Security Operations
SY0-701 · 84 questions
- After imaging clerk workstations for the tax office, security wants consistent hardened settings that stay current. Which approach best applies secure baselines?
- Network staff are locking down servers, switches, and routers that support utility billing. Which hardening focus is most appropriate?
- Inspectors need phones for field work. The city will enroll devices in MDM and must choose how much corporate control versus personal choice to allow. Which statement best matches common deployment models?
- Before placing access points in a concrete courthouse with thick walls, wireless engineers want evidence of coverage and dead zones. What should they use?
- Staff Wi-Fi at the public works yard must use modern encryption and per-user enterprise authentication. Which settings best fit?
- Developers are hardening the city's online payments site against injection and session theft. Which application-security pairing is most relevant?
- Before releasing an internal mobile app for code-enforcement officers, the city wants flaws found in source and assurance the binary is authentic. Which techniques fit?
- Clerks receive citizen email with untrusted attachments. What technique best contains potential malware before files open on the clerk PC?
- After baseline hardening of city IoT cameras and water-plant ICS devices, what ongoing practice should accompany those controls?
- The county is hardening cloud-hosted workloads for records search. Which practice set best fits cloud infrastructure hardening?
- Field assessors connect tablets over cellular, public Wi-Fi, and Bluetooth peripherals. Which statement best reflects security implications of those connection methods?
- Parking-meter controllers run embedded/RTOS software that is rarely patchable. Which primary techniques best compensate?
- Facilities wants to buy a new badge access system. What asset-management step should happen in acquisition?
- IT issues laptops to remote planners. Which assignment practice best supports accountability?
- A closet audit finds undocumented switches bridging segments in city hall. Which asset-management activity most directly finds such shadow devices?
- Old clerk PCs will be sold at a surplus auction. What disposal step is required for the drives first?
- Failed SSDs from the courts cannot be reliably sanitized with available wipe tools. What disposal method is most appropriate?
- Retired backup tapes leave the records office with a destruction vendor. What evidence should the city obtain?
- Security wants incident logs kept long enough for investigations yet not retained forever without justification. Which policy approach fits?
- A county IT team needs a repeatable way to find missing patches and known weaknesses on the public web farm before citizens notice outages. Which vulnerability-management activity best identifies those known issues?
- City development is shipping a custom permitting app and wants coverage for insecure code, runtime flaws, and risky third-party libraries. Which approach best combines application security testing for vulnerability management?
- A municipal SOC learns of emerging VPN appliance flaws from open-source intel, an ISAC bulletin, and a paid feed, then raises patch priority for city remote-access gateways. What vulnerability-management practice is the team applying?
- A researcher emails the city's responsible-disclosure inbox with a clear XSS proof against the citizen portal instead of posting the bug publicly. How should the municipality treat this channel within vulnerability management?
- A vulnerability scanner flags dozens of findings on county servers, but analysts must confirm which alerts are real before briefing the council. Which analysis step best reduces panic from inaccurate scanner noise?
- Two CVEs have similar base CVSS scores: one affects the city's public permitting site and one affects an offline label printer in a locked basement. How should the vulnerability team prioritize remediation?
- A vendor patch for a city payment appliance is delayed, so security segments the device and documents a time-bound exception while continuing to pursue the patch. Which remediation approach does this describe?
- After the library district patches a critical web server CVE, management asks how the team will prove the fix worked. Which validation activity is most appropriate?
- The city CISO must update leadership on open vulnerabilities, remediation progress, and residual risk for critical citizen services. Which vulnerability-management activity does this communication fulfill?
- Authorized testers chain a weak DMZ host, stolen credentials, and a misconfigured jump path to reach an internal municipal database that scanners listed only as separate medium findings. What identification method primarily demonstrated the combined exploitable path?
- An internal audit of water-utility OT finds no defined vulnerability-management cadence for controllers and HMIs even though IT servers are scanned monthly. How should this audit result feed vulnerability management?
- The municipal SOC needs one place that collects firewall, Active Directory, and endpoint logs and correlates them into security events. Which tool best matches that purpose?
- City VPN concentrators suddenly show bursts of failed logons across many accounts. Which monitoring activities best help the SOC notice and act on that pattern?
- Analysts are overwhelmed by low-value firewall 'allow' alerts and miss higher-severity events. Which monitoring improvement best restores focus on true threats?
- County server admins must prove that hardened build settings still match an approved security baseline after each patch cycle. Which monitoring approach best automates that configuration-compliance check?
- A city water-utility OT network has controllers with tiny CPU and memory budgets that cannot host endpoint agents. How should the SOC choose monitoring coverage for those devices?
- During a suspected data exfiltration from the county tax database, analysts need to identify which internal hosts are talking the most to unusual external destinations. Which tool best surfaces that traffic metadata?
- Network ops for city hall suddenly receives notifications that several switch interfaces are flapping up and down. Which monitoring signal is most likely delivering those infrastructure alerts?
- Endpoints that process resident tax filings need malware detection plus controls that stop sensitive returns from being copied to USB or emailed outside policy. Which tooling pair best belongs in that monitoring and control stack?
- A vulnerability scan of the city network shows several unused services reachable from the Internet through overly broad firewall rules. What enterprise-capability change best reduces that unnecessary exposure?
- Architects are redesigning how the city's public website reaches the Internet so a compromise of that host cannot freely traverse into internal finance systems. Which network pattern best supports that goal?
- Threat intel reports a new exploit kit targeting services the county still runs at the edge. What IDS/IPS maintenance actions best keep detections current and useful?
- City employees keep browsing into phishing and malware-hosting sites during work hours. Which web-filtering capability set best reduces that risk whether traffic exits through a central proxy or an endpoint agent?
- Security wants one scalable control that stops city-hall workstations and servers from resolving known-malicious domains no matter which browser or app makes the request. Which control best fits?
- Residents receive forged messages that appear to come from [email protected] asking for gift-card payments. Which email-security controls best help receiving systems detect and reject that domain spoofing?
- A county IT team must lock down domain-joined workstations so local admin rights are removed for staff and idle screens auto-lock after a short timeout. Which OS security mechanism best enforces those settings consistently across the fleet?
- Public-works engineers still open network gear with Telnet and push firmware over FTP, and cleartext credentials appear in packet captures. Which change best improves administrative protocol security?
- Election-office content servers must alert if campaign-filing PDFs or web binaries change outside a change window. Which capability best detects unauthorized file modifications?
- A city NAC solution finds employee laptops missing required patches and disk encryption before they join the staff Wi-Fi. Where should those devices be placed until posture checks pass?
- Finance analysts report odd PowerShell activity on a workstation that touches ACH files. Which enterprise capability is best suited to investigate and contain that endpoint behavior?
- A clerk's account authenticates from City Hall at 9 a.m. and from another continent an hour later while downloading unusually large case archives. Which analytics approach best flags this pattern?
- HR onboards seasonal parks staff on day one and terminates others the same afternoon. What IAM lifecycle practice best limits leftover access?
- Seasonal election workers need ballot-check software for three weeks only. Which permission approach best follows least privilege?
- Contractors need privileged badges and elevated accounts for datacenter work. What must happen before those credentials are issued?
- County employees should sign in once to reach a state benefits portal without separate local passwords on that portal. Which approach best describes this design?
- A mobile 311 app must call city APIs on a resident's behalf without embedding the resident's password in the app. Which technology best fits?
- Multiple municipal applications need a common place to look up user objects, group membership, and attributes. Which directory access protocol is commonly used for that?
- Most city staff access systems by job role, a few apps must also consider time-of-day and building location, and a small set of highly labeled records require system-enforced labels users cannot override. Which access-control mix best matches that need?
- Remote staff VPN into county resources. Leadership wants MFA that combines a memorized secret with a hardware security key, and may later add biometric unlock on managed phones. Which statement best reflects MFA factor classes?
- The library CIO wants stronger passwords without theater: favor length, ban reuse, push a vault, and explore passwordless options for staff apps. Which recommendation best matches modern password guidance?
- Domain admins currently hold standing privileges all year. The county wants just-in-time elevation and short-lived credentials checked out of a vault. Which discipline delivers that model?
- Managers must periodically confirm that their staff still need access to finance systems after role changes. What IAM process is this?
- A legacy permitting app cannot speak SAML, yet the county refuses to weaken MFA for everyone. Which interoperability approach is most appropriate?
- Orphan accounts linger because HR terminations never reliably reach IT. Which automation use case best addresses this?
- New cloud resources for a smart-city project sometimes appear with open security groups. What automation pattern best hardens them at birth?
- When the SIEM raises a critical severity alert, analysts sometimes notice hours later. Which automation improves response speed?
- A municipal DevOps pipeline deploys code to production Friday nights. Leadership wants security checks before release. Where should those checks run?
- The SOC wants leadership buy-in for more playbook automation. Which statement best captures the security-operations benefits?
- Before expanding SOAR across every municipal tool, architects warn about downsides. Which set best lists automation considerations and risks?
- The county wants one playbook to disable an account in IAM, open a ticket, and isolate a host in EDR during an incident. What enables that cross-tool workflow?
- After ransomware hits a county tax system, the IR lead must apply the lifecycle in the right order. Which sequence is correct?
- A city SOC wants to avoid improvising during the next water-utility incident. Which investment best reflects the preparation phase of IR?
- Malware is confirmed on several workstations in a city's billing VLAN. The IR team immediately isolates that VLAN from the rest of the network. Which IR phase does this action represent?
- After containing a library ransomware outbreak, responders delete attacker accounts and persistence, then restore catalog servers from clean backups. Which pair correctly labels those two steps?
- Following a successful phishing incident at the clerk’s office, which action best belongs in the lessons-learned phase?
- A transit agency’s IR plan looks complete on paper, but leadership worries the team has never practiced it. Which activity best keeps the IR capability ready?
- Investigators confirm a county breach began through an unpatched VPN appliance. Which activity ensures fixes address that underlying cause rather than only wiping infected PCs?
- A municipal SOC notices stealthy persistence may exist even when no high-severity alert fired. Which approach best describes threat hunting in this context?
- Courts may later need a laptop seized during a city HR fraud investigation. Which practice best preserves forensic integrity?
- A public-facing outage hits the city’s permit portal during an active incident. Which IR coordination practice is most appropriate?
- Analysts are investigating an after-hours admin login to a utility management console. Which data sources best help reconstruct that access event?
- A school-district SOC sees suspicious process creation on a teacher laptop and a matching unusual sign-in. Which investigative approach strengthens the conclusion?
- A court IT team suspects large data exfiltration, but application logs do not show transfer volume. Which sources are most appropriate to estimate egress?
- Responders believe attackers entered a parks-and-recreation portal via a known CVE. Which investigative context best supports that hypothesis?
- During a county IR exercise, several critical servers have little or no retained authentication history. What should leadership prioritize before the next real incident?