CompTIA Security+ SY0-701 Enterprise Mitigation Techniques Practice Test
Topic 09 focuses on Enterprise Mitigation Techniques for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
Which term describes division of a network into controlled zones or segments to limit communication and reduce blast radius?
Correct Answer: B
Correct Answer
Answer B is correct because Network segmentation means division of a network into controlled zones or segments to limit communication and reduce blast radius.
Incorrect Answers
Answer A is incorrect because Isolation represents a different security function. Isolation refers to separation of a suspicious or high-risk system from normal resources.
Answer C is incorrect because Least privilege addresses a different requirement. Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function.
Answer D is incorrect because Encryption would fit a different scenario. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.
Question 2
To restrict network or resource access to explicitly allowed patterns, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Access control list (ACL) means an ordered rule set that permits or denies traffic or access based on defined criteria.
Incorrect Answers
Answer A is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.
Answer B is incorrect because Security monitoring addresses a different security requirement. Security monitoring refers to continuous or periodic observation of logs, activity, and system state for suspicious conditions.
Answer D is incorrect because Port and protocol reduction would fit a different scenario. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.
Question 3
Which term describes authorization settings defining what actions identities can perform on resources?
Correct Answer: C
Correct Answer
Answer C is correct because Permissions means authorization settings defining what actions identities can perform on resources.
Incorrect Answers
Answer A is incorrect because Encryption would fit a different scenario. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.
Answer B is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.
Answer D is incorrect because Port and protocol reduction represents a different security function. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.
Question 4
To block unknown or unauthorized software from running, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Application allow list means a control that permits execution only for approved applications or binaries.
Incorrect Answers
Answer A is incorrect because Patching addresses a different requirement. Patching refers to application of vendor fixes that correct vulnerabilities and software defects.
Answer B is incorrect because Isolation addresses a different security requirement. Isolation refers to separation of a suspicious or high-risk system from normal resources.
Answer C is incorrect because Host-based intrusion prevention system (HIPS) would fit a different scenario. Host-based intrusion prevention system (HIPS) refers to an endpoint control that detects and blocks suspicious host activity based on rules or behavior.
Question 5
Which term describes separation of a suspicious or high-risk system from normal resources?
Correct Answer: D
Correct Answer
Answer D is correct because Isolation means separation of a suspicious or high-risk system from normal resources.
Incorrect Answers
Answer A is incorrect because Secure decommissioning addresses a different requirement. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.
Answer B is incorrect because Encryption represents a different security function. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.
Answer C is incorrect because Default-credential replacement would fit a different scenario. Default-credential replacement refers to changing factory-set usernames or passwords before production use.
Question 6
To remove known exploitable weaknesses from supported systems, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Patching means application of vendor fixes that correct vulnerabilities and software defects.
Incorrect Answers
Answer A is incorrect because Port and protocol reduction addresses a different security requirement. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.
Answer B is incorrect because Secure decommissioning would fit a different scenario. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.
Answer D is incorrect because Default-credential replacement addresses a different requirement. Default-credential replacement refers to changing factory-set usernames or passwords before production use.
Question 7
Which term describes cryptographic protection that makes information unreadable without the appropriate key?
Correct Answer: B
Correct Answer
Answer B is correct because Encryption means cryptographic protection that makes information unreadable without the appropriate key.
Incorrect Answers
Answer A is incorrect because Host-based intrusion prevention system (HIPS) would fit a different scenario. Host-based intrusion prevention system (HIPS) refers to an endpoint control that detects and blocks suspicious host activity based on rules or behavior.
Answer C is incorrect because Host-based firewall represents a different security function. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.
Answer D is incorrect because Isolation addresses a different requirement. Isolation refers to separation of a suspicious or high-risk system from normal resources.
Question 8
To detect attacks, policy violations, and abnormal behavior early, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Security monitoring means continuous or periodic observation of logs, activity, and system state for suspicious conditions.
Incorrect Answers
Answer A is incorrect because Default-credential replacement addresses a different requirement. Default-credential replacement refers to changing factory-set usernames or passwords before production use.
Answer B is incorrect because Application allow list would fit a different scenario. Application allow list refers to a control that permits execution only for approved applications or binaries.
Answer C is incorrect because Endpoint protection addresses a different security requirement. Endpoint protection refers to host software that prevents, detects, or responds to malicious activity on endpoints.
Question 9
Which term describes granting only the minimum permissions necessary for a subject to perform its required function?
Correct Answer: A
Correct Answer
Answer A is correct because Least privilege means granting only the minimum permissions necessary for a subject to perform its required function.
Incorrect Answers
Answer B is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.
Answer C is incorrect because Secure decommissioning would fit a different scenario. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.
Answer D is incorrect because Configuration enforcement represents a different security function. Configuration enforcement refers to use of policy, automation, or management controls to maintain approved secure settings.
Question 10
To prevent drift from hardened baselines, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Configuration enforcement means use of policy, automation, or management controls to maintain approved secure settings.
Incorrect Answers
Answer B is incorrect because Secure decommissioning addresses a different security requirement. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.
Answer C is incorrect because Patching would fit a different scenario. Patching refers to application of vendor fixes that correct vulnerabilities and software defects.
Answer D is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.
Question 11
Which term describes controlled removal of systems or assets from service with data protection and access cleanup?
Correct Answer: A
Correct Answer
Answer A is correct because Secure decommissioning means controlled removal of systems or assets from service with data protection and access cleanup.
Incorrect Answers
Answer B is incorrect because Port and protocol reduction represents a different security function. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.
Answer C is incorrect because Unnecessary-software removal would fit a different scenario. Unnecessary-software removal refers to uninstalling applications and services that are not required for the system’s role.
Answer D is incorrect because Network segmentation addresses a different requirement. Network segmentation refers to division of a network into controlled zones or segments to limit communication and reduce blast radius.
Question 12
To protect user devices and servers from malware and suspicious behavior, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Endpoint protection means host software that prevents, detects, or responds to malicious activity on endpoints.
Incorrect Answers
Answer A is incorrect because Unnecessary-software removal would fit a different scenario. Unnecessary-software removal refers to uninstalling applications and services that are not required for the system’s role.
Answer B is incorrect because Application allow list addresses a different requirement. Application allow list refers to a control that permits execution only for approved applications or binaries.
Answer D is incorrect because Security monitoring addresses a different security requirement. Security monitoring refers to continuous or periodic observation of logs, activity, and system state for suspicious conditions.
Question 13
Which firewall running on an individual endpoint filters inbound and outbound traffic for that host?
Correct Answer: C
Correct Answer
Answer C is correct because Host-based firewall means a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.
Incorrect Answers
Answer A is incorrect because Port and protocol reduction would fit a different scenario. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.
Answer B is incorrect because Encryption represents a different security function. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.
Answer D is incorrect because Permissions addresses a different requirement. Permissions refers to authorization settings defining what actions identities can perform on resources.
Question 14
To prevent malicious actions locally before they succeed, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Host-based intrusion prevention system (HIPS) means an endpoint control that detects and blocks suspicious host activity based on rules or behavior.
Incorrect Answers
Answer B is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.
Answer C is incorrect because Default-credential replacement addresses a different security requirement. Default-credential replacement refers to changing factory-set usernames or passwords before production use.
Answer D is incorrect because Isolation would fit a different scenario. Isolation refers to separation of a suspicious or high-risk system from normal resources.
Question 15
Which term describes disabling unnecessary services, ports, or protocols?
Correct Answer: D
Correct Answer
Answer D is correct because Port and protocol reduction means disabling unnecessary services, ports, or protocols.
Incorrect Answers
Answer A is incorrect because Network segmentation addresses a different requirement. Network segmentation refers to division of a network into controlled zones or segments to limit communication and reduce blast radius.
Answer B is incorrect because Host-based intrusion prevention system (HIPS) would fit a different scenario. Host-based intrusion prevention system (HIPS) refers to an endpoint control that detects and blocks suspicious host activity based on rules or behavior.
Answer C is incorrect because Least privilege represents a different security function. Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function.
Question 16
To eliminate predictable credentials that attackers commonly try, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Default-credential replacement means changing factory-set usernames or passwords before production use.
Incorrect Answers
Answer A is incorrect because Security monitoring addresses a different requirement. Security monitoring refers to continuous or periodic observation of logs, activity, and system state for suspicious conditions.
Answer C is incorrect because Host-based intrusion prevention system (HIPS) would fit a different scenario. Host-based intrusion prevention system (HIPS) refers to an endpoint control that detects and blocks suspicious host activity based on rules or behavior.
Answer D is incorrect because Permissions addresses a different security requirement. Permissions refers to authorization settings defining what actions identities can perform on resources.
Question 17
Which term describes uninstalling applications and services that are not required for the system’s role?
Correct Answer: B
Correct Answer
Answer B is correct because Unnecessary-software removal means uninstalling applications and services that are not required for the system’s role.
Incorrect Answers
Answer A is incorrect because Endpoint protection addresses a different requirement. Endpoint protection refers to host software that prevents, detects, or responds to malicious activity on endpoints.
Answer C is incorrect because Port and protocol reduction represents a different security function. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.
Answer D is incorrect because Encryption would fit a different scenario. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.
Question 18
To contain compromise and restrict unnecessary east-west movement, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Network segmentation means division of a network into controlled zones or segments to limit communication and reduce blast radius.
Incorrect Answers
Answer A is incorrect because Least privilege would fit a different scenario. Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function.
Answer C is incorrect because Port and protocol reduction represents a different security function. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.
Answer D is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.
Question 19
Which ordered rule set permits or denies traffic or access based on defined criteria?
Correct Answer: C
Correct Answer
Answer C is correct because Access control list (ACL) means an ordered rule set that permits or denies traffic or access based on defined criteria.
Incorrect Answers
Answer A is incorrect because Application allow list would fit a different scenario. Application allow list refers to a control that permits execution only for approved applications or binaries.
Answer B is incorrect because Host-based firewall addresses a different security requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.
Answer D is incorrect because Encryption addresses a different requirement. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.
Question 20
To enforce least privilege at files, applications, services, or other objects, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Permissions means authorization settings defining what actions identities can perform on resources.
Incorrect Answers
Answer B is incorrect because Secure decommissioning would fit a different scenario. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.
Answer C is incorrect because Isolation addresses a different requirement. Isolation refers to separation of a suspicious or high-risk system from normal resources.
Answer D is incorrect because Default-credential replacement represents a different security function. Default-credential replacement refers to changing factory-set usernames or passwords before production use.
Question 21
Which control permits execution only for approved applications or binaries?
Correct Answer: D
Correct Answer
Answer D is correct because Application allow list means a control that permits execution only for approved applications or binaries.
Incorrect Answers
Answer A is incorrect because Secure decommissioning addresses a different requirement. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.
Answer B is incorrect because Least privilege addresses a different security requirement. Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function.
Answer C is incorrect because Port and protocol reduction would fit a different scenario. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.
Question 22
To contain potentially compromised workloads while investigation or remediation occurs, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Isolation means separation of a suspicious or high-risk system from normal resources.
Incorrect Answers
Answer B is incorrect because Application allow list would fit a different scenario. Application allow list refers to a control that permits execution only for approved applications or binaries.
Answer C is incorrect because Least privilege represents a different security function. Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function.
Answer D is incorrect because Port and protocol reduction addresses a different requirement. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.
Question 23
Which term describes application of vendor fixes that correct vulnerabilities and software defects?
Correct Answer: A
Correct Answer
Answer A is correct because Patching means application of vendor fixes that correct vulnerabilities and software defects.
Incorrect Answers
Answer B is incorrect because Endpoint protection addresses a different security requirement. Endpoint protection refers to host software that prevents, detects, or responds to malicious activity on endpoints.
Answer C is incorrect because Encryption would fit a different scenario. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.
Answer D is incorrect because Application allow list addresses a different requirement. Application allow list refers to a control that permits execution only for approved applications or binaries.
Question 24
To reduce data exposure if storage or communications are accessed by an unauthorized party, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Encryption means cryptographic protection that makes information unreadable without the appropriate key.
Incorrect Answers
Answer A is incorrect because Endpoint protection would fit a different scenario. Endpoint protection refers to host software that prevents, detects, or responds to malicious activity on endpoints.
Answer B is incorrect because Security monitoring represents a different security function. Security monitoring refers to continuous or periodic observation of logs, activity, and system state for suspicious conditions.
Answer C is incorrect because Configuration enforcement addresses a different requirement. Configuration enforcement refers to use of policy, automation, or management controls to maintain approved secure settings.
Question 25
Which term describes continuous or periodic observation of logs, activity, and system state for suspicious conditions?
Correct Answer: B
Correct Answer
Answer B is correct because Security monitoring means continuous or periodic observation of logs, activity, and system state for suspicious conditions.
Incorrect Answers
Answer A is incorrect because Default-credential replacement addresses a different security requirement. Default-credential replacement refers to changing factory-set usernames or passwords before production use.
Answer C is incorrect because Application allow list addresses a different requirement. Application allow list refers to a control that permits execution only for approved applications or binaries.
Answer D is incorrect because Secure decommissioning would fit a different scenario. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.
Popular posts
Recent Posts
