SY0-701 exam dumps

SY0-701 practice question 286 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 286

Single answerInventory

A security administrator is responding to a ransomware incident and discovers several engineering workstations were not included in recent vulnerability scans or patching reports. Management asks how these systems were missed for months. The company has both on-premises and cloud-managed assets, and new devices are frequently added by different IT teams. Which control would BEST reduce the chance of unmanaged systems being overlooked in the future?

  1. A

    Implement a centralized asset inventory with automated discovery and regular reconciliation against authorized device records

  2. B

    Increase the password complexity requirements for all user and service accounts

  3. C

    Disable USB storage across all engineering workstations

  4. D

    Perform annual penetration tests focused on the engineering network segment

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement a centralized asset inventory with automated discovery and reconciliation. In Security+ terms, inventory management is a core administrative and technical practice that supports vulnerability management, patching, access control, incident response, and governance. If assets are not inventoried, they often become unmanaged systems that fall outside standard security controls. Industry best practices emphasize maintaining accurate hardware and software asset inventories, using automated discovery where possible, and reconciling discovered devices with authorized baselines. This aligns with common guidance such as the NIST Cybersecurity Framework's asset management practices under Identify, and NIST SP 800-53 controls related to system component inventory (for example, CM-8). The scenario specifically points to a failure in asset visibility, so the most effective corrective action is a control that continuously identifies and tracks devices across the environment.

  • A. Correct.

    Correct. A centralized asset inventory is a foundational security control because an organization cannot protect, scan, or patch systems it does not know exist. Automated discovery helps identify new or previously unknown devices across on-premises and cloud-connected environments, while regular reconciliation compares discovered assets against approved records to find unmanaged or rogue systems. This directly addresses the root cause described in the scenario: incomplete visibility into enterprise assets.

  • B. Incorrect.

    Incorrect. Strong password policies are important for authentication security, but they do not solve the problem of unknown or unmanaged devices being absent from vulnerability scanning and patch management processes. Someone might choose this option because credential security is broadly useful during ransomware defense, but it does not address inventory gaps.

  • C. Incorrect.

    Incorrect. Disabling USB storage can reduce malware introduction and data exfiltration risk, but it does not help the organization identify systems that were never included in security operations workflows. This is a plausible distractor because ransomware defenses often include removable media controls, yet the scenario is specifically about missing assets.

  • D. Incorrect.

    Incorrect. Penetration testing can reveal weaknesses in a network segment, but conducting it annually would not reliably maintain an up-to-date record of all devices added by multiple IT teams throughout the year. A candidate might pick this because testing improves security posture, but it is not the best control for continuous asset visibility and inventory accuracy.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam