SY0-301 Exam Questions
901 real SY0-301 exam questions with expert-verified answers and explanations. Page 14 of 19.
- Question #659Security operations
Which of the following controls mitigates the risk of Matt, an attacker, gaining access to a company network by using a former employee's credential?
account expirationaccess controloffboardingcredential management - Question #660Security program management and oversight
Pete, the Chief Executive Officer (CEO) of a company, has increased his travel plans for the next two years to improve business relations. Which of the following would need to be i...
succession planningbusiness continuitykey person risk - Question #661Security program management and oversight
In order to prevent and detect fraud, which of the following should be implemented?
job rotationfraud preventionseparation of dutiesinternal controls - Question #662Threats, vulnerabilities, and mitigations
Which of the following BEST represents the goal of a vulnerability assessment?
vulnerability assessmentsecurity posturerisk assessment - Question #663Threats, vulnerabilities, and mitigations
An administrator notices an unusual spike in network traffic from many sources. The administrator suspects that:
DDoSnetwork traffic analysisintrusion detection - Question #664Security operations
A customer service department has a business need to send high volumes of confidential information to customers electronically. All emails go through a DLP scanner. Which of the fo...
DLPemail encryptiondata loss preventionconfidential data - Question #665General security concepts
Which of the following cryptographic algorithms is MOST often used with IPSec?
IPSecHMACcryptographic algorithmsVPN - Question #666Security architecture
Users require access to a certain server depending on their job function. Which of the following would be the MOST appropriate strategy for securing the server?
RBACaccess controlauthorizationleast privilege - Question #667Security operations
Pete, a security administrator, has observed repeated attempts to break into the network. Which of the following is designed to stop an intrusion on the network?
NIPSintrusion preventionnetwork security - Question #668Security architecture
Which of the following would Pete, a security administrator, MOST likely implement in order to allow employees to have secure remote access to certain internal network services suc...
VPNremote accesssecure tunneling - Question #669Security operations
Which of the following should be done before resetting a user's password due to expiration?
identity verificationpassword managementauthentication - Question #670General security concepts
Which of the following hardware based encryption devices is used as a part of multi-factor authentication to access a secured computing system?
multi-factor authenticationhardware tokenUSB encryption - Question #671Security program management and oversight
Establishing a published chart of roles, responsibilities, and chain of command to be used during a disaster is an example of which of the following?
succession planningdisaster recoverybusiness continuity - Question #672General security concepts
In PKI, a key pair consists of: (Select TWO).
PKIpublic keyprivate keyasymmetric cryptography - Question #673General security concepts
Speaking a passphrase into a voice print analyzer is an example of which of the following security concepts?
multi-factor authenticationbiometricstwo-factor authentication - Question #674General security concepts
Which of the following secure file transfer methods uses port 22 by default?
SFTPsecure file transferport 22 - Question #675Security architecture
While setting up a secure wireless corporate network, which of the following should Pete, an administrator, avoid implementing?
WEPwireless securityencryption protocols - Question #676Security architecture
Due to limited resources, a company must reduce their hardware budget while still maintaining availability. Which of the following would MOST likely help them achieve their objecti...
virtualizationhigh availabilityhardware consolidation - Question #677Security operations
A user has several random browser windows opening on their computer. Which of the following programs can be installed on his machine to help prevent this from happening?
pop-up blockermalware preventionbrowser security - Question #678Security architecture
A company is installing a new security measure that would allow one person at a time to be authenticated to an area without human interaction. Which of the following does this desc...
mantrapphysical securityaccess control - Question #679General security concepts
When employees that use certificates leave the company they should be added to which of the following?
CRLPKIcertificate revocation - Question #680Security operations
Several departments within a company have a business need to send high volumes of confidential information to customers via email. Which of the following is the BEST solution to mi...
DLPemail encryptiondata loss preventionconfidential data - Question #681Security operations
An administrator is looking to implement a security device which will be able to not only detect network intrusions at the organization level, but help defend against them as well....
NIPSintrusion preventionnetwork security - Question #682Security architecture
A company has implemented PPTP as a VPN solution. Which of the following ports would need to be opened on the firewall in order for this VPN to function properly? (Select TWO).
PPTP VPNfirewall portsGRE protocolVPN protocols - Question #683Threats, vulnerabilities, and mitigations
Mike, a user, states that he is receiving several unwanted emails about home loans. Which of the following is this an example of?
spamemail threatsunwanted email - Question #684General security concepts
Which of the following must a user implement if they want to send a secret message to a co- worker by embedding it within an image?
steganographydata hidingcovert channels - Question #685Security architecture
Pete, a network administrator, is implementing IPv6 in the DMZ. Which of the following protocols must he allow through the firewall to ensure the web servers can be reached via IPv...
IPv6DMZICMPv6firewall rules - Question #686Security operations
Sara, a security technician, has received notice that a vendor coming in for a presentation will require access to a server outside of the network. Currently, users are only able t...
firewall rulesvendor accessremote accessnetwork access control - Question #687Security architecture
Which of the following is the BEST method for ensuring all files and folders are encrypted on all corporate laptops where the file structures are unknown?
whole disk encryptionlaptop securitydata at restFDE - Question #688General security concepts
Encryption used by RADIUS is BEST described as:
RADIUSsymmetric encryptionauthentication protocols - Question #689General security concepts
Which of the following is used by the recipient of a digitally signed email to verify the identity of the sender?
digital signaturespublic key cryptographyPKIemail security - Question #690Security architecture
A security analyst has been tasked with securing a guest wireless network. They recommend the company use an authentication server but are told the funds are not available to set t...
MAC filteringwireless securityguest networkaccess control - Question #691Security operations
A supervisor in the human resources department has been given additional job duties in the accounting department. Part of their new duties will be to check the daily balance sheet...
group membershipleast privilegeIAMaccess control - Question #692Security operations
Which of the following security benefits would be gained by disabling a terminated user account rather than deleting it?
account managementkey retentiontermination procedurescryptographic keys - Question #693Security architecture
Which of the following security architecture elements also has sniffer functionality? (Select TWO).
IDSIPSpacket sniffingnetwork monitoring - Question #694Security architecture
Jane, an IT security technician, needs to create a way to secure company mobile devices. Which of the following BEST meets this need?
mobile device managementdevice encryptionremote wipeMDM - Question #695General security concepts
Which of the following should a security technician implement to identify untrusted certificates?
CRLcertificate revocationPKIcertificate management - Question #696General security concepts
Pete, an employee, needs a certificate to encrypt data. Which of the following would issue Pete a certificate?
certificate authorityPKIcertificate issuance - Question #697General security concepts
Sara, a security engineer, is testing encryption ciphers for performance. Which of the following ciphers offers strong encryption with the FASTEST speed?
Blowfishcipher performancesymmetric encryptioncipher comparison - Question #698General security concepts
Which of the following is an authentication method that can be secured by using SSL?
LDAPLDAPSSSLauthentication protocols - Question #699Security program management and oversight
The Chief Security Officer (CSO) is concerned about misuse of company assets and wishes to determine who may be responsible. Which of the following would be the BEST course of acti...
mandatory vacationinsider threatfraud detectionadministrative controls - Question #700Security architecture
Jane, a VPN administrator, was asked to implement an encryption cipher with a MINIMUM effective security of 128-bits. Which of the following should Jane select for the tunnel encry...
VPN encryptionBlowfishcipher key lengthtunnel encryption - Question #701General security concepts
Which of the following uses both a public and private key?
RSAasymmetric encryptionpublic key cryptographykey pairs - Question #702General security concepts
Which of the following would Matt, a security administrator, use to encrypt transmissions from an internal database to an internal server, keeping in mind that the encryption proce...
symmetric encryption3DEScryptographyencryption latency - Question #703Threats, vulnerabilities, and mitigations
A database administrator receives a call on an outside telephone line from a person who states that they work for a well-known database vendor. The caller states there have been pr...
social engineeringvishingpretextingsecurity awareness - Question #704Security operations
The datacenter manager is reviewing a problem with a humidity factor that is too low. Which of the following environmental problems may occur?
environmental controlshumiditystatic electricitydatacenter physical security - Question #705Security architecture
A UNIX administrator would like to use native commands to provide a secure way of connecting to other devices remotely and to securely transfer files. Which of the following protoc...
SSHSCPsecure remote accessfile transfer protocols - Question #706General security concepts
A network administrator has purchased two devices that will act as failovers for each other. Which of the following concepts does this BEST illustrate?
availabilityredundancyfailoverCIA triad - Question #707Security architecture
Matt, the network engineer, has been tasked with separating network traffic between virtual machines on a single hypervisor. Which of the following would he implement to BEST addre...
virtualizationVLANvirtual switchnetwork segmentation - Question #708Security architecture
Which of the following BEST describes a demilitarized zone?
DMZnetwork segmentationperimeter securitynetwork architecture