CompTIAAssociate levelSY0-701Page 4 of 5

SY0-701 exam dumps: questions 301 to 400 of 490

Page 4 of the free SY0-701 question bank for the Security+ exam. Questions 301 to 400 are listed below, the first 5 in full with answers and explanations. Back to page 1 for the exam overview and FAQ.

Question bank last updated June 2026

Free SY0-701 practice questions

Questions 301 to 305 of 490

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

SY0-701 Question 301

Single answerVulnerability response and remediation: Patching , Insurance , Segmentation , Compensating controls , Exceptions and exemptions

A hospital's security team identifies a critical remote-code-execution vulnerability on a legacy radiology server that processes imaging data for patient care. The vendor has confirmed that no patch is currently available, and replacing the system will take several months due to regulatory validation requirements. The server must remain operational, but the risk of compromise is unacceptable in its current state. Which action should the security team take FIRST to most appropriately address the vulnerability while aligning with sound remediation practices?

  1. A

    Purchase cyber insurance immediately and continue operating the server normally until a patch is released

  2. B

    Create a documented risk exception and accept the vulnerability because the system is required for patient care

  3. C

    Isolate the server in a restricted network segment and apply compensating controls such as tightly limited firewall rules and enhanced monitoring

  4. D

    Disable all logging on the server to reduce performance impact and avoid service interruption during exploitation attempts

Show answer and explanation

Correct answer: C

Explanation

The best answer is to isolate the vulnerable system and apply compensating controls. In vulnerability response and remediation, patching is preferred when available, but when no patch exists and the asset must stay online, organizations should reduce exposure through segmentation, firewall restrictions, access control, and continuous monitoring. This aligns with common security best practices such as defense in depth, least privilege, and risk treatment through mitigation. A formal exception may still be needed for governance purposes, but it should not replace technical risk reduction. Cyber insurance can be part of overall risk management, but it is not a substitute for remediation or mitigation. Guidance from NIST vulnerability and risk management practices, including compensating safeguards and ongoing monitoring, supports implementing interim controls when immediate patching is not possible.

  • A. Incorrect.

    This is incorrect. Cyber insurance may help transfer some financial risk after an incident, but it does not remediate the vulnerability or reduce the likelihood of exploitation. Insurance is not a technical control and should not be the first response to an actively exposed critical vulnerability.

  • B. Incorrect.

    This is incorrect. A documented exception or exemption may be part of governance when immediate remediation is not possible, but simply accepting the risk without first implementing reasonable safeguards is poor security practice. Exceptions should typically be time-bound, formally approved, and paired with compensating controls when feasible.

  • C. Correct.

    This is correct. When patching is not immediately possible, segmentation and compensating controls are appropriate first steps to reduce exposure. Restricting network access, limiting allowed communications, and increasing monitoring can significantly reduce exploitability while the organization pursues a long-term fix or replacement. This is a practical vulnerability response approach for critical legacy systems that must remain online.

  • D. Incorrect.

    This is incorrect. Disabling logging weakens detection and incident response capabilities and does nothing to reduce the underlying vulnerability. In a high-risk scenario, enhanced logging and monitoring are generally more appropriate, not less.

SY0-701 Question 302

Single answerValidation of remediation: Rescanning , Audit , Verification

A security administrator deployed patches to address a critical web server vulnerability identified during last week's vulnerability scan. Change records show the patches were applied successfully, but the organization must now confirm that the issue is actually resolved before closing the ticket. Which action is the BEST next step to validate remediation?

  1. A

    Review the original scan report and mark the finding as resolved because the patch was approved and deployed

  2. B

    Perform a targeted rescan of the affected web server and verify the vulnerability no longer appears

  3. C

    Wait until the next quarterly audit to determine whether the remediation was effective

  4. D

    Ask the system owner to confirm that the application is working normally and close the finding

Show answer and explanation

Correct answer: B

Explanation

The best answer is to perform a targeted rescan of the affected web server and verify that the vulnerability no longer appears. In Security+ terms, validation of remediation focuses on confirming that a corrective action was effective, not just that it was attempted. Rescanning is the most direct technical method for this because it compares the post-remediation state against the original finding. Audit records, change tickets, and deployment logs are important supporting evidence, but they primarily demonstrate that a process was followed. Verification requires evidence that the vulnerability was actually removed or mitigated. In practice, many organizations use a combination of change documentation, rescanning, and analyst review before formally closing findings. This aligns with common vulnerability management best practices from sources such as NIST guidance on continuous monitoring and remediation validation, where organizations are expected to verify that security deficiencies have been corrected rather than assuming success based solely on implementation records.

  • A. Incorrect.

    This is incorrect because reviewing the original scan report does not validate that remediation was successful. The original report only shows the vulnerability existed at the time of the initial assessment. Patch deployment records are useful for change management and audit purposes, but they do not prove the vulnerability is no longer present.

  • B. Correct.

    This is correct because validation of remediation requires confirming that the control or fix actually removed the identified weakness. A targeted rescan of the affected asset is a standard best practice after remediation. It provides current evidence that the vulnerability is no longer detected and supports verification before closing the ticket.

  • C. Incorrect.

    This is incorrect because an audit can help confirm process compliance and documentation, but waiting for a future audit delays validation and leaves uncertainty about the current security posture. Audits are not a substitute for prompt technical verification after remediation.

  • D. Incorrect.

    This is incorrect because functional testing by the system owner may confirm that the application still works, but normal operation does not prove the vulnerability has been eliminated. This is a common misconception: availability or usability checks are not the same as security verification.

SY0-701 Question 303

Single answerValidation of remediation: Rescanning , Audit , Verification

After applying emergency patches to several internet-facing Linux web servers to remediate a critical vulnerability identified during a recent vulnerability scan, a security analyst must validate that the remediation was successful before closing the ticket. Which action BEST demonstrates proper validation of remediation?

  1. A

    Run a targeted rescan of the affected servers and verify the vulnerability no longer appears in the scan results

  2. B

    Close the finding after the system administrator confirms the patches were installed successfully

  3. C

    Wait until the next quarterly audit to determine whether the remediation was effective

  4. D

    Review the original vulnerability report to confirm the issue was documented and risk-ranked correctly

Show answer and explanation

Correct answer: A

Explanation

The best answer is to perform a targeted rescan of the remediated systems and verify that the vulnerability no longer appears. In Security+ terms, validation of remediation means confirming that corrective actions were effective, not just implemented. Rescanning is a primary method because it provides technical evidence that the previously identified weakness is no longer detectable. Verification can also include checking patch levels, configuration states, or manual testing where appropriate, but the most direct answer here is a targeted rescan. Audits serve a different purpose: they assess adherence to policies, procedures, and control requirements, often on a periodic basis, and are not the immediate mechanism for validating a single remediation event. Best practices from vulnerability management programs and common guidance such as NIST vulnerability management processes emphasize remediation followed by verification or rescanning before closure of findings.

  • A. Correct.

    Correct. Validation of remediation requires confirming that the vulnerability is no longer present after the fix is applied. A targeted rescan of the affected assets is the most direct and appropriate way to verify that the patch or configuration change actually resolved the issue. This is a standard post-remediation practice in vulnerability management workflows.

  • B. Incorrect.

    Incorrect. Administrator confirmation is helpful as supporting evidence, but it is not sufficient by itself to validate remediation. A patch may fail, be applied incorrectly, or not fully resolve the finding. Security teams should independently verify the result rather than relying only on attestation.

  • C. Incorrect.

    Incorrect. An audit may later confirm process compliance or control effectiveness, but waiting for a scheduled audit does not provide timely verification that the specific vulnerability was remediated. Validation should occur immediately after remediation, not months later.

  • D. Incorrect.

    Incorrect. Reviewing the original report helps with documentation and understanding scope, but it does not confirm that the environment is now secure. Validation of remediation focuses on confirming the issue has been fixed, typically through rescanning, testing, or other technical verification.

SY0-701 Question 304

Single answerReporting

A security analyst has completed the initial investigation of a ransomware incident affecting several file servers. Executive leadership wants a report within the hour that explains business impact, current containment status, and the immediate actions required from nontechnical stakeholders. At the same time, the incident response team needs a separate document with indicators of compromise, affected hosts, timeline details, and evidence references for continued investigation. Which reporting approach is the MOST appropriate?

  1. A

    Create a single detailed technical report and send it to both executives and the incident response team to ensure everyone has the same information

  2. B

    Prepare an executive summary for leadership and a separate technical incident report for the response team, tailoring the level of detail to each audience

  3. C

    Delay reporting until forensic imaging is complete so the organization does not distribute incomplete or potentially inaccurate information

  4. D

    Provide only a verbal briefing to leadership first and avoid written documentation until the legal department approves every incident detail

Show answer and explanation

Correct answer: B

Explanation

The best answer is to produce separate reports tailored to the intended audience. In Security+ reporting scenarios, a key principle is that reports should be accurate, timely, and relevant to stakeholder needs. Executives usually need a high-level summary covering business impact, operational disruption, financial or reputational considerations, current response status, and decisions or approvals required. Technical teams need deeper detail such as affected assets, attack timeline, observables, evidence locations, and response actions. This aligns with common incident response guidance from NIST, including NIST SP 800-61, which emphasizes coordinated incident handling and communication with different stakeholders throughout the incident lifecycle. Good reporting also supports chain of custody, lessons learned, regulatory response, and management decision-making without overloading nontechnical readers with unnecessary forensic detail.

  • A. Incorrect.

    This is incorrect because using one highly technical report for all audiences is not effective reporting practice. Executives typically need concise, business-focused information such as operational impact, risk, decisions needed, and status, while responders need detailed technical data to continue containment, eradication, and recovery. A single report often overwhelms leadership and still may not provide the structured technical depth responders require.

  • B. Correct.

    This is correct because effective security reporting is audience-specific. Leadership should receive an executive summary focused on business impact, scope, current status, and required decisions, while the incident response team should receive a technical report containing indicators of compromise, systems affected, evidence references, and investigative findings. This approach supports informed decision-making and operational response at the same time.

  • C. Incorrect.

    This is incorrect because incident reporting should be timely, even when all facts are not yet finalized. Waiting for full forensic completion can delay critical business decisions and stakeholder coordination. A preliminary report can clearly state that findings are initial and subject to change. Security best practices emphasize prompt, accurate, and appropriately scoped communication during active incidents.

  • D. Incorrect.

    This is incorrect because verbal briefings may be useful, but relying only on verbal communication creates gaps in documentation, accountability, and continuity. Written reporting is important for tracking actions, preserving timelines, supporting post-incident review, and meeting organizational or regulatory requirements. Legal review may be needed for some external communications, but that does not eliminate the need for prompt internal written reporting.

SY0-701 Question 305

Single answerReporting

A security analyst is preparing a monthly report for executive leadership after several phishing attempts and one confirmed malware infection were handled during the reporting period. The executives want a concise report that helps them decide whether additional funding is needed for email security improvements. Which of the following reporting approaches would BEST meet this need?

  1. A

    Provide a high-level summary showing phishing volume, the number of users affected, business impact, response outcomes, and trends compared with prior months

  2. B

    Include raw SIEM logs, full packet captures, and endpoint forensic artifacts so leadership can independently validate the incident details

  3. C

    Focus the report on every indicator of compromise, hash value, and registry change observed during the malware investigation

  4. D

    Limit the report to a statement that the incidents were resolved successfully and no further action is required

Show answer and explanation

Correct answer: A

Explanation

The best answer is the high-level summary tailored to executive leadership. In Security+ reporting scenarios, an important principle is audience-specific communication: executives need strategic, business-relevant information rather than deep technical artifacts. Effective executive reports typically include incident counts, trends over time, business impact, remediation status, residual risk, and recommendations. This aligns with common incident response and reporting best practices described by NIST, including guidance in NIST SP 800-61 on tailoring communications and reports to stakeholders. Technical details such as IOCs, packet captures, and host-level artifacts are more appropriate for SOC analysts, incident responders, or forensic teams, while executives need concise reporting that supports governance, risk, and funding decisions.

  • A. Correct.

    Correct. Executive reporting should be concise, business-focused, and decision-oriented. For leadership, the most useful report emphasizes metrics and trends such as incident volume, affected users or systems, operational or financial impact, response effectiveness, and whether current controls appear sufficient. This allows executives to assess risk posture and make funding or policy decisions without being overloaded by highly technical evidence.

  • B. Incorrect.

    Incorrect. Raw SIEM logs, packet captures, and forensic artifacts are appropriate for analysts, investigators, or auditors who need technical validation, but they are not appropriate as the primary format for executive reporting. This option reflects the common mistake of sending the same technical report to all audiences instead of tailoring reporting to stakeholder needs.

  • C. Incorrect.

    Incorrect. Indicators of compromise, hashes, and registry changes are valuable for technical incident reports, threat hunting, and detection tuning. However, they do not directly help executives evaluate business impact or justify budget decisions. This option confuses operational reporting for security teams with management reporting for leadership.

  • D. Incorrect.

    Incorrect. A report that only states the incidents were resolved lacks the context needed for informed decision-making. Executives need enough detail to understand frequency, impact, trends, control gaps, and recommendations. Omitting these elements can hide risk and prevent appropriate resource allocation.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

SY0-701 practice questions 301 to 400 of 490

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them. The bank is split into 5 pages of up to 100 questions.

  1. 301.A hospital's security team identifies a critical remote-code-execution vulnerability on a legacy radiology...
  2. 302.A security administrator deployed patches to address a critical web server vulnerability identified during...
  3. 303.After applying emergency patches to several internet-facing Linux web servers to remediate a critical...
  4. 304.A security analyst has completed the initial investigation of a ransomware incident affecting several file...
  5. 305.A security analyst is preparing a monthly report for executive leadership after several phishing attempts and...
  6. 306.A security analyst is overwhelmed by thousands of daily alerts from multiple tools, including the firewall,...
  7. 307.A security analyst is reviewing overnight alerts and sees that a domain controller generated hundreds of...
  8. 308.A security administrator is tuning monitoring controls after a recent incident in which a compromised web...
  9. 309.A security administrator is investigating an intermittent outage affecting a public web application hosted on...
  10. 310.A security analyst at a healthcare company is investigating a suspected phishing campaign that may have led...
  11. 311.A security administrator is improving the company’s monitoring program after an incident in which suspicious...
  12. 312.A security analyst notices that the EDR platform is repeatedly generating high-severity alerts for a finance...
  13. 313.A security analyst is investigating repeated endpoint detection and response (EDR) alerts for a finance...
  14. 314.A security administrator must improve visibility into suspicious outbound traffic from several remote office...
  15. 315.A security team must quickly improve visibility across a hybrid environment that includes on-premises...
  16. 316.A company recently adopted a hybrid work model and allows employees to access internal web applications from...
  17. 317.A company recently acquired a smaller business and needs to give the new employees access to several internal...
  18. 318.A company hosts a public web application in a screened subnet (DMZ). The web server must be reachable from...
  19. 319.A company hosts a public web application in a screened subnet (DMZ). The web server must be reachable from...
  20. 320.A security analyst notices that an organization’s network IPS is generating repeated alerts for outbound...
  21. 321.A security administrator deployed a network IPS at the internet edge and enabled a vendor-provided signature...
  22. 322.A company has moved to a hybrid work model, and many users now work from home without a VPN connection. The...
  23. 323.A company has moved to a hybrid work model, and many employees now work from home or travel frequently. The...
  24. 324.A company manages Windows 11 workstations through Active Directory and hosts a public-facing web application...
  25. 325.A company manages Windows workstations through Active Directory and runs a public-facing web application on a...
  26. 326.A company is deploying a new remote administration solution for Linux servers in a segmented data center. The...
  27. 327.A security administrator is replacing several legacy remote administration services used by network...
  28. 328.A company recently had several users click links in phishing emails that led to newly registered domains...
  29. 329.A company recently had several users click links in phishing emails that attempted to send them to newly...
  30. 330.A company recently moved its outbound marketing emails to a third-party cloud service. Soon after, customers...
  31. 331.A company uses a cloud email gateway to filter inbound and outbound mail for the domain example.com. The...
  32. 332.A security administrator enables file integrity monitoring (FIM) on a Linux-based public web server after a...
  33. 333.A security administrator is deploying file integrity monitoring (FIM) on a public-facing Linux web server...
  34. 334.A company recently allowed employees to use personal email and cloud storage sites from corporate laptops....
  35. 335.A healthcare organization allows employees to use a cloud-based email service and web browser access from...
  36. 336.A company is rolling out a network access control (NAC) solution to reduce the risk of unmanaged devices...
  37. 337.A company is rolling out network access control (NAC) for all wired and wireless connections. The security...
  38. 338.A security analyst is investigating a phishing incident in which a user opened a malicious attachment on a...
  39. 339.A security analyst is investigating a suspected phishing incident. An employee clicked a malicious link, and...
  40. 340.A company uses a SIEM with user behavior analytics (UBA) to detect insider threats. Over the past week, the...
  41. 341.A security analyst is tuning a newly deployed user behavior analytics (UBA) capability in the company SIEM....
  42. 342.A company recently integrated its HR system with its identity provider so that employee status changes...
  43. 343.A company is onboarding 150 temporary contractors for a six-week project. The contractors need access to a...
  44. 344.A company discovers that a recently terminated employee was still able to sign in to a cloud-based...
  45. 345.A company discovered that a recently terminated payroll administrator was still able to sign in to a cloud HR...
  46. 346.A security administrator is reviewing access to a shared finance folder on a Windows file server after an...
  47. 347.A systems administrator is reviewing access to a shared finance folder after an internal audit found that...
  48. 348.A healthcare company is rolling out a self-service process for issuing credentials to newly hired remote...
  49. 349.A healthcare organization is onboarding remote contractors who need access to systems containing regulated...
  50. 350.A company is integrating with a cloud-based partner portal so employees can use their existing corporate...
  51. 351.A company is acquiring a smaller business and needs users from both organizations to access a shared SaaS...
  52. 352.A company is integrating a new cloud-based human resources application with its existing on-premises identity...
  53. 353.A company uses an on-premises Active Directory environment as its central identity source and wants employees...
  54. 354.A healthcare company is integrating a cloud-based identity provider with several on-premises and SaaS...
  55. 355.A company is integrating a cloud-based identity provider with several third-party SaaS applications. The...
  56. 356.A company is rolling out remote access for administrators to manage critical servers from company-issued...
  57. 357.A company allows remote administrators to connect to a critical virtualization cluster only from approved...
  58. 358.A hospital is deploying a new electronic health record (EHR) system. Nurses must be able to view and update...
  59. 359.A hospital is deploying a new electronic health record (EHR) system. Nurses should be able to view and update...
  60. 360.A financial services company is rolling out multifactor authentication for employees who access cloud-based...
  61. 361.A healthcare organization is rolling out MFA for employees who access its cloud-based patient records system....
  62. 362.A financial services company is tightening access to its wire-transfer system after a phishing incident...
  63. 363.A financial services company allows employees to access its trading platform remotely. After several account...
  64. 364.A security administrator is updating the company’s password policy after several help desk tickets revealed...
  65. 365.A company is revising its password policy after a phishing campaign led to several account compromises. The...
  66. 366.A security administrator is revising the company password policy after several user accounts were compromised...
  67. 367.A security administrator is updating the password policy for a company after an internal audit found that...
  68. 368.A security administrator is rolling out a password manager to a hybrid workforce. The company wants to reduce...
  69. 369.A security administrator is deploying a password manager for a hybrid workforce. Employees currently reuse...
  70. 370.A company wants to reduce phishing-related account compromises for employees who access email, HR, and...
  71. 371.A healthcare company is replacing passwords for access to its patient records application because users...
  72. 372.A company is tightening controls over administrator access after an internal audit found that server...
  73. 373.A security administrator at a healthcare company needs to reduce the risk of privileged account misuse on...
  74. 374.A company is moving its administrative access model from shared service-account passwords to a more secure...
  75. 375.A company is moving its administrative access model to reduce the risk of stolen credentials being reused....
  76. 376.A security operations center (SOC) is overwhelmed by repeated phishing emails that deliver the same malicious...
  77. 377.A security operations center (SOC) is overwhelmed by repeated phishing alerts from the email gateway....
  78. 378.A company is moving to an automated joiner/mover/leaver process for cloud and SaaS accounts. The security...
  79. 379.A company is moving its employee onboarding and offboarding process to an automated workflow that integrates...
  80. 380.A company is expanding rapidly and now deploys new cloud-based application servers every week. The security...
  81. 381.A security manager at a rapidly growing company needs to reduce the time required to deploy new cloud servers...
  82. 382.A mid-sized company is replacing its aging VPN solution. The security team proposes a highly customized...
  83. 383.A mid-sized company is replacing its legacy remote access solution. The security team proposes a highly...
  84. 384.A security analyst discovers that a finance department workstation is communicating with a known...
  85. 385.A security analyst receives multiple alerts indicating that a finance department workstation is communicating...
  86. 386.A company’s security team detects ransomware activity on a file server after several users report that shared...
  87. 387.A security analyst discovers that several employee workstations are communicating with a known malicious...
  88. 388.A healthcare company wants to evaluate its incident response plan for a ransomware attack without disrupting...
  89. 389.A security manager wants to validate the company incident response plan for a ransomware attack without...
  90. 390.A security analyst is investigating why several internal file servers became unreachable for 20 minutes...
  91. 391.A security analyst is conducting a threat-hunting exercise after a recent industry alert about attackers...
  92. 392.A security analyst is conducting a threat hunt after receiving industry intelligence that a ransomware group...
  93. 393.A company discovers that a departing employee may have exfiltrated proprietary design files before leaving....
  94. 394.A company discovers that an employee may have exfiltrated sensitive design documents before resigning. Legal...
  95. 395.A security analyst is investigating a suspected compromise of a file server after several users reported...
  96. 396.A security analyst is investigating a suspected account compromise involving a finance employee. At 2:13...
  97. 397.A security analyst is investigating a suspected data exfiltration incident from a finance department...
  98. 398.A security analyst is investigating a suspected data exfiltration incident from a finance application server....
  99. 399.A security analyst is investigating reports that several internal web servers are intermittently failing...
  100. 400.A security analyst sees a spike in failed logon attempts on the SOC dashboard for a public-facing web...