Objective 2.5SY0-701

2.5 Explain the purpose of mitigation techniques used to secure the enterprise

Objective 2.5 sits in Threats, Vulnerabilities, and Mitigations, which carries 22% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Threats, Vulnerabilities, and MitigationsModerate

An engineer needs traffic to a specific destination to route through a deployed security appliance instead of the default system route. Which mechanism should be configured?

Correct.

The concept

Isolation through controlled traffic paths often requires overriding default routing behavior to force inspection.

Why this answer

A user-defined route lets an engineer configure the next-hop address so traffic to a destination passes through a deployed security appliance instead of the default system route.

  • Correct: user-defined routes control the next-hop path for traffic.
  • BA service tag is a named stand-in for a published address range. It shortens rule authoring and never touches the forwarding table.
  • CAugmented rules cut rule count, not hop count.
  • DApplication security groups label which VMs a rule applies to. Membership decides who gets filtered, not where packets go next.
Read the sourceMicrosoft Learn: Azure network security best practices
Verified against learn.microsoft.com · 2026-07-27
isolationaccess-control

Now you: objective 2.5 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Threats, Vulnerabilities, and MitigationsHard

A security team implementing a Zero Trust approach for VM access wants decisions based on more than network location alone. Which combination of factors should drive access decisions?

Sample question 2 of 3

Threats, Vulnerabilities, and MitigationsModerate

A security team must decide which virtual networks require DDoS Network Protection. Which virtual networks should receive this protection?

Sample question 3 of 3

Threats, Vulnerabilities, and MitigationsModerate

A team wants to know within a day when a component it already ships is reported vulnerable. Which practice makes that possible?

That’s 3 of the full Security+ bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practicing

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Threats, Vulnerabilities, and Mitigations