SY0-301 Practice Questions
904 real SY0-301 exam questions with expert-verified answers and explanations. Page 12 of 19.
- Question #553
Which of the following is the BEST concept to maintain required but non-critical server availability?
- Question #554
Prior to leaving for an extended vacation, Joe uses his mobile phone to take a picture of his family in the house living room. Joe posts the picture on a popular social media site...
- Question #555
Which of the following technical controls helps to prevent Smartphones from connecting to a corporate network?
- Question #556
The Chief Risk Officer is concerned about the new employee BYOD device policy and has requested the security department implement mobile security controls to protect corporate data...
- Question #557
A way to assure data at-rest is secure even in the event of loss or theft is to use:
- Question #558
Which of the following would prevent a user from installing a program on a company-owned mobile device?
- Question #559
Which of the following can be used to maintain a higher level of security in a SAN by allowing isolation of mis-configurations or faults?
- Question #560
The act of magnetically erasing all of the data on a disk is known as:
- Question #561
LDAP and Kerberos are commonly used for which of the following?
- Question #562
A recent audit has revealed weaknesses in the process of deploying new servers and network devices. Which of the following practices could be used to increase the security posture...
- Question #563
Joe, a network security engineer, has visibility to network traffic through network monitoring tools. However, he's concerned that a disgruntled employee may be targeting a server...
- Question #564
Ann, a security administrator, wishes to replace their RADIUS authentication with a more secure protocol, which can utilize EAP. Which of the following would BEST fit her objective...
- Question #565
Joe analyzed the following log and determined the security team should implement which of the following as a mitigation method against further attempts? Host 192.168.1.123 [00:00:0...
- Question #566
A computer supply company is located in a building with three wireless networks. The system security team implemented a quarterly security scan and saw the following. Which of the...
- Question #567
Joe, a technician at the local power plant, notices that several turbines had ramp up in cycles during the week. Further investigation by the system engineering team determined tha...
- Question #568
A system administrator has been instructed by the head of security to protect their data at-rest. Which of the following would provide the strongest protection?
- Question #569
An Information Systems Security Officer (ISSO) has been placed in charge of a classified peer-to- peer network that cannot connect to the Internet. The ISSO can update the antiviru...
- Question #570
Ann has taken over as the new head of the IT department. One of her first assignments was to implement AAA in preparation for the company's new telecommuting policy. When she takes...
- Question #571
A group policy requires users in an organization to use strong passwords that must be changed every 15 days. Joe and Ann were hired 16 days ago. When Joe logs into the network, he...
- Question #572
A new web server has been provisioned at a third party hosting provider for processing credit card transactions. The security administrator runs the netstat command on the server a...
- Question #573
Several employee accounts appear to have been cracked by an attacker. Which of the following should the security administrator implement to mitigate password cracking attacks? (Sel...
- Question #574
Human Resources suspects an employee is accessing the employee salary database. The administrator is asked to find out who it is. In order to complete this task, which of the follo...
- Question #575
A cafe provides laptops for Internet access to their customers. The cafe is located in the center corridor of a busy shopping mall. The company has experienced several laptop theft...
- Question #576
An auditor's report discovered several accounts with no activity for over 60 days. The accounts were later identified as contractors' accounts who would be returning in three month...
- Question #577
A company hired Joe, an accountant. The IT administrator will need to create a new account for Joe. The company uses groups for ease of management and administration of user accoun...
- Question #578
Ann, the network administrator, has learned from the helpdesk that employees are accessing the wireless network without entering their domain credentials upon connection. Once the...
- Question #579
Ann works at a small company and she is concerned that there is no oversight in the finance department; specifically, that Joe writes, signs and distributes paychecks, as well as o...
- Question #580
A hospital IT department wanted to secure its doctor's tablets. The IT department wants operating system level security and the ability to secure the data from alteration. Which of...
- Question #581
Customers' credit card information was stolen from a popular video streaming company. A security consultant determined that the information was stolen, while in transit, from the g...
- Question #582
A new intern was assigned to the system engineering department, which consists of the system architect and system software developer's teams. These two teams have separate privileg...
- Question #583
A system security analyst using an enterprise monitoring tool notices an unknown internal host exfiltrating files to several foreign IP addresses. Which of the following would be a...
- Question #584
One of the system administrators at a company is assigned to maintain a secure computer lab. The administrator has rights to configure machines, install software, and perform user...
- Question #585
Which of the following common access control models is commonly used on systems to ensure a "need to know" based on classification levels?
- Question #586
A company's security administrator wants to manage PKI for internal systems to help reduce costs. Which of the following is the FIRST step the security administrator should take?
- Question #587
Which of the following is the BEST approach to perform risk mitigation of user access control rights?
- Question #588
A network consists of various remote sites that connect back to two main locations. Pete, the security administrator, needs to block TELNET access into the network. Which of the fo...
- Question #589
Pete, a security administrator, is informed that people from the HR department should not have access to the accounting department's server, and the accounting department should no...
- Question #590
Which of the following is BEST utilized to actively test security controls on a particular system?
- Question #592
Pete, an employee, attempts to visit a popular social networking site but is blocked. Instead, a page is displayed notifying him that this site cannot be visited. Which of the foll...
- Question #593
Which of the following has serious security implications for large organizations and can potentially allow an attacker to capture conversations?
- Question #594
Which of the following is a step in deploying a WPA2-Enterprise wireless network?
- Question #595
Upper management decides which risk to mitigate based on cost. This is an example of:
- Question #598
Matt, a security administrator, wants to ensure that the message he is sending does not get intercepted or modified in transit. This concern relates to which of the following conce...
- Question #600
Which of the following should be used when a business needs a block cipher with minimal key size for internal encryption?
- Question #601
Which of the following best practices makes a wireless network more difficult to find?
- Question #602
Sara, a user, downloads a keygen to install pirated software. After running the keygen, system performance is extremely slow and numerous antivirus alerts are displayed. Which of t...
- Question #603
The use of social networking sites introduces the risk of:
- Question #604
Which the following flags are used to establish a TCP connection? (Select TWO).
- Question #605
Which of the following describes the process of removing unnecessary accounts and services from an application to reduce risk exposure?
- Question #606
Which of the following MUST Matt, a security administrator, implement to verify both the integrity and authenticity of a message while requiring a shared secret?