Exam SY0-701 Topic 4 Question 876 Discussion
Actual exam question for CompTIA's SY0-701 exam
Question #: 876
Topic #: 4
Question #: 876
Topic #: 4
During a routine audit, an analyst discovers that a department at a high school uses a simulation program that was not properly vetted before deployment.
Which of the following threats is this an example of?
Which of the following threats is this an example of?
Suggested Answer: C Vote an answer
The use of an unapproved, unvetted simulation program is a classic case of Shadow IT, which Security+ SY0-701 defines as technology deployed without the knowledge, review, or authorization of the IT or security department. Shadow IT introduces significant risks, including vulnerabilities, noncompliance, unmonitored data flows, and potential software containing malware or insecure configurations.
In academic or departmental environments where staff independently download tools to support curriculum or instruction, Shadow IT becomes particularly common. This bypasses standard vetting processes such as software approval, patch evaluation, licensing verification, and security risk assessment.
Espionage (A) involves covert intelligence gathering by hostile actors. Data exfiltration (B) refers to unauthorized data theft. Zero-day (D) refers to unknown vulnerabilities exploited before patches exist.
None of these fit the scenario.
Since the core issue is the deployment of an unauthorized application without IT oversight, the correct answer is C: Shadow IT.
In academic or departmental environments where staff independently download tools to support curriculum or instruction, Shadow IT becomes particularly common. This bypasses standard vetting processes such as software approval, patch evaluation, licensing verification, and security risk assessment.
Espionage (A) involves covert intelligence gathering by hostile actors. Data exfiltration (B) refers to unauthorized data theft. Zero-day (D) refers to unknown vulnerabilities exploited before patches exist.
None of these fit the scenario.
Since the core issue is the deployment of an unauthorized application without IT oversight, the correct answer is C: Shadow IT.
by Ellis at Aug 13, 2026, 07:40 PM
Contact Us
If you have any question please leave me your email address, we will reply and send email to you in 12 hours.
Our Working Time: ( GMT 0:00-15:00 ) From Monday to Saturday
Support: Contact now
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).