SY0-301 Exam Questions
901 real SY0-301 exam questions with expert-verified answers and explanations. Page 12 of 19.
- Question #553Security architecture
Which of the following is the BEST concept to maintain required but non-critical server availability?
warm sitedisaster recoverybusiness continuityavailability - Question #554Threats, vulnerabilities, and mitigations
Prior to leaving for an extended vacation, Joe uses his mobile phone to take a picture of his family in the house living room. Joe posts the picture on a popular social media site...
geo-taggingmetadataOSINTsocial media privacy - Question #555Security architecture
Which of the following technical controls helps to prevent Smartphones from connecting to a corporate network?
MDMmobile device managementBYODnetwork access control - Question #556Security architecture
The Chief Risk Officer is concerned about the new employee BYOD device policy and has requested the security department implement mobile security controls to protect corporate data...
device encryptionscreen lockBYODmobile security - Question #557General security concepts
A way to assure data at-rest is secure even in the event of loss or theft is to use:
full disk encryptiondata at restencryption - Question #558Security architecture
Which of the following would prevent a user from installing a program on a company-owned mobile device?
application whitelistingmobile securityaccess control - Question #559Security architecture
Which of the following can be used to maintain a higher level of security in a SAN by allowing isolation of mis-configurations or faults?
VSANSANstorage securitynetwork isolation - Question #560Security operations
The act of magnetically erasing all of the data on a disk is known as:
degaussingdata destructionmedia sanitization - Question #561Security architecture
LDAP and Kerberos are commonly used for which of the following?
LDAPKerberosSSOdirectory services - Question #562Security architecture
A recent audit has revealed weaknesses in the process of deploying new servers and network devices. Which of the following practices could be used to increase the security posture...
server hardeningdefault passwordsunnecessary servicesdeployment security - Question #563Security operations
Joe, a network security engineer, has visibility to network traffic through network monitoring tools. However, he's concerned that a disgruntled employee may be targeting a server...
HIDSinsider threatlog monitoringhost-based detection - Question #564Security architecture
Ann, a security administrator, wishes to replace their RADIUS authentication with a more secure protocol, which can utilize EAP. Which of the following would BEST fit her objective...
RADIUSDiameterEAPauthentication protocols - Question #565Security operations
Joe analyzed the following log and determined the security team should implement which of the following as a mitigation method against further attempts? Host 192.168.1.123 [00:00:0...
log analysisbrute forceRDP attackssystem hardening - Question #566Threats, vulnerabilities, and mitigations
A computer supply company is located in a building with three wireless networks. The system security team implemented a quarterly security scan and saw the following. Which of the...
rogue access pointwireless securitySSIDnetwork scanning - Question #567Security architecture
Joe, a technician at the local power plant, notices that several turbines had ramp up in cycles during the week. Further investigation by the system engineering team determined tha...
SCADA securityVLAN segmentationICSnetwork isolation - Question #568General security concepts
A system administrator has been instructed by the head of security to protect their data at-rest. Which of the following would provide the strongest protection?
data at restfull disk encryptionstorage securityencryption - Question #569Security operations
An Information Systems Security Officer (ISSO) has been placed in charge of a classified peer-to- peer network that cannot connect to the Internet. The ISSO can update the antiviru...
antivirus definitionsfile integrityhash verificationair-gapped network - Question #570Security architecture
Ann has taken over as the new head of the IT department. One of her first assignments was to implement AAA in preparation for the company's new telecommuting policy. When she takes...
AAARADIUScentralized authenticationnetwork access control - Question #571Security operations
A group policy requires users in an organization to use strong passwords that must be changed every 15 days. Joe and Ann were hired 16 days ago. When Joe logs into the network, he...
group policypassword policyaccount managementaccess control - Question #572Security architecture
A new web server has been provisioned at a third party hosting provider for processing credit card transactions. The security administrator runs the netstat command on the server a...
port securityRDPunnecessary servicesweb server hardening - Question #573General security concepts
Several employee accounts appear to have been cracked by an attacker. Which of the following should the security administrator implement to mitigate password cracking attacks? (Sel...
password complexitypassword lengthpassword crackingaccount security - Question #574Security operations
Human Resources suspects an employee is accessing the employee salary database. The administrator is asked to find out who it is. In order to complete this task, which of the follo...
shared accountsaccountabilityuser trackingaccess control - Question #575General security concepts
A cafe provides laptops for Internet access to their customers. The cafe is located in the center corridor of a busy shopping mall. The company has experienced several laptop theft...
physical securitycable locksasset protectionlaptop theft - Question #576Security operations
An auditor's report discovered several accounts with no activity for over 60 days. The accounts were later identified as contractors' accounts who would be returning in three month...
inactive accountsaccount managementcontractor accessaccount lifecycle - Question #577Security program management and oversight
A company hired Joe, an accountant. The IT administrator will need to create a new account for Joe. The company uses groups for ease of management and administration of user accoun...
role-based access controlgroup managementleast privilegeuser provisioning - Question #578Threats, vulnerabilities, and mitigations
Ann, the network administrator, has learned from the helpdesk that employees are accessing the wireless network without entering their domain credentials upon connection. Once the...
evil twinrogue access pointwireless attackcredential capture - Question #579Security program management and oversight
Ann works at a small company and she is concerned that there is no oversight in the finance department; specifically, that Joe writes, signs and distributes paychecks, as well as o...
separation of dutiesfinancial controlsadministrative controlsfraud prevention - Question #580General security concepts
A hospital IT department wanted to secure its doctor's tablets. The IT department wants operating system level security and the ability to secure the data from alteration. Which of...
TPMmobile device securityOS securitydata integrity - Question #581General security concepts
Customers' credit card information was stolen from a popular video streaming company. A security consultant determined that the information was stolen, while in transit, from the g...
data in transitencryptionTCP wrapperscredit card security - Question #582Security operations
A new intern was assigned to the system engineering department, which consists of the system architect and system software developer's teams. These two teams have separate privileg...
group-based access controluser provisioningleast privilegeaccess management - Question #583Security operations
A system security analyst using an enterprise monitoring tool notices an unknown internal host exfiltrating files to several foreign IP addresses. Which of the following would be a...
data exfiltrationrogue machine detectionincident responsenetwork monitoring - Question #584Security architecture
One of the system administrators at a company is assigned to maintain a secure computer lab. The administrator has rights to configure machines, install software, and perform user...
least privilegeaccess controlauthorizationseparation of duties - Question #585Security architecture
Which of the following common access control models is commonly used on systems to ensure a "need to know" based on classification levels?
mandatory access controlclassification levelsneed to knowaccess control models - Question #586Security architecture
A company's security administrator wants to manage PKI for internal systems to help reduce costs. Which of the following is the FIRST step the security administrator should take?
PKIcertificate authoritypublic key infrastructuredigital certificates - Question #587Security program management and oversight
Which of the following is the BEST approach to perform risk mitigation of user access control rights?
user access reviewaccess controlrisk mitigationpermission management - Question #588Security architecture
A network consists of various remote sites that connect back to two main locations. Pete, the security administrator, needs to block TELNET access into the network. Which of the fo...
firewallTELNETport 23network access control - Question #589Security architecture
Pete, a security administrator, is informed that people from the HR department should not have access to the accounting department's server, and the accounting department should no...
VLANnetwork segmentationaccess controlnetwork isolation - Question #590Security operations
Which of the following is BEST utilized to actively test security controls on a particular system?
penetration testingsecurity testingvulnerability assessmentsecurity controls - Question #593Threats, vulnerabilities, and mitigations
Which of the following has serious security implications for large organizations and can potentially allow an attacker to capture conversations?
Jabberinstant messagingeavesdroppingcommunication security - Question #594Security architecture
Which of the following is a step in deploying a WPA2-Enterprise wireless network?
WPA2-Enterprisedigital certificateswireless securityRADIUS authentication - Question #595Security program management and oversight
Upper management decides which risk to mitigate based on cost. This is an example of:
quantitative risk assessmentrisk managementcost-benefit analysisrisk mitigation - Question #598General security concepts
Matt, a security administrator, wants to ensure that the message he is sending does not get intercepted or modified in transit. This concern relates to which of the following conce...
integrityCIA triaddata in transitmessage security - Question #600General security concepts
Which of the following should be used when a business needs a block cipher with minimal key size for internal encryption?
block cipherBlowfishencryption algorithmskey size - Question #601Security architecture
Which of the following best practices makes a wireless network more difficult to find?
SSID broadcastwireless securitynetwork visibilityWAP hardening - Question #603Security program management and oversight
The use of social networking sites introduces the risk of:
social media riskdata disclosureproprietary informationinformation leakage - Question #604General security concepts
Which the following flags are used to establish a TCP connection? (Select TWO).
TCP handshakeTCP flagsSYN ACKnetwork protocols - Question #605Security architecture
Which of the following describes the process of removing unnecessary accounts and services from an application to reduce risk exposure?
application hardeningattack surface reductionsecure configurationleast privilege - Question #606General security concepts
Which of the following MUST Matt, a security administrator, implement to verify both the integrity and authenticity of a message while requiring a shared secret?
HMACmessage authentication codeintegrityshared secret - Question #607Security architecture
Visitors entering a building are required to close the back door before the front door of the same entry room is open. Which of the following is being described?
mantrapphysical securityaccess controltailgating prevention - Question #608Security operations
Which of the following software allows a network administrator to inspect the protocol header in order to troubleshoot network issues?
packet snifferprotocol headernetwork troubleshootingnetwork monitoring