General Security Concepts
SY0-701 · 36 questions
- A county board installs a new badge reader on the data-center door and asks whether that control is technical or physical. How should the security analyst classify the badge reader?
- A city CISO notices staff calling every firewall rule 'detective.' Which statement correctly contrasts a blocking firewall rule with a SIEM alert that only notifies after traffic has already occurred?
- Public works posts 'Authorized Personnel Only' signs on a pump-station fence. Which control type best describes the signs by themselves?
- After ransomware hits the library, IT restores systems from backups and rebuilds servers. Which control type best describes those restoration actions?
- A transit agency cannot yet replace an end-of-life ticket kiosk operating system, so it isolates the kiosk VLAN and adds extra monitoring. Which control type best describes those alternate safeguards?
- HR publishes a mandatory password-change policy for all municipal accounts. Which control category best fits that written policy?
- Nightly log review by SOC analysts is framed as which control category, distinct from the SIEM product itself?
- City council issues a binding directive that all departments must encrypt laptops. Which control type best describes that mandate?
- A school district maps controls on both category and type axes. How should a lobby security camera primarily be labeled?
- A mayor asks what 'integrity' means for property-tax records. Which explanation is most accurate?
- During a storm, the city's 911 CAD system goes down even though no records were stolen. Which CIA objective was primarily violated?
- A contractor denies approving a fraudulent wire after their account was used. Which security concept makes repudiation harder by providing reliable evidence of who authorized an action?
- Library patrons treat 'logging in' as the entire AAA model. Which statement correctly separates the AAA functions?
- After a gap analysis, the water utility lists missing MFA on VPN as a control gap versus policy. What does that gap analysis primarily represent?
- A county moves from trusting the internal LAN by default to verifying every access request. Which principle best describes that shift?
- In a zero-trust design discussion, which pairing correctly places the policy decision and the policy enforcement roles?
- A courthouse lobby uses vehicle bollards outside and an access-control vestibule (mantrap) at the entrance. Which statement best identifies these measures?
- Parks IT creates a honeytoken service account that should never log in; any use triggers a high-fidelity alert. What is the primary purpose of that account?
- A small city runs a honeynet segment that mimics SCADA HMI hosts. How does a honeynet differ from a honeypot?
- Before a firewall cutover, the change board insists on an approval process and a named owner. Why are those steps security-relevant?
- A rushed switch upgrade skips impact analysis and overnight permit systems go dark. What should impact analysis have provided before the change?
- An identity-provider upgrade fails and staff cannot restore the prior configuration because no backout plan exists. Which change-management artifact was missing?
- A vendor patches VPN concentrators at noon on tax-filing day, ignoring maintenance windows and SOPs. Which change-management practice was primarily violated?
- Updates to allow lists and deny lists on the city web filter are treated as restricted activities needing change control. Why?
- After a successful network change, diagrams and procedures are left stale, and later incident responders work from outdated maps. Which change-management requirement was neglected?
- Before cutting over the city's online payment portal, which change-management practice best reduces security and business-process risk?
- A public-health clinic issues laptops that may hold PHI. Which encryption approach best protects that data if a laptop is stolen while powered off?
- A municipal VPN establishes a session by exchanging secrets with public-key cryptography, then encrypts bulk traffic with a shared session key. Which statement correctly separates those roles?
- A records clerk proposes hashing archived city council minutes so the files stay confidential yet can be opened and read later. Why is that proposal incorrect?
- The city identity store hashes passwords and adds a unique salt per account. What security problem does salting primarily address?
- Election equipment receives a vendor software update. Which cryptographic result does verifying the publisher's digital signature on the package primarily provide?
- City laptops use a TPM to protect device keys, while the certificate authority team evaluates an HSM for root and intermediate key operations. How do these technologies differ at a purpose level?
- A recreation-fee system replaces stored cardholder numbers with tokens for processing, and the cashier screen shows only the last four PAN digits. Which statement best contrasts those techniques?
- A city CA issued a certificate that was later revoked after a private-key compromise. What should relying parties do before trusting that certificate?
- An internal library kiosk presents a self-signed TLS certificate with no public CA chain. What is the main trust implication compared with a certificate from a trusted third-party CA?
- The password vault that protects shared municipal admin secrets uses key stretching with a strong algorithm and adequate key length. What is the primary security benefit of key stretching in this context?