SY0-701 exam dumps

SY0-701 practice question 381 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 381

Single answer

A security manager at a rapidly growing company needs to reduce the time required to deploy new cloud servers while ensuring each system meets the organization's security requirements. The current process relies on administrators manually building servers, and recent audits found inconsistent hardening settings and missing logging agents. Which solution would BEST improve efficiency, enforce secure baselines, and allow the environment to scale securely?

  1. A

    Implement infrastructure as code (IaC) using approved hardened templates and automated configuration management

  2. B

    Allow each administrator to maintain a personal server build checklist so they can work faster in their preferred way

  3. C

    Require manual security reviews after each server is deployed to verify settings before production use

  4. D

    Delay server deployments until a senior engineer is available to build each system from scratch

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement infrastructure as code with hardened templates and automated configuration management because it delivers several major security and operational benefits at the same time: efficiency and time savings, enforcement of secure baselines, standard infrastructure configurations, and the ability to scale securely. In practice, teams often use golden images, configuration baselines, and automated provisioning pipelines to ensure every new server is built with required settings such as logging, patch levels, endpoint protection, and access controls. This also improves reaction time during expansion or incident recovery because systems can be rebuilt quickly and consistently. From a Security+ perspective, this reflects secure baseline enforcement and standardized deployment practices. Guidance from sources such as NIST SP 800-128 on security-focused configuration management and NIST SP 800-190 on application container and automation-related security concepts supports the use of standardized, controlled, and automated configurations to reduce misconfiguration risk and improve operational consistency.

  • A. Correct.

    Correct. Infrastructure as code (IaC) combined with hardened templates and configuration management directly addresses the core problems in the scenario. It standardizes infrastructure builds, enforces security baselines consistently, reduces human error, and acts as a workforce multiplier by letting teams deploy securely at scale. Automated provisioning also improves reaction time when new systems must be deployed quickly. This aligns with common security best practices for secure, repeatable, and auditable deployments.

  • B. Incorrect.

    Incorrect. Personal checklists may help individual administrators, but they do not ensure standard infrastructure configurations across the organization. This approach increases variation, makes audits harder, and does not reliably enforce secure baselines. It may seem attractive because experienced administrators often prefer flexibility, but that flexibility is exactly what caused the inconsistent hardening findings in the scenario.

  • C. Incorrect.

    Incorrect. Manual security reviews after deployment may catch some issues, but they do not solve the root problem of inconsistent builds and are not efficient for a rapidly growing environment. This approach slows deployments and does not scale well. It is a common misconception that review-heavy processes alone create security; in practice, preventive controls built into the deployment process are usually more effective than relying mainly on detective controls afterward.

  • D. Incorrect.

    Incorrect. Depending on a senior engineer to manually build every system creates a bottleneck, reduces efficiency, and hurts scalability. It also increases organizational risk because knowledge is concentrated in one person rather than embedded in repeatable processes. While a senior engineer may produce secure builds, this approach does not provide the time savings, standardization, or workforce multiplier benefits the company needs.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam