オンライン問題で最適なSY0-701試験練習問題(最新の702問題)
練習問題SY0-701素晴らしい練習用のCompTIA Security+ Certification Examテスト問題
質問 # 345
A technician is opening ports on a firewall for a new system being deployed and supported by a SaaS provider.
Which of the following is a risk in the new system?
- A. Vulnerable software
- B. Supply chain vendor
- C. Default credentials
- D. Non-segmented network
正解:B
解説:
A supply chain vendor is a third-party entity that provides goods or services to an organization, such as a SaaS provider. A supply chain vendor can pose a risk to the new system if the vendor has poor security practices, breaches, or compromises that could affect the confidentiality, integrity, or availability of the system or its data. The organization should perform due diligence and establish a service level agreement with the vendor to mitigate this risk. The other options are not specific to the scenario of using a SaaS provider, but rather general risks that could apply to any system.
質問 # 346
The Cruel Information Security Officer (CISO) asks a security analyst to install an OS update to a production VM that has a 99% uptime SLA. The CISO tells me analyst the installation must be done as quickly as possible. Which of the following courses of action should the security analyst take first?
- A. Log in to the server and perform a health check on the VM.
- B. Install the patch Immediately.
- C. Confirm that the backup service is running.
- D. Take a snapshot of the VM.
正解:D
解説:
Before applying any updates or patches to a production VM, especially one with a 99% uptime SLA, it is crucial to first take a snapshot of the VM. This snapshot serves as a backup that can be quickly restored in case the update causes any issues, ensuring that the system can be returned to its previous state without violating the SLA. This step mitigates risk and is a standard best practice in change management for critical systems.
質問 # 347
Which of the following threat actors is the most likely to be hired by a foreign government to attack critical systems located in other countries?
- A. Unskilled attacker
- B. Organized crime
- C. Whistleblower
- D. Hacktivist
正解:B
解説:
Explanation
Organized crime is a type of threat actor that is motivated by financial gain and often operates across national borders. Organized crime groups may be hired by foreign governments to conduct cyberattacks on critical systems located in other countries, such as power grids, military networks, or financial institutions. Organized crime groups have the resources, skills, and connections to carry out sophisticated and persistent attacks that can cause significant damage and disruption12. References = 1: Threat Actors - CompTIA Security+ SY0-701
- 2.1 2: CompTIA Security+ SY0-701 Certification Study Guide
質問 # 348
A company is working with a vendor to perform a penetration test. Which of the following includes an estimate about the number of hours required to complete the engagement?
- A. SOW
- B. SLA
- C. NDA
- D. BPA
正解:A
解説:
A Statement of Work (SOW) is a formal document detailing the scope, deliverables, timeline, and estimated hours for services such as penetration testing engagements.
BPA (Blanket Purchase Agreement) covers recurring purchases, SLA (Service Level Agreement) defines service quality expectations, and NDA (Non-Disclosure Agreement) protects confidentiality, none of which specify hours or detailed scope.
SOWs are fundamental in managing third-party risk and engagements, covered under Security Program Management#6:Chapter 16 CompTIA Security+ Study Guide#.
質問 # 349
A client demands at least 99.99% uptime from a service provider's hosted security services.
Which of the following documents includes the information the service provider should return to the client?
- A. SLA
- B. MOA
- C. MOU
- D. SOW
正解:A
解説:
A service level agreement (SLA) is a document that defines the level of service expected by a customer from a service provider, indicating the metrics by which that service is measured, and the remedies or penalties, if any, should the agreed-upon levels not be achieved. An SLA can specify the minimum uptime or availability of a service, such as 99.99%, and the consequences for failing to meet that standard. A memorandum of agreement (MOA), a statement of work (SOW), and a memorandum of understanding (MOU) are other types of documents that can be used to establish a relationship between parties, but they do not typically include the details of service levels and performance metrics that an SLA does.
質問 # 350
A penetration test identifies that an SMBvl Is enabled on multiple servers across an organization. The organization wants to remediate this vulnerability in the most efficient way possible. Which of the following should the organization use for this purpose?
- A. SFTP
- B. ACL
- C. DLP
- D. GPO
正解:D
解説:
"Group Policy Objects (GPOs) are a feature of Microsoft Windows Active Directory that allow administrators to centrally manage and configure settings across multiple systems in an efficient manner. When a vulnerability such as SMBv1 (Server Message Block version 1) is identified on multiple servers, GPOs can be used to disable this outdated and insecure protocol across all affected systems simultaneously. By creating a GPO to enforce a policy that disables SMBv1, the organization can ensure consistent remediation without manually configuring each server individually, making it the most efficient solution for domain-joined environments."
質問 # 351
A company decided to reduce the cost of its annual cyber insurance policy by removing the coverage for ransomware attacks.
Which of the following analysis elements did the company most likely use in making this decision?
- A. IMTTR
- B. MTBF
- C. RTO
- D. ARO
正解:D
解説:
ARO (Annualized Rate of Occurrence) is an analysis element that measures the frequency or likelihood of an event happening in a given year. ARO is often used in risk assessment and management, as it helps to estimate the potential loss or impact of an event. A company can use ARO to calculate the annualized loss expectancy (ALE) of an event, which is the product of ARO and the single loss expectancy (SLE). ALE represents the expected cost of an event per year, and can be used to compare with the cost of implementing a security control or purchasing an insurance policy.
The company most likely used ARO in making the decision to remove the coverage for ransomware attacks from its cyber insurance policy. The company may have estimated the ARO of ransomware attacks based on historical data, industry trends, or threat intelligence, and found that the ARO was low or negligible. The company may have also calculated the ALE of ransomware attacks, and found that the ALE was lower than the cost of the insurance policy. Therefore, the company decided to reduce the cost of its annual cyber insurance policy by removing the coverage for ransomware attacks, as it deemed the risk to be acceptable or manageable.
IMTTR (Incident Management Team Training and Readiness), RTO (Recovery Time Objective), and MTBF (Mean Time Between Failures) are not analysis elements that the company most likely used in making the decision to remove the coverage for ransomware attacks from its cyber insurance policy. IMTTR is a process of preparing and training the incident management team to respond effectively to security incidents. IMTTR does not measure the frequency or impact of an event, but rather the capability and readiness of the team.
RTO is a metric that defines the maximum acceptable time for restoring a system or service after a disruption.
RTO does not measure the frequency or impact of an event, but rather the availability and continuity of the system or service. MTBF is a metric that measures the average time between failures of a system or component. MTBF does not measure the frequency or impact of an event, but rather the reliability and performance of the system or component.
References = CompTIA Security+ SY0-701 Certification Study Guide, page 97-98; Professor Messer's CompTIA SY0-701 Security+ Training Course, video 5.2 - Risk Management, 0:00 - 3:00.
質問 # 352
Which of the following would be the best way to handle a critical business application that is running on a legacy server?
- A. Segmentation
- B. Hardening
- C. Decommissioning
- D. Isolation
正解:B
解説:
Explanation
A legacy server is a server that is running outdated or unsupported software or hardware, which may pose security risks and compatibility issues. A critical business application is an application that is essential for the operation and continuity of the business, such as accounting, payroll, or inventory management. A legacy server running a critical business application may be difficult to replace or upgrade, but it should not be left unsecured or exposed to potential threats.
One of the best ways to handle a legacy server running a critical business application is to harden it. Hardening is the process of applying security measures and configurations to a system to reduce its attack surface and vulnerability. Hardening a legacy server may involve steps such as:
Applying patches and updates to the operating system and the application, if available Removing or disabling unnecessary services, features, or accounts Configuring firewall rules and network access control lists to restrict inbound and outbound traffic Enabling encryption and authentication for data transmission and storage Implementing logging and monitoring tools to detect and respond to anomalous or malicious activity Performing regular backups and testing of the system and the application Hardening a legacy server can help protect the critical business application from unauthorized access, modification, or disruption, while maintaining its functionality and availability. However, hardening a legacy server is not a permanent solution, and it may not be sufficient to address all the security issues and challenges posed by the outdated or unsupported system. Therefore, it is advisable to plan for the eventual decommissioning or migration of the legacy server to a more secure and modern platform, as soon as possible.
References: CompTIA Security+ SY0-701 Certification Study Guide, Chapter 3: Architecture and Design, Section 3.2: Secure System Design, Page 133 1; CompTIA Security+ Certification Exam Objectives, Domain
3: Architecture and Design, Objective 3.2: Explain the importance of secure system design, Subobjective:
Legacy systems 2
質問 # 353
Which of the following is the best reason to complete an audit in a banking environment?
- A. Regulatory requirement
- B. Self-assessment requirement
- C. Organizational change
- D. Service-level requirement
正解:A
解説:
A regulatory requirement is a mandate imposed by a government or an authority that must be followed by an organization or an individual. In a banking environment, audits are often required by regulators to ensure compliance with laws, standards, and policies related to security, privacy, and financial reporting. Audits help to identify and correct any gaps or weaknesses in the security posture and the internal controls of the organization.
References:
Official CompTIA Security+ Study Guide (SY0-701), page 507
Security+ (Plus) Certification | CompTIA IT Certifications 2
質問 # 354
A business uses Wi-Fi with content filleting enabled. An employee noticed a coworker accessed a blocked sue from a work computer and repotted the issue. While Investigating the issue, a security administrator found another device providing internet access to certain employees. Which of the following best describes the security risk?
- A. The host-based security agent Is not running on all computers.
- B. Employees who have certain credentials are using a hidden SSID.
- C. A rogue access point Is allowing users to bypass controls.
- D. A valid access point is being jammed to limit availability.
正解:C
質問 # 355
Which of the following is the best way to validate the integrity and availability of a disaster recovery site?
- A. Develop requirements for database encryption.
- B. Periodically test the generators.
- C. Lead a simulated failover.
- D. Conduct a tabletop exercise.
正解:C
解説:
A simulated failover tests the disaster recovery site's ability to handle a full transition of services.
This ensures all systems can function as expected during an actual disaster.
質問 # 356
Which of the following would be the greatest concern for a company that is aware of the consequences of non-compliance with government regulations?
- A. Right to be forgotten
- B. External compliance reporting
- C. Attestation
- D. Sanctions
正解:D
解説:
Sanctions imposed for non-compliance can include fines, legal actions, and loss of business licenses. These pose a significant financial and reputational risk to organizations.
質問 # 357
Which of the following should a security team do first before a new web server goes live?
- A. Apply patch management
- B. Harden the virtual host.
- C. Enable network intrusion detection.
- D. Create WAF rules.
正解:A
質問 # 358
Which of the following is used to quantitatively measure the criticality of a vulnerability?
- A. CVE
- B. CIA
- C. CVSS
- D. CERT
正解:C
解説:
Explanation
CVSS stands for Common Vulnerability Scoring System, which is a framework that provides a standardized way to assess and communicate the severity and risk of vulnerabilities. CVSS uses a set of metrics and formulas to calculate a numerical score ranging from 0 to 10, where higher scores indicate higher criticality.
CVSS can help organizations prioritize remediation efforts and compare vulnerabilities across different systems and vendors. The other options are not used to measure the criticality of a vulnerability, but rather to identify, classify, or report them. References: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 39
質問 # 359
A company is utilizing an offshore team to help support the finance department. The company wants to keep the data secure by keeping it on a company device but does not want to provide equipment to the offshore team. Which of the following should the company implement to meet this requirement?
- A. VDI
- B. MDM
- C. VPC
- D. VPN
正解:A
解説:
Virtual Desktop Infrastructure (VDI) allows a company to host desktop environments on a centralized server.
Offshore teams can access these virtual desktops remotely, ensuring that sensitive data stays within the company's infrastructure without the need to provide physical devices to the team. This solution is ideal for maintaining data security while enabling remote work, as all data processing occurs on the company's secure servers.
References =
* CompTIA Security+ SY0-701 Course Content: VDI is discussed as a method for securely managing remote access to company resources without compromising data security.
質問 # 360
Which of the following are cases in which an engineer should recommend the decommissioning of a network device? (Select two).
- A. The device is configured to use cleartext passwords.
- B. The device is moved to a different location in the enterprise.
- C. The device is moved to an isolated segment on the enterprise network.
- D. The device is unable to receive authorized updates.
- E. The device's encryption level cannot meet organizational standards.
- F. The device has been moved from a production environment to a test environment.
正解:A、E
解説:
B: The device is configured to use cleartext passwords. This is a major security vulnerability and poses a significant risk of unauthorized access. Devices using cleartext passwords should be decommissioned and replaced with devices using secure authentication methods.
E: The device's encryption level cannot meet organizational standards. If the device cannot encrypt data to the required level, it compromises the confidentiality of sensitive information and should be decommissioned. Organizational security policies should dictate the minimum acceptable encryption level for network devices.
質問 # 361
Which of the following best describes a use case for a DNS sinkhole?
- A. Attackers can see a DNS sinkhole as a highly valuable resource to identify a company's domain structure.
- B. A DNS sinkhole can be used to capture traffic to known-malicious domains used by attackers.
- C. A DNS sinkhole can be used to draw employees away from known-good websites to malicious ones owned by the attacker.
- D. A DNS sinkhole can be set up to attract potential attackers away from a company's network resources.
正解:B
解説:
DNS sinkhole intercepts attempts to visit harmful websites and redirects them so you don't end up reaching a malicious website and keeps your computer safe.
質問 # 362
During the onboarding process, an employee needs to create a password for an intranet account. The password must include ten characters, numbers, and letters, and two special characters. Once the password is created, the company will grant the employee access to other company-owned websites based on the intranet profile.
Which of the following access management concepts is the company most likely using to safeguard intranet accounts and grant access to multiple sites based on a user's intranet account? (Select two).
- A. Default password changes
- B. Federation
- C. Password complexity
- D. Password manager
- E. Identity proofing
- F. Open authentication
正解:B、C
解説:
Federation is an access management concept that allows users to authenticate once and access multiple resources or services across different domains or organizations. Federation relies on a trusted third party that stores the user's credentials and provides them to the requested resources or services without exposing them.
Password complexity is a security measure that requires users to create passwords that meet certain criteria, such as length, character types, and uniqueness. Password complexity can help prevent brute-force attacks, password guessing, and credential stuffing by making passwords harder to crack or guess. References: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 308-309 and 312-
313 1
質問 # 363
A systems administrator is auditing all company servers to ensure. They meet the minimum security baseline While auditing a Linux server, the systems administrator observes the /etc/shadow file has permissions beyond the baseline recommendation. Which of the following commands should the systems administrator use to resolve this issue?
- A. chmod
- B. grep
- C. dd
- D. passwd
正解:A
解説:
The chmod command is used to change file permissions on Unix and Linux systems. If the /etc/shadow file has permissions beyond the baseline recommendation, the systems administrator should use chmod to modify the file's permissions, ensuring it adheres to the security baseline and limits access to authorized users only.
References = CompTIA Security+ SY0-701 study materials, focusing on system hardening and file permissions management.
質問 # 364
Which of the following is the best reason to perform a tabletop exercise?
- A. To address audit findings
- B. To calculate the ROI
- C. To update the IRP
- D. To collect remediation response times
正解:C
質問 # 365
A technician wants to improve the situational and environmental awareness of existing users as they transition from remote to in-office work. Which of the following is the best option?
- A. Update the content of new hire documentation.
- B. Send out periodic security reminders.
- C. Modify the content of recurring training.
D Implement a phishing campaign
正解:C
解説:
Explanation
Recurring training is a type of security awareness training that is conducted periodically to refresh and update the knowledge and skills of the users. Recurring training can help improve the situational and environmental awareness of existing users as they transition from remote to in-office work, as it can cover the latest threats, best practices, and policies that are relevant to their work environment. Modifying the content of recurring training can ensure that the users are aware of the current security landscape and the expectations of their roles. References = CompTIA Security+ Study Guide with over 500 Practice Test Questions: Exam SY0-701,
9th Edition, Chapter 5, page 232. CompTIA Security+ (SY0-701) Certification Exam Objectives, Domain 5.1, page 18.
質問 # 366
A small business uses kiosks on the sales floor to display product information for customers. A security team discovers the kiosks use end-of-life operating systems. Which of the following is the security team most likely to document as a security implication of the current architecture?
- A. Cost of replacement
- B. Ease of recovery
- C. Product software compatibility
- D. Patch availability
正解:D
解説:
End-of-life operating systems are those that are no longer supported by the vendor or manufacturer, meaning they do not receive any security updates or patches. This makes them vulnerable to exploits and attacks that take advantage of known or unknown flaws in the software.
Patch availability is the security implication of using end-of-life operating systems, as it affects the ability to fix or prevent security issues. Other factors, such as product software compatibility, ease of recovery, or cost of replacement, are not directly related to security, but rather to functionality, availability, or budget.
質問 # 367
A company's web filter is configured to scan the URL for strings and deny access when matches are found.
Which of the following search strings should an analyst employ to prohibit access to non-encrypted websites?
- A. http://
- B. www.*.com
- C. :443
- D. encryption=off\
正解:A
解説:
A web filter is a device or software that can monitor, block, or allow web traffic based on predefined rules or policies. One of the common methods of web filtering is to scan the URL for strings and deny access when matches are found. For example, a web filter can block access to websites that contain the words "gambling",
"porn", or "malware" in their URLs. A URL is a uniform resource locator that identifies the location and protocol of a web resource. A URL typically consists of the following components: protocol://domain:port
/path?query#fragment. The protocol specifies the communication method used to access the web resource, such as HTTP, HTTPS, FTP, or SMTP. The domain is the name of the web server that hosts the web resource, such as www.google.com or www.bing.com. The port is an optional number that identifies the specific service or application running on the web server, such as 80 for HTTP or 443 for HTTPS. The path is the specific folder or file name of the web resource, such as /index.html or /images/logo.png. The query is an optional string that contains additional information or parameters for the web resource, such as ?q=security or
?lang=en. The fragment is an optional string that identifies a specific part or section of the web resource, such as #introduction or #summary.
To
prohibit access to non-encrypted websites, an analyst should employ a search string that matches the protocol of non-encrypted web traffic, which is HTTP. HTTP stands for hypertext transfer protocol, and it is a standard protocol for transferring data between web servers and web browsers. However, HTTP does not provide any encryption or security for the data, which means that anyone who intercepts the web traffic can read or modify the data. Therefore, non-encrypted websites are vulnerable to eavesdropping, tampering, or spoofing attacks. To access a non-encrypted website, the URL usually starts with http://, followed by the domain name and optionally the port number. For example, http://www.example.com or http://www.example.com:80. By scanning the URL for the string http://, the web filter can identify and block non-encrypted websites.
The other options are not correct because they do not match the protocol of non-encrypted web traffic.
Encryption=off is a possible query string that indicates the encryption status of the web resource, but it is not a standard or mandatory parameter. Https:// is the protocol of encrypted web traffic, which uses hypertext transfer protocol secure (HTTPS) to provide encryption and security for the data. Www.*.com is a possible domain name that matches any website that starts with www and ends with .com, but it does not specify the protocol. :443 is the port number of HTTPS, which is the protocol of encrypted web traffic. References = CompTIA Security+ Study Guide (SY0-701), Chapter 2: Securing Networks, page
69. Professor Messer's CompTIA SY0-701 Security+ Training Course, Section 2.1: Network Devices and Technologies, video: Web Filter (5:16).
質問 # 368
Which of the following is a common, passive reconnaissance technique employed by penetration testers in the early phases of an engagement?
- A. Exploit validation
- B. Pivoting
- C. Port scanning
- D. Open-source intelligence
正解:D
解説:
OSINT involves gathering information from publicly available sources, such as social media, websites, and online databases, without actively interacting with the target system. This technique helps in identifying potential vulnerabilities and understanding the target's environment before more intrusive methods are used.
質問 # 369
A security analyst receives an alert from a corporate endpoint used by employees to issue visitor badges. The alert contains the following details:
Which of the following best describes the indicator that triggered the alert?
- A. Blocked content
- B. Concurrent session usage
- C. Brute-force attack
- D. Account lockout
正解:C
解説:
Detailed Explanation:The activity described in the table, where multiple connection attempts are made on port
445 (used for SMB services), suggests a brute-force attack. The attacker likely used automated methods to guess credentials, causing multiple failures. Such attempts are a hallmark of brute-force attacks targeting shared resources. Reference: CompTIA Security+ SY0-701 Study Guide, Domain 4: Security Operations, Section: "Indicators of Malicious Activity".
質問 # 370
......
リアルなSY0-701試験別格な練習試験問題:https://www.goshiken.com/CompTIA/SY0-701-mondaishu.html
100%合格率でリアルなSY0-701試験成功ゲット:https://drive.google.com/open?id=1P3uYs2-XA0TzR4eahJ_m1m7fS-4yknQa