SY0-701 exam dumps

SY0-701 practice question 380 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 380

Single answer

A company is expanding rapidly and now deploys new cloud-based application servers every week. The security team has discovered that administrators are building systems manually, which has led to inconsistent firewall rules, missing endpoint agents, and delayed deployment during peak business periods. Leadership wants a solution that improves deployment speed while ensuring every new server meets the same security requirements as existing approved systems. Which solution BEST addresses these goals?

  1. A

    Implement infrastructure as code (IaC) templates with approved secure configurations and automated deployment pipelines

  2. B

    Require administrators to follow a written build checklist and submit each server for manual security review after deployment

  3. C

    Purchase additional servers in advance so the organization can keep spare capacity available during busy periods

  4. D

    Allow each system administrator to maintain their own preferred server image as long as it passes an annual audit

Show answer and explanation

Correct answer: A

Explanation

The best answer is implementing infrastructure as code with secure, approved templates. In Security+ terms, this directly supports key operational and security benefits: efficiency/time saving through automation, enforcing baselines by codifying required controls, standard infrastructure configurations through reusable templates, and scaling in a secure manner by rapidly deploying identical hardened systems. It also improves reaction time during business surges or incident recovery because systems can be rebuilt quickly and consistently. From an organizational perspective, automation can serve as a workforce multiplier and reduce burnout from repetitive manual tasks, which can indirectly support employee retention. This aligns with widely accepted best practices from NIST guidance on secure configuration management and standardized baselines, including concepts reflected in NIST SP 800-128 for configuration management and NIST SP 800-53 controls such as CM-2 (baseline configuration) and CM-6 (configuration settings).

  • A. Correct.

    Correct. Infrastructure as code (IaC) allows the organization to define and deploy systems from standardized, version-controlled templates. This improves efficiency and time savings by automating repetitive provisioning tasks, enforces security baselines by embedding approved settings into the build process, supports standard infrastructure configurations across environments, and enables secure scaling by rapidly deploying identical hardened systems. This also acts as a workforce multiplier because fewer staff hours are needed for repetitive builds and troubleshooting inconsistent configurations.

  • B. Incorrect.

    Incorrect. A written checklist can help reduce mistakes, but it still relies heavily on manual execution and post-deployment review. That approach does not provide the same efficiency gains, consistency, or rapid reaction time as automated provisioning. Manual reviews after deployment also mean insecure systems may already be online before issues are found.

  • C. Incorrect.

    Incorrect. Extra hardware or cloud capacity may help performance or availability planning, but it does not solve the core security problem of inconsistent configurations and missing controls. The organization needs a method to enforce baselines and standardize builds, not just more capacity.

  • D. Incorrect.

    Incorrect. Allowing each administrator to use a different preferred image undermines standardization and baseline enforcement. Even if an annual audit is performed, insecure drift and inconsistent settings can exist for months. This approach also makes scaling and incident response harder because teams must manage multiple configurations instead of a single approved standard.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam