CompTIA Security+ SY0-701 Enterprise Mitigation Techniques Practice Test

 

Topic 09 focuses on Enterprise Mitigation Techniques for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which term describes division of a network into controlled zones or segments to limit communication and reduce blast radius?

  1. Isolation
  2. Network segmentation
  3. Least privilege
  4. Encryption

Correct Answer: B

 

Correct Answer

Answer B is correct because Network segmentation means division of a network into controlled zones or segments to limit communication and reduce blast radius.

Incorrect Answers

Answer A is incorrect because Isolation represents a different security function. Isolation refers to separation of a suspicious or high-risk system from normal resources.

Answer C is incorrect because Least privilege addresses a different requirement. Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function.

Answer D is incorrect because Encryption would fit a different scenario. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.

 

Question 2

To restrict network or resource access to explicitly allowed patterns, which security approach should be selected?

  1. Host-based firewall
  2. Security monitoring
  3. Access control list (ACL)
  4. Port and protocol reduction

Correct Answer: C

 

Correct Answer

Answer C is correct because Access control list (ACL) means an ordered rule set that permits or denies traffic or access based on defined criteria.

Incorrect Answers

Answer A is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.

Answer B is incorrect because Security monitoring addresses a different security requirement. Security monitoring refers to continuous or periodic observation of logs, activity, and system state for suspicious conditions.

Answer D is incorrect because Port and protocol reduction would fit a different scenario. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.

 

Question 3

Which term describes authorization settings defining what actions identities can perform on resources?

  1. Encryption
  2. Host-based firewall
  3. Permissions
  4. Port and protocol reduction

Correct Answer: C

 

Correct Answer

Answer C is correct because Permissions means authorization settings defining what actions identities can perform on resources.

Incorrect Answers

Answer A is incorrect because Encryption would fit a different scenario. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.

Answer B is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.

Answer D is incorrect because Port and protocol reduction represents a different security function. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.

 

Question 4

To block unknown or unauthorized software from running, which security approach should be selected?

  1. Patching
  2. Isolation
  3. Host-based intrusion prevention system (HIPS)
  4. Application allow list

Correct Answer: D

 

Correct Answer

Answer D is correct because Application allow list means a control that permits execution only for approved applications or binaries.

Incorrect Answers

Answer A is incorrect because Patching addresses a different requirement. Patching refers to application of vendor fixes that correct vulnerabilities and software defects.

Answer B is incorrect because Isolation addresses a different security requirement. Isolation refers to separation of a suspicious or high-risk system from normal resources.

Answer C is incorrect because Host-based intrusion prevention system (HIPS) would fit a different scenario. Host-based intrusion prevention system (HIPS) refers to an endpoint control that detects and blocks suspicious host activity based on rules or behavior.

 

Question 5

Which term describes separation of a suspicious or high-risk system from normal resources?

  1. Secure decommissioning
  2. Encryption
  3. Default-credential replacement
  4. Isolation

Correct Answer: D

 

Correct Answer

Answer D is correct because Isolation means separation of a suspicious or high-risk system from normal resources.

Incorrect Answers

Answer A is incorrect because Secure decommissioning addresses a different requirement. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.

Answer B is incorrect because Encryption represents a different security function. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.

Answer C is incorrect because Default-credential replacement would fit a different scenario. Default-credential replacement refers to changing factory-set usernames or passwords before production use.

 

Question 6

To remove known exploitable weaknesses from supported systems, which security approach should be selected?

  1. Port and protocol reduction
  2. Secure decommissioning
  3. Patching
  4. Default-credential replacement

Correct Answer: C

 

Correct Answer

Answer C is correct because Patching means application of vendor fixes that correct vulnerabilities and software defects.

Incorrect Answers

Answer A is incorrect because Port and protocol reduction addresses a different security requirement. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.

Answer B is incorrect because Secure decommissioning would fit a different scenario. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.

Answer D is incorrect because Default-credential replacement addresses a different requirement. Default-credential replacement refers to changing factory-set usernames or passwords before production use.

 

Question 7

Which term describes cryptographic protection that makes information unreadable without the appropriate key?

  1. Host-based intrusion prevention system (HIPS)
  2. Encryption
  3. Host-based firewall
  4. Isolation

Correct Answer: B

 

Correct Answer

Answer B is correct because Encryption means cryptographic protection that makes information unreadable without the appropriate key.

Incorrect Answers

Answer A is incorrect because Host-based intrusion prevention system (HIPS) would fit a different scenario. Host-based intrusion prevention system (HIPS) refers to an endpoint control that detects and blocks suspicious host activity based on rules or behavior.

Answer C is incorrect because Host-based firewall represents a different security function. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.

Answer D is incorrect because Isolation addresses a different requirement. Isolation refers to separation of a suspicious or high-risk system from normal resources.

 

Question 8

To detect attacks, policy violations, and abnormal behavior early, which security approach should be selected?

  1. Default-credential replacement
  2. Application allow list
  3. Endpoint protection
  4. Security monitoring

Correct Answer: D

 

Correct Answer

Answer D is correct because Security monitoring means continuous or periodic observation of logs, activity, and system state for suspicious conditions.

Incorrect Answers

Answer A is incorrect because Default-credential replacement addresses a different requirement. Default-credential replacement refers to changing factory-set usernames or passwords before production use.

Answer B is incorrect because Application allow list would fit a different scenario. Application allow list refers to a control that permits execution only for approved applications or binaries.

Answer C is incorrect because Endpoint protection addresses a different security requirement. Endpoint protection refers to host software that prevents, detects, or responds to malicious activity on endpoints.

 

Question 9

Which term describes granting only the minimum permissions necessary for a subject to perform its required function?

  1. Least privilege
  2. Host-based firewall
  3. Secure decommissioning
  4. Configuration enforcement

Correct Answer: A

 

Correct Answer

Answer A is correct because Least privilege means granting only the minimum permissions necessary for a subject to perform its required function.

Incorrect Answers

Answer B is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.

Answer C is incorrect because Secure decommissioning would fit a different scenario. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.

Answer D is incorrect because Configuration enforcement represents a different security function. Configuration enforcement refers to use of policy, automation, or management controls to maintain approved secure settings.

 

Question 10

To prevent drift from hardened baselines, which security approach should be selected?

  1. Configuration enforcement
  2. Secure decommissioning
  3. Patching
  4. Host-based firewall

Correct Answer: A

 

Correct Answer

Answer A is correct because Configuration enforcement means use of policy, automation, or management controls to maintain approved secure settings.

Incorrect Answers

Answer B is incorrect because Secure decommissioning addresses a different security requirement. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.

Answer C is incorrect because Patching would fit a different scenario. Patching refers to application of vendor fixes that correct vulnerabilities and software defects.

Answer D is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.

 

Question 11

Which term describes controlled removal of systems or assets from service with data protection and access cleanup?

  1. Secure decommissioning
  2. Port and protocol reduction
  3. Unnecessary-software removal
  4. Network segmentation

Correct Answer: A

 

Correct Answer

Answer A is correct because Secure decommissioning means controlled removal of systems or assets from service with data protection and access cleanup.

Incorrect Answers

Answer B is incorrect because Port and protocol reduction represents a different security function. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.

Answer C is incorrect because Unnecessary-software removal would fit a different scenario. Unnecessary-software removal refers to uninstalling applications and services that are not required for the system’s role.

Answer D is incorrect because Network segmentation addresses a different requirement. Network segmentation refers to division of a network into controlled zones or segments to limit communication and reduce blast radius.

 

Question 12

To protect user devices and servers from malware and suspicious behavior, which security approach should be selected?

  1. Unnecessary-software removal
  2. Application allow list
  3. Endpoint protection
  4. Security monitoring

Correct Answer: C

 

Correct Answer

Answer C is correct because Endpoint protection means host software that prevents, detects, or responds to malicious activity on endpoints.

Incorrect Answers

Answer A is incorrect because Unnecessary-software removal would fit a different scenario. Unnecessary-software removal refers to uninstalling applications and services that are not required for the system’s role.

Answer B is incorrect because Application allow list addresses a different requirement. Application allow list refers to a control that permits execution only for approved applications or binaries.

Answer D is incorrect because Security monitoring addresses a different security requirement. Security monitoring refers to continuous or periodic observation of logs, activity, and system state for suspicious conditions.

 

Question 13

Which firewall running on an individual endpoint filters inbound and outbound traffic for that host?

  1. Port and protocol reduction
  2. Encryption
  3. Host-based firewall
  4. Permissions

Correct Answer: C

 

Correct Answer

Answer C is correct because Host-based firewall means a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.

Incorrect Answers

Answer A is incorrect because Port and protocol reduction would fit a different scenario. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.

Answer B is incorrect because Encryption represents a different security function. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.

Answer D is incorrect because Permissions addresses a different requirement. Permissions refers to authorization settings defining what actions identities can perform on resources.

 

Question 14

To prevent malicious actions locally before they succeed, which security approach should be selected?

  1. Host-based intrusion prevention system (HIPS)
  2. Host-based firewall
  3. Default-credential replacement
  4. Isolation

Correct Answer: A

 

Correct Answer

Answer A is correct because Host-based intrusion prevention system (HIPS) means an endpoint control that detects and blocks suspicious host activity based on rules or behavior.

Incorrect Answers

Answer B is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.

Answer C is incorrect because Default-credential replacement addresses a different security requirement. Default-credential replacement refers to changing factory-set usernames or passwords before production use.

Answer D is incorrect because Isolation would fit a different scenario. Isolation refers to separation of a suspicious or high-risk system from normal resources.

 

Question 15

Which term describes disabling unnecessary services, ports, or protocols?

  1. Network segmentation
  2. Host-based intrusion prevention system (HIPS)
  3. Least privilege
  4. Port and protocol reduction

Correct Answer: D

 

Correct Answer

Answer D is correct because Port and protocol reduction means disabling unnecessary services, ports, or protocols.

Incorrect Answers

Answer A is incorrect because Network segmentation addresses a different requirement. Network segmentation refers to division of a network into controlled zones or segments to limit communication and reduce blast radius.

Answer B is incorrect because Host-based intrusion prevention system (HIPS) would fit a different scenario. Host-based intrusion prevention system (HIPS) refers to an endpoint control that detects and blocks suspicious host activity based on rules or behavior.

Answer C is incorrect because Least privilege represents a different security function. Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function.

 

Question 16

To eliminate predictable credentials that attackers commonly try, which security approach should be selected?

  1. Security monitoring
  2. Default-credential replacement
  3. Host-based intrusion prevention system (HIPS)
  4. Permissions

Correct Answer: B

 

Correct Answer

Answer B is correct because Default-credential replacement means changing factory-set usernames or passwords before production use.

Incorrect Answers

Answer A is incorrect because Security monitoring addresses a different requirement. Security monitoring refers to continuous or periodic observation of logs, activity, and system state for suspicious conditions.

Answer C is incorrect because Host-based intrusion prevention system (HIPS) would fit a different scenario. Host-based intrusion prevention system (HIPS) refers to an endpoint control that detects and blocks suspicious host activity based on rules or behavior.

Answer D is incorrect because Permissions addresses a different security requirement. Permissions refers to authorization settings defining what actions identities can perform on resources.

 

Question 17

Which term describes uninstalling applications and services that are not required for the system’s role?

  1. Endpoint protection
  2. Unnecessary-software removal
  3. Port and protocol reduction
  4. Encryption

Correct Answer: B

 

Correct Answer

Answer B is correct because Unnecessary-software removal means uninstalling applications and services that are not required for the system’s role.

Incorrect Answers

Answer A is incorrect because Endpoint protection addresses a different requirement. Endpoint protection refers to host software that prevents, detects, or responds to malicious activity on endpoints.

Answer C is incorrect because Port and protocol reduction represents a different security function. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.

Answer D is incorrect because Encryption would fit a different scenario. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.

 

Question 18

To contain compromise and restrict unnecessary east-west movement, which security approach should be selected?

  1. Least privilege
  2. Network segmentation
  3. Port and protocol reduction
  4. Host-based firewall

Correct Answer: B

 

Correct Answer

Answer B is correct because Network segmentation means division of a network into controlled zones or segments to limit communication and reduce blast radius.

Incorrect Answers

Answer A is incorrect because Least privilege would fit a different scenario. Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function.

Answer C is incorrect because Port and protocol reduction represents a different security function. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.

Answer D is incorrect because Host-based firewall addresses a different requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.

 

Question 19

Which ordered rule set permits or denies traffic or access based on defined criteria?

  1. Application allow list
  2. Host-based firewall
  3. Access control list (ACL)
  4. Encryption

Correct Answer: C

 

Correct Answer

Answer C is correct because Access control list (ACL) means an ordered rule set that permits or denies traffic or access based on defined criteria.

Incorrect Answers

Answer A is incorrect because Application allow list would fit a different scenario. Application allow list refers to a control that permits execution only for approved applications or binaries.

Answer B is incorrect because Host-based firewall addresses a different security requirement. Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host.

Answer D is incorrect because Encryption addresses a different requirement. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.

 

Question 20

To enforce least privilege at files, applications, services, or other objects, which security approach should be selected?

  1. Permissions
  2. Secure decommissioning
  3. Isolation
  4. Default-credential replacement

Correct Answer: A

 

Correct Answer

Answer A is correct because Permissions means authorization settings defining what actions identities can perform on resources.

Incorrect Answers

Answer B is incorrect because Secure decommissioning would fit a different scenario. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.

Answer C is incorrect because Isolation addresses a different requirement. Isolation refers to separation of a suspicious or high-risk system from normal resources.

Answer D is incorrect because Default-credential replacement represents a different security function. Default-credential replacement refers to changing factory-set usernames or passwords before production use.

 

Question 21

Which control permits execution only for approved applications or binaries?

  1. Secure decommissioning
  2. Least privilege
  3. Port and protocol reduction
  4. Application allow list

Correct Answer: D

 

Correct Answer

Answer D is correct because Application allow list means a control that permits execution only for approved applications or binaries.

Incorrect Answers

Answer A is incorrect because Secure decommissioning addresses a different requirement. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.

Answer B is incorrect because Least privilege addresses a different security requirement. Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function.

Answer C is incorrect because Port and protocol reduction would fit a different scenario. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.

 

Question 22

To contain potentially compromised workloads while investigation or remediation occurs, which security approach should be selected?

  1. Isolation
  2. Application allow list
  3. Least privilege
  4. Port and protocol reduction

Correct Answer: A

 

Correct Answer

Answer A is correct because Isolation means separation of a suspicious or high-risk system from normal resources.

Incorrect Answers

Answer B is incorrect because Application allow list would fit a different scenario. Application allow list refers to a control that permits execution only for approved applications or binaries.

Answer C is incorrect because Least privilege represents a different security function. Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function.

Answer D is incorrect because Port and protocol reduction addresses a different requirement. Port and protocol reduction refers to disabling unnecessary services, ports, or protocols.

 

Question 23

Which term describes application of vendor fixes that correct vulnerabilities and software defects?

  1. Patching
  2. Endpoint protection
  3. Encryption
  4. Application allow list

Correct Answer: A

 

Correct Answer

Answer A is correct because Patching means application of vendor fixes that correct vulnerabilities and software defects.

Incorrect Answers

Answer B is incorrect because Endpoint protection addresses a different security requirement. Endpoint protection refers to host software that prevents, detects, or responds to malicious activity on endpoints.

Answer C is incorrect because Encryption would fit a different scenario. Encryption refers to cryptographic protection that makes information unreadable without the appropriate key.

Answer D is incorrect because Application allow list addresses a different requirement. Application allow list refers to a control that permits execution only for approved applications or binaries.

 

Question 24

To reduce data exposure if storage or communications are accessed by an unauthorized party, which security approach should be selected?

  1. Endpoint protection
  2. Security monitoring
  3. Configuration enforcement
  4. Encryption

Correct Answer: D

 

Correct Answer

Answer D is correct because Encryption means cryptographic protection that makes information unreadable without the appropriate key.

Incorrect Answers

Answer A is incorrect because Endpoint protection would fit a different scenario. Endpoint protection refers to host software that prevents, detects, or responds to malicious activity on endpoints.

Answer B is incorrect because Security monitoring represents a different security function. Security monitoring refers to continuous or periodic observation of logs, activity, and system state for suspicious conditions.

Answer C is incorrect because Configuration enforcement addresses a different requirement. Configuration enforcement refers to use of policy, automation, or management controls to maintain approved secure settings.

 

Question 25

Which term describes continuous or periodic observation of logs, activity, and system state for suspicious conditions?

  1. Default-credential replacement
  2. Security monitoring
  3. Application allow list
  4. Secure decommissioning

Correct Answer: B

 

Correct Answer

Answer B is correct because Security monitoring means continuous or periodic observation of logs, activity, and system state for suspicious conditions.

Incorrect Answers

Answer A is incorrect because Default-credential replacement addresses a different security requirement. Default-credential replacement refers to changing factory-set usernames or passwords before production use.

Answer C is incorrect because Application allow list addresses a different requirement. Application allow list refers to a control that permits execution only for approved applications or binaries.

Answer D is incorrect because Secure decommissioning would fit a different scenario. Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup.

img