SY0-701 exam dumps

SY0-701 practice question 255 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 255

Select 2

A manufacturing company is connecting new IoT environmental sensors to an existing ICS/SCADA network to monitor temperature and humidity on the production floor. The sensors use an embedded OS and communicate with a central management server. During a security review, the administrator discovers that the devices still use vendor default passwords, expose unnecessary management services, and cannot support traditional endpoint protection agents. The company wants to reduce the likelihood of device compromise without disrupting production traffic. Which TWO actions should the administrator take FIRST to harden these devices most effectively?

  1. A

    Change default credentials, disable unnecessary services, and place the devices on a restricted network segment with tightly controlled access

  2. B

    Install a host-based EDR agent on each sensor and enable aggressive real-time scanning

  3. C

    Implement allowlisting and strict ACLs on the switch or firewall so the sensors can communicate only with required management systems

  4. D

    Allow direct internet access from the sensors so they can automatically download updates from the vendor

  5. E

    Enable remote administration over insecure legacy protocols to simplify troubleshooting during deployment

Show answer and explanation

Correct answers: A, C

Explanation

The best initial hardening steps are to remove common, high-risk weaknesses on the devices themselves and then apply strong network-level compensating controls. In embedded, IoT, RTOS, and ICS/SCADA environments, organizations often cannot rely on traditional host-based security tools, so administrators must emphasize basic secure configuration, credential management, service reduction, segmentation, and ACL-based traffic restriction. These measures support widely accepted best practices such as least privilege, least functionality, and network segmentation for operational technology. Guidance from NIST, including concepts reflected in SP 800-82 for ICS security and IoT-focused guidance such as NISTIR 8259, emphasizes minimizing exposed services, changing default passwords, restricting communications, and limiting unnecessary connectivity, especially internet access.

  • A. Correct.

    This is correct. For embedded and IoT devices in ICS/SCADA environments, changing default credentials and disabling unnecessary services are fundamental hardening steps. Because these devices often have limited security capabilities, placing them on a segmented network with restricted access is also a high-value control that reduces exposure and limits lateral movement if a device is compromised.

  • B. Incorrect.

    This is incorrect. Many embedded, IoT, and RTOS-based devices cannot support traditional endpoint security agents due to limited CPU, memory, storage, or unsupported operating systems. Attempting to install EDR is often impractical and may disrupt device stability in operational technology environments.

  • C. Correct.

    This is correct. When endpoint controls are limited, network-based hardening becomes critical. Allowlisting communications and using ACLs to restrict traffic so the sensors can talk only to necessary management or data collection systems is a strong compensating control. This aligns with least functionality and least privilege principles commonly applied to ICS and IoT deployments.

  • D. Incorrect.

    This is incorrect. Direct internet access increases attack surface and is generally discouraged for ICS/SCADA and IoT devices. Updates should be carefully managed through controlled processes, such as vendor-validated patching and staged deployment, rather than unrestricted outbound connectivity from operational devices.

  • E. Incorrect.

    This is incorrect. Enabling insecure legacy remote administration protocols weakens the environment and creates additional attack paths. In OT and embedded environments, management access should be minimized, secured, and limited to approved administrators over protected channels rather than broadened for convenience.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam