SY0-301 Exam Questions
901 real SY0-301 exam questions with expert-verified answers and explanations. Page 13 of 19.
- Question #609Security architecture
Which of the following ports would be blocked if Pete, a security administrator, wants to deny access to websites?
port numbersHTTP port 80firewall rulesweb access control - Question #610Security architecture
Which of the following would Pete, a security administrator, do to limit a wireless signal from penetrating the exterior walls?
wireless securityantenna placementRF signal containmentphysical security - Question #611Threats, vulnerabilities, and mitigations
Which of the following is where an unauthorized device is found allowing access to a network?
rogue access pointwireless securityunauthorized devicenetwork intrusion - Question #612Threats, vulnerabilities, and mitigations
Which of the following attacks allows access to contact lists on cellular phones?
bluesnarfingBluetooth attacksmobile securitycontact list theft - Question #613General security concepts
Which of the following can hide confidential or malicious data in the whitespace of other files (e.g. JPEGs)?
steganographydata hidingcovert channelsJPEG - Question #614General security concepts
Which of the following identifies certificates that have been compromised or suspected of being compromised?
certificate revocation listPKIdigital certificatescertificate management - Question #615Security operations
Which of the following BEST allows Pete, a security administrator, to determine the type, source, and flags of the packet traversing a network for troubleshooting purposes?
protocol analyzerpacket analysisnetwork troubleshootingtraffic inspection - Question #616Security operations
Which of the following is the MOST important step for preserving evidence during forensic procedures?
chain of custodydigital forensicsevidence preservationincident response - Question #617Threats, vulnerabilities, and mitigations
Highly sensitive data is stored in a database and is accessed by an application on a DMZ server. The disk drives on all servers are fully encrypted. Communication between the appli...
SQL injectionapplication securityDMZdefense in depth - Question #618General security concepts
The fundamental information security principals include confidentiality, availability and which of the following?
CIA triadintegrityinformation security fundamentalsdata protection - Question #619General security concepts
Which of the following is the MOST likely cause of users being unable to verify a single user's email signature and that user being unable to decrypt sent messages?
key pairsPKIdigital signaturesasymmetric encryption - Question #620Security architecture
Full disk encryption is MOST effective against which of the following threats?
full disk encryptiondata at resthardware theftphysical security - Question #621Threats, vulnerabilities, and mitigations
Which of the following may cause Jane, the security administrator, to seek an ACL work around?
zero day exploitACL bypassvulnerability managementthreat mitigation - Question #622Security architecture
In order to use a two-way trust model the security administrator MUST implement which of the following?
PKItrust modelscertificate authoritymutual authentication - Question #623General security concepts
Which of the following would a security administrator use to verify the integrity of a file?
hashingfile integritycryptographydata verification - Question #624Security architecture
Which of the following is a best practice when securing a switch from physical access?
switch hardeningphysical securityunused portsnetwork device security - Question #625Security operations
A security administrator needs to image a large hard drive for forensic analysis. Which of the following will allow for faster imaging to a second hard drive?
forensic imagingdd commanddisk forensicsevidence collection - Question #626Security program management and oversight
Sara, an employee, tethers her smartphone to her work PC to bypass the corporate web security gateway while connected to the LAN. While Sara is out at lunch her PC is compromised v...
security policyinsider threatmobile tetheringsecurity awareness training - Question #627Security architecture
Which of the following can be implemented if a security administrator wants only certain devices connecting to the wireless network?
MAC filteringwireless securityaccess controlnetwork access restriction - Question #628Threats, vulnerabilities, and mitigations
Which of the following malware types typically allows an attacker to monitor a user's computer, is characterized by a drive-by download, and requires no user interaction?
spywaremalware typesdrive-by downloadcovert monitoring - Question #629Threats, vulnerabilities, and mitigations
Which of the following malware types may require user interaction, does not hide itself, and is commonly identified by marketing pop-ups based on browsing habits?
adwaremalware typespop-upsbrowsing habits - Question #630Threats, vulnerabilities, and mitigations
Which of the following is characterized by an attack against a mobile device?
bluejackingBluetooth attacksmobile device securitywireless threats - Question #631Threats, vulnerabilities, and mitigations
Which of the following application attacks is used against a corporate directory service where there are unknown servers on the network?
LDAP injectioninjection attacksdirectory servicesapplication attacks - Question #632Security architecture
Which of the following protocols allows for the LARGEST address space?
IPv6network protocolsaddress spaceIP addressing - Question #633Security operations
Who should be contacted FIRST in the event of a security breach?
incident responsebreach notificationsecurity proceduresescalation - Question #634Threats, vulnerabilities, and mitigations
A security administrator examines a network session to a compromised database server with a packet analyzer. Within the session there is a repeated series of the hex character 90 (...
buffer overflowNOP sledpacket analysisexploit identification - Question #635Security operations
Which of the following is an example of a false negative?
false negativeIDSdetection accuracyalert analysis - Question #636General security concepts
Which of the following access controls enforces permissions based on data labeling at specific levels?
mandatory access controldata labelingaccess control modelsclassification levels - Question #637General security concepts
Sara, a security administrator, manually hashes all network device configuration files daily and compares them to the previous days' hashes. Which of the following security concept...
file integrityhashingintegrity monitoringCIA triad - Question #638Security operations
Which of the following would be used to identify the security posture of a network without actually exploiting any weaknesses?
vulnerability scanningsecurity assessmentpenetration testingrisk identification - Question #639General security concepts
Which of the following authentication services uses a ticket granting system to provide access?
Kerberosticket grantingauthentication protocolsSSO - Question #640Security operations
Matt, a security administrator, wants to configure all the switches and routers in the network in order to securely monitor their status. Which of the following protocols would he...
SNMPv3network monitoringsecure protocolsnetwork device management - Question #641Security architecture
Jane, the security administrator, sets up a new AP but realizes too many outsiders are able to connect to that AP and gain unauthorized access. Which of the following would be the...
MAC filteringSSID broadcastwireless securityaccess point hardening - Question #642General security concepts
The public key is used to perform which of the following? (Select THREE).
public key cryptographyasymmetric encryptiondigital signaturesPKI - Question #643Security architecture
Which of the following is BEST used to break a group of IP addresses into smaller network segments or blocks?
subnettingIP addressingnetwork segmentation - Question #644Security program management and oversight
Which of the following would BEST be used to calculate the expected loss of an event, if the likelihood of an event occurring is known? (Select TWO).
ALESLEAROrisk quantification - Question #645Security operations
An administrator wants to minimize the amount of time needed to perform backups during the week. It is also acceptable to the administrator for restoration to take an extended time...
backup strategiesincremental backupdifferential backuprecovery time - Question #646Security operations
Which of the following can be utilized in order to provide temporary IT support during a disaster, where the organization sets aside funds for contingencies, but does not necessari...
mobile sitedisaster recoverybusiness continuityrecovery sites - Question #647Security operations
Which of the following is BEST utilized to identify common misconfigurations throughout the enterprise?
vulnerability scanningmisconfigurationsecurity assessment - Question #648Threats, vulnerabilities, and mitigations
Which of the following is an attack vector that can cause extensive physical damage to a datacenter without physical access?
environmental controlsphysical securityattack vectorsdatacenter - Question #649Security program management and oversight
Which of the following policies is implemented in order to minimize data loss or theft?
PII handlingdata loss preventionpolicydata protection - Question #650Security architecture
Which of the following provides the HIGHEST level of confidentiality on a wireless network?
WPA2wireless securityencryptionconfidentiality - Question #651Threats, vulnerabilities, and mitigations
A security administrator is aware that a portion of the company's Internet-facing network tends to be non-secure due to poorly configured and patched systems. The business owner ha...
penetration testinglateral movementrisk acceptancenetwork security - Question #652Security architecture
Which of the following should be implemented to stop an attacker from mapping out addresses and/or devices on a network?
DNS zone transfernetwork reconnaissanceinformation disclosure - Question #653Security operations
Sara, the Chief Information Officer (CIO), has requested an audit take place to determine what services and operating systems are running on the corporate network. Which of the fol...
port scanningfingerprintingOS detectionnetwork audit - Question #654Security architecture
Matt, a systems security engineer, is determining which credential-type authentication to use within a planned 802.1x deployment. He is looking for a method that does not require a...
802.1xPEAP-MSCHAPv2EAPwireless authentication - Question #655Threats, vulnerabilities, and mitigations
Matt, the Chief Information Security Officer (CISO), tells the network administrator that a security company has been hired to perform a penetration test against his network. The s...
black box testingpenetration testingsecurity assessment - Question #656Threats, vulnerabilities, and mitigations
Corporate IM presents multiple concerns to enterprise IT. Which of the following concerns should Jane, the IT security manager, ensure are under control? (Select THREE).
instant messagingdata leakagemalwarecompliance - Question #657Threats, vulnerabilities, and mitigations
The use of social networking sites introduces the risk of:
social networkingproprietary informationdata disclosurerisk - Question #658Threats, vulnerabilities, and mitigations
Account lockout is a mitigation strategy used by Jane, the administrator, to combat which of the following attacks? (Select TWO).
account lockoutbrute forcedictionary attackauthentication