SY0-701 exam dumps

SY0-701 practice question 64 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 64

Single answerFile-based

A security analyst is reviewing alerts from several Linux servers and notices repeated detections of files matching known malware hashes in users' home directories. The analyst wants to reduce the risk of users executing malicious files that arrive through email attachments or browser downloads, while minimizing impact on the operating system and installed applications. Which control would BEST address this requirement?

  1. A

    Implement file-based allowlisting so only approved executables can run from user-accessible directories

  2. B

    Enable full-disk encryption on all Linux servers to prevent malware from executing

  3. C

    Configure a network-based firewall rule to block outbound traffic from the affected servers

  4. D

    Disable all file shares on the Linux servers to stop users from accessing malicious files

Show answer and explanation

Correct answer: A

Explanation

The best answer is file-based allowlisting because the scenario focuses on preventing execution of malicious files already landing in user-accessible locations. In Security+ terms, this is an application control technique that reduces attack surface by allowing only trusted files to execute. It is especially effective when applied to user-writable directories, where phishing attachments and browser downloads commonly land. By contrast, full-disk encryption protects stored data but does not stop malware execution, firewalls control network traffic rather than local process launch, and disabling file shares is not targeted to the stated threat vector. This approach aligns with widely accepted security best practices from sources such as NIST guidance on application allowlisting and endpoint protection, which emphasize restricting execution of untrusted code as a strong preventive control.

  • A. Correct.

    Correct. File-based allowlisting is designed to permit execution only of approved files, hashes, paths, or publishers, depending on the platform. In this scenario, restricting execution from user-writable locations such as home or download directories directly reduces the likelihood that downloaded malware can run, while still allowing approved operating system and application files to execute. This is a practical preventive control aligned with application control best practices.

  • B. Incorrect.

    Incorrect. Full-disk encryption protects data at rest if a device or drive is lost or stolen, but it does not prevent a user or process from executing malicious files after the system is booted and the disk is unlocked. This is a common misconception because encryption improves confidentiality, not runtime execution control.

  • C. Incorrect.

    Incorrect. A network-based firewall may limit command-and-control traffic or data exfiltration, but it does not directly stop a user from launching a malicious file already present on the system. It is a compensating or detective/containment measure, not the best primary control for preventing file execution in this scenario.

  • D. Incorrect.

    Incorrect. Disabling all file shares is overly broad and does not specifically address malware arriving through email attachments or browser downloads into local user directories. It would also likely disrupt legitimate business operations. The scenario asks for a control that minimizes impact while reducing execution risk, which makes file-based allowlisting the better fit.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam