CompTIA Security+ SY0-701 Security Automation and Orchestration Practice Test 2

 

Topic 20 Practice Test 2 covers Security Automation and Orchestration for CompTIA Security+ SY0-701 and maps to objective 4.7: Explain the importance of automation and orchestration related to secure operations. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

Which term describes automation that repeatedly applies approved configurations and detects or corrects drift?

  1. Baseline enforcement benefit
  2. Automated service disablement
  3. API integration
  4. Automated security-group management

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Baseline enforcement benefit means automation that repeatedly applies approved configurations and detects or corrects drift. That makes it the best answer here; Automated security-group management addresses use of code or workflow to create and update network or cloud access rules consistently, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Automated service disablement refers to workflow that disables accounts, services, or access when risk conditions are met. This could be appropriate elsewhere, but the required function is automation that repeatedly applies approved configurations and detects or corrects drift; that makes Baseline enforcement benefit the precise choice.

Answer C is incorrect because API integration refers to programmatic connection between security tools so one system can query or trigger actions in another. The concept is valid, but it does not match this stem. The required function is automation that repeatedly applies approved configurations and detects or corrects drift, which maps to Baseline enforcement benefit.

Answer D is incorrect because Automated security-group management refers to use of code or workflow to create and update network or cloud access rules consistently. The concept is valid, but it does not match this stem. The required function is automation that repeatedly applies approved configurations and detects or corrects drift, which maps to Baseline enforcement benefit.

 

Question 2

To contain compromise quickly while preserving auditable decision logic, which security approach should be selected?

  1. Technical debt risk
  2. Continuous integration security testing
  3. Automated service disablement
  4. Workforce-multiplier benefit

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Automated service disablement means workflow that disables accounts, services, or access when risk conditions are met. This matches the requirement as written. Technical debt risk can be valid in another context, but it is used for future maintenance burden created by quick or poorly documented automation choices.

Incorrect Answers

 

Answer A is incorrect because Technical debt risk refers to future maintenance burden created by quick or poorly documented automation choices. The concept is valid, but it does not match this stem. The required function is workflow that disables accounts, services, or access when risk conditions are met, which maps to Automated service disablement.

Answer B is incorrect because Continuous integration security testing refers to automated security checks integrated into software build and delivery pipelines. The scenario instead requires workflow that disables accounts, services, or access when risk conditions are met, which is why Automated service disablement is the better answer; this option serves the different function defined above.

Answer D is incorrect because Workforce-multiplier benefit refers to use of automation to handle repeatable tasks so analysts can focus on higher-value decisions. The question is not asking for this function. It is testing workflow that disables accounts, services, or access when risk conditions are met, so Automated service disablement is the stronger fit.

 

Question 3

A design decision in a security-automation engineering review must provide use of code or workflow to create and update network or cloud access rules consistently. Which choice most directly satisfies that requirement?

  1. Automated security-group management
  2. Automated escalation
  3. Technical debt risk
  4. Workforce-multiplier benefit

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Automated security-group management means use of code or workflow to create and update network or cloud access rules consistently. This matches the requirement as written. Workforce-multiplier benefit can be valid in another context, but it is used for use of automation to handle repeatable tasks so analysts can focus on higher-value decisions.

Incorrect Answers

 

Answer B is incorrect because Automated escalation means routing of alerts or tasks to higher-priority responders based on severity, time, or conditions. That concept can be valid in another scenario, but this question is testing use of code or workflow to create and update network or cloud access rules consistently; Automated security-group management therefore fits the requirement more directly.

Answer C is incorrect because Technical debt risk means future maintenance burden created by quick or poorly documented automation choices. The question is not asking for this function. It is testing use of code or workflow to create and update network or cloud access rules consistently, so Automated security-group management is the stronger fit.

Answer D is incorrect because Workforce-multiplier benefit means use of automation to handle repeatable tasks so analysts can focus on higher-value decisions. The question is not asking for this function. It is testing use of code or workflow to create and update network or cloud access rules consistently, so Automated security-group management is the stronger fit.

 

Question 4

Which term describes routing of alerts or tasks to higher-priority responders based on severity, time, or conditions?

  1. Automated escalation
  2. Single-point-of-failure risk
  3. Guardrail
  4. Automated user provisioning

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Automated escalation means routing of alerts or tasks to higher-priority responders based on severity, time, or conditions. The deciding point is functional fit: this option covers the stated need, while Guardrail addresses an automated policy constraint that prevents or flags insecure configurations while still allowing approved self-service.

Incorrect Answers

 

Answer B is incorrect because Single-point-of-failure risk refers to risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails. This could be appropriate elsewhere, but the required function is routing of alerts or tasks to higher-priority responders based on severity, time, or conditions; that makes Automated escalation the precise choice.

Answer C is incorrect because Guardrail refers to an automated policy constraint that prevents or flags insecure configurations while still allowing approved self-service. That concept can be valid in another scenario, but this question is testing routing of alerts or tasks to higher-priority responders based on severity, time, or conditions; Automated escalation therefore fits the requirement more directly.

Answer D is incorrect because Automated user provisioning refers to use of scripts, workflows, or identity systems to create accounts and access based on approved triggers. The question is not asking for this function. It is testing routing of alerts or tasks to higher-priority responders based on severity, time, or conditions, so Automated escalation is the stronger fit.

 

Question 5

A review during a security-automation engineering review identifies two gaps. One requires use of automation to handle repeatable tasks so analysts can focus on higher-value decisions. The other requires future maintenance burden created by quick or poorly documented automation choices. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Automated resource provisioning
  2. Automated user provisioning
  3. Technical debt risk
  4. Baseline enforcement benefit
  5. Workforce-multiplier benefit

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because Technical debt risk means future maintenance burden created by quick or poorly documented automation choices. It belongs in the fixed-count answer set because it covers one of the stated requirements. Baseline enforcement benefit instead serves automation that repeatedly applies approved configurations and detects or corrects drift and cannot replace this function.

Answer E is correct because Workforce-multiplier benefit means use of automation to handle repeatable tasks so analysts can focus on higher-value decisions. This option satisfies a specific requirement in the stem; Baseline enforcement benefit serves automation that repeatedly applies approved configurations and detects or corrects drift and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Automated resource provisioning means creation of infrastructure or services through code, templates, or workflow. The scenario calls for Technical debt risk, Workforce-multiplier benefit. Selecting this option would leave one of those required functions uncovered.

Answer B is incorrect because Automated user provisioning means use of scripts, workflows, or identity systems to create accounts and access based on approved triggers. The question requires exactly 2 selections: Technical debt risk, Workforce-multiplier benefit. This option falls outside that required set.

Answer D is incorrect because Baseline enforcement benefit means automation that repeatedly applies approved configurations and detects or corrects drift. The question requires exactly 2 selections: Technical debt risk, Workforce-multiplier benefit. This option falls outside that required set. For example, Technical debt risk is required for future maintenance burden created by quick or poorly documented automation choices.

 

Question 6

To design redundancy and safe failure modes for central automation components, which security approach should be selected?

  1. Automation complexity risk
  2. API integration
  3. Workforce-multiplier benefit
  4. Single-point-of-failure risk

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Single-point-of-failure risk means risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails. That makes it the best answer here; Workforce-multiplier benefit addresses use of automation to handle repeatable tasks so analysts can focus on higher-value decisions, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Automation complexity risk refers to operational risk created when automated workflows become difficult to understand, test, or troubleshoot. The question is not asking for this function. It is testing risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails, so Single-point-of-failure risk is the stronger fit.

Answer B is incorrect because API integration refers to programmatic connection between security tools so one system can query or trigger actions in another. This could be appropriate elsewhere, but the required function is risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails; that makes Single-point-of-failure risk the precise choice.

Answer C is incorrect because Workforce-multiplier benefit refers to use of automation to handle repeatable tasks so analysts can focus on higher-value decisions. The question is not asking for this function. It is testing risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails, so Single-point-of-failure risk is the stronger fit.

 

Question 7

To apply approved connectivity policy at scale, which security approach should be selected?

  1. Automated escalation
  2. Automated security-group management
  3. Technical debt risk
  4. Automation complexity risk

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Automated security-group management means use of code or workflow to create and update network or cloud access rules consistently. The requirement maps directly to this function, whereas Automation complexity risk is aimed at operational risk created when automated workflows become difficult to understand, test, or troubleshoot.

Incorrect Answers

 

Answer A is incorrect because Automated escalation refers to routing of alerts or tasks to higher-priority responders based on severity, time, or conditions. The question is not asking for this function. It is testing use of code or workflow to create and update network or cloud access rules consistently, so Automated security-group management is the stronger fit.

Answer C is incorrect because Technical debt risk refers to future maintenance burden created by quick or poorly documented automation choices. The scenario instead requires use of code or workflow to create and update network or cloud access rules consistently, which is why Automated security-group management is the better answer; this option serves the different function defined above.

Answer D is incorrect because Automation complexity risk refers to operational risk created when automated workflows become difficult to understand, test, or troubleshoot. The scenario instead requires use of code or workflow to create and update network or cloud access rules consistently, which is why Automated security-group management is the better answer; this option serves the different function defined above.

 

Question 8

Two requirements remain open in a security-automation engineering review: automated security checks integrated into software build and delivery pipelines; reduction in delay between detection and a predefined response action. Which TWO options close those specific gaps? Choose TWO.

  1. Workforce-multiplier benefit
  2. Guardrail
  3. Automated security-group management
  4. Continuous integration security testing
  5. Reaction-time benefit

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because Continuous integration security testing means automated security checks integrated into software build and delivery pipelines. This selection maps directly to one of the named needs. Workforce-multiplier benefit addresses use of automation to handle repeatable tasks so analysts can focus on higher-value decisions, so it does not satisfy the same slot.

Answer E is correct because Reaction-time benefit means reduction in delay between detection and a predefined response action. The fixed-count item needs this function in the answer set. Workforce-multiplier benefit covers use of automation to handle repeatable tasks so analysts can focus on higher-value decisions, a different requirement.

Incorrect Answers

 

Answer A is incorrect because Workforce-multiplier benefit means use of automation to handle repeatable tasks so analysts can focus on higher-value decisions. The fixed-count answer set is Continuous integration security testing, Reaction-time benefit; this option does not fill one of those named functions.

Answer B is incorrect because Guardrail means an automated policy constraint that prevents or flags insecure configurations while still allowing approved self-service. The scenario calls for Continuous integration security testing, Reaction-time benefit. Selecting this option would leave one of those required functions uncovered.

Answer C is incorrect because Automated security-group management means use of code or workflow to create and update network or cloud access rules consistently. The required choices are Continuous integration security testing, Reaction-time benefit. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 9

A design decision in a security-automation engineering review must provide generation of service or incident records directly from monitoring or workflow events. Which choice most directly satisfies that requirement?

  1. Automated escalation
  2. Automated ticket creation
  3. Continuous integration security testing
  4. Automated resource provisioning

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Automated ticket creation means generation of service or incident records directly from monitoring or workflow events. That is the function the question is testing. Automated resource provisioning would instead be used for creation of infrastructure or services through code, templates, or workflow.

Incorrect Answers

 

Answer A is incorrect because Automated escalation means routing of alerts or tasks to higher-priority responders based on severity, time, or conditions. The key mismatch is functional: Automated ticket creation addresses generation of service or incident records directly from monitoring or workflow events, the need stated by the question.

Answer C is incorrect because Continuous integration security testing means automated security checks integrated into software build and delivery pipelines. The scenario instead requires generation of service or incident records directly from monitoring or workflow events, which is why Automated ticket creation is the better answer; this option serves the different function defined above.

Answer D is incorrect because Automated resource provisioning means creation of infrastructure or services through code, templates, or workflow. The scenario instead requires generation of service or incident records directly from monitoring or workflow events, which is why Automated ticket creation is the better answer; this option serves the different function defined above.

 

Question 10

A security engineer is working through a security-automation engineering review. The immediate requirement is risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails. Which choice is the best fit?

  1. Technical debt risk
  2. Automated escalation
  3. Single-point-of-failure risk
  4. Automated ticket creation

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Single-point-of-failure risk means risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails. That is the function the question is testing. Automated escalation would instead be used for routing of alerts or tasks to higher-priority responders based on severity, time, or conditions.

Incorrect Answers

 

Answer A is incorrect because Technical debt risk means future maintenance burden created by quick or poorly documented automation choices. The scenario instead requires risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails, which is why Single-point-of-failure risk is the better answer; this option serves the different function defined above.

Answer B is incorrect because Automated escalation means routing of alerts or tasks to higher-priority responders based on severity, time, or conditions. The scenario instead requires risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails, which is why Single-point-of-failure risk is the better answer; this option serves the different function defined above.

Answer D is incorrect because Automated ticket creation means generation of service or incident records directly from monitoring or workflow events. The key mismatch is functional: Single-point-of-failure risk addresses risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails, the need stated by the question.

 

Question 11

Which term describes use of scripts, workflows, or identity systems to create accounts and access based on approved triggers?

  1. Automated security-group management
  2. Automation complexity risk
  3. Automated resource provisioning
  4. Automated user provisioning

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Automated user provisioning means use of scripts, workflows, or identity systems to create accounts and access based on approved triggers. That makes it the best answer here; Automation complexity risk addresses operational risk created when automated workflows become difficult to understand, test, or troubleshoot, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Automated security-group management refers to use of code or workflow to create and update network or cloud access rules consistently. The question is not asking for this function. It is testing use of scripts, workflows, or identity systems to create accounts and access based on approved triggers, so Automated user provisioning is the stronger fit.

Answer B is incorrect because Automation complexity risk refers to operational risk created when automated workflows become difficult to understand, test, or troubleshoot. The key mismatch is functional: Automated user provisioning addresses use of scripts, workflows, or identity systems to create accounts and access based on approved triggers, the need stated by the question.

Answer C is incorrect because Automated resource provisioning refers to creation of infrastructure or services through code, templates, or workflow. The scenario instead requires use of scripts, workflows, or identity systems to create accounts and access based on approved triggers, which is why Automated user provisioning is the better answer; this option serves the different function defined above.

 

Question 12

An architect working on a security-automation engineering review needs one capability that provides generation of service or incident records directly from monitoring or workflow events and another that provides programmatic connection between security tools so one system can query or trigger actions in another. Which TWO selections are the best match? Choose TWO.

  1. API integration
  2. Continuous integration security testing
  3. Automated ticket creation
  4. Reaction-time benefit
  5. Automated escalation

Correct Answers: A, C

Correct Answers

 

 

Answer A is correct because API integration means programmatic connection between security tools so one system can query or trigger actions in another. This option satisfies a specific requirement in the stem; Reaction-time benefit serves reduction in delay between detection and a predefined response action and therefore is not interchangeable with it.

Answer C is correct because Automated ticket creation means generation of service or incident records directly from monitoring or workflow events. It belongs in the fixed-count answer set because it covers one of the stated requirements. Reaction-time benefit instead serves reduction in delay between detection and a predefined response action and cannot replace this function.

Incorrect Answers

 

Answer B is incorrect because Continuous integration security testing means automated security checks integrated into software build and delivery pipelines. Every answer slot must map to a stated requirement. The correct set is API integration, Automated ticket creation, so this option cannot replace one of those selections.

Answer D is incorrect because Reaction-time benefit means reduction in delay between detection and a predefined response action. The scenario calls for API integration, Automated ticket creation. Selecting this option would leave one of those required functions uncovered. For example, Automated ticket creation is required for generation of service or incident records directly from monitoring or workflow events.

Answer E is incorrect because Automated escalation means routing of alerts or tasks to higher-priority responders based on severity, time, or conditions. The required choices are API integration, Automated ticket creation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 13

To improve consistency across large environments, which security approach should be selected?

  1. Automation complexity risk
  2. API integration
  3. Automated security-group management
  4. Baseline enforcement benefit

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Baseline enforcement benefit means automation that repeatedly applies approved configurations and detects or corrects drift. The deciding point is functional fit: this option covers the stated need, while API integration addresses programmatic connection between security tools so one system can query or trigger actions in another.

Incorrect Answers

 

Answer A is incorrect because Automation complexity risk refers to operational risk created when automated workflows become difficult to understand, test, or troubleshoot. The scenario instead requires automation that repeatedly applies approved configurations and detects or corrects drift, which is why Baseline enforcement benefit is the better answer; this option serves the different function defined above.

Answer B is incorrect because API integration refers to programmatic connection between security tools so one system can query or trigger actions in another. The scenario instead requires automation that repeatedly applies approved configurations and detects or corrects drift, which is why Baseline enforcement benefit is the better answer; this option serves the different function defined above.

Answer C is incorrect because Automated security-group management refers to use of code or workflow to create and update network or cloud access rules consistently. The scenario instead requires automation that repeatedly applies approved configurations and detects or corrects drift, which is why Baseline enforcement benefit is the better answer; this option serves the different function defined above.

 

Question 14

A security plan created during a security-automation engineering review must provide use of scripts, workflows, or identity systems to create accounts and access based on approved triggers, workflow that disables accounts, services, or access when risk conditions are met, and programmatic connection between security tools so one system can query or trigger actions in another. Which THREE options should be selected? Choose THREE.

  1. Automated resource provisioning
  2. Technical debt risk
  3. Automated user provisioning
  4. Workforce-multiplier benefit
  5. Automated service disablement
  6. API integration

Correct Answers: C, E, F

Correct Answers

 

 

Answer C is correct because Automated user provisioning means use of scripts, workflows, or identity systems to create accounts and access based on approved triggers. The fixed-count item needs this function in the answer set. Automated resource provisioning covers creation of infrastructure or services through code, templates, or workflow, a different requirement.

Answer E is correct because Automated service disablement means workflow that disables accounts, services, or access when risk conditions are met. This selection maps directly to one of the named needs. Technical debt risk addresses future maintenance burden created by quick or poorly documented automation choices, so it does not satisfy the same slot.

Answer F is correct because API integration means programmatic connection between security tools so one system can query or trigger actions in another. This selection maps directly to one of the named needs. Technical debt risk addresses future maintenance burden created by quick or poorly documented automation choices, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because Automated resource provisioning means creation of infrastructure or services through code, templates, or workflow. The fixed-count answer set is Automated service disablement, Automated user provisioning, API integration; this option does not fill one of those named functions.

Answer B is incorrect because Technical debt risk means future maintenance burden created by quick or poorly documented automation choices. The fixed-count answer set is Automated service disablement, Automated user provisioning, API integration; this option does not fill one of those named functions.

Answer D is incorrect because Workforce-multiplier benefit means use of automation to handle repeatable tasks so analysts can focus on higher-value decisions. The scenario calls for Automated service disablement, Automated user provisioning, API integration. Selecting this option would leave one of those required functions uncovered.

 

Question 15

The control set for a security-automation engineering review must address both programmatic connection between security tools so one system can query or trigger actions in another and automation that repeatedly applies approved configurations and detects or corrects drift. Which TWO choices map directly to those needs? Choose TWO.

  1. Automated service disablement
  2. API integration
  3. Reaction-time benefit
  4. Baseline enforcement benefit
  5. Single-point-of-failure risk

Correct Answers: B, D

Correct Answers

 

 

Answer B is correct because API integration means programmatic connection between security tools so one system can query or trigger actions in another. It belongs in the fixed-count answer set because it covers one of the stated requirements. Reaction-time benefit instead serves reduction in delay between detection and a predefined response action and cannot replace this function.

Answer D is correct because Baseline enforcement benefit means automation that repeatedly applies approved configurations and detects or corrects drift. This option satisfies a specific requirement in the stem; Reaction-time benefit serves reduction in delay between detection and a predefined response action and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Automated service disablement means workflow that disables accounts, services, or access when risk conditions are met. Every answer slot must map to a stated requirement. The correct set is Baseline enforcement benefit, API integration, so this option cannot replace one of those selections.

Answer C is incorrect because Reaction-time benefit means reduction in delay between detection and a predefined response action. The fixed-count answer set is Baseline enforcement benefit, API integration; this option does not fill one of those named functions. For example, API integration is required for programmatic connection between security tools so one system can query or trigger actions in another.

Answer E is incorrect because Single-point-of-failure risk means risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails. The scenario calls for Baseline enforcement benefit, API integration. Selecting this option would leave one of those required functions uncovered.

 

Question 16

Which term describes use of code or workflow to create and update network or cloud access rules consistently?

  1. Automated resource provisioning
  2. Single-point-of-failure risk
  3. API integration
  4. Automated security-group management

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Automated security-group management means use of code or workflow to create and update network or cloud access rules consistently. The requirement maps directly to this function, whereas Automated resource provisioning is aimed at creation of infrastructure or services through code, templates, or workflow.

Incorrect Answers

 

Answer A is incorrect because Automated resource provisioning refers to creation of infrastructure or services through code, templates, or workflow. The key mismatch is functional: Automated security-group management addresses use of code or workflow to create and update network or cloud access rules consistently, the need stated by the question.

Answer B is incorrect because Single-point-of-failure risk refers to risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails. The scenario instead requires use of code or workflow to create and update network or cloud access rules consistently, which is why Automated security-group management is the better answer; this option serves the different function defined above.

Answer C is incorrect because API integration refers to programmatic connection between security tools so one system can query or trigger actions in another. The question is not asking for this function. It is testing use of code or workflow to create and update network or cloud access rules consistently, so Automated security-group management is the stronger fit.

 

Question 17

During a security-automation engineering review, the team has two independent requirements: (1) risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails; and (2) future maintenance burden created by quick or poorly documented automation choices. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Continuous integration security testing
  2. API integration
  3. Technical debt risk
  4. Single-point-of-failure risk
  5. Automated security-group management

Correct Answers: C, D

Correct Answers

 

 

Answer C is correct because Technical debt risk means future maintenance burden created by quick or poorly documented automation choices. This selection maps directly to one of the named needs. API integration addresses programmatic connection between security tools so one system can query or trigger actions in another, so it does not satisfy the same slot.

Answer D is correct because Single-point-of-failure risk means risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails. It belongs in the fixed-count answer set because it covers one of the stated requirements. Continuous integration security testing instead serves automated security checks integrated into software build and delivery pipelines and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Continuous integration security testing means automated security checks integrated into software build and delivery pipelines. The scenario calls for Single-point-of-failure risk, Technical debt risk. Selecting this option would leave one of those required functions uncovered.

Answer B is incorrect because API integration means programmatic connection between security tools so one system can query or trigger actions in another. The fixed-count answer set is Single-point-of-failure risk, Technical debt risk; this option does not fill one of those named functions.

Answer E is incorrect because Automated security-group management means use of code or workflow to create and update network or cloud access rules consistently. The fixed-count answer set is Single-point-of-failure risk, Technical debt risk; this option does not fill one of those named functions.

 

Question 18

Which term describes creation of infrastructure or services through code, templates, or workflow?

  1. Automated service disablement
  2. Automated user provisioning
  3. Automated resource provisioning
  4. Automated security-group management

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Automated resource provisioning means creation of infrastructure or services through code, templates, or workflow. That is the function the question is testing. Automated user provisioning would instead be used for use of scripts, workflows, or identity systems to create accounts and access based on approved triggers.

Incorrect Answers

 

Answer A is incorrect because Automated service disablement refers to workflow that disables accounts, services, or access when risk conditions are met. This could be appropriate elsewhere, but the required function is creation of infrastructure or services through code, templates, or workflow; that makes Automated resource provisioning the precise choice.

Answer B is incorrect because Automated user provisioning refers to use of scripts, workflows, or identity systems to create accounts and access based on approved triggers. The key mismatch is functional: Automated resource provisioning addresses creation of infrastructure or services through code, templates, or workflow, the need stated by the question.

Answer D is incorrect because Automated security-group management refers to use of code or workflow to create and update network or cloud access rules consistently. This could be appropriate elsewhere, but the required function is creation of infrastructure or services through code, templates, or workflow; that makes Automated resource provisioning the precise choice.

 

Question 19

To orchestrate security workflows across multiple platforms, which security approach should be selected?

  1. Single-point-of-failure risk
  2. Automation complexity risk
  3. API integration
  4. Workforce-multiplier benefit

Correct Answer: C

Correct Answer

 

 

Answer C is correct because API integration means programmatic connection between security tools so one system can query or trigger actions in another. This is the precise fit for the scenario. Workforce-multiplier benefit serves the different purpose of use of automation to handle repeatable tasks so analysts can focus on higher-value decisions.

Incorrect Answers

 

Answer A is incorrect because Single-point-of-failure risk refers to risk that one orchestrator, integration, or dependency can disrupt many automated processes if it fails. The question is not asking for this function. It is testing programmatic connection between security tools so one system can query or trigger actions in another, so API integration is the stronger fit.

Answer B is incorrect because Automation complexity risk refers to operational risk created when automated workflows become difficult to understand, test, or troubleshoot. The key mismatch is functional: API integration addresses programmatic connection between security tools so one system can query or trigger actions in another, the need stated by the question.

Answer D is incorrect because Workforce-multiplier benefit refers to use of automation to handle repeatable tasks so analysts can focus on higher-value decisions. The scenario instead requires programmatic connection between security tools so one system can query or trigger actions in another, which is why API integration is the better answer; this option serves the different function defined above. This question specifically tests the requirement represented by API integration.

 

Question 20

Which term describes operational risk created when automated workflows become difficult to understand, test, or troubleshoot?

  1. Guardrail
  2. Automation complexity risk
  3. Continuous integration security testing
  4. Automated ticket creation

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Automation complexity risk means operational risk created when automated workflows become difficult to understand, test, or troubleshoot. The deciding point is functional fit: this option covers the stated need, while Continuous integration security testing addresses automated security checks integrated into software build and delivery pipelines.

Incorrect Answers

 

Answer A is incorrect because Guardrail refers to an automated policy constraint that prevents or flags insecure configurations while still allowing approved self-service. That concept can be valid in another scenario, but this question is testing operational risk created when automated workflows become difficult to understand, test, or troubleshoot; Automation complexity risk therefore fits the requirement more directly.

Answer C is incorrect because Continuous integration security testing refers to automated security checks integrated into software build and delivery pipelines. The scenario instead requires operational risk created when automated workflows become difficult to understand, test, or troubleshoot, which is why Automation complexity risk is the better answer; this option serves the different function defined above.

Answer D is incorrect because Automated ticket creation refers to generation of service or incident records directly from monitoring or workflow events. The concept is valid, but it does not match this stem. The required function is operational risk created when automated workflows become difficult to understand, test, or troubleshoot, which maps to Automation complexity risk.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!