SY0-701 exam dumps

SY0-701 practice question 189 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 189

Single answerEmbedded systems

A hospital is deploying new network-connected infusion pumps that run a stripped-down embedded operating system. During a security review, the team discovers the pumps are rarely rebooted, have limited storage and processing capacity, and cannot support traditional endpoint detection software. The manufacturer provides digitally signed firmware updates through a centralized management platform. Which security control would BEST reduce the risk of unauthorized code running on the pumps while still fitting the technical constraints of these embedded systems?

  1. A

    Require secure boot and only allow digitally signed firmware to load

  2. B

    Install a full-featured host-based intrusion prevention agent on each pump

  3. C

    Enable weekly vulnerability scans directly against each pump using aggressive scan settings

  4. D

    Allow local administrators to apply emergency firmware updates from any USB drive

Show answer and explanation

Correct answer: A

Explanation

Embedded systems such as infusion pumps, HVAC controllers, IP cameras, and industrial sensors often have limited resources and cannot run standard endpoint security agents. In these environments, preventing unauthorized code execution is commonly achieved through platform integrity controls such as secure boot, trusted boot chains, code signing, and vendor-signed firmware updates. This aligns with embedded-device best practices from sources such as NIST guidance on IoT and device cybersecurity, which emphasize secure update mechanisms, software integrity, and least functionality. In this scenario, the most effective and practical control is to require secure boot and only load digitally signed firmware, because it directly addresses the risk of malicious or unapproved code while respecting the technical limitations of the embedded platform.

  • A. Correct.

    Correct. Secure boot helps ensure the device starts only trusted software by validating signatures during the boot process, and restricting firmware to digitally signed updates reduces the chance of unauthorized or malicious code being installed. This is especially appropriate for embedded systems with limited CPU, memory, and storage, where lightweight integrity controls are more practical than traditional endpoint security tools.

  • B. Incorrect.

    Incorrect. Full host-based intrusion prevention or endpoint detection agents are often not feasible on embedded medical devices because of limited system resources, vendor support restrictions, and patient safety concerns. A candidate might choose this because HIPS is effective on general-purpose systems, but embedded devices frequently cannot support it.

  • C. Incorrect.

    Incorrect. Vulnerability scanning is useful for identifying weaknesses, but aggressive scans can destabilize embedded or medical devices and do not directly prevent unauthorized code from executing. Someone might choose this option because scanning is a common security practice, but it is not the best control for maintaining code integrity on constrained embedded systems.

  • D. Incorrect.

    Incorrect. Allowing firmware updates from any USB drive increases the risk of tampering, malware introduction, and supply-chain compromise. Although emergency update flexibility may sound operationally helpful, bypassing signature validation and trusted update channels undermines firmware integrity.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam