CompTIA Security+ SY0-701 Enterprise Mitigation Techniques Practice Test 2

 

Topic 09 Practice Test 2 covers Enterprise Mitigation Techniques for CompTIA Security+ SY0-701 and maps to objective 2.5: Explain the purpose of mitigation techniques used to secure the enterprise. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

A review during an enterprise hardening and mitigation review identifies two gaps. One requires division of a network into controlled zones or segments to limit communication and reduce blast radius. The other requires disabling unnecessary services, ports, or protocols. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Host-based firewall
  2. Unnecessary-software removal
  3. Application allow list
  4. Network segmentation
  5. Port and protocol reduction

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because Network segmentation means division of a network into controlled zones or segments to limit communication and reduce blast radius. It belongs in the fixed-count answer set because it covers one of the stated requirements. Unnecessary-software removal instead serves uninstalling applications and services that are not required for the system’s role and cannot replace this function.

Answer E is correct because Port and protocol reduction means disabling unnecessary services, ports, or protocols. This option satisfies a specific requirement in the stem; Host-based firewall serves a firewall running on an individual endpoint that filters inbound and outbound traffic for that host and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Host-based firewall means a firewall running on an individual endpoint that filters inbound and outbound traffic for that host. The question requires exactly 2 selections: Network segmentation, Port and protocol reduction. This option falls outside that required set.

Answer B is incorrect because Unnecessary-software removal means uninstalling applications and services that are not required for the system’s role. The fixed-count answer set is Network segmentation, Port and protocol reduction; this option does not fill one of those named functions.

Answer C is incorrect because Application allow list means a control that permits execution only for approved applications or binaries. The scenario calls for Network segmentation, Port and protocol reduction. Selecting this option would leave one of those required functions uncovered.

 

Question 2

The control set for an enterprise hardening and mitigation review must address both authorization settings defining what actions identities can perform on resources and cryptographic protection that makes information unreadable without the appropriate key. Which TWO choices map directly to those needs? Choose TWO.

  1. Permissions
  2. Encryption
  3. Security monitoring
  4. Port and protocol reduction
  5. Network segmentation

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Permissions means authorization settings defining what actions identities can perform on resources. This option satisfies a specific requirement in the stem; Security monitoring serves continuous or periodic observation of logs, activity, and system state for suspicious conditions and therefore is not interchangeable with it.

Answer B is correct because Encryption means cryptographic protection that makes information unreadable without the appropriate key. One required function is exactly what this option provides. Port and protocol reduction may be useful elsewhere, but it is used for disabling unnecessary services, ports, or protocols.

Incorrect Answers

 

Answer C is incorrect because Security monitoring means continuous or periodic observation of logs, activity, and system state for suspicious conditions. The required choices are Permissions, Encryption. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Port and protocol reduction means disabling unnecessary services, ports, or protocols. The question requires exactly 2 selections: Permissions, Encryption. This option falls outside that required set. For example, Permissions is required for authorization settings defining what actions identities can perform on resources.

Answer E is incorrect because Network segmentation means division of a network into controlled zones or segments to limit communication and reduce blast radius. The required choices are Permissions, Encryption. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 3

Which term describes separation of a suspicious or high-risk system from normal resources?

  1. Default-credential replacement
  2. Encryption
  3. Isolation
  4. Secure decommissioning

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Isolation means separation of a suspicious or high-risk system from normal resources. The deciding point is functional fit: this option covers the stated need, while Secure decommissioning addresses controlled removal of systems or assets from service with data protection and access cleanup.

Incorrect Answers

 

Answer A is incorrect because Default-credential replacement refers to changing factory-set usernames or passwords before production use. The question is not asking for this function. It is testing separation of a suspicious or high-risk system from normal resources, so Isolation is the stronger fit.

Answer B is incorrect because Encryption refers to cryptographic protection that makes information unreadable without the appropriate key. The scenario instead requires separation of a suspicious or high-risk system from normal resources, which is why Isolation is the better answer; this option serves the different function defined above.

Answer D is incorrect because Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup. The key mismatch is functional: Isolation addresses separation of a suspicious or high-risk system from normal resources, the need stated by the question.

 

Question 4

As part of an enterprise hardening and mitigation review, reviewers identify a need for application of vendor fixes that correct vulnerabilities and software defects. Which option should they select?

  1. Port and protocol reduction
  2. Patching
  3. Endpoint protection
  4. Unnecessary-software removal

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Patching means application of vendor fixes that correct vulnerabilities and software defects. The requirement maps directly to this function, whereas Endpoint protection is aimed at host software that prevents, detects, or responds to malicious activity on endpoints.

Incorrect Answers

 

Answer A is incorrect because Port and protocol reduction means disabling unnecessary services, ports, or protocols. This could be appropriate elsewhere, but the required function is application of vendor fixes that correct vulnerabilities and software defects; that makes Patching the precise choice.

Answer C is incorrect because Endpoint protection means host software that prevents, detects, or responds to malicious activity on endpoints. The concept is valid, but it does not match this stem. The required function is application of vendor fixes that correct vulnerabilities and software defects, which maps to Patching.

Answer D is incorrect because Unnecessary-software removal means uninstalling applications and services that are not required for the system’s role. The question is not asking for this function. It is testing application of vendor fixes that correct vulnerabilities and software defects, so Patching is the stronger fit.

 

Question 5

To protect user devices and servers from malware and suspicious behavior, which security approach should be selected?

  1. Endpoint protection
  2. Application allow list
  3. Unnecessary-software removal
  4. Security monitoring

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Endpoint protection means host software that prevents, detects, or responds to malicious activity on endpoints. That is the function the question is testing. Unnecessary-software removal would instead be used for uninstalling applications and services that are not required for the system’s role.

Incorrect Answers

 

Answer B is incorrect because Application allow list refers to a control that permits execution only for approved applications or binaries. The key mismatch is functional: Endpoint protection addresses host software that prevents, detects, or responds to malicious activity on endpoints, the need stated by the question.

Answer C is incorrect because Unnecessary-software removal refers to uninstalling applications and services that are not required for the system’s role. The scenario instead requires host software that prevents, detects, or responds to malicious activity on endpoints, which is why Endpoint protection is the better answer; this option serves the different function defined above.

Answer D is incorrect because Security monitoring refers to continuous or periodic observation of logs, activity, and system state for suspicious conditions. The concept is valid, but it does not match this stem. The required function is host software that prevents, detects, or responds to malicious activity on endpoints, which maps to Endpoint protection.

 

Question 6

To eliminate predictable credentials that attackers commonly try, which security approach should be selected?

  1. Security monitoring
  2. Permissions
  3. Host-based intrusion prevention system (HIPS)
  4. Default-credential replacement

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Default-credential replacement means changing factory-set usernames or passwords before production use. That is the function the question is testing. Permissions would instead be used for authorization settings defining what actions identities can perform on resources.

Incorrect Answers

 

Answer A is incorrect because Security monitoring refers to continuous or periodic observation of logs, activity, and system state for suspicious conditions. The key mismatch is functional: Default-credential replacement addresses changing factory-set usernames or passwords before production use, the need stated by the question.

Answer B is incorrect because Permissions refers to authorization settings defining what actions identities can perform on resources. The concept is valid, but it does not match this stem. The required function is changing factory-set usernames or passwords before production use, which maps to Default-credential replacement.

Answer C is incorrect because Host-based intrusion prevention system (HIPS) refers to an endpoint control that detects and blocks suspicious host activity based on rules or behavior. The concept is valid, but it does not match this stem. The required function is changing factory-set usernames or passwords before production use, which maps to Default-credential replacement.

 

Question 7

During an enterprise hardening and mitigation review, the team has two independent requirements: (1) ordered rule set that permits or denies traffic or access based on defined criteria; and (2) endpoint control that detects and blocks suspicious host activity based on rules or behavior. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Access control list (ACL)
  2. Permissions
  3. Network segmentation
  4. Host-based intrusion prevention system (HIPS)
  5. Default-credential replacement

Correct Answers: A, D

Correct Answers

 

 

Answer A is correct because Access control list (ACL) means an ordered rule set that permits or denies traffic or access based on defined criteria. This option satisfies a specific requirement in the stem; Permissions serves authorization settings defining what actions identities can perform on resources and therefore is not interchangeable with it.

Answer D is correct because Host-based intrusion prevention system (HIPS) means an endpoint control that detects and blocks suspicious host activity based on rules or behavior. This selection maps directly to one of the named needs. Network segmentation addresses division of a network into controlled zones or segments to limit communication and reduce blast radius, so it does not satisfy the same slot.

Incorrect Answers

 

Answer B is incorrect because Permissions means authorization settings defining what actions identities can perform on resources. The question requires exactly 2 selections: Host-based intrusion prevention system (HIPS), Access control list (ACL). This option falls outside that required set.

Answer C is incorrect because Network segmentation means division of a network into controlled zones or segments to limit communication and reduce blast radius. The question requires exactly 2 selections: Host-based intrusion prevention system (HIPS), Access control list (ACL). This option falls outside that required set.

Answer E is incorrect because Default-credential replacement means changing factory-set usernames or passwords before production use. The scenario calls for Host-based intrusion prevention system (HIPS), Access control list (ACL). Selecting this option would leave one of those required functions uncovered.

 

Question 8

A design decision in an enterprise hardening and mitigation review must provide separation of a suspicious or high-risk system from normal resources. Which choice most directly satisfies that requirement?

  1. Permissions
  2. Isolation
  3. Least privilege
  4. Port and protocol reduction

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Isolation means separation of a suspicious or high-risk system from normal resources. That is the function the question is testing. Least privilege would instead be used for granting only the minimum permissions necessary for a subject to perform its required function.

Incorrect Answers

 

Answer A is incorrect because Permissions means authorization settings defining what actions identities can perform on resources. The scenario instead requires separation of a suspicious or high-risk system from normal resources, which is why Isolation is the better answer; this option serves the different function defined above.

Answer C is incorrect because Least privilege means granting only the minimum permissions necessary for a subject to perform its required function. That concept can be valid in another scenario, but this question is testing separation of a suspicious or high-risk system from normal resources; Isolation therefore fits the requirement more directly.

Answer D is incorrect because Port and protocol reduction means disabling unnecessary services, ports, or protocols. The scenario instead requires separation of a suspicious or high-risk system from normal resources, which is why Isolation is the better answer; this option serves the different function defined above.

 

Question 9

An architect working on an enterprise hardening and mitigation review needs one capability that provides control that permits execution only for approved applications or binaries and another that provides endpoint control that detects and blocks suspicious host activity based on rules or behavior. Which TWO selections are the best match? Choose TWO.

  1. Host-based intrusion prevention system (HIPS)
  2. Application allow list
  3. Access control list (ACL)
  4. Endpoint protection
  5. Unnecessary-software removal

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Host-based intrusion prevention system (HIPS) means an endpoint control that detects and blocks suspicious host activity based on rules or behavior. This selection maps directly to one of the named needs. Unnecessary-software removal addresses uninstalling applications and services that are not required for the system’s role, so it does not satisfy the same slot.

Answer B is correct because Application allow list means a control that permits execution only for approved applications or binaries. The fixed-count item needs this function in the answer set. Endpoint protection covers host software that prevents, detects, or responds to malicious activity on endpoints, a different requirement.

Incorrect Answers

 

Answer C is incorrect because Access control list (ACL) means an ordered rule set that permits or denies traffic or access based on defined criteria. The question requires exactly 2 selections: Host-based intrusion prevention system (HIPS), Application allow list. This option falls outside that required set.

Answer D is incorrect because Endpoint protection means host software that prevents, detects, or responds to malicious activity on endpoints. The required choices are Host-based intrusion prevention system (HIPS), Application allow list. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Unnecessary-software removal means uninstalling applications and services that are not required for the system’s role. Every answer slot must map to a stated requirement. The correct set is Host-based intrusion prevention system (HIPS), Application allow list, so this option cannot replace one of those selections.

 

Question 10

To enforce least privilege at files, applications, services, or other objects, which security approach should be selected?

  1. Isolation
  2. Permissions
  3. Secure decommissioning
  4. Default-credential replacement

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Permissions means authorization settings defining what actions identities can perform on resources. This is the precise fit for the scenario. Default-credential replacement serves the different purpose of changing factory-set usernames or passwords before production use.

Incorrect Answers

 

Answer A is incorrect because Isolation refers to separation of a suspicious or high-risk system from normal resources. That concept can be valid in another scenario, but this question is testing authorization settings defining what actions identities can perform on resources; Permissions therefore fits the requirement more directly.

Answer C is incorrect because Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup. This could be appropriate elsewhere, but the required function is authorization settings defining what actions identities can perform on resources; that makes Permissions the precise choice.

Answer D is incorrect because Default-credential replacement refers to changing factory-set usernames or passwords before production use. The scenario instead requires authorization settings defining what actions identities can perform on resources, which is why Permissions is the better answer; this option serves the different function defined above.

 

Question 11

To restrict network or resource access to explicitly allowed patterns, which security approach should be selected?

  1. Security monitoring
  2. Port and protocol reduction
  3. Host-based firewall
  4. Access control list (ACL)

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Access control list (ACL) means an ordered rule set that permits or denies traffic or access based on defined criteria. The requirement maps directly to this function, whereas Security monitoring is aimed at continuous or periodic observation of logs, activity, and system state for suspicious conditions.

Incorrect Answers

 

Answer A is incorrect because Security monitoring refers to continuous or periodic observation of logs, activity, and system state for suspicious conditions. The question is not asking for this function. It is testing an ordered rule set that permits or denies traffic or access based on defined criteria, so Access control list (ACL) is the stronger fit.

Answer B is incorrect because Port and protocol reduction refers to disabling unnecessary services, ports, or protocols. This could be appropriate elsewhere, but the required function is an ordered rule set that permits or denies traffic or access based on defined criteria; that makes Access control list (ACL) the precise choice.

Answer C is incorrect because Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host. That concept can be valid in another scenario, but this question is testing an ordered rule set that permits or denies traffic or access based on defined criteria; Access control list (ACL) therefore fits the requirement more directly.

 

Question 12

Which control permits execution only for approved applications or binaries?

  1. Port and protocol reduction
  2. Least privilege
  3. Application allow list
  4. Secure decommissioning

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Application allow list means a control that permits execution only for approved applications or binaries. That makes it the best answer here; Least privilege addresses granting only the minimum permissions necessary for a subject to perform its required function, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Port and protocol reduction refers to disabling unnecessary services, ports, or protocols. This could be appropriate elsewhere, but the required function is a control that permits execution only for approved applications or binaries; that makes Application allow list the precise choice.

Answer B is incorrect because Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function. The key mismatch is functional: Application allow list addresses a control that permits execution only for approved applications or binaries, the need stated by the question.

Answer D is incorrect because Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup. The concept is valid, but it does not match this stem. The required function is a control that permits execution only for approved applications or binaries, which maps to Application allow list.

 

Question 13

A security engineer is working through an enterprise hardening and mitigation review. The immediate requirement is cryptographic protection that makes information unreadable without the appropriate key. Which choice is the best fit?

  1. Encryption
  2. Security monitoring
  3. Permissions
  4. Secure decommissioning

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Encryption means cryptographic protection that makes information unreadable without the appropriate key. The deciding point is functional fit: this option covers the stated need, while Security monitoring addresses continuous or periodic observation of logs, activity, and system state for suspicious conditions.

Incorrect Answers

 

Answer B is incorrect because Security monitoring means continuous or periodic observation of logs, activity, and system state for suspicious conditions. The concept is valid, but it does not match this stem. The required function is cryptographic protection that makes information unreadable without the appropriate key, which maps to Encryption.

Answer C is incorrect because Permissions means authorization settings defining what actions identities can perform on resources. That concept can be valid in another scenario, but this question is testing cryptographic protection that makes information unreadable without the appropriate key; Encryption therefore fits the requirement more directly.

Answer D is incorrect because Secure decommissioning means controlled removal of systems or assets from service with data protection and access cleanup. This could be appropriate elsewhere, but the required function is cryptographic protection that makes information unreadable without the appropriate key; that makes Encryption the precise choice.

 

Question 14

Which ordered rule set permits or denies traffic or access based on defined criteria?

  1. Host-based firewall
  2. Encryption
  3. Access control list (ACL)
  4. Application allow list

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Access control list (ACL) means an ordered rule set that permits or denies traffic or access based on defined criteria. This is the precise fit for the scenario. Encryption serves the different purpose of cryptographic protection that makes information unreadable without the appropriate key.

Incorrect Answers

 

Answer A is incorrect because Host-based firewall refers to a firewall running on an individual endpoint that filters inbound and outbound traffic for that host. That concept can be valid in another scenario, but this question is testing an ordered rule set that permits or denies traffic or access based on defined criteria; Access control list (ACL) therefore fits the requirement more directly. This question specifically tests the requirement represented by Access control list (ACL).

Answer B is incorrect because Encryption refers to cryptographic protection that makes information unreadable without the appropriate key. The scenario instead requires an ordered rule set that permits or denies traffic or access based on defined criteria, which is why Access control list (ACL) is the better answer; this option serves the different function defined above.

Answer D is incorrect because Application allow list refers to a control that permits execution only for approved applications or binaries. The key mismatch is functional: Access control list (ACL) addresses an ordered rule set that permits or denies traffic or access based on defined criteria, the need stated by the question.

 

Question 15

Which term describes continuous or periodic observation of logs, activity, and system state for suspicious conditions?

  1. Security monitoring
  2. Application allow list
  3. Secure decommissioning
  4. Default-credential replacement

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Security monitoring means continuous or periodic observation of logs, activity, and system state for suspicious conditions. The requirement maps directly to this function, whereas Application allow list is aimed at a control that permits execution only for approved applications or binaries.

Incorrect Answers

 

Answer B is incorrect because Application allow list refers to a control that permits execution only for approved applications or binaries. This could be appropriate elsewhere, but the required function is continuous or periodic observation of logs, activity, and system state for suspicious conditions; that makes Security monitoring the precise choice.

Answer C is incorrect because Secure decommissioning refers to controlled removal of systems or assets from service with data protection and access cleanup. The concept is valid, but it does not match this stem. The required function is continuous or periodic observation of logs, activity, and system state for suspicious conditions, which maps to Security monitoring.

Answer D is incorrect because Default-credential replacement refers to changing factory-set usernames or passwords before production use. This could be appropriate elsewhere, but the required function is continuous or periodic observation of logs, activity, and system state for suspicious conditions; that makes Security monitoring the precise choice.

 

Question 16

During an enterprise hardening and mitigation review, three requirements must be addressed: (1) controlled removal of systems or assets from service with data protection and access cleanup; (2) disabling unnecessary services, ports, or protocols; and (3) uninstalling applications and services that are not required for the system’s role. Which THREE choices best satisfy them? Choose THREE.

  1. Permissions
  2. Unnecessary-software removal
  3. Secure decommissioning
  4. Isolation
  5. Configuration enforcement
  6. Port and protocol reduction

Correct Answers: B, C, F

Correct Answers

 

 

Answer B is correct because Unnecessary-software removal means uninstalling applications and services that are not required for the system’s role. The fixed-count item needs this function in the answer set. Isolation covers separation of a suspicious or high-risk system from normal resources, a different requirement.

Answer C is correct because Secure decommissioning means controlled removal of systems or assets from service with data protection and access cleanup. One required function is exactly what this option provides. Isolation may be useful elsewhere, but it is used for separation of a suspicious or high-risk system from normal resources.

Answer F is correct because Port and protocol reduction means disabling unnecessary services, ports, or protocols. One required function is exactly what this option provides. Isolation may be useful elsewhere, but it is used for separation of a suspicious or high-risk system from normal resources.

Incorrect Answers

 

Answer A is incorrect because Permissions means authorization settings defining what actions identities can perform on resources. The question requires exactly 3 selections: Secure decommissioning, Port and protocol reduction, Unnecessary-software removal. This option falls outside that required set. For example, Unnecessary-software removal is required for uninstalling applications and services that are not required for the system’s role.

Answer D is incorrect because Isolation means separation of a suspicious or high-risk system from normal resources. The required choices are Secure decommissioning, Port and protocol reduction, Unnecessary-software removal. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Configuration enforcement means use of policy, automation, or management controls to maintain approved secure settings. The scenario calls for Secure decommissioning, Port and protocol reduction, Unnecessary-software removal. Selecting this option would leave one of those required functions uncovered.

 

Question 17

A review during an enterprise hardening and mitigation review identifies two gaps. One requires application of vendor fixes that correct vulnerabilities and software defects. The other requires use of policy, automation, or management controls to maintain approved secure settings. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Access control list (ACL)
  2. Permissions
  3. Host-based intrusion prevention system (HIPS)
  4. Configuration enforcement
  5. Patching

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because Configuration enforcement means use of policy, automation, or management controls to maintain approved secure settings. It belongs in the fixed-count answer set because it covers one of the stated requirements. Access control list (ACL) instead serves an ordered rule set that permits or denies traffic or access based on defined criteria and cannot replace this function.

Answer E is correct because Patching means application of vendor fixes that correct vulnerabilities and software defects. It belongs in the fixed-count answer set because it covers one of the stated requirements. Host-based intrusion prevention system (HIPS) instead serves an endpoint control that detects and blocks suspicious host activity based on rules or behavior and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Access control list (ACL) means an ordered rule set that permits or denies traffic or access based on defined criteria. The required choices are Configuration enforcement, Patching. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer B is incorrect because Permissions means authorization settings defining what actions identities can perform on resources. The question requires exactly 2 selections: Configuration enforcement, Patching. This option falls outside that required set. For example, Patching is required for application of vendor fixes that correct vulnerabilities and software defects.

Answer C is incorrect because Host-based intrusion prevention system (HIPS) means an endpoint control that detects and blocks suspicious host activity based on rules or behavior. The fixed-count answer set is Configuration enforcement, Patching; this option does not fill one of those named functions.

 

Question 18

Which term describes division of a network into controlled zones or segments to limit communication and reduce blast radius?

  1. Encryption
  2. Least privilege
  3. Isolation
  4. Network segmentation

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Network segmentation means division of a network into controlled zones or segments to limit communication and reduce blast radius. The requirement maps directly to this function, whereas Least privilege is aimed at granting only the minimum permissions necessary for a subject to perform its required function.

Incorrect Answers

 

Answer A is incorrect because Encryption refers to cryptographic protection that makes information unreadable without the appropriate key. The concept is valid, but it does not match this stem. The required function is division of a network into controlled zones or segments to limit communication and reduce blast radius, which maps to Network segmentation.

Answer B is incorrect because Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function. That concept can be valid in another scenario, but this question is testing division of a network into controlled zones or segments to limit communication and reduce blast radius; Network segmentation therefore fits the requirement more directly. This question specifically tests the requirement represented by Network segmentation.

Answer C is incorrect because Isolation refers to separation of a suspicious or high-risk system from normal resources. That concept can be valid in another scenario, but this question is testing division of a network into controlled zones or segments to limit communication and reduce blast radius; Network segmentation therefore fits the requirement more directly.

 

Question 19

To contain potentially compromised workloads while investigation or remediation occurs, which security approach should be selected?

  1. Port and protocol reduction
  2. Least privilege
  3. Application allow list
  4. Isolation

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Isolation means separation of a suspicious or high-risk system from normal resources. The requirement maps directly to this function, whereas Application allow list is aimed at a control that permits execution only for approved applications or binaries.

Incorrect Answers

 

Answer A is incorrect because Port and protocol reduction refers to disabling unnecessary services, ports, or protocols. That concept can be valid in another scenario, but this question is testing separation of a suspicious or high-risk system from normal resources; Isolation therefore fits the requirement more directly.

Answer B is incorrect because Least privilege refers to granting only the minimum permissions necessary for a subject to perform its required function. This could be appropriate elsewhere, but the required function is separation of a suspicious or high-risk system from normal resources; that makes Isolation the precise choice.

Answer C is incorrect because Application allow list refers to a control that permits execution only for approved applications or binaries. The concept is valid, but it does not match this stem. The required function is separation of a suspicious or high-risk system from normal resources, which maps to Isolation.

 

Question 20

Which term describes application of vendor fixes that correct vulnerabilities and software defects?

  1. Patching
  2. Encryption
  3. Application allow list
  4. Endpoint protection

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Patching means application of vendor fixes that correct vulnerabilities and software defects. The requirement maps directly to this function, whereas Application allow list is aimed at a control that permits execution only for approved applications or binaries.

Incorrect Answers

 

Answer B is incorrect because Encryption refers to cryptographic protection that makes information unreadable without the appropriate key. The concept is valid, but it does not match this stem. The required function is application of vendor fixes that correct vulnerabilities and software defects, which maps to Patching.

Answer C is incorrect because Application allow list refers to a control that permits execution only for approved applications or binaries. The concept is valid, but it does not match this stem. The required function is application of vendor fixes that correct vulnerabilities and software defects, which maps to Patching.

Answer D is incorrect because Endpoint protection refers to host software that prevents, detects, or responds to malicious activity on endpoints. The question is not asking for this function. It is testing application of vendor fixes that correct vulnerabilities and software defects, so Patching is the stronger fit.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!