SY0-701 exam dumps

SY0-701 practice question 1 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 1

Select 21.1 Compare and contrast various types of security controls.

A healthcare company experienced a phishing incident that led to unauthorized access to an employee's email account. During the post-incident review, management decides to reduce the likelihood of similar compromises and to improve the ability to detect them quickly if they occur again. Which TWO security controls best meet these goals?

  1. A

    Implement mandatory annual security awareness training focused on phishing recognition

  2. B

    Deploy multifactor authentication (MFA) for employee email access

  3. C

    Install bollards outside the main office entrance

  4. D

    Enable security information and event management (SIEM) alerting for suspicious sign-in activity

  5. E

    Purchase cyber liability insurance

Show answer and explanation

Correct answers: B, D

Explanation

This question tests the ability to compare and apply different types of security controls in a real-world scenario. The best answers are MFA and SIEM alerting because they align directly with the two stated goals: prevention and detection. MFA is a preventive technical control that reduces the chance of successful account compromise after credential theft. SIEM alerting is a detective technical control that improves visibility into suspicious authentication events so responders can act quickly. Security awareness training is also valuable and is commonly recommended in security programs, but in this scenario it addresses only part of the requirement and does not provide direct technical detection. Physical controls like bollards and risk-transfer measures like insurance are valid security-related measures, but they do not address the email account compromise scenario. This mapping of controls is consistent with common Security+ classifications such as preventive, detective, corrective, deterrent, compensating, physical, technical, and administrative controls, and aligns with widely accepted guidance such as NIST security control families and general best practices for identity and access management and security monitoring.

  • A. Incorrect.

    This is a plausible choice because security awareness training is an administrative control and can help reduce phishing success. However, the scenario asks for controls that both reduce the likelihood of account compromise and improve rapid detection if compromise occurs. Training helps prevention but does not directly improve technical detection of suspicious account use. It is beneficial, but it does not best satisfy both goals together compared with MFA and SIEM alerting.

  • B. Correct.

    This is correct. MFA is a preventive technical control that reduces the likelihood that stolen credentials alone will result in unauthorized access. In real environments, phishing often captures passwords, and MFA adds an additional factor that significantly limits account takeover risk.

  • C. Incorrect.

    This is incorrect. Bollards are a physical preventive control designed to protect people and facilities from vehicle-based threats. They do not address phishing-related email compromise or account misuse, so they are not relevant to the stated goals.

  • D. Correct.

    This is correct. SIEM alerting for suspicious sign-in activity is a detective technical control. It helps security teams identify anomalous behavior such as impossible travel, repeated failed logins, unusual geolocation, or atypical login times, improving the organization's ability to detect compromised accounts quickly.

  • E. Incorrect.

    This is incorrect. Cyber liability insurance is a compensating or risk-transfer measure that can help offset financial impact after an incident, but it does not prevent phishing-based compromise or improve operational detection of malicious sign-in activity.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam