CompTIA Security+ Certification Exam SY0-701 Practice Test 1 Flashcards
Which of the following answers can be used to describe technical security controls? (Select 3 answers)
A) Focused on protecting material assets
B) Sometimes called logical security controls
C) Executed by computer systems (instead of people)
D) Also known as administrative controls
E) Implemented with technology
F) Primarily implemented and executed by people (as opposed to computer systems)
B) Sometimes called logical security controls
C) Executed by computer systems (instead of people)
E) Implemented with technology
Which of the answers listed below refer to examples of technical security controls? (Select 3 answers)
A) Security audits
B) Encryption
C) Organizational security policy
D) IDSs
E) Configuration management
F)Firewalls
B) Encryption
D) IDSs
F)Firewalls
Which of the following answers refer to the characteristic features of managerial security controls? (Select 3 answers)
A) Also known as administrative controls
B) Sometimes referred to as logical security controls
C) Focused on reducing the risk of security incidents
D) Executed by computer systems (instead of people)
E) Documented in written policies
F) Focused on protecting material assets
A) Also known as administrative controls
C) Focused on reducing the risk of security incidents
E) Documented in written policies
Examples of managerial security controls include: (Select 3 answers)
A) Configuration management
B) Data backups
C) Organizational security policy
D) Risk assessments
E) Security awareness training
C) Organizational security policy
D) Risk assessments
E) Security awareness training
Which of the answers listed below can be used to describe operational security controls (Select 3 answers)
A) Also known as administrative controls
B) Focused on the day-to-day procedures of an organization
C) Executed by computer systems (instead of people)
D) Used to ensure that the equipment continues to work as specified
E) Focused on managing risk
F) Primarily implemented and executed by people (as opposed to computer systems)
B) Focused on the day-to-day procedures of an organization
D) Used to ensure that the equipment continues to work as specified
F) Primarily implemented and executed by people (as opposed to computer systems)
Which of the following examples fall into the category of operational security controls? (Select 3 answers)
A) Risk assessments
B) Configuration management
C) System backups
D) Authentication protocols
E) Patch management
B) Configuration management
C) System backups
E) Patch management
Which of the answers listed below refers to security controls designed to deter, detect, and prevent unauthorized access, theft, damage, or destruction of material assets?
A) Managerial security controls
B) Physical security controls
C) Technical security controls
D) Operational security controls
B) Physical security controls
Which of the following examples do not fall into the category of physical security controls? (Select 3 answers)
A) Lighting
B) Access control vestibules
C) Data backups
D) Fencing/Bollards/Barricades
E) Firewalls
F) Security guards
G) Asset management
C) Data backups
E) Firewalls
G) Asset management
What are the examples of preventive security controls? (Select 3 answers)
A) Encryption
B) IDS
C) Sensors
D) Firewalls
E) Warning signs
F) AV software
A) Encryption
D) Firewalls
F) AV software
Examples of deterrent security controls include: (Select 3 answers)
A) Warning signs
B) Sensors
C) Lighting
D) Video surveillance
E) Security audits
F) Fencing/Bollards
A) Warning signs
C) Lighting
F) Fencing/Bollards
Which of the answers listed below refer(s) to detective security control(s)? (Select all that apply)
A) Lighting
B) Log monitoring
C) Sandboxing
D) Security audits
E) CCTV
F) IDS
G) Vulnerability scanning
B) Log monitoring
D) Security audits
E) CCTV
F) IDS
G) Vulnerability scanning
Which of the following answers refer(s) to corrective security control(s)? (Select all that apply)
A) Recovering data from backup copies
B) Applying software updates and patches to fix vulnerabilities
C) Developing and implementing IRPs to respond to and recover from security incidents
D) Regularly reviewing logs for anomalies or patterns indicative of attacks
E) Activating and executing DRPs to restore operations after a major incident
A) Recovering data from backup copies
B) Applying software updates and patches to fix vulnerabilities
C) Developing and implementing IRPs to respond to and recover from security incidents
E) Activating and executing DRPs to restore operations after a major incident
Which of the answers listed below refer(s) to compensating security control(s)? (Select all that apply)
A) Backup power systems
B) Video surveillance
C) MFA
D) Application sandboxing
E) Network segmentation
A) Backup power systems
C) MFA
D) Application sandboxing
E) Network segmentation
The term “Directive security controls” refers to the category of security controls that are implemented through policies and procedures.
A) True
B) False
A) True
Which of the following terms fall into the category of directive security controls? (Select 2 answers)
A) IRP
B) AUP
C) IDS
D) MFA
E) IPS
A) IRP
B) AUP