SY0-701 exam dumps

SY0-701 practice question 406 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 406

Single answer

A software company discovers that a recently deployed web application update is exposing customer data through an API misconfiguration. The security team confirms the issue began immediately after a Friday evening release. Management wants to restore service quickly, preserve evidence for investigation, and prevent similar issues in future releases. Which action should be taken FIRST according to security best practices?

  1. A

    Initiate the incident response process, contain the exposure, and follow documented change management procedures for rollback or emergency fixes

  2. B

    Update the acceptable use policy to prohibit developers from making direct production changes

  3. C

    Activate the disaster recovery plan and fail over all systems to the alternate site

  4. D

    Revise the business continuity plan to prioritize customer-facing applications during outages

Show answer and explanation

Correct answer: A

Explanation

The best answer is to start with incident response and coordinated containment, because the organization is experiencing an active data exposure. Standard incident response phases include preparation, detection/analysis, containment, eradication, recovery, and lessons learned. Since the issue began after a deployment, change management is also relevant: rollback, emergency patching, and approval documentation should occur through established procedures to reduce additional risk and preserve accountability. This scenario also highlights the role of the SDLC, since future releases should include stronger security testing, code review, and deployment validation to prevent similar misconfigurations. By contrast, an acceptable use policy governs user behavior, business continuity focuses on maintaining operations, and disaster recovery focuses on restoring systems after major outages or destruction. Best-practice references include NIST SP 800-61 for incident response and general change control practices aligned with frameworks such as ITIL and organizational security policy standards.

  • A. Correct.

    Correct. This scenario is an active security incident caused by a recent change. The first priority is to invoke the incident response process so the organization can identify, contain, and remediate the issue while preserving relevant evidence. Because the problem is tied to a deployment, any rollback or hotfix should still follow documented change management procedures, including emergency change handling where applicable. This response addresses both immediate risk reduction and procedural control.

  • B. Incorrect.

    Incorrect. Updating the acceptable use policy may help define appropriate user behavior, but an AUP governs how users may use organizational systems and resources. It does not directly address immediate containment of a production security incident. This option confuses user conduct policy with operational security response.

  • C. Incorrect.

    Incorrect. Disaster recovery is generally used to restore IT operations after major disruptive events such as site failure, ransomware impact, or catastrophic system loss. In this case, the issue is an application misconfiguration introduced by a release, not a disaster requiring site failover. Using DR first would likely add complexity and delay while failing to address the root cause.

  • D. Incorrect.

    Incorrect. Business continuity planning is focused on maintaining essential business functions during disruption. While BCP may inform service priorities, revising the plan does not solve the current exposure. This option reflects a longer-term governance activity rather than the immediate operational response required for a live security incident.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam