{"id":11759,"date":"2026-09-14T11:55:28","date_gmt":"2026-09-14T11:55:28","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11759"},"modified":"2026-09-14T11:55:28","modified_gmt":"2026-09-14T11:55:28","slug":"comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-17-q321-340\/","title":{"rendered":"CompTIA Security+ SY0-701 Practice Test Questions and Exam Dumps \u2014 Part 17 (Q321\u2013340)"},"content":{"rendered":"<h3>View Full\u00a0<a href=\"https:\/\/www.examlabs.com\/sy0-701-exam-dumps\">CompTIA SY0-701 Exam Dumps<\/a>\u00a0and Practice Test Dumps.<\/h3>\n<p>&nbsp;<\/p>\n<h3><b>Question 321<\/b><\/h3>\n<p><b>Which security technology is designed to identify suspicious activity by analyzing events collected from multiple systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Security Information and Event Management (SIEM) platform collects, centralizes, and correlates security logs and events from multiple systems, applications, servers, and network devices. By analyzing information from different sources, a SIEM can identify suspicious patterns that might not be obvious when examining individual logs. Security teams can use SIEM alerts to investigate potential attacks, monitor user activity, detect anomalies, and support incident response and compliance requirements.<\/span><\/p>\n<h3><b>Question 322<\/b><\/h3>\n<p><b>Which type of attack attempts to gain unauthorized access by trying many possible passwords against a single account?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A brute-force attack attempts to discover a user&#8217;s password by repeatedly trying different password combinations against a single account. Attackers may use automated tools to test thousands or millions of possible combinations. Strong and unique passwords make brute-force attacks more difficult. Additional protections such as account lockouts, rate limiting, multifactor authentication, and monitoring for repeated failed login attempts can further reduce the likelihood of successful unauthorized access.<\/span><\/p>\n<h3><b>Question 323<\/b><\/h3>\n<p><b>Which security mechanism verifies that a user has permission to access a requested resource?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accounting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authorization determines what an authenticated user is allowed to access or perform within a system. After authentication confirms the user&#8217;s identity, authorization checks assigned permissions, roles, or access-control policies before allowing the requested action. For example, an employee may be authenticated successfully but still be unauthorized to access confidential financial records. Proper authorization helps enforce least privilege and prevents users from accessing resources beyond their assigned responsibilities.<\/span><\/p>\n<h3><b>Question 324<\/b><\/h3>\n<p><b>Which component of AAA records information about user activities and resource usage?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accounting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In the AAA security framework, accounting records information about user activities and resource usage. It can include login and logout times, session duration, commands executed, accessed resources, and other relevant activity details. This information can help organizations investigate security incidents, monitor resource usage, support auditing, and maintain accountability. Authentication verifies identity, while authorization determines permissions. Accounting focuses specifically on recording and tracking activities after access occurs.<\/span><\/p>\n<h3><b>Question 325<\/b><\/h3>\n<p><b>Which attack involves sending fraudulent text messages that attempt to steal credentials or financial information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spear phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pretexting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Smishing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Smishing is a form of phishing that uses SMS or other text messaging services to manipulate victims. Attackers may send messages claiming that an account is locked, a payment failed, or an urgent verification is required. These messages often contain malicious links or requests for sensitive information. Users should avoid clicking unexpected links, verify requests through official channels, and never provide passwords or financial information through suspicious text messages.<\/span><\/p>\n<h3><b>Question 326<\/b><\/h3>\n<p><b>Which security control can identify unauthorized modifications to important operating system files?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FIM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File Integrity Monitoring (FIM) tracks important files and detects unauthorized or unexpected modifications. It can monitor system files, configuration files, application files, and other sensitive resources. When a monitored file changes, FIM can generate an alert for administrators or security personnel to investigate. This capability can help identify malware activity, unauthorized configuration changes, and potential system compromise. FIM is especially valuable for protecting critical systems.<\/span><\/p>\n<h3><b>Question 327<\/b><\/h3>\n<p><b>Which type of malware provides unauthorized remote control of an infected system while attempting to remain hidden?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Logic bomb<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A rootkit is malicious software designed to maintain unauthorized access while hiding its presence from users and security tools. Rootkits may conceal files, processes, network connections, or other evidence of compromise. Some rootkits operate with highly privileged system-level access, making them particularly difficult to detect and remove. Security teams can use endpoint protection, integrity monitoring, behavioral analysis, and specialized scanning tools to help identify rootkit activity.<\/span><\/p>\n<h3><b>Question 328<\/b><\/h3>\n<p><b>Which security technique divides a network into separate zones to restrict unauthorized lateral movement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation divides a network into separate security zones or segments and applies access controls between them. For example, servers, employee workstations, and sensitive databases can be placed into different network segments. If an attacker compromises one system, segmentation can prevent unrestricted communication with other systems. This limits lateral movement and reduces the potential impact of a breach. Firewalls, VLANs, and access-control rules can support network segmentation.<\/span><\/p>\n<h3><b>Question 329<\/b><\/h3>\n<p><b>Which type of encryption uses a pair of mathematically related keys?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Symmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asymmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asymmetric encryption uses two mathematically related keys: a public key and a private key. The public key can generally be distributed openly, while the private key must be protected. Depending on the cryptographic operation, one key may be used to encrypt information while the corresponding key is used to decrypt it. Asymmetric cryptography is commonly used for secure communications, digital certificates, and establishing trust between systems.<\/span><\/p>\n<h3><b>Question 330<\/b><\/h3>\n<p><b>Which security control can block unauthorized applications from executing on a workstation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting is a security control that permits only specifically approved applications or software to execute on a system. Any application that is not included on the approved list can be blocked. This approach can reduce the risk of malware, unauthorized software, and potentially dangerous applications running on endpoints. Organizations can maintain allowlists based on trusted publishers, file hashes, application paths, or other approved identification methods.<\/span><\/p>\n<h3><b>Question 331<\/b><\/h3>\n<p><b>Which type of attack uses a fake identity or fabricated story to convince an employee to disclose sensitive information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pretexting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wardriving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replay attack<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pretexting is a social engineering technique in which an attacker creates a believable story or false identity to manipulate a victim. The attacker may pretend to be a manager, technical support employee, vendor, bank representative, or another trusted person. The goal is usually to obtain sensitive information, credentials, or access. Security awareness training and verification procedures can help employees recognize and resist pretexting attempts.<\/span><\/p>\n<h3><b>Question 332<\/b><\/h3>\n<p><b>Which security technology protects web applications from malicious HTTP and HTTPS requests?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Web Application Firewall (WAF) monitors and filters HTTP and HTTPS traffic directed toward web applications. It can help detect and block common application-layer attacks, including SQL injection, cross-site scripting, malicious requests, and certain automated attacks. A WAF operates differently from a traditional network firewall because it focuses specifically on web application traffic. Proper WAF configuration can provide an additional security layer around internet-facing applications.<\/span><\/p>\n<h3><b>Question 333<\/b><\/h3>\n<p><b>Which security principle requires users to receive only the permissions necessary to complete their assigned responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege requires users, applications, and systems to receive only the permissions necessary to perform their legitimate responsibilities. Limiting permissions reduces the potential damage caused by compromised accounts, malware, or accidental actions. For example, a user who only needs to read documents should not receive permission to delete or modify them. Applying least privilege helps organizations reduce attack surfaces and improve overall access control.<\/span><\/p>\n<h3><b>Question 334<\/b><\/h3>\n<p><b>Which type of attack attempts to manipulate a database query through malicious input?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">XSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL injection occurs when an attacker inserts malicious SQL commands or syntax into application input that is improperly handled by the application. If the application is vulnerable, the attacker may manipulate database queries to access, modify, or delete information. SQL injection can be reduced through parameterized queries, prepared statements, input validation, and secure application development practices. Proper database permissions should also limit the potential impact of an attack.<\/span><\/p>\n<h3><b>Question 335<\/b><\/h3>\n<p><b>Which security technology can isolate suspicious files or applications in a controlled environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sandbox<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy ARP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A sandbox provides an isolated and controlled environment where suspicious files, applications, or code can be executed and analyzed without giving them unrestricted access to production systems. Security professionals can observe application behavior, network connections, file changes, and other activities inside the sandbox. This can help identify potentially malicious software before allowing it to interact with critical systems. Sandboxing is commonly used in malware analysis and endpoint security.<\/span><\/p>\n<h3><b>Question 336<\/b><\/h3>\n<p><b>Which physical security control is designed to stop vehicles from entering a protected area?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bollard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mantrap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Badge reader<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Turnstile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bollards are physical security barriers designed to prevent or restrict unauthorized vehicles from entering protected areas. They are commonly installed around building entrances, pedestrian zones, government facilities, and other sensitive locations. Bollards can be fixed, removable, or designed to rise and lower automatically. A mantrap controls pedestrian access, a badge reader verifies personnel credentials, and a turnstile regulates individual entry through controlled access points.<\/span><\/p>\n<h3><b>Question 337<\/b><\/h3>\n<p><b>Which security method allows administrators to monitor and control activities performed using privileged accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PAM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged Access Management (PAM) is designed to control and monitor accounts with elevated permissions. PAM solutions can provide features such as credential vaulting, privileged-session monitoring, access approval, password rotation, and temporary privilege assignment. These controls help reduce the risk associated with administrator accounts because attackers often target highly privileged credentials. PAM also improves accountability by allowing organizations to track who accessed privileged systems and what actions were performed.<\/span><\/p>\n<h3><b>Question 338<\/b><\/h3>\n<p><b>Which type of backup contains only data that has changed since the previous backup?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Differential<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incremental<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An incremental backup stores only the data that has changed since the most recent backup, whether that backup was full or incremental. Because each incremental backup usually contains a smaller amount of data, it can reduce backup time and storage requirements. However, restoring data may require the original full backup and all subsequent incremental backups. A differential backup instead stores changes made since the last full backup.<\/span><\/p>\n<h3><b>Question 339<\/b><\/h3>\n<p><b>Which security control can prevent an attacker from moving freely between compromised systems on an internal network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation separates systems into different security zones and restricts unnecessary communication between those zones. This can significantly limit an attacker&#8217;s ability to move laterally after compromising one system. For example, employee workstations can be separated from database servers using firewalls, VLANs, or access-control policies. Even if one endpoint becomes compromised, segmentation can prevent the attacker from directly reaching sensitive systems and reduce the overall impact of the incident.<\/span><\/p>\n<h3><b>Question 340<\/b><\/h3>\n<p><b>Which incident response activity focuses on removing malware, malicious accounts, and other threats from affected systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preparation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lessons learned<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eradication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication is the incident response phase focused on removing the root cause and remaining traces of a security incident from affected systems. Activities may include deleting malware, removing persistence mechanisms, disabling compromised accounts, closing exploited vulnerabilities, and eliminating unauthorized access methods. The goal is to ensure the threat is no longer present before systems return to normal operation. After eradication, organizations can proceed with recovery and verify that systems are secure.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full\u00a0CompTIA SY0-701 Exam Dumps\u00a0and Practice Test Dumps. &nbsp; Question 321 Which security technology is designed to identify suspicious activity by analyzing events collected from multiple systems? NAC WAF HSM SIEM Correct Answer: 4 Explanation A Security Information and Event Management (SIEM) platform collects, centralizes, and correlates security logs and events from multiple systems, applications, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11759"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11759"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11759\/revisions"}],"predecessor-version":[{"id":11760,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11759\/revisions\/11760"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11759"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11759"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11759"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}