3>\n<p><b>Which security technology can detect malicious behavior on an endpoint even when the specific malware signature is unknown?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Behavioral analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Behavioral analysis identifies suspicious activity based on how software or processes behave rather than relying solely on known malware signatures.<\/span><\/p>\n<h3><b>Question 238<\/b><\/h3>\n<p><b>Which access control model assigns permissions according to a user&#8217;s job function or organizational role?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RBAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rule-based routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Role-Based Access Control (RBAC) assigns permissions to roles, and users receive access according to the roles assigned to them. This simplifies permission management in organizations.<\/span><\/p>\n<h3><b>Question 239<\/b><\/h3>\n<p><b>Which security measure can prevent employees from connecting unauthorized USB storage devices to corporate computers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data hashing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Device control allows organizations to manage or restrict peripheral devices such as USB drives. It can reduce the risk of malware infections and unauthorized data transfers.<\/span><\/p>\n<h3><b>Question 240<\/b><\/h3>\n<p><b>Which incident response phase focuses on stopping an attacker from continuing to affect systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lessons learned<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preparation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reporting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"> Containment focuses on limiting the impact and spread of an incident. Actions may include isolating affected systems, disabling compromised accounts, or blocking malicious network traffic.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full\u00a0CompTIA SY0-701 Exam Dumps\u00a0and Practice Test Dumps. &nbsp; Question 221 Which security control is designed to prevent unauthorized software from executing on an endpoint? Application allowlisting Network segmentation Data masking Port mirroring Correct Answer: 1 Explanation Application allowlisting permits only approved applications to execute. This can prevent unknown or unauthorized software, including many types [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11575"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11575"}],"version-history":[{"count":3,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11575\/revisions"}],"predecessor-version":[{"id":11632,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11575\/revisions\/11632"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11575"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11575"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11575"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}