SY0-701 exam dumps

SY0-701 practice question 265 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 265

Single answerConnection methods: Cellular , Wi-Fi , Bluetooth

A healthcare organization issues tablets to nurses for bedside charting. The tablets normally use the hospital's WPA3-Enterprise Wi-Fi, but staff report intermittent Wi-Fi dead zones in one wing. To maintain connectivity, some nurses have started using personal smartphone hotspots, and a few have paired the tablets with nearby Bluetooth peripherals without approval. The security administrator must reduce the risk of data exposure while still allowing nurses to work during Wi-Fi outages. Which of the following is the BEST solution?

  1. A

    Require tablets to connect only to the hospital's approved Wi-Fi and disable Bluetooth and cellular fallback entirely

  2. B

    Configure the tablets to use an organization-managed cellular connection as a backup, disable unauthorized tethering/hotspots, and restrict Bluetooth to approved paired devices only

  3. C

    Allow users to choose any available connection method as long as HTTPS is used for the charting application

  4. D

    Enable Bluetooth discovery mode permanently so approved peripherals can reconnect faster when nurses move between rooms

Show answer and explanation

Correct answer: B

Explanation

The best solution is to use a managed cellular backup while keeping control over wireless connection methods. In real environments, Wi-Fi may be the primary enterprise connection method, but cellular can provide resilient failover when coverage gaps or outages occur. From a Security+ perspective, the key issue is not just encryption of application traffic, but governance of the connection path itself. Personal hotspots create shadow IT and can bypass enterprise controls such as logging, traffic inspection, NAC, and mobile device management policy enforcement. Bluetooth should also be limited because unauthorized pairing can expose the device to data leakage or nearby attacks. Industry best practices from enterprise wireless and mobile security guidance emphasize using centrally managed connectivity, disabling unnecessary radios or features, enforcing least functionality, and allowing only approved Bluetooth pairings and profiles. This approach best balances confidentiality, integrity, and availability.

  • A. Incorrect.

    This would reduce some attack surface, but it does not meet the operational requirement to maintain connectivity during Wi-Fi outages. In a healthcare setting, loss of access during dead zones can directly affect patient care. Security+ scenarios typically require balancing security with availability, and disabling all fallback methods is too restrictive.

  • B. Correct.

    This is the best answer because it preserves availability while maintaining centralized control. An organization-managed cellular connection provides a controlled backup path when Wi-Fi is unavailable, unlike personal hotspots, which bypass enterprise monitoring and policy enforcement. Disabling unauthorized tethering reduces the risk of users connecting through unmanaged networks. Restricting Bluetooth to approved paired devices only reduces exposure to rogue devices, unauthorized data transfer, and pairing-based attacks while still supporting legitimate peripherals.

  • C. Incorrect.

    HTTPS protects application traffic in transit, but it does not address the risks of unmanaged personal hotspots, rogue access paths, or unauthorized Bluetooth pairing. Users choosing any available connection method creates significant exposure because the organization loses visibility and control over the network path and nearby wireless device trust relationships.

  • D. Incorrect.

    Keeping Bluetooth discovery enabled increases visibility to nearby devices and expands the attack surface. Best practice is to disable discovery when not needed and limit Bluetooth use to specifically authorized devices. Permanent discoverability is not necessary for secure reconnection and makes the tablets easier to target.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam