SY0-701 exam dumps

SY0-701 practice question 125 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 125

Single answer2.5 Explain the purpose of mitigation techniques used to secure the enterprise.

A company is expanding its remote workforce and has discovered that several employees' home computers were infected with malware after they used personal web browsers and downloaded unapproved software while connected to the corporate VPN. Leadership wants a mitigation technique that reduces the attack surface on company-managed laptops by preventing users from installing unauthorized applications and by allowing only approved software to run. Which of the following is the BEST solution?

  1. A

    Implement application allow listing on company-managed endpoints

  2. B

    Deploy a network intrusion prevention system at the VPN concentrator

  3. C

    Require full-disk encryption on all company-managed laptops

  4. D

    Enable port security on the corporate access layer switches

Show answer and explanation

Correct answer: A

Explanation

The best answer is application allow listing because the scenario specifically calls for a mitigation technique that reduces attack surface by preventing unauthorized applications from being installed or executed. In Security+ objectives related to enterprise mitigation techniques, application allow listing is a core hardening control for limiting software execution to trusted applications only. This is aligned with widely accepted best practices such as NIST guidance on application control and endpoint hardening, including principles found in NIST SP 800-53 controls related to least functionality and software restrictions. The other options are valid security controls in other contexts: NIPS helps inspect and block malicious traffic, full-disk encryption protects data at rest, and port security protects wired network access. However, none of them directly satisfies the requirement to allow only approved software to run on managed endpoints.

  • A. Correct.

    Correct. Application allow listing is a mitigation technique that permits only explicitly approved executables, libraries, or scripts to run on endpoints. In this scenario, the organization wants to prevent installation and execution of unauthorized software on company-managed laptops, which is exactly the purpose of allow listing. This directly reduces endpoint attack surface and is commonly recommended as part of endpoint hardening and application control.

  • B. Incorrect.

    Incorrect. A network intrusion prevention system (NIPS) at the VPN concentrator can help detect or block malicious network traffic, but it does not primarily prevent users from installing unauthorized applications or ensure that only approved software runs on endpoints. It is a useful network-layer control, but it does not address the core requirement as directly as application allow listing.

  • C. Incorrect.

    Incorrect. Full-disk encryption protects data at rest if a laptop is lost or stolen, helping preserve confidentiality. However, it does not stop users from installing unapproved software or prevent malware from executing while the system is powered on and in use. This is a common misconception because encryption is an important security control, but it addresses a different risk.

  • D. Incorrect.

    Incorrect. Port security is used on switches to limit which MAC addresses can connect to a physical switch port and can help prevent unauthorized devices on a wired network. It has little relevance to remote employees using company laptops over a VPN from home networks, and it does not control what software can be installed or executed on those laptops.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam