SY0-701 exam dumps

SY0-701 practice question 484 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 484

Single answer

A company has shifted to a hybrid work model. Several recent incidents have occurred: an employee plugged an unknown USB drive found in the parking lot into a company laptop, a remote worker discussed a confidential product launch while working from a coffee shop, and another employee entered corporate credentials into a fake VPN login page received by email. Management wants to reduce the likelihood of similar events without relying primarily on new technical controls. Which action would BEST address the root cause of these incidents?

  1. A

    Deploy a stricter email spam filter and block all external USB storage devices

  2. B

    Update the employee handbook and conduct recurring security awareness training focused on social engineering, removable media, password handling, and operational security for remote work

  3. C

    Require all employees to change their passwords every 30 days and use longer passwords

  4. D

    Implement a policy requiring managers to approve all remote work from public locations

Show answer and explanation

Correct answer: B

Explanation

The best answer is to strengthen user guidance and training through updated policies and recurring awareness education. The scenario highlights multiple human-factor failures common in Security+ objectives: social engineering, password and credential handling, removable media risks, situational awareness, insider-risk reduction through policy adherence, and operational security in hybrid or remote settings. A well-maintained employee handbook and formal security awareness program should clearly instruct users not to connect unknown USB devices, to verify login portals and report phishing attempts, to protect credentials, and to avoid discussing sensitive information in public spaces. This aligns with established best practices from sources such as NIST SP 800-50 on building information technology security awareness and training programs, NIST SP 800-61 for incident-related user reporting readiness, and NIST guidance promoting phishing resistance, least privilege, and secure remote work behavior. While technical controls are useful layers, the question asks for the best action without relying primarily on them, making policy updates and recurring training the most appropriate response.

  • A. Incorrect.

    This would help mitigate parts of the problem, but it does not best address the root cause across all three incidents. Technical controls such as spam filtering and USB blocking can reduce exposure, but the scenario specifically asks for a solution that does not rely primarily on new technical controls. The repeated pattern is poor user judgment and lack of security awareness in hybrid work situations.

  • B. Correct.

    This is correct because the incidents involve user behavior and judgment: plugging in unknown removable media, exposing sensitive information in public, and falling for a phishing page. Updating policy and handbook content, then reinforcing it through recurring security awareness training, directly addresses situational awareness, social engineering resistance, password and credential handling, removable media safety, and operational security in hybrid or remote environments. This is the most comprehensive nontechnical corrective action.

  • C. Incorrect.

    Frequent password changes alone would not prevent an employee from entering credentials into a phishing site, discussing sensitive topics in public, or using untrusted removable media. In fact, overly frequent forced password changes are not considered a primary modern best practice unless there is evidence of compromise, because they can encourage weaker password behaviors. The option is too narrow and does not address the broader training and policy gap.

  • D. Incorrect.

    Manager approval for working in public locations may reduce some exposure, but it does not address phishing susceptibility, unsafe USB use, or the broader need for secure behavior wherever employees work. It is an administrative restriction rather than a targeted improvement to user guidance and training, so it does not best address the root cause.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam