{"id":11761,"date":"2026-09-14T11:56:19","date_gmt":"2026-09-14T11:56:19","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11761"},"modified":"2026-09-14T11:56:19","modified_gmt":"2026-09-14T11:56:19","slug":"comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-security-sy0-701-practice-test-questions-and-exam-dumps-part-18-q341-360\/","title":{"rendered":"CompTIA Security+ SY0-701 Practice Test Questions and Exam Dumps \u2014 Part 18 (Q341\u2013360)"},"content":{"rendered":"<h3>View Full\u00a0<a href=\"https:\/\/www.examlabs.com\/sy0-701-exam-dumps\">CompTIA SY0-701 Exam Dumps<\/a>\u00a0and Practice Test Dumps.<\/h3>\n<p>&nbsp;<\/p>\n<h3><b>Question 341<\/b><\/h3>\n<p><b>Which security solution is primarily designed to collect and correlate logs from multiple systems to identify suspicious activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Security Information and Event Management (SIEM) solution is designed to collect, centralize, and analyze security logs and events from multiple systems and devices. These sources can include servers, firewalls, applications, endpoints, and network devices. SIEM correlates information from different sources to identify patterns that may indicate suspicious or malicious activity. It can generate alerts when predefined rules or unusual behaviors are detected, helping security teams investigate potential incidents. SIEM also supports security monitoring, incident response, reporting, and compliance requirements. By providing a centralized view of security events, SIEM helps organizations detect threats more efficiently and respond to incidents quickly.<\/span><\/p>\n<h3><b>Question 342<\/b><\/h3>\n<p><b>An attacker repeatedly attempts different passwords against one user account. Which attack is most likely occurring?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A brute-force attack occurs when an attacker repeatedly tries different passwords or password combinations against a specific user account until the correct credential is discovered. The attacker may use automated tools to test a large number of possible combinations. This differs from password spraying, where attackers typically try one or a few common passwords against many different accounts. Brute-force attacks can be made more difficult through account lockout policies, strong password requirements, multi-factor authentication, and login monitoring. Organizations can also detect repeated failed authentication attempts and investigate suspicious activity. The key characteristic of this attack is trying many passwords against one account.<\/span><\/p>\n<h3><b>Question 343<\/b><\/h3>\n<p><b>Which security principle ensures that a user receives only the permissions required to perform assigned duties?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Non-repudiation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege ensures that users, applications, and systems receive only the minimum permissions necessary to perform their required tasks. This reduces the potential damage caused by compromised accounts, malware, insider threats, or accidental actions. For example, an employee who only needs to view certain files should not receive permission to modify or delete them. Least privilege should be applied to user accounts, administrator accounts, applications, services, and devices. Organizations can enforce this principle by regularly reviewing permissions and removing unnecessary access. By limiting privileges, organizations reduce the attack surface and make unauthorized access or privilege abuse more difficult.<\/span><\/p>\n<h3><b>Question 344<\/b><\/h3>\n<p><b>Which technology can prevent unauthorized devices from connecting to a corporate network based on security policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HIDS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Access Control (NAC) is a security technology that controls which devices are allowed to connect to a corporate network. NAC can evaluate devices based on security policies such as device identity, authentication status, operating system, security software, and patch level. If a device does not meet the required security standards, NAC can deny access, place the device in a restricted network, or require remediation before allowing normal access. This helps organizations prevent unauthorized or noncompliant devices from connecting to sensitive resources. NAC is commonly used in enterprise environments to improve network security and ensure that only approved and properly configured devices receive network access.<\/span><\/p>\n<h3><b>Question 345<\/b><\/h3>\n<p><b>An employee receives a fraudulent text message asking them to verify their banking credentials through a link. What type of attack is this?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pharming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pretexting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Smishing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Smishing is a form of phishing that uses SMS messages or other text-based messaging services to deceive victims. In this scenario, the attacker sends a fraudulent message pretending to represent a trusted bank or organization and asks the employee to verify their credentials through a link. The link may lead to a fake website designed to steal usernames, passwords, banking details, or other sensitive information. Attackers often use urgency or threatening messages to encourage victims to act quickly. Users should avoid clicking suspicious links and should verify requests through official channels. Smishing is specifically associated with phishing attacks delivered through text messages.<\/span><\/p>\n<h3><b>Question 346<\/b><\/h3>\n<p><b>Which mechanism is used to verify that a file has not been altered since its original hash value was recorded?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash comparison<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Steganography<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hash comparison is a method used to determine whether a file has been changed since a trusted hash value was created. A hashing algorithm processes the file and produces a unique-looking fixed-length value called a hash. If the file is modified, even slightly, its new hash will normally be different from the original value. By calculating the file&#8217;s current hash and comparing it with the previously recorded trusted hash, administrators can identify unauthorized or unexpected changes. Hash comparison is commonly used for file integrity monitoring, software verification, and security investigations. However, a hash by itself does not provide confidentiality because it does not encrypt the original data.<\/span><\/p>\n<h3><b>Question 347<\/b><\/h3>\n<p><b>A security administrator separates a company&#8217;s accounting network from its guest wireless network. Which security technique is being implemented?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation is a security technique that divides a larger network into separate logical or physical sections. In this example, separating the accounting network from the guest wireless network prevents unnecessary communication between sensitive internal systems and untrusted guest devices. Access between network segments can be controlled using firewalls, access control lists, or other security technologies. Segmentation helps reduce the attack surface and can limit an attacker\u2019s ability to move laterally if one part of the network becomes compromised. It is commonly used to separate sensitive systems, employee devices, guest networks, servers, and other resources according to their security requirements and business functions.<\/span><\/p>\n<h3><b>Question 348<\/b><\/h3>\n<p><b>Which encryption approach uses a public key and a private key for secure communication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asymmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Symmetric encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asymmetric encryption uses a mathematically related pair of cryptographic keys: a public key and a private key. The public key can be shared openly, while the private key must be kept secret and securely protected. Depending on the cryptographic process, information encrypted with one key can be processed using the corresponding key. Asymmetric cryptography is commonly used for secure communication, digital signatures, authentication, and exchanging information securely. It differs from symmetric encryption, which uses the same secret key for encryption and decryption. Asymmetric encryption generally requires more computational resources than symmetric encryption, so it is often combined with symmetric encryption in secure communication systems.<\/span><\/p>\n<h3><b>Question 349<\/b><\/h3>\n<p><b>Which security technology is specifically designed to inspect and filter HTTP and HTTPS requests sent to a web application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Web Application Firewall (WAF) is a security technology specifically designed to monitor, inspect, and filter HTTP and HTTPS traffic directed toward web applications. It can analyze web requests and responses to identify potentially malicious activity. A WAF can help protect applications against common attacks such as SQL injection, Cross-Site Scripting (XSS), malicious requests, and other application-layer threats. Security administrators can configure rules that allow legitimate traffic while blocking or alerting on suspicious requests. Unlike a traditional network firewall, which primarily controls network traffic based on addresses and ports, a WAF focuses specifically on protecting web applications and their associated HTTP or HTTPS traffic.<\/span><\/p>\n<h3><b>Question 350<\/b><\/h3>\n<p><b>An organization allows only preapproved applications to execute on company endpoints. Which control is being used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting is a security control that permits only specifically approved applications to execute on company systems. Instead of allowing all software to run by default, the organization creates a list of trusted applications and prevents unauthorized programs from executing. This can reduce the risk of malware, ransomware, unauthorized software, and other potentially harmful programs running on endpoints. Allowlisting can be especially useful in environments where systems perform specific business functions and only a limited number of applications are required. Administrators should regularly review and update the approved application list to ensure legitimate software can operate while unnecessary or suspicious programs remain blocked.<\/span><\/p>\n<h3><b>Question 351<\/b><\/h3>\n<p><b>Which type of attack attempts to manipulate a vulnerable application by inserting malicious SQL statements into input fields?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL injection is a web application attack in which an attacker inserts malicious SQL statements into application input fields or other user-controlled data. If the application does not properly validate or handle the input, the injected commands may be interpreted by the database as legitimate SQL instructions. Depending on the vulnerability, an attacker may be able to access, modify, delete, or manipulate database information. SQL injection can also expose sensitive data stored by the application. Secure coding practices such as parameterized queries, prepared statements, proper input validation, and least-privilege database accounts can help prevent this type of attack and reduce its potential impact.<\/span><\/p>\n<h3><b>Question 352<\/b><\/h3>\n<p><b>Which authentication factor category does a fingerprint represent?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you are<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you have<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Somewhere you are<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A fingerprint represents the \u201csomething you are\u201d category of authentication because it is a biometric characteristic that is physically associated with an individual. Other examples of this factor include facial recognition, iris patterns, voice characteristics, and other measurable biological traits. In comparison, \u201csomething you know\u201d includes passwords or PINs, while \u201csomething you have\u201d includes security tokens, smart cards, or mobile devices. Authentication systems may combine different factor categories to provide stronger security through multi-factor authentication. Biometric authentication can make unauthorized access more difficult because biometric characteristics are generally harder to share or guess than traditional passwords.<\/span><\/p>\n<h3><b>Question 353<\/b><\/h3>\n<p><b>A company requires two employees to approve a high-value financial transaction. Which security principle does this demonstrate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties is a security principle that divides important or sensitive responsibilities among multiple individuals. In this example, requiring two employees to approve a high-value financial transaction prevents a single person from independently completing the entire operation. This reduces the risk of fraud, misuse of authority, and unauthorized transactions. It also creates an additional verification step because more than one person must participate in the process. Separation of duties is commonly used in financial systems, administrative processes, security operations, and other environments involving sensitive activities. The principle helps provide accountability and ensures that critical actions receive appropriate oversight before they are completed.<\/span><\/p>\n<h3><b>Question 354<\/b><\/h3>\n<p><b>Which backup type contains all changes made since the last full backup?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Snapshot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mirror<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Differential<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incremental<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A differential backup stores all data that has changed since the most recent full backup. Each new differential backup continues to include changes made after that original full backup, so its size generally increases over time until another full backup is created. During restoration, a full backup and the latest differential backup are typically required. This differs from an incremental backup, which stores only the changes made since the previous backup of any type. Differential backups can make restoration simpler than a sequence of multiple incremental backups, although they may require more storage as they grow. Organizations choose backup methods based on recovery requirements, storage capacity, and operational needs.<\/span><\/p>\n<h3><b>Question 355<\/b><\/h3>\n<p><b>Which security device can actively block malicious network traffic after detecting an intrusion?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Prevention System (IPS) is a security device or technology that can detect malicious network activity and automatically take action to block or prevent the detected threat. An IPS can analyze traffic for known attack signatures, suspicious patterns, or policy violations and then block harmful connections or packets. This helps prevent attacks from reaching protected systems. An Intrusion Detection System (IDS), in contrast, primarily monitors activity and generates alerts when suspicious behavior is detected but does not normally block the traffic itself. IPS solutions are commonly deployed at network boundaries or other strategic locations where they can inspect traffic and respond to threats in real time.<\/span><\/p>\n<h3><b>Question 356<\/b><\/h3>\n<p><b>A user is redirected to a fraudulent website after entering the correct domain name into a browser. Which attack could cause this behavior by manipulating DNS information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS poisoning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS poisoning is an attack in which an attacker corrupts or manipulates Domain Name System (DNS) information so that legitimate domain requests can resolve to an incorrect or malicious destination. As a result, a user may enter the correct website address but be redirected to a fraudulent website controlled by the attacker. The fake website may attempt to steal usernames, passwords, financial information, or other sensitive data. DNS poisoning can affect users who rely on the compromised DNS information. Organizations can reduce this risk through secure DNS practices, monitoring, DNS security mechanisms, and proper network protection. The attack targets the process used to translate domain names into IP addresses.<\/span><\/p>\n<h3><b>Question 357<\/b><\/h3>\n<p><b>Which control is most appropriate for preventing unauthorized individuals from physically following employees through a secured entrance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bollard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cable lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security camera<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mantrap<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A mantrap is a physical security control designed to prevent unauthorized individuals from following authorized personnel through a secured entrance. It typically consists of a small enclosed area with two controlled doors. The first door must normally close and lock before the second door can open, allowing the access-control system to verify the person before granting entry. This helps prevent tailgating, also known as piggybacking, where an unauthorized person attempts to enter a restricted area by following an authorized employee. Mantraps are commonly used in locations requiring strong physical security, including data centers, government facilities, financial institutions, and other sensitive environments.<\/span><\/p>\n<h3><b>Question 358<\/b><\/h3>\n<p><b>Which technology can securely store cryptographic keys and perform sensitive cryptographic operations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Hardware Security Module (HSM) is a specialized security device designed to protect cryptographic keys and perform sensitive cryptographic operations. HSMs can securely generate, store, manage, and use encryption keys while helping prevent unauthorized access to the keys themselves. They can also perform operations such as encryption, decryption, digital signing, and certificate-related functions within a protected hardware environment. HSMs are commonly used by banks, governments, cloud providers, and large organizations where strong protection of cryptographic keys is required. By providing dedicated hardware-based security, an HSM can reduce the risk of sensitive keys being exposed through ordinary software or operating system environments.<\/span><\/p>\n<h3><b>Question 359<\/b><\/h3>\n<p><b>An attacker gains control of a legitimate user\u2019s active web session by stealing the session identifier. What type of attack is this?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pharming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replay attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Session hijacking is an attack in which an attacker obtains a valid session identifier or session token and uses it to impersonate an authenticated user. Web applications commonly create session identifiers after a user successfully logs in, allowing the user to remain authenticated without repeatedly entering their password. If an attacker steals this identifier, they may be able to take control of the active session and access resources as the legitimate user. Attackers may obtain session information through various security weaknesses, including insecure applications or compromised devices. Secure session management, HTTPS, protected cookies, session expiration, and other controls can help reduce the risk of session hijacking.<\/span><\/p>\n<h3><b>Question 360<\/b><\/h3>\n<p><b>Which security approach assumes that no user or device should automatically be trusted, even when connecting from inside the corporate network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust is a security approach based on the principle that users, devices, applications, and network connections should not be automatically trusted simply because they are inside a corporate network. Instead, access requests should be continuously evaluated and verified based on factors such as identity, device security, location, requested resource, and risk. Zero Trust commonly follows the principle of \u201cnever trust, always verify\u201d and applies least-privilege access to reduce unnecessary permissions. This approach helps limit the impact of compromised accounts or devices and reduces opportunities for attackers to move through internal networks. Zero Trust is increasingly used to protect modern cloud, hybrid, and enterprise environments.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full\u00a0CompTIA SY0-701 Exam Dumps\u00a0and Practice Test Dumps. &nbsp; Question 341 Which security solution is primarily designed to collect and correlate logs from multiple systems to identify suspicious activity? DLP NAC SIEM HSM Correct Answer: 3 Explanation A Security Information and Event Management (SIEM) solution is designed to collect, centralize, and analyze security logs and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11761"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11761"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11761\/revisions"}],"predecessor-version":[{"id":11762,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11761\/revisions\/11762"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11761"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11761"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11761"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}