CompTIA Security+ SY0-701 Enterprise Security Capabilities Practice Test

 

Topic 18 focuses on Enterprise Security Capabilities for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which policy statement permits, denies, or otherwise handles network traffic matching defined conditions?

  1. IDS signature
  2. Firewall rule
  3. DMARC
  4. URL scanning

Correct Answer: B

 

Correct Answer

Answer B is correct because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

Incorrect Answers

Answer A is incorrect because IDS signature represents a different security function. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.

Answer C is incorrect because DMARC addresses a different requirement. DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.

Answer D is incorrect because URL scanning would fit a different scenario. URL scanning refers to analysis of requested web addresses for policy or security risk.

 

Question 2

To isolate public-facing systems from sensitive internal resources, which security approach should be selected?

  1. Agent-based web filter
  2. DNS filtering
  3. Screened subnet
  4. Reputation filtering

Correct Answer: C

 

Correct Answer

Answer C is correct because Screened subnet means a network segment separated from internal networks and used for externally reachable services.

Incorrect Answers

Answer A is incorrect because Agent-based web filter would fit a different scenario. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.

Answer B is incorrect because DNS filtering addresses a different requirement. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.

Answer D is incorrect because Reputation filtering addresses a different security requirement. Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files.

 

Question 3

Which detection pattern is used to identify known malicious or suspicious activity?

  1. Group Policy
  2. Centralized proxy filter
  3. IPS blocking
  4. IDS signature

Correct Answer: D

 

Correct Answer

Answer D is correct because IDS signature means a detection pattern used to identify known malicious or suspicious activity.

Incorrect Answers

Answer A is incorrect because Group Policy would fit a different scenario. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Answer B is incorrect because Centralized proxy filter represents a different security function. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.

Answer C is incorrect because IPS blocking addresses a different requirement. IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy.

 

Question 4

To stop suspicious activity before it reaches the target, which security approach should be selected?

  1. IPS blocking
  2. Screened subnet
  3. User behavior analytics
  4. DKIM

Correct Answer: A

 

Correct Answer

Answer A is correct because IPS blocking means active prevention of traffic that matches malicious signatures, behavior, or policy.

Incorrect Answers

Answer B is incorrect because Screened subnet addresses a different security requirement. Screened subnet refers to a network segment separated from internal networks and used for externally reachable services.

Answer C is incorrect because User behavior analytics would fit a different scenario. User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies.

Answer D is incorrect because DKIM addresses a different requirement. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.

 

Question 5

Which term describes web-control software installed on endpoints to enforce browsing policy locally?

  1. Agent-based web filter
  2. Screened subnet
  3. Endpoint detection and response (EDR)
  4. Network access control (NAC)

Correct Answer: A

 

Correct Answer

Answer A is correct because Agent-based web filter means web-control software installed on endpoints to enforce browsing policy locally.

Incorrect Answers

Answer B is incorrect because Screened subnet addresses a different requirement. Screened subnet refers to a network segment separated from internal networks and used for externally reachable services.

Answer C is incorrect because Endpoint detection and response (EDR) would fit a different scenario. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Answer D is incorrect because Network access control (NAC) represents a different security function. Network access control (NAC) refers to policy enforcement that evaluates identity, device state, or compliance before granting network connectivity.

 

Question 6

To control and log web access through a shared enforcement point, which security approach should be selected?

  1. Endpoint detection and response (EDR)
  2. Content categorization
  3. Reputation filtering
  4. Centralized proxy filter

Correct Answer: D

 

Correct Answer

Answer D is correct because Centralized proxy filter means a gateway that receives client web requests and applies filtering or inspection centrally.

Incorrect Answers

Answer A is incorrect because Endpoint detection and response (EDR) addresses a different requirement. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Answer B is incorrect because Content categorization addresses a different security requirement. Content categorization refers to classification of web content into categories used by access policy.

Answer C is incorrect because Reputation filtering would fit a different scenario. Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files.

 

Question 7

Which term describes analysis of requested web addresses for policy or security risk?

  1. User behavior analytics
  2. DNS filtering
  3. URL scanning
  4. SELinux

Correct Answer: C

 

Correct Answer

Answer C is correct because URL scanning means analysis of requested web addresses for policy or security risk.

Incorrect Answers

Answer A is incorrect because User behavior analytics addresses a different requirement. User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies.

Answer B is incorrect because DNS filtering represents a different security function. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.

Answer D is incorrect because SELinux would fit a different scenario. SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.

 

Question 8

To apply browsing rules based on content type rather than individual URLs alone, which security approach should be selected?

  1. Agent-based web filter
  2. User behavior analytics
  3. IPS blocking
  4. Content categorization

Correct Answer: D

 

Correct Answer

Answer D is correct because Content categorization means classification of web content into categories used by access policy.

Incorrect Answers

Answer A is incorrect because Agent-based web filter would fit a different scenario. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.

Answer B is incorrect because User behavior analytics addresses a different requirement. User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies.

Answer C is incorrect because IPS blocking addresses a different security requirement. IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy.

 

Question 9

Which term describes use of reputation intelligence to allow, warn, or block destinations, senders, or files?

  1. SELinux
  2. Reputation filtering
  3. Firewall rule
  4. Content categorization

Correct Answer: B

 

Correct Answer

Answer B is correct because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files.

Incorrect Answers

Answer A is incorrect because SELinux addresses a different requirement. SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.

Answer C is incorrect because Firewall rule represents a different security function. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

Answer D is incorrect because Content categorization would fit a different scenario. Content categorization refers to classification of web content into categories used by access policy.

 

Question 10

To enforce Windows configuration consistently across managed endpoints, which security approach should be selected?

  1. Secure protocol selection
  2. Group Policy
  3. DNS filtering
  4. SPF

Correct Answer: B

 

Correct Answer

Answer B is correct because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Incorrect Answers

Answer A is incorrect because Secure protocol selection would fit a different scenario. Secure protocol selection refers to use of authenticated and encrypted protocols instead of insecure legacy alternatives.

Answer C is incorrect because DNS filtering addresses a different requirement. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.

Answer D is incorrect because SPF addresses a different security requirement. SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain.

 

Question 11

Which Linux mandatory access control framework enforces policy beyond standard discretionary permissions?

  1. SELinux
  2. URL scanning
  3. IDS signature
  4. Group Policy

Correct Answer: A

 

Correct Answer

Answer A is correct because SELinux means a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.

Incorrect Answers

Answer B is incorrect because URL scanning would fit a different scenario. URL scanning refers to analysis of requested web addresses for policy or security risk.

Answer C is incorrect because IDS signature addresses a different requirement. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.

Answer D is incorrect because Group Policy represents a different security function. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

 

Question 12

To protect credentials and content during network communication, which security approach should be selected?

  1. Group Policy
  2. Secure protocol selection
  3. URL scanning
  4. Centralized proxy filter

Correct Answer: B

 

Correct Answer

Answer B is correct because Secure protocol selection means use of authenticated and encrypted protocols instead of insecure legacy alternatives.

Incorrect Answers

Answer A is incorrect because Group Policy addresses a different security requirement. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Answer C is incorrect because URL scanning addresses a different requirement. URL scanning refers to analysis of requested web addresses for policy or security risk.

Answer D is incorrect because Centralized proxy filter would fit a different scenario. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.

 

Question 13

Which term describes control of DNS resolution to block malicious, prohibited, or risky domains?

  1. DKIM
  2. DNS filtering
  3. Firewall rule
  4. Agent-based web filter

Correct Answer: B

 

Correct Answer

Answer B is correct because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains.

Incorrect Answers

Answer A is incorrect because DKIM represents a different security function. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.

Answer C is incorrect because Firewall rule would fit a different scenario. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

Answer D is incorrect because Agent-based web filter addresses a different requirement. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.

 

Question 14

To tell receiving domains how to handle messages that fail authenticated domain checks, which security approach should be selected?

  1. DMARC
  2. Reputation filtering
  3. Firewall rule
  4. IDS signature

Correct Answer: A

 

Correct Answer

Answer A is correct because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.

Incorrect Answers

Answer B is incorrect because Reputation filtering would fit a different scenario. Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files.

Answer C is incorrect because Firewall rule addresses a different requirement. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

Answer D is incorrect because IDS signature addresses a different security requirement. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.

 

Question 15

Which term describes email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit?

  1. IPS blocking
  2. Group Policy
  3. Content categorization
  4. DKIM

Correct Answer: D

 

Correct Answer

Answer D is correct because DKIM means email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.

Incorrect Answers

Answer A is incorrect because IPS blocking would fit a different scenario. IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy.

Answer B is incorrect because Group Policy represents a different security function. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Answer C is incorrect because Content categorization addresses a different requirement. Content categorization refers to classification of web content into categories used by access policy.

 

Question 16

To help receiving systems detect forged envelope-sender domains, which security approach should be selected?

  1. Firewall rule
  2. Endpoint detection and response (EDR)
  3. SPF
  4. Group Policy

Correct Answer: C

 

Correct Answer

Answer C is correct because SPF means a DNS-published policy identifying servers authorized to send mail for a domain.

Incorrect Answers

Answer A is incorrect because Firewall rule would fit a different scenario. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

Answer B is incorrect because Endpoint detection and response (EDR) addresses a different security requirement. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Answer D is incorrect because Group Policy addresses a different requirement. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

 

Question 17

Which term describes monitoring that detects unauthorized or unexpected changes to selected files and configurations?

  1. File integrity monitoring
  2. Reputation filtering
  3. Firewall rule
  4. Extended detection and response (XDR)

Correct Answer: A

 

Correct Answer

Answer A is correct because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations.

Incorrect Answers

Answer B is incorrect because Reputation filtering addresses a different requirement. Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files.

Answer C is incorrect because Firewall rule represents a different security function. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

Answer D is incorrect because Extended detection and response (XDR) would fit a different scenario. Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains.

 

Question 18

To restrict network access for unauthorized or noncompliant devices, which security approach should be selected?

  1. Extended detection and response (XDR)
  2. DMARC
  3. File integrity monitoring
  4. Network access control (NAC)

Correct Answer: D

 

Correct Answer

Answer D is correct because Network access control (NAC) means policy enforcement that evaluates identity, device state, or compliance before granting network connectivity.

Incorrect Answers

Answer A is incorrect because Extended detection and response (XDR) addresses a different requirement. Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains.

Answer B is incorrect because DMARC addresses a different security requirement. DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.

Answer C is incorrect because File integrity monitoring would fit a different scenario. File integrity monitoring refers to monitoring that detects unauthorized or unexpected changes to selected files and configurations.

 

Question 19

Which term describes endpoint security focused on detailed telemetry, detection, investigation, and response actions?

  1. Endpoint detection and response (EDR)
  2. DNS filtering
  3. Group Policy
  4. Screened subnet

Correct Answer: A

 

Correct Answer

Answer A is correct because Endpoint detection and response (EDR) means endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Incorrect Answers

Answer B is incorrect because DNS filtering represents a different security function. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.

Answer C is incorrect because Group Policy would fit a different scenario. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Answer D is incorrect because Screened subnet addresses a different requirement. Screened subnet refers to a network segment separated from internal networks and used for externally reachable services.

 

Question 20

To connect signals from multiple control planes into broader investigations, which security approach should be selected?

  1. Extended detection and response (XDR)
  2. User behavior analytics
  3. URL scanning
  4. DNS filtering

Correct Answer: A

 

Correct Answer

Answer A is correct because Extended detection and response (XDR) means detection and response that correlates telemetry across endpoints and other security domains.

Incorrect Answers

Answer B is incorrect because User behavior analytics would fit a different scenario. User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies.

Answer C is incorrect because URL scanning addresses a different requirement. URL scanning refers to analysis of requested web addresses for policy or security risk.

Answer D is incorrect because DNS filtering addresses a different security requirement. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.

 

Question 21

Which term describes analysis of identity and user activity patterns to detect anomalies?

  1. Extended detection and response (XDR)
  2. User behavior analytics
  3. SELinux
  4. Centralized proxy filter

Correct Answer: B

 

Correct Answer

Answer B is correct because User behavior analytics means analysis of identity and user activity patterns to detect anomalies.

Incorrect Answers

Answer A is incorrect because Extended detection and response (XDR) addresses a different requirement. Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains.

Answer C is incorrect because SELinux represents a different security function. SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.

Answer D is incorrect because Centralized proxy filter would fit a different scenario. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.

 

Question 22

To control network flows according to source, destination, service, state, or application context, which security approach should be selected?

  1. DNS filtering
  2. Agent-based web filter
  3. Firewall rule
  4. Group Policy

Correct Answer: C

 

Correct Answer

Answer C is correct because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

Incorrect Answers

Answer A is incorrect because DNS filtering would fit a different scenario. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.

Answer B is incorrect because Agent-based web filter addresses a different requirement. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.

Answer D is incorrect because Group Policy represents a different security function. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

 

Question 23

What is a network segment separated from internal networks and used for externally reachable services?

  1. DMARC
  2. Screened subnet
  3. Group Policy
  4. Endpoint detection and response (EDR)

Correct Answer: B

 

Correct Answer

Answer B is correct because Screened subnet means a network segment separated from internal networks and used for externally reachable services.

Incorrect Answers

Answer A is incorrect because DMARC addresses a different security requirement. DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.

Answer C is incorrect because Group Policy addresses a different requirement. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Answer D is incorrect because Endpoint detection and response (EDR) would fit a different scenario. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.

 

Question 24

To recognize previously characterized attack behavior and generate alerts, which security approach should be selected?

  1. IDS signature
  2. DKIM
  3. Centralized proxy filter
  4. Firewall rule

Correct Answer: A

 

Correct Answer

Answer A is correct because IDS signature means a detection pattern used to identify known malicious or suspicious activity.

Incorrect Answers

Answer B is incorrect because DKIM would fit a different scenario. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.

Answer C is incorrect because Centralized proxy filter addresses a different requirement. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.

Answer D is incorrect because Firewall rule represents a different security function. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

 

Question 25

Which term describes active prevention of traffic that matches malicious signatures, behavior, or policy?

  1. Endpoint detection and response (EDR)
  2. Agent-based web filter
  3. IPS blocking
  4. DKIM

Correct Answer: C

 

Correct Answer

Answer C is correct because IPS blocking means active prevention of traffic that matches malicious signatures, behavior, or policy.

Incorrect Answers

Answer A is incorrect because Endpoint detection and response (EDR) would fit a different scenario. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Answer B is incorrect because Agent-based web filter addresses a different requirement. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.

Answer D is incorrect because DKIM addresses a different security requirement. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.

 

Question 26

To apply URL and content rules even when the device is away from the corporate network, which security approach should be selected?

  1. Secure protocol selection
  2. SPF
  3. Agent-based web filter
  4. IDS signature

Correct Answer: C

 

Correct Answer

Answer C is correct because Agent-based web filter means web-control software installed on endpoints to enforce browsing policy locally.

Incorrect Answers

Answer A is incorrect because Secure protocol selection would fit a different scenario. Secure protocol selection refers to use of authenticated and encrypted protocols instead of insecure legacy alternatives.

Answer B is incorrect because SPF represents a different security function. SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain.

Answer D is incorrect because IDS signature addresses a different requirement. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.

 

Question 27

Which gateway receives client web requests and applies filtering or inspection centrally?

  1. DNS filtering
  2. Centralized proxy filter
  3. Endpoint detection and response (EDR)
  4. Agent-based web filter

Correct Answer: B

 

Correct Answer

Answer B is correct because Centralized proxy filter means a gateway that receives client web requests and applies filtering or inspection centrally.

Incorrect Answers

Answer A is incorrect because DNS filtering addresses a different requirement. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.

Answer C is incorrect because Endpoint detection and response (EDR) would fit a different scenario. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Answer D is incorrect because Agent-based web filter addresses a different security requirement. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.

 

Question 28

To block access to known malicious or prohibited destinations, which security approach should be selected?

  1. IPS blocking
  2. File integrity monitoring
  3. URL scanning
  4. SPF

Correct Answer: C

 

Correct Answer

Answer C is correct because URL scanning means analysis of requested web addresses for policy or security risk.

Incorrect Answers

Answer A is incorrect because IPS blocking addresses a different requirement. IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy.

Answer B is incorrect because File integrity monitoring would fit a different scenario. File integrity monitoring refers to monitoring that detects unauthorized or unexpected changes to selected files and configurations.

Answer D is incorrect because SPF represents a different security function. SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain.

 

Question 29

Which term describes classification of web content into categories used by access policy?

  1. Content categorization
  2. Centralized proxy filter
  3. Endpoint detection and response (EDR)
  4. Firewall rule

Correct Answer: A

 

Correct Answer

Answer A is correct because Content categorization means classification of web content into categories used by access policy.

Incorrect Answers

Answer B is incorrect because Centralized proxy filter addresses a different security requirement. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.

Answer C is incorrect because Endpoint detection and response (EDR) addresses a different requirement. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Answer D is incorrect because Firewall rule would fit a different scenario. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

 

Question 30

To reduce exposure to entities with a history of malicious behavior, which security approach should be selected?

  1. Firewall rule
  2. Secure protocol selection
  3. DKIM
  4. Reputation filtering

Correct Answer: D

 

Correct Answer

Answer D is correct because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files.

Incorrect Answers

Answer A is incorrect because Firewall rule addresses a different requirement. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

Answer B is incorrect because Secure protocol selection represents a different security function. Secure protocol selection refers to use of authenticated and encrypted protocols instead of insecure legacy alternatives.

Answer C is incorrect because DKIM would fit a different scenario. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.

 

Question 31

Which term describes microsoft domain-based centralized configuration used to apply security and operating settings to users and computers?

  1. Group Policy
  2. Endpoint detection and response (EDR)
  3. Network access control (NAC)
  4. Firewall rule

Correct Answer: A

 

Correct Answer

Answer A is correct because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Incorrect Answers

Answer B is incorrect because Endpoint detection and response (EDR) would fit a different scenario. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Answer C is incorrect because Network access control (NAC) addresses a different requirement. Network access control (NAC) refers to policy enforcement that evaluates identity, device state, or compliance before granting network connectivity.

Answer D is incorrect because Firewall rule addresses a different security requirement. Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

 

Question 32

To confine processes and limit damage even when traditional file permissions would allow access, which security approach should be selected?

  1. Extended detection and response (XDR)
  2. DNS filtering
  3. SELinux
  4. Centralized proxy filter

Correct Answer: C

 

Correct Answer

Answer C is correct because SELinux means a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.

Incorrect Answers

Answer A is incorrect because Extended detection and response (XDR) addresses a different requirement. Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains.

Answer B is incorrect because DNS filtering would fit a different scenario. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.

Answer D is incorrect because Centralized proxy filter represents a different security function. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.

 

Question 33

Which term describes use of authenticated and encrypted protocols instead of insecure legacy alternatives?

  1. Endpoint detection and response (EDR)
  2. DMARC
  3. SPF
  4. Secure protocol selection

Correct Answer: D

 

Correct Answer

Answer D is correct because Secure protocol selection means use of authenticated and encrypted protocols instead of insecure legacy alternatives.

Incorrect Answers

Answer A is incorrect because Endpoint detection and response (EDR) addresses a different requirement. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Answer B is incorrect because DMARC addresses a different security requirement. DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.

Answer C is incorrect because SPF would fit a different scenario. SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain.

 

Question 34

To prevent many connections before clients establish sessions with unwanted destinations, which security approach should be selected?

  1. SPF
  2. Endpoint detection and response (EDR)
  3. Reputation filtering
  4. DNS filtering

Correct Answer: D

 

Correct Answer

Answer D is correct because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains.

Incorrect Answers

Answer A is incorrect because SPF addresses a different requirement. SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain.

Answer B is incorrect because Endpoint detection and response (EDR) represents a different security function. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Answer C is incorrect because Reputation filtering would fit a different scenario. Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files.

 

Question 35

What is an email-authentication policy and reporting mechanism built on SPF and DKIM alignment?

  1. Endpoint detection and response (EDR)
  2. DMARC
  3. IDS signature
  4. SELinux

Correct Answer: B

 

Correct Answer

Answer B is correct because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.

Incorrect Answers

Answer A is incorrect because Endpoint detection and response (EDR) addresses a different requirement. Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Answer C is incorrect because IDS signature addresses a different security requirement. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.

Answer D is incorrect because SELinux would fit a different scenario. SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.

 

Question 36

To provide cryptographic domain-level message integrity and origin assurance, which security approach should be selected?

  1. IDS signature
  2. Centralized proxy filter
  3. DKIM
  4. Content categorization

Correct Answer: C

 

Correct Answer

Answer C is correct because DKIM means email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.

Incorrect Answers

Answer A is incorrect because IDS signature addresses a different requirement. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.

Answer B is incorrect because Centralized proxy filter represents a different security function. Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally.

Answer D is incorrect because Content categorization would fit a different scenario. Content categorization refers to classification of web content into categories used by access policy.

 

Question 37

Which DNS-published policy identifying servers are authorized to send mail for a domain?

  1. Content categorization
  2. Group Policy
  3. URL scanning
  4. SPF

Correct Answer: D

 

Correct Answer

Answer D is correct because SPF means a DNS-published policy identifying servers authorized to send mail for a domain.

Incorrect Answers

Answer A is incorrect because Content categorization would fit a different scenario. Content categorization refers to classification of web content into categories used by access policy.

Answer B is incorrect because Group Policy addresses a different security requirement. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Answer C is incorrect because URL scanning addresses a different requirement. URL scanning refers to analysis of requested web addresses for policy or security risk.

 

Question 38

To identify tampering with critical system or application files, which security approach should be selected?

  1. DNS filtering
  2. File integrity monitoring
  3. DMARC
  4. IDS signature

Correct Answer: B

 

Correct Answer

Answer B is correct because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations.

Incorrect Answers

Answer A is incorrect because DNS filtering addresses a different requirement. DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains.

Answer C is incorrect because DMARC would fit a different scenario. DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.

Answer D is incorrect because IDS signature represents a different security function. IDS signature refers to a detection pattern used to identify known malicious or suspicious activity.

 

Question 39

Which term describes policy enforcement that evaluates identity, device state, or compliance before granting network connectivity?

  1. URL scanning
  2. Group Policy
  3. Network access control (NAC)
  4. Extended detection and response (XDR)

Correct Answer: C

 

Correct Answer

Answer C is correct because Network access control (NAC) means policy enforcement that evaluates identity, device state, or compliance before granting network connectivity.

Incorrect Answers

Answer A is incorrect because URL scanning addresses a different requirement. URL scanning refers to analysis of requested web addresses for policy or security risk.

Answer B is incorrect because Group Policy addresses a different security requirement. Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Answer D is incorrect because Extended detection and response (XDR) would fit a different scenario. Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains.

 

Question 40

To investigate and contain suspicious endpoint behavior, which security approach should be selected?

  1. DKIM
  2. Agent-based web filter
  3. File integrity monitoring
  4. Endpoint detection and response (EDR)

Correct Answer: D

 

Correct Answer

Answer D is correct because Endpoint detection and response (EDR) means endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Incorrect Answers

Answer A is incorrect because DKIM addresses a different requirement. DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.

Answer B is incorrect because Agent-based web filter represents a different security function. Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally.

Answer C is incorrect because File integrity monitoring would fit a different scenario. File integrity monitoring refers to monitoring that detects unauthorized or unexpected changes to selected files and configurations.

img