Topic 18 Practice Test 2 covers Enterprise Security Capabilities for CompTIA Security+ SY0-701 and maps to objective 4.5: Given a scenario, modify enterprise capabilities to enhance security. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
The control set for an enterprise security-control modernization project must address both email-authentication policy and reporting mechanism built on SPF and DKIM alignment and monitoring that detects unauthorized or unexpected changes to selected files and configurations. Which TWO choices map directly to those needs? Choose TWO.
- File integrity monitoring
- User behavior analytics
- IDS signature
- DMARC
- Endpoint detection and response (EDR)
Correct Answers: A, D
Correct Answers
Answer A is correct because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations. One required function is exactly what this option provides. Endpoint detection and response (EDR) may be useful elsewhere, but it is used for endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Answer D is correct because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. This option satisfies a specific requirement in the stem; Endpoint detection and response (EDR) serves endpoint security focused on detailed telemetry, detection, investigation, and response actions and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because User behavior analytics means analysis of identity and user activity patterns to detect anomalies. The scenario calls for DMARC, File integrity monitoring. Selecting this option would leave one of those required functions uncovered. For example, File integrity monitoring is required for monitoring that detects unauthorized or unexpected changes to selected files and configurations.
Answer C is incorrect because IDS signature means a detection pattern used to identify known malicious or suspicious activity. The scenario calls for DMARC, File integrity monitoring. Selecting this option would leave one of those required functions uncovered. For example, File integrity monitoring is required for monitoring that detects unauthorized or unexpected changes to selected files and configurations.
Answer E is incorrect because Endpoint detection and response (EDR) means endpoint security focused on detailed telemetry, detection, investigation, and response actions. Every answer slot must map to a stated requirement. The correct set is DMARC, File integrity monitoring, so this option cannot replace one of those selections.
Question 2
Which term describes use of reputation intelligence to allow, warn, or block destinations, senders, or files?
- Reputation filtering
- Content categorization
- Firewall rule
- SELinux
Correct Answer: A
Correct Answer
Answer A is correct because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files. That makes it the best answer here; Content categorization addresses classification of web content into categories used by access policy, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Content categorization refers to classification of web content into categories used by access policy. That concept can be valid in another scenario, but this question is testing use of reputation intelligence to allow, warn, or block destinations, senders, or files; Reputation filtering therefore fits the requirement more directly.
Answer C is incorrect because Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The key mismatch is functional: Reputation filtering addresses use of reputation intelligence to allow, warn, or block destinations, senders, or files, the need stated by the question.
Answer D is incorrect because SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions. That concept can be valid in another scenario, but this question is testing use of reputation intelligence to allow, warn, or block destinations, senders, or files; Reputation filtering therefore fits the requirement more directly.
Question 3
An architect working on an enterprise security-control modernization project needs one capability that provides control of DNS resolution to block malicious, prohibited, or risky domains and another that provides endpoint security focused on detailed telemetry, detection, investigation, and response actions. Which TWO selections are the best match? Choose TWO.
- Group Policy
- Endpoint detection and response (EDR)
- File integrity monitoring
- IDS signature
- DNS filtering
Correct Answers: B, E
Correct Answers
Answer B is correct because Endpoint detection and response (EDR) means endpoint security focused on detailed telemetry, detection, investigation, and response actions. It belongs in the fixed-count answer set because it covers one of the stated requirements. IDS signature instead serves a detection pattern used to identify known malicious or suspicious activity and cannot replace this function.
Answer E is correct because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains. It belongs in the fixed-count answer set because it covers one of the stated requirements. File integrity monitoring instead serves monitoring that detects unauthorized or unexpected changes to selected files and configurations and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. Every answer slot must map to a stated requirement. The correct set is DNS filtering, Endpoint detection and response (EDR), so this option cannot replace one of those selections.
Answer C is incorrect because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations. Every answer slot must map to a stated requirement. The correct set is DNS filtering, Endpoint detection and response (EDR), so this option cannot replace one of those selections.
Answer D is incorrect because IDS signature means a detection pattern used to identify known malicious or suspicious activity. The fixed-count answer set is DNS filtering, Endpoint detection and response (EDR); this option does not fill one of those named functions.
Question 4
To connect signals from multiple control planes into broader investigations, which security approach should be selected?
- User behavior analytics
- DNS filtering
- URL scanning
- Extended detection and response (XDR)
Correct Answer: D
Correct Answer
Answer D is correct because Extended detection and response (XDR) means detection and response that correlates telemetry across endpoints and other security domains. The requirement maps directly to this function, whereas DNS filtering is aimed at control of DNS resolution to block malicious, prohibited, or risky domains.
Incorrect Answers
Answer A is incorrect because User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies. That concept can be valid in another scenario, but this question is testing detection and response that correlates telemetry across endpoints and other security domains; Extended detection and response (XDR) therefore fits the requirement more directly.
Answer B is incorrect because DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains. This could be appropriate elsewhere, but the required function is detection and response that correlates telemetry across endpoints and other security domains; that makes Extended detection and response (XDR) the precise choice.
Answer C is incorrect because URL scanning refers to analysis of requested web addresses for policy or security risk. This could be appropriate elsewhere, but the required function is detection and response that correlates telemetry across endpoints and other security domains; that makes Extended detection and response (XDR) the precise choice.
Question 5
To identify tampering with critical system or application files, which security approach should be selected?
- DMARC
- IDS signature
- DNS filtering
- File integrity monitoring
Correct Answer: D
Correct Answer
Answer D is correct because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations. That is the function the question is testing. IDS signature would instead be used for a detection pattern used to identify known malicious or suspicious activity.
Incorrect Answers
Answer A is incorrect because DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. This could be appropriate elsewhere, but the required function is monitoring that detects unauthorized or unexpected changes to selected files and configurations; that makes File integrity monitoring the precise choice.
Answer B is incorrect because IDS signature refers to a detection pattern used to identify known malicious or suspicious activity. The key mismatch is functional: File integrity monitoring addresses monitoring that detects unauthorized or unexpected changes to selected files and configurations, the need stated by the question.
Answer C is incorrect because DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains. The scenario instead requires monitoring that detects unauthorized or unexpected changes to selected files and configurations, which is why File integrity monitoring is the better answer; this option serves the different function defined above.
Question 6
A review during an enterprise security-control modernization project identifies two gaps. One requires use of reputation intelligence to allow, warn, or block destinations, senders, or files. The other requires DNS-published policy identifying servers authorized to send mail for a domain. Which TWO options should be included in the remediation plan? Choose TWO.
- Group Policy
- SPF
- Firewall rule
- File integrity monitoring
- Reputation filtering
Correct Answers: B, E
Correct Answers
Answer B is correct because SPF means a DNS-published policy identifying servers authorized to send mail for a domain. The fixed-count item needs this function in the answer set. File integrity monitoring covers monitoring that detects unauthorized or unexpected changes to selected files and configurations, a different requirement.
Answer E is correct because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files. One required function is exactly what this option provides. File integrity monitoring may be useful elsewhere, but it is used for monitoring that detects unauthorized or unexpected changes to selected files and configurations.
Incorrect Answers
Answer A is incorrect because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. The scenario calls for SPF, Reputation filtering. Selecting this option would leave one of those required functions uncovered.
Answer C is incorrect because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The question requires exactly 2 selections: SPF, Reputation filtering. This option falls outside that required set. For example, Reputation filtering is required for use of reputation intelligence to allow, warn, or block destinations, senders, or files.
Answer D is incorrect because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations. The fixed-count answer set is SPF, Reputation filtering; this option does not fill one of those named functions.
Question 7
Which gateway receives client web requests and applies filtering or inspection centrally?
- Endpoint detection and response (EDR)
- DNS filtering
- Centralized proxy filter
- Agent-based web filter
Correct Answer: C
Correct Answer
Answer C is correct because Centralized proxy filter means a gateway that receives client web requests and applies filtering or inspection centrally. That is the function the question is testing. Endpoint detection and response (EDR) would instead be used for endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Incorrect Answers
Answer A is incorrect because Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions. The question is not asking for this function. It is testing a gateway that receives client web requests and applies filtering or inspection centrally, so Centralized proxy filter is the stronger fit.
Answer B is incorrect because DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains. The question is not asking for this function. It is testing a gateway that receives client web requests and applies filtering or inspection centrally, so Centralized proxy filter is the stronger fit.
Answer D is incorrect because Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally. The question is not asking for this function. It is testing a gateway that receives client web requests and applies filtering or inspection centrally, so Centralized proxy filter is the stronger fit.
Question 8
Which term describes monitoring that detects unauthorized or unexpected changes to selected files and configurations?
- Extended detection and response (XDR)
- File integrity monitoring
- Firewall rule
- Reputation filtering
Correct Answer: B
Correct Answer
Answer B is correct because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations. That makes it the best answer here; Reputation filtering addresses use of reputation intelligence to allow, warn, or block destinations, senders, or files, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains. This could be appropriate elsewhere, but the required function is monitoring that detects unauthorized or unexpected changes to selected files and configurations; that makes File integrity monitoring the precise choice.
Answer C is incorrect because Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. That concept can be valid in another scenario, but this question is testing monitoring that detects unauthorized or unexpected changes to selected files and configurations; File integrity monitoring therefore fits the requirement more directly.
Answer D is incorrect because Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files. The question is not asking for this function. It is testing monitoring that detects unauthorized or unexpected changes to selected files and configurations, so File integrity monitoring is the stronger fit.
Question 9
To investigate and contain suspicious endpoint behavior, which security approach should be selected?
- Endpoint detection and response (EDR)
- DKIM
- Agent-based web filter
- File integrity monitoring
Correct Answer: A
Correct Answer
Answer A is correct because Endpoint detection and response (EDR) means endpoint security focused on detailed telemetry, detection, investigation, and response actions. This matches the requirement as written. File integrity monitoring can be valid in another context, but it is used for monitoring that detects unauthorized or unexpected changes to selected files and configurations.
Incorrect Answers
Answer B is incorrect because DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit. This could be appropriate elsewhere, but the required function is endpoint security focused on detailed telemetry, detection, investigation, and response actions; that makes Endpoint detection and response (EDR) the precise choice.
Answer C is incorrect because Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally. The key mismatch is functional: Endpoint detection and response (EDR) addresses endpoint security focused on detailed telemetry, detection, investigation, and response actions, the need stated by the question.
Answer D is incorrect because File integrity monitoring refers to monitoring that detects unauthorized or unexpected changes to selected files and configurations. The question is not asking for this function. It is testing endpoint security focused on detailed telemetry, detection, investigation, and response actions, so Endpoint detection and response (EDR) is the stronger fit.
Question 10
Which term describes active prevention of traffic that matches malicious signatures, behavior, or policy?
- IPS blocking
- Endpoint detection and response (EDR)
- Agent-based web filter
- DKIM
Correct Answer: A
Correct Answer
Answer A is correct because IPS blocking means active prevention of traffic that matches malicious signatures, behavior, or policy. That makes it the best answer here; Agent-based web filter addresses web-control software installed on endpoints to enforce browsing policy locally, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions. The scenario instead requires active prevention of traffic that matches malicious signatures, behavior, or policy, which is why IPS blocking is the better answer; this option serves the different function defined above.
Answer C is incorrect because Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally. The key mismatch is functional: IPS blocking addresses active prevention of traffic that matches malicious signatures, behavior, or policy, the need stated by the question.
Answer D is incorrect because DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit. This could be appropriate elsewhere, but the required function is active prevention of traffic that matches malicious signatures, behavior, or policy; that makes IPS blocking the precise choice.
Question 11
Which term describes classification of web content into categories used by access policy?
- Endpoint detection and response (EDR)
- Content categorization
- Firewall rule
- Centralized proxy filter
Correct Answer: B
Correct Answer
Answer B is correct because Content categorization means classification of web content into categories used by access policy. This matches the requirement as written. Endpoint detection and response (EDR) can be valid in another context, but it is used for endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Incorrect Answers
Answer A is incorrect because Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions. The concept is valid, but it does not match this stem. The required function is classification of web content into categories used by access policy, which maps to Content categorization.
Answer C is incorrect because Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The question is not asking for this function. It is testing classification of web content into categories used by access policy, so Content categorization is the stronger fit.
Answer D is incorrect because Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally. That concept can be valid in another scenario, but this question is testing classification of web content into categories used by access policy; Content categorization therefore fits the requirement more directly.
Question 12
An architect working on an enterprise security-control modernization project needs one capability that provides network segment separated from internal networks and used for externally reachable services and another that provides control of DNS resolution to block malicious, prohibited, or risky domains. Which TWO selections are the best match? Choose TWO.
- DNS filtering
- SELinux
- User behavior analytics
- Screened subnet
- IDS signature
Correct Answers: A, D
Correct Answers
Answer A is correct because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains. One required function is exactly what this option provides. SELinux may be useful elsewhere, but it is used for a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.
Answer D is correct because Screened subnet means a network segment separated from internal networks and used for externally reachable services. It belongs in the fixed-count answer set because it covers one of the stated requirements. User behavior analytics instead serves analysis of identity and user activity patterns to detect anomalies and cannot replace this function.
Incorrect Answers
Answer B is incorrect because SELinux means a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions. Every answer slot must map to a stated requirement. The correct set is DNS filtering, Screened subnet, so this option cannot replace one of those selections.
Answer C is incorrect because User behavior analytics means analysis of identity and user activity patterns to detect anomalies. Every answer slot must map to a stated requirement. The correct set is DNS filtering, Screened subnet, so this option cannot replace one of those selections.
Answer E is incorrect because IDS signature means a detection pattern used to identify known malicious or suspicious activity. The fixed-count answer set is DNS filtering, Screened subnet; this option does not fill one of those named functions. For example, DNS filtering is required for control of DNS resolution to block malicious, prohibited, or risky domains.
Question 13
To block access to known malicious or prohibited destinations, which security approach should be selected?
- URL scanning
- SPF
- IPS blocking
- File integrity monitoring
Correct Answer: A
Correct Answer
Answer A is correct because URL scanning means analysis of requested web addresses for policy or security risk. That is the function the question is testing. SPF would instead be used for a DNS-published policy identifying servers authorized to send mail for a domain.
Incorrect Answers
Answer B is incorrect because SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain. That concept can be valid in another scenario, but this question is testing analysis of requested web addresses for policy or security risk; URL scanning therefore fits the requirement more directly.
Answer C is incorrect because IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy. That concept can be valid in another scenario, but this question is testing analysis of requested web addresses for policy or security risk; URL scanning therefore fits the requirement more directly.
Answer D is incorrect because File integrity monitoring refers to monitoring that detects unauthorized or unexpected changes to selected files and configurations. The key mismatch is functional: URL scanning addresses analysis of requested web addresses for policy or security risk, the need stated by the question.
Question 14
A security plan created during an enterprise security-control modernization project must provide Linux mandatory access control framework that enforces policy beyond standard discretionary permissions, email-authentication policy and reporting mechanism built on SPF and DKIM alignment, and detection and response that correlates telemetry across endpoints and other security domains. Which THREE options should be selected? Choose THREE.
- Extended detection and response (XDR)
- Firewall rule
- DMARC
- User behavior analytics
- SELinux
- Centralized proxy filter
Correct Answers: A, C, E
Correct Answers
Answer A is correct because Extended detection and response (XDR) means detection and response that correlates telemetry across endpoints and other security domains. One required function is exactly what this option provides. User behavior analytics may be useful elsewhere, but it is used for analysis of identity and user activity patterns to detect anomalies.
Answer C is correct because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. One required function is exactly what this option provides. User behavior analytics may be useful elsewhere, but it is used for analysis of identity and user activity patterns to detect anomalies.
Answer E is correct because SELinux means a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions. This option satisfies a specific requirement in the stem; User behavior analytics serves analysis of identity and user activity patterns to detect anomalies and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. Every answer slot must map to a stated requirement. The correct set is SELinux, Extended detection and response (XDR), DMARC, so this option cannot replace one of those selections.
Answer D is incorrect because User behavior analytics means analysis of identity and user activity patterns to detect anomalies. Every answer slot must map to a stated requirement. The correct set is SELinux, Extended detection and response (XDR), DMARC, so this option cannot replace one of those selections.
Answer F is incorrect because Centralized proxy filter means a gateway that receives client web requests and applies filtering or inspection centrally. The fixed-count answer set is SELinux, Extended detection and response (XDR), DMARC; this option does not fill one of those named functions.
Question 15
To protect credentials and content during network communication, which security approach should be selected?
- URL scanning
- Centralized proxy filter
- Secure protocol selection
- Group Policy
Correct Answer: C
Correct Answer
Answer C is correct because Secure protocol selection means use of authenticated and encrypted protocols instead of insecure legacy alternatives. This matches the requirement as written. Group Policy can be valid in another context, but it is used for Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.
Incorrect Answers
Answer A is incorrect because URL scanning refers to analysis of requested web addresses for policy or security risk. The key mismatch is functional: Secure protocol selection addresses use of authenticated and encrypted protocols instead of insecure legacy alternatives, the need stated by the question.
Answer B is incorrect because Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally. The question is not asking for this function. It is testing use of authenticated and encrypted protocols instead of insecure legacy alternatives, so Secure protocol selection is the stronger fit.
Answer D is incorrect because Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. The concept is valid, but it does not match this stem. The required function is use of authenticated and encrypted protocols instead of insecure legacy alternatives, which maps to Secure protocol selection.
Question 16
To confine processes and limit damage even when traditional file permissions would allow access, which security approach should be selected?
- Extended detection and response (XDR)
- SELinux
- Centralized proxy filter
- DNS filtering
Correct Answer: B
Correct Answer
Answer B is correct because SELinux means a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions. The requirement maps directly to this function, whereas Extended detection and response (XDR) is aimed at detection and response that correlates telemetry across endpoints and other security domains.
Incorrect Answers
Answer A is incorrect because Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains. This could be appropriate elsewhere, but the required function is a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions; that makes SELinux the precise choice.
Answer C is incorrect because Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally. The key mismatch is functional: SELinux addresses a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions, the need stated by the question.
Answer D is incorrect because DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains. The scenario instead requires a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions, which is why SELinux is the better answer; this option serves the different function defined above.
Question 17
Two requirements remain open in an enterprise security-control modernization project: network segment separated from internal networks and used for externally reachable services; DNS-published policy identifying servers authorized to send mail for a domain. Which TWO options close those specific gaps? Choose TWO.
- DNS filtering
- Screened subnet
- Firewall rule
- SPF
- Network access control (NAC)
Correct Answers: B, D
Correct Answers
Answer B is correct because Screened subnet means a network segment separated from internal networks and used for externally reachable services. It belongs in the fixed-count answer set because it covers one of the stated requirements. DNS filtering instead serves control of DNS resolution to block malicious, prohibited, or risky domains and cannot replace this function.
Answer D is correct because SPF means a DNS-published policy identifying servers authorized to send mail for a domain. It belongs in the fixed-count answer set because it covers one of the stated requirements. Firewall rule instead serves a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions and cannot replace this function.
Incorrect Answers
Answer A is incorrect because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains. Every answer slot must map to a stated requirement. The correct set is SPF, Screened subnet, so this option cannot replace one of those selections.
Answer C is incorrect because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The scenario calls for SPF, Screened subnet. Selecting this option would leave one of those required functions uncovered.
Answer E is incorrect because Network access control (NAC) means policy enforcement that evaluates identity, device state, or compliance before granting network connectivity. Every answer slot must map to a stated requirement. The correct set is SPF, Screened subnet, so this option cannot replace one of those selections.
Question 18
To control and log web access through a shared enforcement point, which security approach should be selected?
- Reputation filtering
- Centralized proxy filter
- Endpoint detection and response (EDR)
- Content categorization
Correct Answer: B
Correct Answer
Answer B is correct because Centralized proxy filter means a gateway that receives client web requests and applies filtering or inspection centrally. This matches the requirement as written. Endpoint detection and response (EDR) can be valid in another context, but it is used for endpoint security focused on detailed telemetry, detection, investigation, and response actions.
Incorrect Answers
Answer A is incorrect because Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files. The key mismatch is functional: Centralized proxy filter addresses a gateway that receives client web requests and applies filtering or inspection centrally, the need stated by the question.
Answer C is incorrect because Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions. The scenario instead requires a gateway that receives client web requests and applies filtering or inspection centrally, which is why Centralized proxy filter is the better answer; this option serves the different function defined above.
Answer D is incorrect because Content categorization refers to classification of web content into categories used by access policy. The concept is valid, but it does not match this stem. The required function is a gateway that receives client web requests and applies filtering or inspection centrally, which maps to Centralized proxy filter.
Question 19
Which term describes email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit?
- Group Policy
- Content categorization
- IPS blocking
- DKIM
Correct Answer: D
Correct Answer
Answer D is correct because DKIM means email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit. That makes it the best answer here; Content categorization addresses classification of web content into categories used by access policy, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. This could be appropriate elsewhere, but the required function is email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit; that makes DKIM the precise choice.
Answer B is incorrect because Content categorization refers to classification of web content into categories used by access policy. The concept is valid, but it does not match this stem. The required function is email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit, which maps to DKIM.
Answer C is incorrect because IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy. That concept can be valid in another scenario, but this question is testing email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit; DKIM therefore fits the requirement more directly.
Question 20
Which term describes analysis of identity and user activity patterns to detect anomalies?
- Extended detection and response (XDR)
- Centralized proxy filter
- User behavior analytics
- SELinux
Correct Answer: C
Correct Answer
Answer C is correct because User behavior analytics means analysis of identity and user activity patterns to detect anomalies. The deciding point is functional fit: this option covers the stated need, while SELinux addresses a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions.
Incorrect Answers
Answer A is incorrect because Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains. The concept is valid, but it does not match this stem. The required function is analysis of identity and user activity patterns to detect anomalies, which maps to User behavior analytics.
Answer B is incorrect because Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally. That concept can be valid in another scenario, but this question is testing analysis of identity and user activity patterns to detect anomalies; User behavior analytics therefore fits the requirement more directly.
Answer D is incorrect because SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions. The question is not asking for this function. It is testing analysis of identity and user activity patterns to detect anomalies, so User behavior analytics is the stronger fit.