CompTIA Security+ (SY0-701) practice questions
256 free questions with answers and explanations.
- 251.A security administrator is configuring access controls for a new application. The policy states that 'users in the 'Managers' group can access financial reports only if their department is 'Sales' AND the current time is between 9 AM and 5 PM on a weekday.' Which access control model is being implemented?Security Operations
- 252.A security analyst is investigating a suspected data exfiltration event. The analyst discovers that several internal IP addresses are making uncharacteristic outbound connections to a known malicious IP address associated with a botnet command and control server. Which type of threat intelligence is the analyst primarily using to identify this activity?Security Operations
- 253.A company is implementing a security awareness program. They want to simulate real-world phishing attacks to assess employee susceptibility and provide targeted training. Which of the following activities would BEST achieve this goal?Security Operations
- 254.A security analyst is conducting a forensic investigation after a suspected intrusion. To ensure the integrity and authenticity of the collected digital evidence, the analyst calculates a hash value of each piece of evidence immediately after acquisition and before any analysis. Which fundamental principle of digital forensics is being addressed by this action?Security Operations
- 255.A security analyst is conducting a forensic investigation after a suspected intrusion. To ensure the integrity of the collected evidence, the analyst must create a mathematically verifiable copy of a hard drive before performing any analysis. Which of the following tools or techniques is essential for this step?Security Operations
- 256.A security analyst is investigating a suspected data breach. Forensic analysis reveals that an attacker gained access to a database containing sensitive customer information. To prevent future unauthorized access to this data, the analyst recommends implementing a control that will prevent the database from being accessed directly from the internet, and instead require all access to pass through a web application firewall (WAF) and an intrusion prevention system (IPS). Which type of control category is the analyst recommending?General Security Concepts