CompTIA Security+ SY0-701 Enterprise Security Capabilities Practice Test 1

 

Topic 18 Practice Test 1 covers Enterprise Security Capabilities for CompTIA Security+ SY0-701 and maps to objective 4.5: Given a scenario, modify enterprise capabilities to enhance security. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

Which term describes web-control software installed on endpoints to enforce browsing policy locally?

  1. Screened subnet
  2. Network access control (NAC)
  3. Endpoint detection and response (EDR)
  4. Agent-based web filter

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Agent-based web filter means web-control software installed on endpoints to enforce browsing policy locally. This is the precise fit for the scenario. Network access control (NAC) serves the different purpose of policy enforcement that evaluates identity, device state, or compliance before granting network connectivity.

Incorrect Answers

 

Answer A is incorrect because Screened subnet refers to a network segment separated from internal networks and used for externally reachable services. The question is not asking for this function. It is testing web-control software installed on endpoints to enforce browsing policy locally, so Agent-based web filter is the stronger fit.

Answer B is incorrect because Network access control (NAC) refers to policy enforcement that evaluates identity, device state, or compliance before granting network connectivity. The scenario instead requires web-control software installed on endpoints to enforce browsing policy locally, which is why Agent-based web filter is the better answer; this option serves the different function defined above.

Answer C is incorrect because Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions. The key mismatch is functional: Agent-based web filter addresses web-control software installed on endpoints to enforce browsing policy locally, the need stated by the question.

 

Question 2

During an enterprise security-control modernization project, the team has two independent requirements: (1) detection pattern used to identify known malicious or suspicious activity; and (2) active prevention of traffic that matches malicious signatures, behavior, or policy. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Firewall rule
  2. Agent-based web filter
  3. Group Policy
  4. IDS signature
  5. IPS blocking

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because IDS signature means a detection pattern used to identify known malicious or suspicious activity. This option satisfies a specific requirement in the stem; Group Policy serves Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers and therefore is not interchangeable with it.

Answer E is correct because IPS blocking means active prevention of traffic that matches malicious signatures, behavior, or policy. The fixed-count item needs this function in the answer set. Agent-based web filter covers web-control software installed on endpoints to enforce browsing policy locally, a different requirement.

Incorrect Answers

 

Answer A is incorrect because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The question requires exactly 2 selections: IDS signature, IPS blocking. This option falls outside that required set.

Answer B is incorrect because Agent-based web filter means web-control software installed on endpoints to enforce browsing policy locally. The question requires exactly 2 selections: IDS signature, IPS blocking. This option falls outside that required set. For example, IPS blocking is required for active prevention of traffic that matches malicious signatures, behavior, or policy.

Answer C is incorrect because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. The required choices are IDS signature, IPS blocking. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 3

To help receiving systems detect forged envelope-sender domains, which security approach should be selected?

  1. Group Policy
  2. Firewall rule
  3. SPF
  4. Endpoint detection and response (EDR)

Correct Answer: C

Correct Answer

 

 

Answer C is correct because SPF means a DNS-published policy identifying servers authorized to send mail for a domain. The deciding point is functional fit: this option covers the stated need, while Endpoint detection and response (EDR) addresses endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Incorrect Answers

 

Answer A is incorrect because Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. That concept can be valid in another scenario, but this question is testing a DNS-published policy identifying servers authorized to send mail for a domain; SPF therefore fits the requirement more directly.

Answer B is incorrect because Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. That concept can be valid in another scenario, but this question is testing a DNS-published policy identifying servers authorized to send mail for a domain; SPF therefore fits the requirement more directly.

Answer D is incorrect because Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions. That concept can be valid in another scenario, but this question is testing a DNS-published policy identifying servers authorized to send mail for a domain; SPF therefore fits the requirement more directly.

 

Question 4

To prevent many connections before clients establish sessions with unwanted destinations, which security approach should be selected?

  1. Endpoint detection and response (EDR)
  2. DNS filtering
  3. Reputation filtering
  4. SPF

Correct Answer: B

Correct Answer

 

 

Answer B is correct because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains. The requirement maps directly to this function, whereas Endpoint detection and response (EDR) is aimed at endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Incorrect Answers

 

Answer A is incorrect because Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions. The scenario instead requires control of DNS resolution to block malicious, prohibited, or risky domains, which is why DNS filtering is the better answer; this option serves the different function defined above.

Answer C is incorrect because Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files. The scenario instead requires control of DNS resolution to block malicious, prohibited, or risky domains, which is why DNS filtering is the better answer; this option serves the different function defined above.

Answer D is incorrect because SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain. This could be appropriate elsewhere, but the required function is control of DNS resolution to block malicious, prohibited, or risky domains; that makes DNS filtering the precise choice.

 

Question 5

Reviewers working through an enterprise security-control modernization project identify three separate needs: email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit; policy enforcement that evaluates identity, device state, or compliance before granting network connectivity; analysis of identity and user activity patterns to detect anomalies. Which THREE choices map to those needs? Choose THREE.

  1. Network access control (NAC)
  2. Group Policy
  3. URL scanning
  4. User behavior analytics
  5. Endpoint detection and response (EDR)
  6. DKIM

Correct Answers: A, D, F

Correct Answers

 

 

Answer A is correct because Network access control (NAC) means policy enforcement that evaluates identity, device state, or compliance before granting network connectivity. The fixed-count item needs this function in the answer set. Group Policy covers Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers, a different requirement.

Answer D is correct because User behavior analytics means analysis of identity and user activity patterns to detect anomalies. This option satisfies a specific requirement in the stem; Group Policy serves Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers and therefore is not interchangeable with it.

Answer F is correct because DKIM means email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit. This option satisfies a specific requirement in the stem; Endpoint detection and response (EDR) serves endpoint security focused on detailed telemetry, detection, investigation, and response actions and therefore is not interchangeable with it.

Incorrect Answers

 

Answer B is incorrect because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. The required choices are DKIM, Network access control (NAC), User behavior analytics. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer C is incorrect because URL scanning means analysis of requested web addresses for policy or security risk. The fixed-count answer set is DKIM, Network access control (NAC), User behavior analytics; this option does not fill one of those named functions.

Answer E is incorrect because Endpoint detection and response (EDR) means endpoint security focused on detailed telemetry, detection, investigation, and response actions. The question requires exactly 3 selections: DKIM, Network access control (NAC), User behavior analytics. This option falls outside that required set.

 

Question 6

Two requirements remain open in an enterprise security-control modernization project: Linux mandatory access control framework that enforces policy beyond standard discretionary permissions; DNS-published policy identifying servers authorized to send mail for a domain. Which TWO options close those specific gaps? Choose TWO.

  1. SPF
  2. DNS filtering
  3. SELinux
  4. Agent-based web filter
  5. Group Policy

Correct Answers: A, C

Correct Answers

 

 

Answer A is correct because SPF means a DNS-published policy identifying servers authorized to send mail for a domain. This selection maps directly to one of the named needs. Agent-based web filter addresses web-control software installed on endpoints to enforce browsing policy locally, so it does not satisfy the same slot.

Answer C is correct because SELinux means a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions. It belongs in the fixed-count answer set because it covers one of the stated requirements. Group Policy instead serves Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers and cannot replace this function.

Incorrect Answers

 

Answer B is incorrect because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains. Every answer slot must map to a stated requirement. The correct set is SELinux, SPF, so this option cannot replace one of those selections.

Answer D is incorrect because Agent-based web filter means web-control software installed on endpoints to enforce browsing policy locally. Every answer slot must map to a stated requirement. The correct set is SELinux, SPF, so this option cannot replace one of those selections.

Answer E is incorrect because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. The fixed-count answer set is SELinux, SPF; this option does not fill one of those named functions.

 

Question 7

Which detection pattern is used to identify known malicious or suspicious activity?

  1. IPS blocking
  2. Centralized proxy filter
  3. IDS signature
  4. Group Policy

Correct Answer: C

Correct Answer

 

 

Answer C is correct because IDS signature means a detection pattern used to identify known malicious or suspicious activity. That is the function the question is testing. Group Policy would instead be used for Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Incorrect Answers

 

Answer A is incorrect because IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy. That concept can be valid in another scenario, but this question is testing a detection pattern used to identify known malicious or suspicious activity; IDS signature therefore fits the requirement more directly.

Answer B is incorrect because Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally. The scenario instead requires a detection pattern used to identify known malicious or suspicious activity, which is why IDS signature is the better answer; this option serves the different function defined above.

Answer D is incorrect because Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. The question is not asking for this function. It is testing a detection pattern used to identify known malicious or suspicious activity, so IDS signature is the stronger fit.

 

Question 8

What is a network segment separated from internal networks and used for externally reachable services?

  1. DMARC
  2. Endpoint detection and response (EDR)
  3. Screened subnet
  4. Group Policy

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Screened subnet means a network segment separated from internal networks and used for externally reachable services. That is the function the question is testing. Group Policy would instead be used for Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Incorrect Answers

 

Answer A is incorrect because DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. That concept can be valid in another scenario, but this question is testing a network segment separated from internal networks and used for externally reachable services; Screened subnet therefore fits the requirement more directly.

Answer B is incorrect because Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions. The question is not asking for this function. It is testing a network segment separated from internal networks and used for externally reachable services, so Screened subnet is the stronger fit.

Answer D is incorrect because Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. The concept is valid, but it does not match this stem. The required function is a network segment separated from internal networks and used for externally reachable services, which maps to Screened subnet.

 

Question 9

Which term describes use of authenticated and encrypted protocols instead of insecure legacy alternatives?

  1. DMARC
  2. Endpoint detection and response (EDR)
  3. SPF
  4. Secure protocol selection

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Secure protocol selection means use of authenticated and encrypted protocols instead of insecure legacy alternatives. That is the function the question is testing. Endpoint detection and response (EDR) would instead be used for endpoint security focused on detailed telemetry, detection, investigation, and response actions.

Incorrect Answers

 

Answer A is incorrect because DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. This could be appropriate elsewhere, but the required function is use of authenticated and encrypted protocols instead of insecure legacy alternatives; that makes Secure protocol selection the precise choice.

Answer B is incorrect because Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions. This could be appropriate elsewhere, but the required function is use of authenticated and encrypted protocols instead of insecure legacy alternatives; that makes Secure protocol selection the precise choice.

Answer C is incorrect because SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain. The key mismatch is functional: Secure protocol selection addresses use of authenticated and encrypted protocols instead of insecure legacy alternatives, the need stated by the question.

 

Question 10

Which term describes microsoft domain-based centralized configuration used to apply security and operating settings to users and computers?

  1. Firewall rule
  2. Endpoint detection and response (EDR)
  3. Network access control (NAC)
  4. Group Policy

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. That makes it the best answer here; Endpoint detection and response (EDR) addresses endpoint security focused on detailed telemetry, detection, investigation, and response actions, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The question is not asking for this function. It is testing Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers, so Group Policy is the stronger fit.

Answer B is incorrect because Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions. The key mismatch is functional: Group Policy addresses Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers, the need stated by the question.

Answer C is incorrect because Network access control (NAC) refers to policy enforcement that evaluates identity, device state, or compliance before granting network connectivity. The scenario instead requires Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers, which is why Group Policy is the better answer; this option serves the different function defined above.

 

Question 11

Which term describes policy enforcement that evaluates identity, device state, or compliance before granting network connectivity?

  1. Network access control (NAC)
  2. Extended detection and response (XDR)
  3. URL scanning
  4. Group Policy

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Network access control (NAC) means policy enforcement that evaluates identity, device state, or compliance before granting network connectivity. This is the precise fit for the scenario. Extended detection and response (XDR) serves the different purpose of detection and response that correlates telemetry across endpoints and other security domains.

Incorrect Answers

 

Answer B is incorrect because Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains. This could be appropriate elsewhere, but the required function is policy enforcement that evaluates identity, device state, or compliance before granting network connectivity; that makes Network access control (NAC) the precise choice.

Answer C is incorrect because URL scanning refers to analysis of requested web addresses for policy or security risk. The scenario instead requires policy enforcement that evaluates identity, device state, or compliance before granting network connectivity, which is why Network access control (NAC) is the better answer; this option serves the different function defined above.

Answer D is incorrect because Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. The question is not asking for this function. It is testing policy enforcement that evaluates identity, device state, or compliance before granting network connectivity, so Network access control (NAC) is the stronger fit.

 

Question 12

Two requirements remain open in an enterprise security-control modernization project: email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit; policy enforcement that evaluates identity, device state, or compliance before granting network connectivity. Which TWO options close those specific gaps? Choose TWO.

  1. IDS signature
  2. SPF
  3. File integrity monitoring
  4. Network access control (NAC)
  5. DKIM

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because Network access control (NAC) means policy enforcement that evaluates identity, device state, or compliance before granting network connectivity. This selection maps directly to one of the named needs. IDS signature addresses a detection pattern used to identify known malicious or suspicious activity, so it does not satisfy the same slot.

Answer E is correct because DKIM means email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit. This option satisfies a specific requirement in the stem; IDS signature serves a detection pattern used to identify known malicious or suspicious activity and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because IDS signature means a detection pattern used to identify known malicious or suspicious activity. The question requires exactly 2 selections: DKIM, Network access control (NAC). This option falls outside that required set. For example, Network access control (NAC) is required for policy enforcement that evaluates identity, device state, or compliance before granting network connectivity.

Answer B is incorrect because SPF means a DNS-published policy identifying servers authorized to send mail for a domain. The question requires exactly 2 selections: DKIM, Network access control (NAC). This option falls outside that required set. For example, DKIM is required for email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.

Answer C is incorrect because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations. Every answer slot must map to a stated requirement. The correct set is DKIM, Network access control (NAC), so this option cannot replace one of those selections.

 

Question 13

Which term describes control of DNS resolution to block malicious, prohibited, or risky domains?

  1. DNS filtering
  2. DKIM
  3. Agent-based web filter
  4. Firewall rule

Correct Answer: A

Correct Answer

 

 

Answer A is correct because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains. That is the function the question is testing. Agent-based web filter would instead be used for web-control software installed on endpoints to enforce browsing policy locally.

Incorrect Answers

 

Answer B is incorrect because DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit. The scenario instead requires control of DNS resolution to block malicious, prohibited, or risky domains, which is why DNS filtering is the better answer; this option serves the different function defined above.

Answer C is incorrect because Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally. The concept is valid, but it does not match this stem. The required function is control of DNS resolution to block malicious, prohibited, or risky domains, which maps to DNS filtering.

Answer D is incorrect because Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. That concept can be valid in another scenario, but this question is testing control of DNS resolution to block malicious, prohibited, or risky domains; DNS filtering therefore fits the requirement more directly.

 

Question 14

To recognize previously characterized attack behavior and generate alerts, which security approach should be selected?

  1. IDS signature
  2. Centralized proxy filter
  3. DKIM
  4. Firewall rule

Correct Answer: A

Correct Answer

 

 

Answer A is correct because IDS signature means a detection pattern used to identify known malicious or suspicious activity. The requirement maps directly to this function, whereas DKIM is aimed at email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit.

Incorrect Answers

 

Answer B is incorrect because Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally. The key mismatch is functional: IDS signature addresses a detection pattern used to identify known malicious or suspicious activity, the need stated by the question.

Answer C is incorrect because DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit. The concept is valid, but it does not match this stem. The required function is a detection pattern used to identify known malicious or suspicious activity, which maps to IDS signature.

Answer D is incorrect because Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. That concept can be valid in another scenario, but this question is testing a detection pattern used to identify known malicious or suspicious activity; IDS signature therefore fits the requirement more directly.

 

Question 15

Which term describes endpoint security focused on detailed telemetry, detection, investigation, and response actions?

  1. Endpoint detection and response (EDR)
  2. Screened subnet
  3. DNS filtering
  4. Group Policy

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Endpoint detection and response (EDR) means endpoint security focused on detailed telemetry, detection, investigation, and response actions. The requirement maps directly to this function, whereas DNS filtering is aimed at control of DNS resolution to block malicious, prohibited, or risky domains.

Incorrect Answers

 

Answer B is incorrect because Screened subnet refers to a network segment separated from internal networks and used for externally reachable services. The scenario instead requires endpoint security focused on detailed telemetry, detection, investigation, and response actions, which is why Endpoint detection and response (EDR) is the better answer; this option serves the different function defined above.

Answer C is incorrect because DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains. The scenario instead requires endpoint security focused on detailed telemetry, detection, investigation, and response actions, which is why Endpoint detection and response (EDR) is the better answer; this option serves the different function defined above.

Answer D is incorrect because Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. This could be appropriate elsewhere, but the required function is endpoint security focused on detailed telemetry, detection, investigation, and response actions; that makes Endpoint detection and response (EDR) the precise choice.

 

Question 16

To reduce exposure to entities with a history of malicious behavior, which security approach should be selected?

  1. Secure protocol selection
  2. Reputation filtering
  3. DKIM
  4. Firewall rule

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files. This is the precise fit for the scenario. Firewall rule serves the different purpose of a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions.

Incorrect Answers

 

Answer A is incorrect because Secure protocol selection refers to use of authenticated and encrypted protocols instead of insecure legacy alternatives. The scenario instead requires use of reputation intelligence to allow, warn, or block destinations, senders, or files, which is why Reputation filtering is the better answer; this option serves the different function defined above.

Answer C is incorrect because DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit. This could be appropriate elsewhere, but the required function is use of reputation intelligence to allow, warn, or block destinations, senders, or files; that makes Reputation filtering the precise choice.

Answer D is incorrect because Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The concept is valid, but it does not match this stem. The required function is use of reputation intelligence to allow, warn, or block destinations, senders, or files, which maps to Reputation filtering.

 

Question 17

During an enterprise security-control modernization project, the team has two independent requirements: (1) Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers; and (2) detection and response that correlates telemetry across endpoints and other security domains. Which TWO choices best satisfy those requirements? Choose TWO.

  1. IPS blocking
  2. Screened subnet
  3. Extended detection and response (XDR)
  4. Group Policy
  5. Reputation filtering

Correct Answers: C, D

Correct Answers

 

 

Answer C is correct because Extended detection and response (XDR) means detection and response that correlates telemetry across endpoints and other security domains. The fixed-count item needs this function in the answer set. Reputation filtering covers use of reputation intelligence to allow, warn, or block destinations, senders, or files, a different requirement.

Answer D is correct because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. This option satisfies a specific requirement in the stem; IPS blocking serves active prevention of traffic that matches malicious signatures, behavior, or policy and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because IPS blocking means active prevention of traffic that matches malicious signatures, behavior, or policy. The required choices are Extended detection and response (XDR), Group Policy. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer B is incorrect because Screened subnet means a network segment separated from internal networks and used for externally reachable services. The fixed-count answer set is Extended detection and response (XDR), Group Policy; this option does not fill one of those named functions.

Answer E is incorrect because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files. The question requires exactly 2 selections: Extended detection and response (XDR), Group Policy. This option falls outside that required set.

 

Question 18

During an enterprise security-control modernization project, the team has two independent requirements: (1) classification of web content into categories used by access policy; and (2) Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Firewall rule
  2. Content categorization
  3. SPF
  4. DMARC
  5. Group Policy

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Content categorization means classification of web content into categories used by access policy. One required function is exactly what this option provides. SPF may be useful elsewhere, but it is used for a DNS-published policy identifying servers authorized to send mail for a domain.

Answer E is correct because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. The fixed-count item needs this function in the answer set. SPF covers a DNS-published policy identifying servers authorized to send mail for a domain, a different requirement.

Incorrect Answers

 

Answer A is incorrect because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The fixed-count answer set is Content categorization, Group Policy; this option does not fill one of those named functions.

Answer C is incorrect because SPF means a DNS-published policy identifying servers authorized to send mail for a domain. Every answer slot must map to a stated requirement. The correct set is Content categorization, Group Policy, so this option cannot replace one of those selections.

Answer D is incorrect because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. The required choices are Content categorization, Group Policy. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 19

Which Linux mandatory access control framework enforces policy beyond standard discretionary permissions?

  1. Group Policy
  2. SELinux
  3. URL scanning
  4. IDS signature

Correct Answer: B

Correct Answer

 

 

Answer B is correct because SELinux means a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions. That makes it the best answer here; Group Policy addresses Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. The scenario instead requires a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions, which is why SELinux is the better answer; this option serves the different function defined above.

Answer C is incorrect because URL scanning refers to analysis of requested web addresses for policy or security risk. The question is not asking for this function. It is testing a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions, so SELinux is the stronger fit.

Answer D is incorrect because IDS signature refers to a detection pattern used to identify known malicious or suspicious activity. That concept can be valid in another scenario, but this question is testing a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions; SELinux therefore fits the requirement more directly.

 

Question 20

Which term describes analysis of requested web addresses for policy or security risk?

  1. DNS filtering
  2. SELinux
  3. User behavior analytics
  4. URL scanning

Correct Answer: D

Correct Answer

 

 

Answer D is correct because URL scanning means analysis of requested web addresses for policy or security risk. That makes it the best answer here; User behavior analytics addresses analysis of identity and user activity patterns to detect anomalies, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains. This could be appropriate elsewhere, but the required function is analysis of requested web addresses for policy or security risk; that makes URL scanning the precise choice.

Answer B is incorrect because SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions. The scenario instead requires analysis of requested web addresses for policy or security risk, which is why URL scanning is the better answer; this option serves the different function defined above.

Answer C is incorrect because User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies. The key mismatch is functional: URL scanning addresses analysis of requested web addresses for policy or security risk, the need stated by the question.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!