CompTIA Security+ SY0-701 Enterprise Security Capabilities Practice Test 3

 

Topic 18 Practice Test 3 covers Enterprise Security Capabilities for CompTIA Security+ SY0-701 and maps to objective 4.5: Given a scenario, modify enterprise capabilities to enhance security. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

A design decision in an enterprise security-control modernization project must provide detection and response that correlates telemetry across endpoints and other security domains. Which choice most directly satisfies that requirement?

  1. User behavior analytics
  2. Extended detection and response (XDR)
  3. IDS signature
  4. SPF

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Extended detection and response (XDR) means detection and response that correlates telemetry across endpoints and other security domains. That makes it the best answer here; SPF addresses a DNS-published policy identifying servers authorized to send mail for a domain, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because User behavior analytics means analysis of identity and user activity patterns to detect anomalies. The key mismatch is functional: Extended detection and response (XDR) addresses detection and response that correlates telemetry across endpoints and other security domains, the need stated by the question.

Answer C is incorrect because IDS signature means a detection pattern used to identify known malicious or suspicious activity. The question is not asking for this function. It is testing detection and response that correlates telemetry across endpoints and other security domains, so Extended detection and response (XDR) is the stronger fit.

Answer D is incorrect because SPF means a DNS-published policy identifying servers authorized to send mail for a domain. The concept is valid, but it does not match this stem. The required function is detection and response that correlates telemetry across endpoints and other security domains, which maps to Extended detection and response (XDR).

 

Question 2

Two requirements remain open in an enterprise security-control modernization project: use of authenticated and encrypted protocols instead of insecure legacy alternatives; email-authentication policy and reporting mechanism built on SPF and DKIM alignment. Which TWO options close those specific gaps? Choose TWO.

  1. Reputation filtering
  2. DMARC
  3. File integrity monitoring
  4. Endpoint detection and response (EDR)
  5. Secure protocol selection

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. The fixed-count item needs this function in the answer set. Endpoint detection and response (EDR) covers endpoint security focused on detailed telemetry, detection, investigation, and response actions, a different requirement.

Answer E is correct because Secure protocol selection means use of authenticated and encrypted protocols instead of insecure legacy alternatives. This selection maps directly to one of the named needs. Endpoint detection and response (EDR) addresses endpoint security focused on detailed telemetry, detection, investigation, and response actions, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files. The question requires exactly 2 selections: Secure protocol selection, DMARC. This option falls outside that required set. For example, Secure protocol selection is required for use of authenticated and encrypted protocols instead of insecure legacy alternatives.

Answer C is incorrect because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations. The required choices are Secure protocol selection, DMARC. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Endpoint detection and response (EDR) means endpoint security focused on detailed telemetry, detection, investigation, and response actions. The question requires exactly 2 selections: Secure protocol selection, DMARC. This option falls outside that required set.

 

Question 3

To stop suspicious activity before it reaches the target, which security approach should be selected?

  1. IPS blocking
  2. User behavior analytics
  3. DKIM
  4. Screened subnet

Correct Answer: A

Correct Answer

 

 

Answer A is correct because IPS blocking means active prevention of traffic that matches malicious signatures, behavior, or policy. The deciding point is functional fit: this option covers the stated need, while User behavior analytics addresses analysis of identity and user activity patterns to detect anomalies.

Incorrect Answers

 

Answer B is incorrect because User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies. The scenario instead requires active prevention of traffic that matches malicious signatures, behavior, or policy, which is why IPS blocking is the better answer; this option serves the different function defined above.

Answer C is incorrect because DKIM refers to email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit. The scenario instead requires active prevention of traffic that matches malicious signatures, behavior, or policy, which is why IPS blocking is the better answer; this option serves the different function defined above.

Answer D is incorrect because Screened subnet refers to a network segment separated from internal networks and used for externally reachable services. The concept is valid, but it does not match this stem. The required function is active prevention of traffic that matches malicious signatures, behavior, or policy, which maps to IPS blocking.

 

Question 4

To provide cryptographic domain-level message integrity and origin assurance, which security approach should be selected?

  1. DKIM
  2. IDS signature
  3. Centralized proxy filter
  4. Content categorization

Correct Answer: A

Correct Answer

 

 

Answer A is correct because DKIM means email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit. That makes it the best answer here; Content categorization addresses classification of web content into categories used by access policy, not the function requested in the stem. This question specifically tests the requirement represented by DKIM.

Incorrect Answers

 

Answer B is incorrect because IDS signature refers to a detection pattern used to identify known malicious or suspicious activity. This could be appropriate elsewhere, but the required function is email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit; that makes DKIM the precise choice.

Answer C is incorrect because Centralized proxy filter refers to a gateway that receives client web requests and applies filtering or inspection centrally. That concept can be valid in another scenario, but this question is testing email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit; DKIM therefore fits the requirement more directly.

Answer D is incorrect because Content categorization refers to classification of web content into categories used by access policy. The question is not asking for this function. It is testing email authentication that uses a digital signature so recipients can validate a message was authorized by a domain and was not altered in transit, so DKIM is the stronger fit.

 

Question 5

To isolate public-facing systems from sensitive internal resources, which security approach should be selected?

  1. Agent-based web filter
  2. Screened subnet
  3. Reputation filtering
  4. DNS filtering

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Screened subnet means a network segment separated from internal networks and used for externally reachable services. That makes it the best answer here; Agent-based web filter addresses web-control software installed on endpoints to enforce browsing policy locally, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally. The concept is valid, but it does not match this stem. The required function is a network segment separated from internal networks and used for externally reachable services, which maps to Screened subnet.

Answer C is incorrect because Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files. The concept is valid, but it does not match this stem. The required function is a network segment separated from internal networks and used for externally reachable services, which maps to Screened subnet.

Answer D is incorrect because DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains. The scenario instead requires a network segment separated from internal networks and used for externally reachable services, which is why Screened subnet is the better answer; this option serves the different function defined above.

 

Question 6

Which policy statement permits, denies, or otherwise handles network traffic matching defined conditions?

  1. IDS signature
  2. URL scanning
  3. Firewall rule
  4. DMARC

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The requirement maps directly to this function, whereas DMARC is aimed at an email-authentication policy and reporting mechanism built on SPF and DKIM alignment.

Incorrect Answers

 

Answer A is incorrect because IDS signature refers to a detection pattern used to identify known malicious or suspicious activity. The question is not asking for this function. It is testing a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions, so Firewall rule is the stronger fit.

Answer B is incorrect because URL scanning refers to analysis of requested web addresses for policy or security risk. The concept is valid, but it does not match this stem. The required function is a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions, which maps to Firewall rule.

Answer D is incorrect because DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. The scenario instead requires a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions, which is why Firewall rule is the better answer; this option serves the different function defined above.

 

Question 7

To control network flows according to source, destination, service, state, or application context, which security approach should be selected?

  1. Firewall rule
  2. DNS filtering
  3. Agent-based web filter
  4. Group Policy

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The deciding point is functional fit: this option covers the stated need, while Agent-based web filter addresses web-control software installed on endpoints to enforce browsing policy locally.

Incorrect Answers

 

Answer B is incorrect because DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains. That concept can be valid in another scenario, but this question is testing a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions; Firewall rule therefore fits the requirement more directly.

Answer C is incorrect because Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally. That concept can be valid in another scenario, but this question is testing a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions; Firewall rule therefore fits the requirement more directly.

Answer D is incorrect because Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. That concept can be valid in another scenario, but this question is testing a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions; Firewall rule therefore fits the requirement more directly.

 

Question 8

The control set for an enterprise security-control modernization project must address both use of authenticated and encrypted protocols instead of insecure legacy alternatives and monitoring that detects unauthorized or unexpected changes to selected files and configurations. Which TWO choices map directly to those needs? Choose TWO.

  1. SELinux
  2. File integrity monitoring
  3. Secure protocol selection
  4. Reputation filtering
  5. Centralized proxy filter

Correct Answers: B, C

Correct Answers

 

 

Answer B is correct because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations. This option satisfies a specific requirement in the stem; Reputation filtering serves use of reputation intelligence to allow, warn, or block destinations, senders, or files and therefore is not interchangeable with it.

Answer C is correct because Secure protocol selection means use of authenticated and encrypted protocols instead of insecure legacy alternatives. This selection maps directly to one of the named needs. SELinux addresses a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because SELinux means a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions. The question requires exactly 2 selections: Secure protocol selection, File integrity monitoring. This option falls outside that required set.

Answer D is incorrect because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files. The scenario calls for Secure protocol selection, File integrity monitoring. Selecting this option would leave one of those required functions uncovered.

Answer E is incorrect because Centralized proxy filter means a gateway that receives client web requests and applies filtering or inspection centrally. The scenario calls for Secure protocol selection, File integrity monitoring. Selecting this option would leave one of those required functions uncovered.

 

Question 9

A review during an enterprise security-control modernization project identifies two gaps. One requires gateway that receives client web requests and applies filtering or inspection centrally. The other requires DNS-published policy identifying servers authorized to send mail for a domain. Which TWO options should be included in the remediation plan? Choose TWO.

  1. SPF
  2. User behavior analytics
  3. File integrity monitoring
  4. Centralized proxy filter
  5. Screened subnet

Correct Answers: A, D

Correct Answers

 

 

Answer A is correct because SPF means a DNS-published policy identifying servers authorized to send mail for a domain. This selection maps directly to one of the named needs. Screened subnet addresses a network segment separated from internal networks and used for externally reachable services, so it does not satisfy the same slot.

Answer D is correct because Centralized proxy filter means a gateway that receives client web requests and applies filtering or inspection centrally. This selection maps directly to one of the named needs. User behavior analytics addresses analysis of identity and user activity patterns to detect anomalies, so it does not satisfy the same slot.

Incorrect Answers

 

Answer B is incorrect because User behavior analytics means analysis of identity and user activity patterns to detect anomalies. The scenario calls for SPF, Centralized proxy filter. Selecting this option would leave one of those required functions uncovered. For example, Centralized proxy filter is required for a gateway that receives client web requests and applies filtering or inspection centrally.

Answer C is incorrect because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations. Every answer slot must map to a stated requirement. The correct set is SPF, Centralized proxy filter, so this option cannot replace one of those selections.

Answer E is incorrect because Screened subnet means a network segment separated from internal networks and used for externally reachable services. The fixed-count answer set is SPF, Centralized proxy filter; this option does not fill one of those named functions.

 

Question 10

To apply URL and content rules even when the device is away from the corporate network, which security approach should be selected?

  1. SPF
  2. Secure protocol selection
  3. IDS signature
  4. Agent-based web filter

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Agent-based web filter means web-control software installed on endpoints to enforce browsing policy locally. The requirement maps directly to this function, whereas Secure protocol selection is aimed at use of authenticated and encrypted protocols instead of insecure legacy alternatives.

Incorrect Answers

 

Answer A is incorrect because SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain. This could be appropriate elsewhere, but the required function is web-control software installed on endpoints to enforce browsing policy locally; that makes Agent-based web filter the precise choice.

Answer B is incorrect because Secure protocol selection refers to use of authenticated and encrypted protocols instead of insecure legacy alternatives. That concept can be valid in another scenario, but this question is testing web-control software installed on endpoints to enforce browsing policy locally; Agent-based web filter therefore fits the requirement more directly.

Answer C is incorrect because IDS signature refers to a detection pattern used to identify known malicious or suspicious activity. The concept is valid, but it does not match this stem. The required function is web-control software installed on endpoints to enforce browsing policy locally, which maps to Agent-based web filter.

 

Question 11

To restrict network access for unauthorized or noncompliant devices, which security approach should be selected?

  1. File integrity monitoring
  2. Extended detection and response (XDR)
  3. DMARC
  4. Network access control (NAC)

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Network access control (NAC) means policy enforcement that evaluates identity, device state, or compliance before granting network connectivity. This matches the requirement as written. File integrity monitoring can be valid in another context, but it is used for monitoring that detects unauthorized or unexpected changes to selected files and configurations.

Incorrect Answers

 

Answer A is incorrect because File integrity monitoring refers to monitoring that detects unauthorized or unexpected changes to selected files and configurations. The key mismatch is functional: Network access control (NAC) addresses policy enforcement that evaluates identity, device state, or compliance before granting network connectivity, the need stated by the question.

Answer B is incorrect because Extended detection and response (XDR) refers to detection and response that correlates telemetry across endpoints and other security domains. The scenario instead requires policy enforcement that evaluates identity, device state, or compliance before granting network connectivity, which is why Network access control (NAC) is the better answer; this option serves the different function defined above.

Answer C is incorrect because DMARC refers to an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. That concept can be valid in another scenario, but this question is testing policy enforcement that evaluates identity, device state, or compliance before granting network connectivity; Network access control (NAC) therefore fits the requirement more directly.

 

Question 12

The control set for an enterprise security-control modernization project must address both Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers and email-authentication policy and reporting mechanism built on SPF and DKIM alignment. Which TWO choices map directly to those needs? Choose TWO.

  1. Group Policy
  2. DNS filtering
  3. Screened subnet
  4. DMARC
  5. Reputation filtering

Correct Answers: A, D

Correct Answers

 

 

Answer A is correct because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. It belongs in the fixed-count answer set because it covers one of the stated requirements. Screened subnet instead serves a network segment separated from internal networks and used for externally reachable services and cannot replace this function.

Answer D is correct because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. One required function is exactly what this option provides. Reputation filtering may be useful elsewhere, but it is used for use of reputation intelligence to allow, warn, or block destinations, senders, or files.

Incorrect Answers

 

Answer B is incorrect because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains. The fixed-count answer set is DMARC, Group Policy; this option does not fill one of those named functions. For example, Group Policy is required for Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers.

Answer C is incorrect because Screened subnet means a network segment separated from internal networks and used for externally reachable services. Every answer slot must map to a stated requirement. The correct set is DMARC, Group Policy, so this option cannot replace one of those selections.

Answer E is incorrect because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files. The scenario calls for DMARC, Group Policy. Selecting this option would leave one of those required functions uncovered.

 

Question 13

Which DNS-published policy identifying servers are authorized to send mail for a domain?

  1. URL scanning
  2. Group Policy
  3. Content categorization
  4. SPF

Correct Answer: D

Correct Answer

 

 

Answer D is correct because SPF means a DNS-published policy identifying servers authorized to send mail for a domain. The deciding point is functional fit: this option covers the stated need, while URL scanning addresses analysis of requested web addresses for policy or security risk.

Incorrect Answers

 

Answer A is incorrect because URL scanning refers to analysis of requested web addresses for policy or security risk. The question is not asking for this function. It is testing a DNS-published policy identifying servers authorized to send mail for a domain, so SPF is the stronger fit.

Answer B is incorrect because Group Policy refers to Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. This could be appropriate elsewhere, but the required function is a DNS-published policy identifying servers authorized to send mail for a domain; that makes SPF the precise choice.

Answer C is incorrect because Content categorization refers to classification of web content into categories used by access policy. The key mismatch is functional: SPF addresses a DNS-published policy identifying servers authorized to send mail for a domain, the need stated by the question.

 

Question 14

Reviewers working through an enterprise security-control modernization project identify three separate needs: control of DNS resolution to block malicious, prohibited, or risky domains; email-authentication policy and reporting mechanism built on SPF and DKIM alignment; DNS-published policy identifying servers authorized to send mail for a domain. Which THREE choices map to those needs? Choose THREE.

  1. SPF
  2. DMARC
  3. Network access control (NAC)
  4. Firewall rule
  5. Centralized proxy filter
  6. DNS filtering

Correct Answers: A, B, F

Correct Answers

 

 

Answer A is correct because SPF means a DNS-published policy identifying servers authorized to send mail for a domain. This option satisfies a specific requirement in the stem; Centralized proxy filter serves a gateway that receives client web requests and applies filtering or inspection centrally and therefore is not interchangeable with it.

Answer B is correct because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. The fixed-count item needs this function in the answer set. Centralized proxy filter covers a gateway that receives client web requests and applies filtering or inspection centrally, a different requirement.

Answer F is correct because DNS filtering means control of DNS resolution to block malicious, prohibited, or risky domains. This selection maps directly to one of the named needs. Centralized proxy filter addresses a gateway that receives client web requests and applies filtering or inspection centrally, so it does not satisfy the same slot.

Incorrect Answers

 

Answer C is incorrect because Network access control (NAC) means policy enforcement that evaluates identity, device state, or compliance before granting network connectivity. Every answer slot must map to a stated requirement. The correct set is DMARC, SPF, DNS filtering, so this option cannot replace one of those selections.

Answer D is incorrect because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The fixed-count answer set is DMARC, SPF, DNS filtering; this option does not fill one of those named functions.

Answer E is incorrect because Centralized proxy filter means a gateway that receives client web requests and applies filtering or inspection centrally. The scenario calls for DMARC, SPF, DNS filtering. Selecting this option would leave one of those required functions uncovered.

 

Question 15

To apply browsing rules based on content type rather than individual URLs alone, which security approach should be selected?

  1. IPS blocking
  2. Content categorization
  3. User behavior analytics
  4. Agent-based web filter

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Content categorization means classification of web content into categories used by access policy. That makes it the best answer here; Agent-based web filter addresses web-control software installed on endpoints to enforce browsing policy locally, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because IPS blocking refers to active prevention of traffic that matches malicious signatures, behavior, or policy. The question is not asking for this function. It is testing classification of web content into categories used by access policy, so Content categorization is the stronger fit.

Answer C is incorrect because User behavior analytics refers to analysis of identity and user activity patterns to detect anomalies. The concept is valid, but it does not match this stem. The required function is classification of web content into categories used by access policy, which maps to Content categorization.

Answer D is incorrect because Agent-based web filter refers to web-control software installed on endpoints to enforce browsing policy locally. This could be appropriate elsewhere, but the required function is classification of web content into categories used by access policy; that makes Content categorization the precise choice.

 

Question 16

What is an email-authentication policy and reporting mechanism built on SPF and DKIM alignment?

  1. SELinux
  2. IDS signature
  3. DMARC
  4. Endpoint detection and response (EDR)

Correct Answer: C

Correct Answer

 

 

Answer C is correct because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. This matches the requirement as written. IDS signature can be valid in another context, but it is used for a detection pattern used to identify known malicious or suspicious activity.

Incorrect Answers

 

Answer A is incorrect because SELinux refers to a Linux mandatory access control framework that enforces policy beyond standard discretionary permissions. The concept is valid, but it does not match this stem. The required function is an email-authentication policy and reporting mechanism built on SPF and DKIM alignment, which maps to DMARC.

Answer B is incorrect because IDS signature refers to a detection pattern used to identify known malicious or suspicious activity. This could be appropriate elsewhere, but the required function is an email-authentication policy and reporting mechanism built on SPF and DKIM alignment; that makes DMARC the precise choice.

Answer D is incorrect because Endpoint detection and response (EDR) refers to endpoint security focused on detailed telemetry, detection, investigation, and response actions. The question is not asking for this function. It is testing an email-authentication policy and reporting mechanism built on SPF and DKIM alignment, so DMARC is the stronger fit.

 

Question 17

The control set for an enterprise security-control modernization project must address both classification of web content into categories used by access policy and monitoring that detects unauthorized or unexpected changes to selected files and configurations. Which TWO choices map directly to those needs? Choose TWO.

  1. Group Policy
  2. Network access control (NAC)
  3. User behavior analytics
  4. File integrity monitoring
  5. Content categorization

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because File integrity monitoring means monitoring that detects unauthorized or unexpected changes to selected files and configurations. This selection maps directly to one of the named needs. Group Policy addresses Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers, so it does not satisfy the same slot.

Answer E is correct because Content categorization means classification of web content into categories used by access policy. The fixed-count item needs this function in the answer set. Group Policy covers Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers, a different requirement.

Incorrect Answers

 

Answer A is incorrect because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. The fixed-count answer set is Content categorization, File integrity monitoring; this option does not fill one of those named functions.

Answer B is incorrect because Network access control (NAC) means policy enforcement that evaluates identity, device state, or compliance before granting network connectivity. The scenario calls for Content categorization, File integrity monitoring. Selecting this option would leave one of those required functions uncovered.

Answer C is incorrect because User behavior analytics means analysis of identity and user activity patterns to detect anomalies. Every answer slot must map to a stated requirement. The correct set is Content categorization, File integrity monitoring, so this option cannot replace one of those selections.

 

Question 18

To tell receiving domains how to handle messages that fail authenticated domain checks, which security approach should be selected?

  1. IDS signature
  2. DMARC
  3. Firewall rule
  4. Reputation filtering

Correct Answer: B

Correct Answer

 

 

Answer B is correct because DMARC means an email-authentication policy and reporting mechanism built on SPF and DKIM alignment. The requirement maps directly to this function, whereas IDS signature is aimed at a detection pattern used to identify known malicious or suspicious activity.

Incorrect Answers

 

Answer A is incorrect because IDS signature refers to a detection pattern used to identify known malicious or suspicious activity. The key mismatch is functional: DMARC addresses an email-authentication policy and reporting mechanism built on SPF and DKIM alignment, the need stated by the question.

Answer C is incorrect because Firewall rule refers to a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. The concept is valid, but it does not match this stem. The required function is an email-authentication policy and reporting mechanism built on SPF and DKIM alignment, which maps to DMARC.

Answer D is incorrect because Reputation filtering refers to use of reputation intelligence to allow, warn, or block destinations, senders, or files. The question is not asking for this function. It is testing an email-authentication policy and reporting mechanism built on SPF and DKIM alignment, so DMARC is the stronger fit.

 

Question 19

The team is resolving a gap found during an enterprise security-control modernization project: it needs gateway that receives client web requests and applies filtering or inspection centrally. Which option is most appropriate?

  1. Reputation filtering
  2. Secure protocol selection
  3. Centralized proxy filter
  4. Firewall rule

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Centralized proxy filter means a gateway that receives client web requests and applies filtering or inspection centrally. The deciding point is functional fit: this option covers the stated need, while Secure protocol selection addresses use of authenticated and encrypted protocols instead of insecure legacy alternatives.

Incorrect Answers

 

Answer A is incorrect because Reputation filtering means use of reputation intelligence to allow, warn, or block destinations, senders, or files. The question is not asking for this function. It is testing a gateway that receives client web requests and applies filtering or inspection centrally, so Centralized proxy filter is the stronger fit.

Answer B is incorrect because Secure protocol selection means use of authenticated and encrypted protocols instead of insecure legacy alternatives. The scenario instead requires a gateway that receives client web requests and applies filtering or inspection centrally, which is why Centralized proxy filter is the better answer; this option serves the different function defined above.

Answer D is incorrect because Firewall rule means a policy statement that permits, denies, or otherwise handles network traffic matching defined conditions. That concept can be valid in another scenario, but this question is testing a gateway that receives client web requests and applies filtering or inspection centrally; Centralized proxy filter therefore fits the requirement more directly.

 

Question 20

To enforce Windows configuration consistently across managed endpoints, which security approach should be selected?

  1. Secure protocol selection
  2. DNS filtering
  3. Group Policy
  4. SPF

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Group Policy means Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers. That is the function the question is testing. Secure protocol selection would instead be used for use of authenticated and encrypted protocols instead of insecure legacy alternatives.

Incorrect Answers

 

Answer A is incorrect because Secure protocol selection refers to use of authenticated and encrypted protocols instead of insecure legacy alternatives. That concept can be valid in another scenario, but this question is testing Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers; Group Policy therefore fits the requirement more directly.

Answer B is incorrect because DNS filtering refers to control of DNS resolution to block malicious, prohibited, or risky domains. The question is not asking for this function. It is testing Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers, so Group Policy is the stronger fit.

Answer D is incorrect because SPF refers to a DNS-published policy identifying servers authorized to send mail for a domain. The scenario instead requires Microsoft domain-based centralized configuration used to apply security and operating settings to users and computers, which is why Group Policy is the better answer; this option serves the different function defined above.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!