SY0-701 — Frequently Asked Questions

Community-vetted answers to 30 common questions about this exam.

CCTV systems are a Detective control, while warning signs are a Deterrent control.

Decommissioning is recommended when a device is end-of-life (EOL), no longer receives security patches, and poses a significant risk to the network.

Key controls include a VPN for encrypted access, Multi-Factor Authentication (MFA) for strong identity verification, and strict Access Control Lists (ACLs).

The Policy Engine is the core component that makes the final decision to allow or deny access to resources in the Data Plane.

This action is typically associated with the 'Traffic Signaling' or 'Redirector' technique, used to reroute network traffic for interception or manipulation.

An SDLC typically includes phases such as Planning, Analysis, Design, Implementation (Coding), Testing, Deployment, and Maintenance.

The best approach is to segment the server on an isolated VLAN or network segment to limit its exposure and prevent lateral movement in case of a compromise.

It enhances accountability and aids in asset management by creating a clear audit trail that links a specific physical device to a single user.

The laptop should be securely wiped using a data sanitization method (like a DoD wipe) and then re-imaged with a fresh OS installation before being reissued.

Analysts should expand the shortened URL using a safe, trusted tool to inspect the final destination before determining if it is malicious.

This is known as a False Positive, where a security tool incorrectly identifies a benign condition as a threat.

Implementing full-disk encryption and enforcing strong screen locks (PIN, password, biometrics) are the most effective controls to protect data on a lost device.

Enable 802.1X network access control (NAC) with MAC Authentication Bypass (MAB) to authenticate both the IP phone and any device connected to its data port.

The first step is to conduct targeted security awareness training for the affected users, focusing on the specific attack vector used (e.g., phishing).

This is known as an End-of-Life (EOL) or End-of-Service (EOS) device, which represents a significant security risk.

The primary risk is the presence of unpatched, known vulnerabilities, as the vendor no longer provides security updates or patches.

The Red Team (or Penetration Testers) is responsible for simulating real-world attacks to validate the exploitability of vulnerabilities.

Obfuscation is a technique used to alter the appearance of malicious code to evade detection by signature-based security controls like antivirus software.

Using a password (Know), a built-in fingerprint reader (Are), and a pre-existing company smartphone with an authenticator app (Have) is a cost-effective solution.

An AUP is a Preventative Administrative control, as it sets rules to prevent undesirable behavior.

A Disaster Recovery Plan (DRP) focuses on the technical steps to restore IT infrastructure and operations after a major disruption.

The first step is to conduct a comprehensive data inventory and classification to understand what personal data is collected, where it is stored, and how it is processed.

This technique is called Salting. It adds a unique, random value to each password before hashing to prevent attacks using rainbow tables.

This is a DNS Poisoning (or DNS Cache Poisoning) attack, where corrupt DNS data is introduced into a resolver's cache.

A Honeypot is a decoy system designed to attract attackers, allowing security teams to study their methods and detect unauthorized activity.

Symmetric encryption uses a single, shared secret key for both the encryption and decryption of data.

The first step is to identify and classify the sensitive data that the DLP solution needs to protect (e.g., PII, PHI, intellectual property).

This is a Business Email Compromise (BEC) attack, which is a sophisticated form of spear-phishing.

The Rules of Engagement (RoE) document formally outlines the scope, limitations, and authorized activities for a penetration test.

A Secure Access Service Edge (SASE) or Zero Trust Network Access (ZTNA) architecture allows for this by routing traffic through a cloud security service.

Ready to practice?

Access 100 SY0-701 questions with instant feedback and detailed explanations.

View SY0-701 Practice Questions →

← Back to SY0-701 CompTIA Security+ Study Guide