SY0-701 exam dumps

SY0-701 practice question 3 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 3

Single answerCategories: Technical , Managerial , Operational , Physical

A company is opening a small satellite office that will not have dedicated on-site security staff. The security manager must recommend a set of controls that addresses risks across administrative/managerial, technical, operational, and physical categories before employees move in. Which of the following combinations BEST meets this requirement?

  1. A

    Deploy badge-controlled door locks, require a clean desk policy and visitor sign-in procedures, enforce MFA for remote access, and perform a site risk assessment

  2. B

    Install antivirus on employee laptops, purchase cyber insurance, and place a privacy screen on the receptionist's monitor

  3. C

    Require employees to change passwords every 30 days, encrypt all email, and add a fence around the parking lot

  4. D

    Hire a guard for business hours, disable unused switch ports, and create an incident response contact list

Show answer and explanation

Correct answer: A

Explanation

The best answer is the one that demonstrates defense in depth while also mapping controls to the requested categories. In Security+ terminology, managerial/administrative controls include activities such as risk assessments, policy development, governance, and planning. Technical controls include mechanisms such as MFA, firewalls, and endpoint protection. Operational controls are people-driven and process-oriented, such as visitor procedures, awareness activities, and clean desk practices. Physical controls include locks, cameras, guards, fences, and badge access systems. A site risk assessment is especially important before occupancy because it helps identify local threats, likelihood, impact, and compensating control needs. This aligns with common best practices reflected in NIST guidance such as NIST SP 800-53 control families and NIST risk management concepts, where organizations select a mix of administrative, technical, and physical safeguards based on assessed risk.

  • A. Correct.

    Correct. This option includes a physical control (badge-controlled door locks), operational controls (clean desk policy and visitor sign-in procedures), a technical control (MFA for remote access), and a managerial/administrative control (site risk assessment). Security+ commonly expects candidates to distinguish among these control categories and choose a layered approach that addresses multiple domains. The scenario specifically asks for coverage across managerial, technical, operational, and physical categories, and this is the only option that clearly includes all four.

  • B. Incorrect.

    Incorrect. Antivirus is a technical control, cyber insurance is generally a risk-transfer measure associated with managerial risk treatment, and a privacy screen is a physical safeguard. However, this option does not clearly include an operational control such as procedures, day-to-day processes, or staff-led security practices. It is partially useful but does not satisfy the requirement to address all categories.

  • C. Incorrect.

    Incorrect. Password changes and email encryption are technical or policy-driven measures, and a fence is a physical control. However, this choice lacks a clear operational control and does not provide a strong managerial element such as governance, risk assessment, or formal security planning. Also, frequent password expiration by itself is no longer broadly considered a best-practice default unless driven by specific risk or compromise indicators, making this option less aligned with modern guidance.

  • D. Incorrect.

    Incorrect. A guard is a physical/deterrent control, disabling unused switch ports is a technical control, and an incident response contact list can support operations. However, this option does not clearly include a managerial/administrative control such as a risk assessment, policy approval, or governance activity. It is a plausible set of controls, which makes it a good distractor, but it does not fully satisfy the category coverage required by the scenario.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam