11.11 Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Last Attempt SY0-701 Questions

Page: 4 / 26
Total 345 questions

CompTIA Security+ Exam 2024 Questions and Answers

Question 13

In a rush to meet an end-of-year business goal, the IT department was told to implement a new business application. The security engineer reviews the attributes of the application and decides the time needed to perform due diligence is insufficient from a cybersecurity perspective. Which of the following best describes the security engineer's response?

Options:

A.

Risk tolerance

B.

Risk acceptance

C.

Risk importance

D.

Risk appetite

Question 14

Which of the following enables the use of an input field to run commands that can view or manipulate data?

Options:

A.

Cross-site scripting

B.

Side loading

C.

Buffer overflow

D.

SQL injection

Question 15

A company tested and validated the effectiveness of network security appliances within the corporate network. The IDS detected a high rate of SQL injection attacks against the company's servers, and the company's perimeter firewall is at capacity. Which of the following would be the best action to maintain security and reduce the traffic to the perimeter firewall?

Options:

A.

Set the appliance to IPS mode and place it in front of the company firewall.

B.

Convert the firewall to a WAF and use IPSec tunnels to increase throughput.

C.

Set the firewall to fail open if it is overloaded with traffic and send alerts to the SIEM.

D.

Configure the firewall to perform deep packet inspection and monitor TLS traffic.

Question 16

A security analyst is creating base for the server team to follow when hardening new devices for deployment. Which of the following beet describes what the analyst is creating?

Options:

A.

Change management procedure

B.

Information security policy

C.

Cybersecurity framework

D.

Secure configuration guide

Page: 4 / 26
Total 345 questions