Which of the following Is a common, passive reconnaissance technique employed by penetration testers in the early phases of an engagement?
Correct Answer: B
SY0-701 Exam Question 212
Which of the following practices would be best to prevent an insider from introducing malicious code into a company's development process?
Correct Answer: D
The correct answer is D. Peer review and approval. Peer review and approval help prevent a single developer or insider from inserting malicious code without oversight. This practice supports separation of duties, accountability, secure software development, and change control. Requiring another qualified person to review and approve code changes increases the chance that suspicious, unauthorized, or malicious code will be identified before it enters production. Why the other options are incorrect: A). Code scanning for vulnerabilities Code scanning can identify known vulnerabilities, insecure coding patterns, and some misconfigurations. However, malicious code intentionally written to appear legitimate may not always be detected by automated scanning. B). Open-source component usage Using open-source components does not prevent insider abuse. In fact, open-source dependencies may introduce additional supply chain risk if not properly reviewed. C). Quality assurance testing Quality assurance testing verifies whether software works as intended, but it may not detect intentionally malicious logic hidden in the code. Therefore, peer review and approval is the best practice to prevent an insider from introducing malicious code into the development process.
SY0-701 Exam Question 213
The Chief Information Security Officer (CISO) has determined the company is non-compliant with local data privacy regulations. The CISO needs to justify the budget request for more resources. Which of the following should the CISO present to the board as the direct consequence of non-compliance?
Correct Answer: A
The most direct and immediate consequence of non-compliance with local data privacy regulations is fines. CompTIA Security+ SY0-701 emphasizes that privacy and data protection laws (such as GDPR, HIPAA, or regional privacy statutes) include explicit financial penalties for organizations that fail to meet compliance requirements. These fines are measurable, enforceable, and frequently cited by regulators as primary enforcement mechanisms. While reputational damage (B) and contractual implications (D) are serious secondary effects, they are indirect and harder to quantify. Sanctions (C) typically apply in geopolitical or trade contexts rather than routine privacy enforcement. Boards of directors are often most responsive to clearly defined financial exposure; fines provide a concrete, defensible rationale for allocating additional budget to compliance, tooling, staffing, and process improvements. Security+ SY0-701 highlights risk communication to executives using quantifiable impacts. Presenting the likelihood and magnitude of regulatory fines directly supports a cost-benefit analysis and demonstrates fiduciary responsibility. Therefore, A: Fines is the most appropriate consequence to present.
SY0-701 Exam Question 214
A security administrator needs to reduce the attack surface in the company's data centers. Which of the following should the security administrator do to complete this task?
Correct Answer: D
Upgrading end-of-support operating systemsisone of the most effective ways to reduce the attack surface. Unsupported OS versionsno longer receive security patches, making them prime targets for attackers. Removing outdated softwareensures that known vulnerabilities cannot be exploited. A (honeynet)is used for threat analysis, not reducing the attack surface. B (Group Policy)helps enforce security policies butdoes not address outdated vulnerabilities. C (High availability)focuses on uptime, not security risk reduction. Reference:CompTIA Security+ SY0-701 Official Study Guide, Security Architecture domain.
SY0-701 Exam Question 215
A service provider wants a cost-effective way to rapidly expand from providing internet links to managing them. Which of the following methods will allow the service provider to best scale its services while maintaining performance consistency?
Correct Answer: C
Baseline enforcement involves establishing standard configurations and operational baselines that allow a service provider to scale services efficiently while ensuring consistent performance and security. By enforcing baselines, automation can be applied, reducing manual intervention and variability, which supports rapid, cost- effective expansion. Increasing workforce (B) adds operational cost and may introduce inconsistency. Escalation support (A) is reactive and does not inherently support scaling. Technical debt (D) refers to accumulated suboptimal design or quick fixes that hamper future scalability and is a negative factor. Baseline enforcement is recognized as a best practice in the Security Program Management domain for scaling services reliably#6:Chapter 16 CompTIA Security+ Study Guide#.