SY0-701 exam dumps

SY0-701 practice question 408 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 408

Select 3Standards: Password , Access control , Physical security , Encryption

A healthcare clinic is renovating a satellite office that will handle patient check-ins and insurance payments. The office has a small reception area, a locked network closet, and two shared workstations used by rotating staff. During a security review, the clinic identifies these issues: staff sometimes write passwords on sticky notes at the desk, former contractors still appear in the badge-access system, and the shared workstations cache patient account data locally in case of a reboot. The clinic must reduce the risk of unauthorized access while aligning with common security standards and best practices. Which THREE actions should the security administrator implement first?

  1. A

    Require unique user accounts with a password policy and prohibit shared credentials for the reception workstations

  2. B

    Encrypt the workstation drives and configure automatic screen locking after a short period of inactivity

  3. C

    Keep the existing contractor badges active in case they are needed for future maintenance visits

  4. D

    Review and remove inactive badge-access permissions for former contractors and other terminated personnel

  5. E

    Store a printed list of current passwords in the locked network closet for emergency access

Show answer and explanation

Correct answers: A, B, D

Explanation

The best answers are to enforce unique accounts and a password policy, encrypt the shared workstations and enable automatic locking, and remove inactive badge permissions. These actions directly address the clinic's identified risks across password standards, access control, physical security, and encryption. Unique credentials provide individual accountability and support auditing. Deprovisioning old contractor badges enforces physical access restrictions and reduces insider and unauthorized-entry risk. Full-disk encryption protects locally cached sensitive data, while session locking limits opportunistic misuse of unattended systems. These recommendations align with broadly accepted security practices reflected in guidance such as NIST SP 800-53 for access control and media protection, NIST SP 800-63B for authentication and password-related practices, and CIS Controls for account management, secure configuration, and data protection.

  • A. Correct.

    This is correct. Unique user accounts support accountability, auditing, and least privilege. Shared credentials make it difficult to attribute actions to a specific user and are inconsistent with standard access control practices. A defined password policy helps reduce weak password use and discourages insecure workarounds such as writing passwords down.

  • B. Correct.

    This is correct. Full-disk encryption helps protect cached patient data if a workstation is stolen or improperly accessed, and automatic screen locking reduces the chance of unauthorized viewing or use when staff step away from shared systems. Together, these controls address encryption and logical access concerns in a practical office environment.

  • C. Incorrect.

    This is incorrect. Leaving contractor badges active violates physical access control best practices and increases the risk of unauthorized entry. Access should be provisioned only for current authorized personnel and removed promptly when no longer needed. Retaining active badges for convenience creates unnecessary exposure.

  • D. Correct.

    This is correct. Prompt deprovisioning of inactive or terminated users from the badge-access system is a core physical security and access control requirement. Former contractors should not retain access to facility areas after their engagement ends. Regular access reviews are a common control to enforce this standard.

  • E. Incorrect.

    This is incorrect. Storing printed passwords, even in a locked closet, undermines password security and increases the chance of disclosure. Emergency access should be handled through approved privileged access procedures, password vaulting, or break-glass accounts with strong controls, not paper password lists.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam