A security analyst must prevent remote users from accessing malicious URLs. The sites need to be checked inline for reputation, content, or categorization. Which of the following technologies will help secure the enterprise?
Secure Access Service Edge (SASE) is the technology best suited for preventing remote users from accessing malicious URLs. According to the CompTIA Security+ SY0-701 framework, SASE integrates cloud-native security capabilities such as DNS filtering, secure web gateways, CASB, and URL categorization, all delivered inline. This means every URL request from a remote user is checked in real time for reputation, content, and category before access is granted.
This solution is specifically designed for remote workforces because security enforcement happens in the cloud, regardless of user location---eliminating reliance on on-premise proxies or VPN routing. SASE also enables consistent policy application and real-time enforcement across distributed networks.
A VPN (A) only encrypts traffic; it does not perform URL reputation checks. IDS (C) detects malicious activity but does not block URL access. SD-WAN (D) optimizes WAN routing but is not focused on content filtering or URL reputation.
Therefore, SASE is the correct and most effective solution for inline URL inspection and preventing remote users from reaching malicious sites.
Which of the following best explains a concern with OS-based vulnerabilities?
The best answer is A. An exploit will give an attacker access to system functions that span multiple applications.
Operating system vulnerabilities are especially concerning because the OS sits underneath and supports many applications and services. If an attacker exploits an OS-level flaw, the impact can extend across the entire system and affect multiple applications, services, and security controls.
This makes OS-based vulnerabilities particularly serious because compromise at the operating system level can provide broad control over:
system processes
memory and storage access
user accounts and privileges
network services
multiple installed applications
Why the other options are incorrect:
B . The OS vendor's patch cycle is not frequent enough to mitigate the large number of threats.This is not a universal or defining concern with OS-based vulnerabilities.
C . Most users trust the core operating system features and may not notice if the system has been compromised.This may be true in some situations, but it is not the best explanation of the inherent risk of OS vulnerabilities.
D . Exploitation of an operating system vulnerability is typically easier than any other vulnerability.This is too absolute and not generally true.
From a Security+ standpoint, OS vulnerabilities are especially dangerous because they can affect the foundational functions of the system and potentially impact many applications at once, making A the best answer.
A small business initially plans to open common communications ports (21, 22, 25, 80, 443) on its firewall to allow broad access to its screened subnet. However, their security consultant advises against this action. Which of the following security principles is the consultant addressing?
The correct answer is Attack surface because opening multiple common service ports unnecessarily increases the number of potential entry points an attacker can target. In the Security+ SY0-701 exam objectives, the attack surface is defined as the total number of exposed interfaces, services, ports, protocols, and access points that an attacker could attempt to exploit. Each open port corresponds to a listening service, and every exposed service represents an opportunity for reconnaissance, exploitation, or abuse.
In this scenario, the business intends to open ports for FTP, SSH, SMTP, HTTP, and HTTPS without clearly limiting access. While some of these services may be required, opening all of them broadly---especially to a screened subnet---significantly expands the attack surface. If any of these services are misconfigured, unpatched, or vulnerable, attackers could exploit them to gain unauthorized access. The SY0-701 study guide emphasizes minimizing exposed services as a foundational defensive strategy, often referred to as reducing attack surface area.
Option C, least privilege, is related but not the best answer. Least privilege focuses on granting users or systems only the minimum access required, whereas this question specifically concerns exposed network services rather than access rights. Option A, secure access service edge (SASE), is a cloud-based architecture model and is unrelated to basic firewall port exposure decisions. Option D, separation of duties, applies to role and responsibility distribution, not network exposure.
By advising against opening multiple common ports, the consultant is recommending a reduction in exposed services to limit opportunities for attack. This aligns directly with SY0-701 guidance on secure network design, firewall hardening, and minimizing externally accessible services.
In summary, limiting open ports reduces the organization's attack surface, making Attack surface the correct and best answer.
Which of the following is an example of a false negative vulnerability detection in a scan report?
A false negative occurs when a security control or scanning tool fails to detect a vulnerability that actually exists. In vulnerability scanning, this means the scan reports a system as secure even though it is vulnerable. Therefore, a result that shows no known vulnerability is an example of a false negative if a vulnerability is present but undetected.
CompTIA Security+ SY0-701 explains that false negatives are particularly dangerous because they provide a false sense of security, potentially leaving systems exposed to exploitation. Causes of false negatives include outdated vulnerability signatures, misconfigured scanners, credentialed scan failures, or unsupported legacy systems.
Option A describes a false positive, where a vulnerability is reported but does not exist. Option B may indicate an outdated scan result, not necessarily a false negative. Option D is incorrect because zero-day vulnerabilities do not have known remediations and are typically not detected by signature-based scanners.
Thus, the correct example of a false negative is C: A result that shows no known vulnerability.
A network administrator wants to ensure that network traffic is highly secure while in transit. Which of the following actions best describes the actions the network administrator should take?
Andrew Taylor
5 days agoRyan Wilson
19 days agoDonald Jackson
1 month agoKenneth Thompson
2 months agoJames Howard
2 months agoThomas Rivera
3 months agoRichard Rivera
3 months agoDennis Miller
2 months agoCharles Wright
2 months agoJennifer Baker
2 months agoMarguerita
3 months agoJanessa
4 months agoLeota
4 months agoDianne
4 months agoDorinda
4 months agoEllsworth
5 months agoParis
5 months agoTeddy
5 months agoMalcolm
6 months agoJosephine
6 months agoDaniel
6 months agoHoa
6 months agoYolando
7 months agoCherry
7 months agoAnnmarie
7 months agoLindsey
7 months agoShawnna
8 months agoDesmond
8 months agoBlair
8 months agoMargurite
8 months agoBettina
9 months agoIndia
9 months agoVirgina
9 months agoLatanya
9 months agoWillard
10 months agoLoreta
10 months agoBrent
10 months agoZoila
10 months agoKatina
11 months agoKate
11 months agoRosendo
1 year agoLavonna
1 year agoJerry
1 year agoBarbra
1 year agoGearldine
1 year agoadam zampa
1 year agoyetodol
1 year agodejevi
1 year agojamini
1 year agoDerrick
1 year agojames
1 year agocameron
1 year agokeven
1 year agoGregg
1 year agoaliena
1 year agoSon
1 year agoMargery
1 year agoVanna
1 year agoTu
1 year agoValentin
1 year agoNaulen
1 year agoPrecious
1 year agoYolande
1 year agoSue
1 year agoMarjory
1 year agoNoel
2 years agoFiliberto
2 years agoAlesia
2 years agoHassie
2 years agoTresa
2 years agoLilli
2 years agoCherelle
2 years agoKaran
2 years agoCelestina
2 years agoAlton
2 years agoTamie
2 years agoCraig
2 years agoDorthy
2 years agoVenita
2 years agoKaran
2 years agoJesusita
2 years agoNathalie
2 years agoLelia
2 years agoBettina
2 years agoElfriede
2 years agoFernanda
2 years agoAshlyn
2 years agoMarget
2 years agoLaurel
2 years agoLera
2 years agoLorenza
2 years agoParis
2 years agoPura
2 years agoAriel
2 years agoJoye
2 years agoKeech
2 years agoMark james
2 years agoBrook
2 years agoHelina
2 years agoMark james
2 years agoChauncey
2 years agojohnes
2 years ago