CompTIA Security+ SY0-701 Enterprise Security Capabilities Practice Test
Topic 18 focuses on Enterprise Security Capabilities for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
Which policy statement permits, denies, or otherwise handles network traffic matching defined conditions?
Correct Answer: B
Correct Answer
Answer B is correct because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.
Incorrect Answers
Answer A is incorrect because IDS signature represents a different security function. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.
Answer C is incorrect because DMARC addresses a different requirement. DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.
Answer D is incorrect because URL scanning would fit a different scenario. URL scanning refers to analysis of requested web addresses for policy or security risk.
Question 2
To isolate public-facing systems from sensitive internal resources, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Screened subnet means a network segment separated from internal networks and used for externally reachable services.
Incorrect Answers
Answer A is incorrect because Agent-based web filter would fit a different scenario. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.
Answer B is incorrect because DNS filtering addresses a different requirement. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.
Answer D is incorrect because Reputation filtering addresses a different security requirement. Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files.
Question 3
Which detection pattern is used to identify known malicious or suspicious activity?
Correct Answer: D
Correct Answer
Answer D is correct because IDS signature means a detection pattern used to identify known malicious or suspicious activity.
Incorrect Answers
Answer A is incorrect because Group Policy would fit a different scenario. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Answer B is incorrect because Centralized proxy filter represents a different security function. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.
Answer C is incorrect because IPS blocking addresses a different requirement. IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy.
Question 4
To stop suspicious activity before it reaches the target, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because IPS blocking means active prevention of traffic that matches malicious signatures, behavior, or policy.
Incorrect Answers
Answer B is incorrect because Screened subnet addresses a different security requirement. Screened subnet refers to a network segment separated from internal networks and used for externally reachable services.
Answer C is incorrect because User behavior analytics would fit a different scenario. User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies.
Answer D is incorrect because DKIM addresses a different requirement. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.
Question 5
Which term describes web-control software installed on endpoints to enforce browsing policy locally?
Correct Answer: A
Correct Answer
Answer A is correct because Agent-based web filter means web-control software installed on endpoints to enforce browsing policy locally.
Incorrect Answers
Answer B is incorrect because Screened subnet addresses a different requirement. Screened subnet refers to a network segment separated from internal networks and used for externally reachable services.
Answer C is incorrect because Endpoint detection and response (EDR) would fit a different scenario. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Answer D is incorrect because Network access control (NAC) represents a different security function. Network access control (NAC) refers to policy enforcement that evaluates identity, device state, or compliance before granting network connectivity.
Question 6
To control and log web access through a shared enforcement point, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Centralized proxy filter means a gateway that receives client web requests and applies filtering or inspection centrally.
Incorrect Answers
Answer A is incorrect because Endpoint detection and response (EDR) addresses a different requirement. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Answer B is incorrect because Content categorization addresses a different security requirement. Content categorization refers to classification of web content into categories used by access policy.
Answer C is incorrect because Reputation filtering would fit a different scenario. Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files.
Question 7
Which term describes analysis of requested web addresses for policy or security risk?
Correct Answer: C
Correct Answer
Answer C is correct because URL scanning means analysis of requested web addresses for policy or security risk.
Incorrect Answers
Answer A is incorrect because User behavior analytics addresses a different requirement. User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies.
Answer B is incorrect because DNS filtering represents a different security function. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.
Answer D is incorrect because SELinux would fit a different scenario. SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.
Question 8
To apply browsing rules based on content type rather than individual URLs alone, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Content categorization means classification of web content into categories used by access policy.
Incorrect Answers
Answer A is incorrect because Agent-based web filter would fit a different scenario. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.
Answer B is incorrect because User behavior analytics addresses a different requirement. User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies.
Answer C is incorrect because IPS blocking addresses a different security requirement. IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy.
Question 9
Which term describes use of reputation intelligence to allow, warn, or block destinations, senders, or files?
Correct Answer: B
Correct Answer
Answer B is correct because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files.
Incorrect Answers
Answer A is incorrect because SELinux addresses a different requirement. SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.
Answer C is incorrect because Firewall rule represents a different security function. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.
Answer D is incorrect because Content categorization would fit a different scenario. Content categorization refers to classification of web content into categories used by access policy.
Question 10
To enforce Windows configuration consistently across managed endpoints, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Incorrect Answers
Answer A is incorrect because Secure protocol selection would fit a different scenario. Secure protocol selection refers to use of authenticated and encrypted protocols instead of insecure legacy alternatives.
Answer C is incorrect because DNS filtering addresses a different requirement. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.
Answer D is incorrect because SPF addresses a different security requirement. SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain.
Question 11
Which Linux mandatory access control framework enforces policy beyond standard discretionary permissions?
Correct Answer: A
Correct Answer
Answer A is correct because SELinux means a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.
Incorrect Answers
Answer B is incorrect because URL scanning would fit a different scenario. URL scanning refers to analysis of requested web addresses for policy or security risk.
Answer C is incorrect because IDS signature addresses a different requirement. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.
Answer D is incorrect because Group Policy represents a different security function. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Question 12
To protect credentials and content during network communication, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Secure protocol selection means use of authenticated and encrypted protocols instead of insecure legacy alternatives.
Incorrect Answers
Answer A is incorrect because Group Policy addresses a different security requirement. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Answer C is incorrect because URL scanning addresses a different requirement. URL scanning refers to analysis of requested web addresses for policy or security risk.
Answer D is incorrect because Centralized proxy filter would fit a different scenario. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.
Question 13
Which term describes control of DNS resolution to block malicious, prohibited, or risky domains?
Correct Answer: B
Correct Answer
Answer B is correct because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains.
Incorrect Answers
Answer A is incorrect because DKIM represents a different security function. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.
Answer C is incorrect because Firewall rule would fit a different scenario. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.
Answer D is incorrect because Agent-based web filter addresses a different requirement. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.
Question 14
To tell receiving domains how to handle messages that fail authenticated domain checks, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.
Incorrect Answers
Answer B is incorrect because Reputation filtering would fit a different scenario. Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files.
Answer C is incorrect because Firewall rule addresses a different requirement. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.
Answer D is incorrect because IDS signature addresses a different security requirement. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.
Question 15
Which term describes email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit?
Correct Answer: D
Correct Answer
Answer D is correct because DKIM means email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.
Incorrect Answers
Answer A is incorrect because IPS blocking would fit a different scenario. IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy.
Answer B is incorrect because Group Policy represents a different security function. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Answer C is incorrect because Content categorization addresses a different requirement. Content categorization refers to classification of web content into categories used by access policy.
Question 16
To help receiving systems detect forged envelope-sender domains, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because SPF means a DNS-published policy identifying servers authorized to send mail for a domain.
Incorrect Answers
Answer A is incorrect because Firewall rule would fit a different scenario. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.
Answer B is incorrect because Endpoint detection and response (EDR) addresses a different security requirement. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Answer D is incorrect because Group Policy addresses a different requirement. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Question 17
Which term describes monitoring that detects unauthorized or unexpected changes to selected files and configurations?
Correct Answer: A
Correct Answer
Answer A is correct because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations.
Incorrect Answers
Answer B is incorrect because Reputation filtering addresses a different requirement. Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files.
Answer C is incorrect because Firewall rule represents a different security function. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.
Answer D is incorrect because Extended detection and response (XDR) would fit a different scenario. Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains.
Question 18
To restrict network access for unauthorized or noncompliant devices, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Network access control (NAC) means policy enforcement that evaluates identity, device state, or compliance before granting network connectivity.
Incorrect Answers
Answer A is incorrect because Extended detection and response (XDR) addresses a different requirement. Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains.
Answer B is incorrect because DMARC addresses a different security requirement. DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.
Answer C is incorrect because File integrity monitoring would fit a different scenario. File integrity monitoring refers to monitoring that detects unauthorized or unexpected changes to selected files and configurations.
Question 19
Which term describes endpoint security focused on detailed telemetry, detection, investigation, and response actions?
Correct Answer: A
Correct Answer
Answer A is correct because Endpoint detection and response (EDR) means endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Incorrect Answers
Answer B is incorrect because DNS filtering represents a different security function. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.
Answer C is incorrect because Group Policy would fit a different scenario. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Answer D is incorrect because Screened subnet addresses a different requirement. Screened subnet refers to a network segment separated from internal networks and used for externally reachable services.
Question 20
To connect signals from multiple control planes into broader investigations, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Extended detection and response (XDR) means detection and response that correlates telemetry across endpoints and other security domains.
Incorrect Answers
Answer B is incorrect because User behavior analytics would fit a different scenario. User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies.
Answer C is incorrect because URL scanning addresses a different requirement. URL scanning refers to analysis of requested web addresses for policy or security risk.
Answer D is incorrect because DNS filtering addresses a different security requirement. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.
Question 21
Which term describes analysis of identity and user activity patterns to detect anomalies?
Correct Answer: B
Correct Answer
Answer B is correct because User behavior analytics means analysis of identity and user activity patterns to detect anomalies.
Incorrect Answers
Answer A is incorrect because Extended detection and response (XDR) addresses a different requirement. Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains.
Answer C is incorrect because SELinux represents a different security function. SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.
Answer D is incorrect because Centralized proxy filter would fit a different scenario. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.
Question 22
To control network flows according to source, destination, service, state, or application context, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.
Incorrect Answers
Answer A is incorrect because DNS filtering would fit a different scenario. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.
Answer B is incorrect because Agent-based web filter addresses a different requirement. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.
Answer D is incorrect because Group Policy represents a different security function. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Question 23
What is a network segment separated from internal networks and used for externally reachable services?
Correct Answer: B
Correct Answer
Answer B is correct because Screened subnet means a network segment separated from internal networks and used for externally reachable services.
Incorrect Answers
Answer A is incorrect because DMARC addresses a different security requirement. DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.
Answer C is incorrect because Group Policy addresses a different requirement. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Answer D is incorrect because Endpoint detection and response (EDR) would fit a different scenario. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Question 24
To recognize previously characterized attack behavior and generate alerts, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because IDS signature means a detection pattern used to identify known malicious or suspicious activity.
Incorrect Answers
Answer B is incorrect because DKIM would fit a different scenario. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.
Answer C is incorrect because Centralized proxy filter addresses a different requirement. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.
Answer D is incorrect because Firewall rule represents a different security function. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.
Question 25
Which term describes active prevention of traffic that matches malicious signatures, behavior, or policy?
Correct Answer: C
Correct Answer
Answer C is correct because IPS blocking means active prevention of traffic that matches malicious signatures, behavior, or policy.
Incorrect Answers
Answer A is incorrect because Endpoint detection and response (EDR) would fit a different scenario. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Answer B is incorrect because Agent-based web filter addresses a different requirement. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.
Answer D is incorrect because DKIM addresses a different security requirement. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.
Question 26
To apply URL and content rules even when the device is away from the corporate network, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Agent-based web filter means web-control software installed on endpoints to enforce browsing policy locally.
Incorrect Answers
Answer A is incorrect because Secure protocol selection would fit a different scenario. Secure protocol selection refers to use of authenticated and encrypted protocols instead of insecure legacy alternatives.
Answer B is incorrect because SPF represents a different security function. SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain.
Answer D is incorrect because IDS signature addresses a different requirement. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.
Question 27
Which gateway receives client web requests and applies filtering or inspection centrally?
Correct Answer: B
Correct Answer
Answer B is correct because Centralized proxy filter means a gateway that receives client web requests and applies filtering or inspection centrally.
Incorrect Answers
Answer A is incorrect because DNS filtering addresses a different requirement. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.
Answer C is incorrect because Endpoint detection and response (EDR) would fit a different scenario. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Answer D is incorrect because Agent-based web filter addresses a different security requirement. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.
Question 28
To block access to known malicious or prohibited destinations, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because URL scanning means analysis of requested web addresses for policy or security risk.
Incorrect Answers
Answer A is incorrect because IPS blocking addresses a different requirement. IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy.
Answer B is incorrect because File integrity monitoring would fit a different scenario. File integrity monitoring refers to monitoring that detects unauthorized or unexpected changes to selected files and configurations.
Answer D is incorrect because SPF represents a different security function. SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain.
Question 29
Which term describes classification of web content into categories used by access policy?
Correct Answer: A
Correct Answer
Answer A is correct because Content categorization means classification of web content into categories used by access policy.
Incorrect Answers
Answer B is incorrect because Centralized proxy filter addresses a different security requirement. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.
Answer C is incorrect because Endpoint detection and response (EDR) addresses a different requirement. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Answer D is incorrect because Firewall rule would fit a different scenario. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.
Question 30
To reduce exposure to entities with a history of malicious behavior, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files.
Incorrect Answers
Answer A is incorrect because Firewall rule addresses a different requirement. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.
Answer B is incorrect because Secure protocol selection represents a different security function. Secure protocol selection refers to use of authenticated and encrypted protocols instead of insecure legacy alternatives.
Answer C is incorrect because DKIM would fit a different scenario. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.
Question 31
Which term describes microsoft domain-based centralized configuration used to apply security and operating settings to users and computers?
Correct Answer: A
Correct Answer
Answer A is correct because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Incorrect Answers
Answer B is incorrect because Endpoint detection and response (EDR) would fit a different scenario. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Answer C is incorrect because Network access control (NAC) addresses a different requirement. Network access control (NAC) refers to policy enforcement that evaluates identity, device state, or compliance before granting network connectivity.
Answer D is incorrect because Firewall rule addresses a different security requirement. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.
Question 32
To confine processes and limit damage even when traditional file permissions would allow access, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because SELinux means a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.
Incorrect Answers
Answer A is incorrect because Extended detection and response (XDR) addresses a different requirement. Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains.
Answer B is incorrect because DNS filtering would fit a different scenario. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.
Answer D is incorrect because Centralized proxy filter represents a different security function. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.
Question 33
Which term describes use of authenticated and encrypted protocols instead of insecure legacy alternatives?
Correct Answer: D
Correct Answer
Answer D is correct because Secure protocol selection means use of authenticated and encrypted protocols instead of insecure legacy alternatives.
Incorrect Answers
Answer A is incorrect because Endpoint detection and response (EDR) addresses a different requirement. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Answer B is incorrect because DMARC addresses a different security requirement. DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.
Answer C is incorrect because SPF would fit a different scenario. SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain.
Question 34
To prevent many connections before clients establish sessions with unwanted destinations, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains.
Incorrect Answers
Answer A is incorrect because SPF addresses a different requirement. SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain.
Answer B is incorrect because Endpoint detection and response (EDR) represents a different security function. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Answer C is incorrect because Reputation filtering would fit a different scenario. Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files.
Question 35
What is an email-authentication policy and reporting mechanism built on SPF and DKIM alignment?
Correct Answer: B
Correct Answer
Answer B is correct because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.
Incorrect Answers
Answer A is incorrect because Endpoint detection and response (EDR) addresses a different requirement. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Answer C is incorrect because IDS signature addresses a different security requirement. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.
Answer D is incorrect because SELinux would fit a different scenario. SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.
Question 36
To provide cryptographic domain-level message integrity and origin assurance, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because DKIM means email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.
Incorrect Answers
Answer A is incorrect because IDS signature addresses a different requirement. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.
Answer B is incorrect because Centralized proxy filter represents a different security function. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.
Answer D is incorrect because Content categorization would fit a different scenario. Content categorization refers to classification of web content into categories used by access policy.
Question 37
Which DNS-published policy identifying servers are authorized to send mail for a domain?
Correct Answer: D
Correct Answer
Answer D is correct because SPF means a DNS-published policy identifying servers authorized to send mail for a domain.
Incorrect Answers
Answer A is incorrect because Content categorization would fit a different scenario. Content categorization refers to classification of web content into categories used by access policy.
Answer B is incorrect because Group Policy addresses a different security requirement. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Answer C is incorrect because URL scanning addresses a different requirement. URL scanning refers to analysis of requested web addresses for policy or security risk.
Question 38
To identify tampering with critical system or application files, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations.
Incorrect Answers
Answer A is incorrect because DNS filtering addresses a different requirement. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.
Answer C is incorrect because DMARC would fit a different scenario. DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.
Answer D is incorrect because IDS signature represents a different security function. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.
Question 39
Which term describes policy enforcement that evaluates identity, device state, or compliance before granting network connectivity?
Correct Answer: C
Correct Answer
Answer C is correct because Network access control (NAC) means policy enforcement that evaluates identity, device state, or compliance before granting network connectivity.
Incorrect Answers
Answer A is incorrect because URL scanning addresses a different requirement. URL scanning refers to analysis of requested web addresses for policy or security risk.
Answer B is incorrect because Group Policy addresses a different security requirement. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Answer D is incorrect because Extended detection and response (XDR) would fit a different scenario. Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains.
Question 40
To investigate and contain suspicious endpoint behavior, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Endpoint detection and response (EDR) means endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Incorrect Answers
Answer A is incorrect because DKIM addresses a different requirement. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.
Answer B is incorrect because Agent-based web filter represents a different security function. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.
Answer C is incorrect because File integrity monitoring would fit a different scenario. File integrity monitoring refers to monitoring that detects unauthorized or unexpected changes to selected files and configurations.
Popular posts
Recent Posts
