A recent audit cited a risk involving numerous low-criticality vulnerabilities created by a web application using a third-party library. The development staff state there are still customers using the application even though it is end of life and it would be a substantial burden to update the application for compatibility with more secure libraries.
Which of the following would be the MOST prudent course of action?
A. Accept the risk if there is a clear road map for timely decommissionWhich of the following is the primary reason why false negatives on a vulnerability scan should be a concern?
A. The system has vulnerabilities that are not being detected.Which of the following aspects of the data management life cycle is most directly impacted by local and international regulations?
A. DestructionA third-party vendor is moving a particular application to the end-of-life stage at the end of the current year.
Which of the following is the most critical risk if the company chooses to continue running the application?
A. Lack of security updatesA new vulnerability enables a type of malware that allows the unauthorized movement of data from a system.
Which of the following would detect this behavior?
A. Implementing encryptionA security team is addressing a risk associated with the attack surface of the organization's web application over port 443. Currently, no advanced network security capabilities are in place.
Which of the following would be best to set up? (Choose two.)
A. NIDSWhich of the following provides the details about the terms of a test with a third-party penetration tester?
A. Rules of engagementAn external security assessment report indicates a high click rate on suspicious emails. The Chief Intelligence Security Officer (CISO) must reduce this behavior.
Which of the following should the CISO do first?
A. Update the acceptable use policy.A security analyst received a tip that sensitive proprietary information was leaked to the public. The analyst is reviewing the PCAP and notices traffic between an internal server and an external host that includes the following:
...
12:47:22.327233 PPPoE [ses 0x8122] IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto IPv6 (41), length 331) 10.5.1.1 > 52.165.16.154: IP6 (hlim E3, next-header TCP (6) paylcad length: 271) 2001:67c:2158:a019::ace.53104 >
2001:0:5ef5:79fd:380c:dddd:a601:24fa.13788: Flags [P.], cksum 0xd7ee (correct), seq 97:348, ack 102, win 16444, length 251 ...
Which of the following was most likely used to exfiltrate the data?
A. EncapsulationAs part of new compliance audit requirements, multiple servers need to be segmented on different networks and should be reachable only from authorized internal systems.
Which of the following would meet the requirements?
A. Configure firewall rules to block external access to Internal resources.Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-701 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.