{"id":11754,"date":"2026-09-14T11:52:02","date_gmt":"2026-09-14T11:52:02","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11754"},"modified":"2026-09-14T11:52:02","modified_gmt":"2026-09-14T11:52:02","slug":"comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-15-q281-300","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-15-q281-300\/","title":{"rendered":"CompTIA Security+ SY0-701 Practice Test Questions and Exam Dumps \u2014 Part 15 (Q281\u2013300)"},"content":{"rendered":"<h3>View Full\u00a0<a href=\"https:\/\/www.examlabs.com\/sy0-701-exam-dumps\">CompTIA SY0-701 Exam Dumps<\/a>\u00a0and Practice Test Dumps.<\/h3>\n<p>&nbsp;<\/p>\n<h3><b>Question 281<\/b><\/h3>\n<p><b>Which security control is used to verify that a device meets organizational security requirements before allowing network access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Access Control (NAC) verifies whether a device meets organizational security requirements before granting network access. It can check authentication, patch status, antivirus protection, device configuration, and other security policies. If a device does not meet the required standards, NAC can block or restrict its access until compliance is achieved. WAF protects web applications, SIEM analyzes security events, and HSM manages cryptographic keys. Therefore, NAC is the correct answer.<\/span><\/p>\n<h3><b>Question 282<\/b><\/h3>\n<p><b>Which attack attempts to obtain sensitive information by manipulating a victim through a fabricated scenario?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wardriving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pretexting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pretexting is a social engineering technique in which an attacker creates a believable but fabricated scenario to manipulate a victim into revealing sensitive information or performing a specific action. The attacker may pretend to be a trusted person, such as a coworker, bank representative, or technical support agent. Wardriving involves searching for wireless networks, DDoS attacks overwhelm systems with traffic, and port scanning identifies open network ports. Therefore, Pretexting is the correct answer.<\/span><\/p>\n<h3><b>Question 283<\/b><\/h3>\n<p><b>Which security technology protects data by converting readable information into an unreadable format using a cryptographic key?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption protects sensitive data by converting readable plaintext into an unreadable format called ciphertext using a cryptographic algorithm and key. Only authorized users with the appropriate decryption key can restore the data to its original form. Hashing converts data into a fixed-length value and is generally designed to be irreversible. Tokenization replaces sensitive data with non-sensitive tokens, while data classification categorizes information based on sensitivity. Therefore, Encryption is the correct answer.<\/span><\/p>\n<h3><b>Question 284<\/b><\/h3>\n<p><b>Which type of attack attempts to discover wireless networks and their characteristics while moving through an area?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pharming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wardriving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vishing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Wardriving is an attack or reconnaissance technique that involves searching for and identifying wireless networks while moving through a specific area. Attackers may use laptops, smartphones, GPS devices, and specialized software to detect nearby Wi-Fi networks and collect details such as network names, signal strength, and security settings. Tailgating involves unauthorized physical access, pharming redirects users to fraudulent websites, and vishing uses voice-based social engineering. Therefore, Wardriving is the correct answer.<\/span><\/p>\n<h3><b>Question 285<\/b><\/h3>\n<p><b>Which security control is designed to prevent unauthorized physical access to a server room by requiring authentication at the entrance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Badge reader<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A badge reader is a physical security control used to restrict access to sensitive areas such as server rooms. It requires users to present an authorized credential, such as an access card or badge, before allowing entry. This helps ensure that only approved personnel can enter restricted facilities. A firewall protects network traffic, an IDS detects suspicious activity, and a proxy server manages or filters network requests. Therefore, Badge reader is the correct answer.<\/span><\/p>\n<h3><b>Question 286<\/b><\/h3>\n<p><b>Which cryptographic technique produces a fixed-length value from input data and is commonly used to verify data integrity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Steganography<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hashing is a cryptographic technique that converts input data into a fixed-length value called a hash or digest. Even a small change in the original data typically produces a different hash, making hashing useful for verifying data integrity. Encryption protects data by making it unreadable, tokenization replaces sensitive information with tokens, and steganography hides information within another file or medium. Therefore, Hashing is the correct answer.<\/span><\/p>\n<h3><b>Question 287<\/b><\/h3>\n<p><b>Which attack attempts to use a stolen authentication token to access a user&#8217;s account?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dumpster diving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS poisoning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Session hijacking is an attack in which an attacker obtains a valid session token or identifier and uses it to impersonate an authenticated user. By stealing the token, the attacker may gain access to the victim\u2019s account without needing to know the password. Dumpster diving involves searching discarded materials for sensitive information, password spraying attempts common passwords against multiple accounts, and DNS poisoning manipulates DNS responses. Therefore, Session hijacking is the correct answer.<\/span><\/p>\n<h3><b>Question 288<\/b><\/h3>\n<p><b>Which security control provides a warning that unauthorized activity is prohibited and may be monitored?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Honeypot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Banner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A banner is a security control that displays a warning to users before or during system access, stating that unauthorized activity is prohibited and that system use may be monitored. It helps communicate organizational security policies and can provide legal notice about acceptable use and monitoring. A honeypot is a decoy system designed to attract and detect attackers, encryption protects data, and a load balancer distributes network traffic across multiple systems. Therefore, Banner is the correct answer.<\/span><\/p>\n<h3><b>Question 289<\/b><\/h3>\n<p><b>Which security solution is specifically designed to filter malicious or unauthorized web requests before they reach a web application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Web Application Firewall (WAF) protects web applications by inspecting incoming HTTP and HTTPS requests before they reach the application. It can detect and block malicious or unauthorized traffic, including common attacks such as SQL injection and cross-site scripting. NAC controls network access based on device or user requirements, SIEM collects and analyzes security events, while EDR monitors and responds to threats affecting endpoints. Therefore, WAF is the correct answer.<\/span><\/p>\n<h3><b>Question 290<\/b><\/h3>\n<p><b>Which type of attack exploits an application by inserting unexpected commands into user-supplied input?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Injection attacks occur when an attacker inserts malicious or unexpected commands into user-supplied input, causing an application to interpret the input as legitimate commands or queries. Common examples include SQL injection, which targets databases, and command injection, which attempts to execute operating system commands. Tailgating involves unauthorized physical entry, DDoS attacks overwhelm systems with excessive traffic, and shoulder surfing involves observing sensitive information directly. Therefore, Injection is the correct answer.<\/span><\/p>\n<h3><b>Question 291<\/b><\/h3>\n<p><b>Which security principle requires every access request to be evaluated rather than automatically trusting users inside the corporate network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network flattening<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero trust<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero trust is a security principle that requires every access request to be verified and authorized, regardless of whether the user or device is inside or outside the corporate network. It assumes that no user, device, or connection should be automatically trusted. Access decisions can consider factors such as identity, device security, location, and requested resources. Open trust and implicit trust rely on automatic trust, while network flattening refers to network architecture rather than an access control principle. Therefore, Zero trust is the correct answer.<\/span><\/p>\n<h3><b>Question 292<\/b><\/h3>\n<p><b>Which security technology can detect unusual login behavior based on established patterns for a user?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UEBA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and Entity Behavior Analytics (UEBA) monitors user and system activity to establish normal behavioral patterns and identify unusual or suspicious behavior. It can detect anomalies such as unexpected login locations, unusual access times, abnormal resource usage, or changes in typical activity. DHCP assigns IP addresses, NAT translates private and public IP addresses, while RAID provides data redundancy and performance improvements for storage systems. Therefore, UEBA is the correct answer.<\/span><\/p>\n<h3><b>Question 293<\/b><\/h3>\n<p><b>Which type of authentication factor is represented by a password or PIN?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you have<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you are<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Somewhere you are<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Passwords and PINs are authentication factors classified as \u201csomething you know\u201d because they rely on information that the user remembers and provides during the authentication process. \u201cSomething you have\u201d refers to a physical item, such as a security token or smart card. \u201cSomething you are\u201d refers to biometric characteristics, such as fingerprints or facial features. \u201cSomewhere you are\u201d represents a location-based factor, such as a specific geographic area or trusted network. Therefore, Something you know is the correct answer.<\/span><\/p>\n<h3><b>Question 294<\/b><\/h3>\n<p><b>Which security mechanism can restrict access to a network based on the physical location of a user or device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Geofencing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Geofencing is a security mechanism that uses defined geographic boundaries to control or trigger actions based on the physical location of a user or device. Organizations can use geofencing to restrict access to systems or resources when a device moves outside an approved area. Tokenization replaces sensitive information with tokens, hashing generates fixed-length values for data verification, while file integrity monitoring detects unauthorized changes to files. Therefore, Geofencing is the correct answer.<\/span><\/p>\n<h3><b>Question 295<\/b><\/h3>\n<p><b>Which type of backup stores only the changes made since the most recent backup of any type?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Differential<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mirror<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incremental<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An incremental backup stores only the data that has changed since the most recent backup, regardless of whether it was a full or another incremental backup. This approach reduces backup time and storage requirements because only new or modified data is saved. A differential backup stores changes made since the last full backup, while a full backup copies all selected data. A mirror backup maintains an exact copy of the source data. Therefore, Incremental is the correct answer.<\/span><\/p>\n<h3><b>Question 296<\/b><\/h3>\n<p><b>Which security control can automatically block network traffic that matches a known malicious signature?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Syslog<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Prevention System (IPS) monitors network traffic for known malicious patterns, signatures, and suspicious activity. When it detects traffic matching a known threat, it can automatically block or prevent that traffic from reaching protected systems. An IDS can detect and alert on suspicious activity but typically does not block it automatically. SIEM collects and analyzes security logs from multiple sources, while Syslog is a protocol used to transmit and store system messages. Therefore, IPS is the correct answer.<\/span><\/p>\n<h3><b>Question 297<\/b><\/h3>\n<p><b>Which type of attack occurs when an attacker follows an authorized person through a secured entrance without using their own credentials?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pharming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tailgating is a physical security attack in which an unauthorized person follows an authorized individual through a secured entrance without providing their own credentials. The attacker may take advantage of courtesy or distraction to gain access to a restricted area. Phishing uses deceptive messages to steal information, pharming redirects users to fraudulent websites, and credential stuffing uses stolen username and password combinations to access accounts. Physical access controls, security personnel, and user awareness can help prevent tailgating. Therefore, Tailgating is the correct answer.<\/span><\/p>\n<h3><b>Question 298<\/b><\/h3>\n<p><b>Which security practice ensures that an organization&#8217;s critical data can be restored after ransomware or another destructive incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup and recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account enumeration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Backup and recovery practices help organizations restore critical data after ransomware attacks, system failures, accidental deletion, or other destructive incidents. Regular backups should be stored securely and recovery procedures should be tested to ensure data can be restored when needed. Offline or immutable backups provide additional protection because attackers may be unable to modify or encrypt them. Port scanning identifies open ports, traffic shaping manages network bandwidth, and account enumeration identifies valid accounts. Therefore, Backup and recovery is the correct answer.<\/span><\/p>\n<h3><b>Question 299<\/b><\/h3>\n<p><b>Which security assessment identifies systems, services, or applications that may contain known vulnerabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident containment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account provisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability scanning is a security assessment that uses automated tools to identify known weaknesses in systems, applications, network services, and devices. The results can help security teams determine which vulnerabilities require attention and prioritize remediation based on risk. Data classification organizes information according to sensitivity, incident containment limits the impact of a security incident, and account provisioning creates or manages user accounts and access permissions. Therefore, Vulnerability scanning is the correct answer.<\/span><\/p>\n<h3><b>Question 300<\/b><\/h3>\n<p><b>Which security control is primarily responsible for recording events such as successful and failed user logins?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit logging records security-relevant events such as successful and failed login attempts, administrative activities, system changes, and access requests. These records help security teams monitor user activity, investigate suspicious behavior, identify potential incidents, and meet compliance requirements. Data masking hides sensitive information, tokenization replaces sensitive data with tokens, while network segmentation separates networks or systems to limit unauthorized access. Audit logs therefore provide an important record of authentication and other security-related activities. Therefore, Audit logging is the correct answer.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full\u00a0CompTIA SY0-701 Exam Dumps\u00a0and Practice Test Dumps. &nbsp; Question 281 Which security control is used to verify that a device meets organizational security requirements before allowing network access? WAF SIEM NAC HSM Correct Answer: 3 Explanation Network Access Control (NAC) verifies whether a device meets organizational security requirements before granting network access. It can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11754"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11754"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11754\/revisions"}],"predecessor-version":[{"id":11756,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11754\/revisions\/11756"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11754"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}