SY0-301 Exam Questions
901 real SY0-301 exam questions with expert-verified answers and explanations. Page 15 of 19.
- Question #709Security program management and oversight
XYZ Corporation is about to purchase another company to expand its operations. The CEO is concerned about information leaking out, especially with the cleaning crew that comes in a...
clean desk policyphysical securitydata leakagesecurity policy - Question #710Security architecture
The administrator would like to implement hardware assisted full disk encryption on laptops. Which of the following would MOST likely be used to meet this goal?
TPMfull disk encryptionhardware securityendpoint protection - Question #711Security operations
Jane, a security administrator, wants to harden the web server. Which of the following could she perform to accomplish this task?
server hardeningunnecessary servicessystem configurationattack surface reduction - Question #712Security program management and oversight
Which of the following policies could be implemented to help prevent users from displaying their login credentials in open view for everyone to see?
clean desk policycredential exposurephysical securitypolicy - Question #713Security operations
Pete, the system administrator, has concerns regarding users losing their company provided smartphones. Pete's focus is on equipment recovery. Which of the following BEST addresses...
mobile device managementGPS trackingdevice recoverymobile security - Question #714Threats, vulnerabilities, and mitigations
A security administrator wants to deploy security controls to mitigate the threat of company employees' personal information being captured online. Which of the following would BES...
anti-spywareendpoint securitydata privacymalware protection - Question #715Security program management and oversight
Which of the following statements is MOST likely to be included in the security awareness training about P2P?
P2Psecurity awareness trainingbandwidth consumptionacceptable use policy - Question #716Security program management and oversight
A company's chief information officer (CIO) has analyzed the financial loss associated with the company's database breach. They calculated that one single breach could cost the com...
business impact analysisfinancial lossrisk quantificationBIA - Question #717Security program management and oversight
After a production outage, which of the following documents contains detailed information on the order in which the system should be restored to service?
disaster recovery planrestoration orderDRPbusiness continuity - Question #718Threats, vulnerabilities, and mitigations
Which of the following wireless protocols could be vulnerable to a brute-force password attack? (Select TWO).
wireless securityWPA2-PSKLEAPbrute-force attack - Question #719Security architecture
An auditor is given access to a conference room to conduct an analysis. When they connect their laptop's Ethernet cable into the wall jack, they are not able to get a connection to...
Network Access ControlNAC802.1xnetwork authentication - Question #720General security concepts
Which of the following types of trust models is used by a PKI?
PKItrust modelcertificate authoritycentralized trust - Question #721Security architecture
A security architect has developed a framework in which several authentication servers work together to increase processing power for an application. Which of the following does th...
clusteringhigh availabilityauthentication serversscalability - Question #722Security operations
A technician has implemented a system in which all workstations on the network will receive security updates on the same schedule. Which of the following concepts does this illustr...
patch managementupdate managementworkstation security - Question #723Security architecture
Which of the following offers the LEAST amount of protection against data theft by USB drives?
DLPUSB securitydata loss preventionendpoint controls - Question #724Security program management and oversight
A security analyst has been informed that the development team has plans to develop an application which does not meet the company's password policy. Which of the following should...
password policysecurity policy complianceapplication developmentrisk acceptance - Question #725Threats, vulnerabilities, and mitigations
A security administrator develops a web page and limits input into their fields on the web page as well as filters special characters in output. The administrator is trying to prev...
XSSinput validationoutput encodingweb application security - Question #726Threats, vulnerabilities, and mitigations
Sara, a hacker, is completing a website form to request a free coupon. The site has a field that limits the request to 3 or fewer coupons. While submitting the form, Sara runs an a...
proxy attackHTTP interceptionparameter tamperingweb application attack - Question #727Security operations
Several users report to the administrator that they are having issues downloading files from the file server. Which of the following assessment tools can be used to determine if th...
baselinesperformance monitoringsecurity assessmenttroubleshooting - Question #728Security architecture
When a new network drop was installed, the cable was run across several fluorescent lights. The users of the new network drop experience intermittent connectivity. Which of the fol...
EMI shieldingnetwork cablingenvironmental controlsphysical security - Question #729Security architecture
An administrator configures all wireless access points to make use of a new network certificate authority. Which of the following is being used?
EAP-TLSwireless securitycertificate authenticationPKI - Question #730Security operations
A security analyst noticed a colleague typing the following command: `Telnet some-host 443' Which of the following was the colleague performing?
port testingnetwork diagnosticstelnetservice discovery - Question #731General security concepts
An information bank has been established to store contacts, phone numbers and other records. An application running on UNIX would like to connect to this index server using port 88...
Kerberosauthentication protocolsport numbersAAA - Question #732Security architecture
A database administrator contacts a security administrator to request firewall changes for a connection to a new internal application. The security administrator notices that the n...
access control listsfirewall rulesport securitynetwork security - Question #733Threats, vulnerabilities, and mitigations
Which of the following BEST describes a SQL Injection attack?
SQL injectionweb attacksdatabase attacks - Question #734General security concepts
Digital signatures are used for ensuring which of the following items? (Select TWO).
digital signaturesintegritynon-repudiationPKI - Question #735Threats, vulnerabilities, and mitigations
Matt, an administrator, is concerned about the wireless network being discovered by war driving. Which of the following can be done to mitigate this?
war drivingSSID broadcastingwireless securitynetwork discovery - Question #736Security operations
A company wants to ensure that its hot site is prepared and functioning. Which of the following would be the BEST process to verify the backup datacenter is prepared for such a sce...
hot sitedisaster recovery exercisebusiness continuityDR testing - Question #737General security concepts
Which of the following are restricted to 64-bit block sizes? (Select TWO).
symmetric encryptionblock cipherDES3DES - Question #738Security architecture
A security administrator is segregating all web-facing server traffic from the internal network and restricting it to a single interface on a firewall. Which of the following BEST...
DMZnetwork segmentationfirewallweb server isolation - Question #742General security concepts
Public keys are used for which of the following?
public key cryptographydigital signaturesasymmetric encryptionPKI - Question #743General security concepts
Which of the following is a requirement when implementing PKI if data loss is unacceptable?
PKIkey escrowkey managementdata recovery - Question #744General security concepts
Which of the following is true about PKI? (Select TWO).
asymmetric encryptionPKIpublic keyprivate key - Question #745General security concepts
The recovery agent is used to recover the:
key recoverykey escrowPKIprivate key - Question #746General security concepts
Which of the following is true about the CRL?
CRLcertificate revocationPKI - Question #747Security operations
A password history value of three means which of the following?
password historypassword policyaccount management - Question #748Security operations
A user has forgotten their account password. Which of the following is the BEST recovery strategy?
password recoveryaccount managementauthenticationtemporary password - Question #749Threats, vulnerabilities, and mitigations
Allowing unauthorized removable devices to connect to computers increases the risk of which of the following?
data exfiltrationremovable mediaendpoint security - Question #750Security architecture
A computer is put into a restricted VLAN until the computer's virus definitions are up-to-date. Which of the following BEST describes this system type?
NACVLANendpoint compliancenetwork access control - Question #751Threats, vulnerabilities, and mitigations
Without validating user input, an application becomes vulnerable to all of the following EXCEPT:
input validationSQL injectionbuffer overflowinjection attacks - Question #752Security operations
To protect corporate data on removable media, a security policy should mandate that all removable devices use which of the following?
full disk encryptionremovable mediadata protection - Question #753General security concepts
Which of the following wireless security technologies continuously supplies new keys for WEP?
TKIPWEPwireless securityencryption keys - Question #754Threats, vulnerabilities, and mitigations
Which of the following malware types is MOST likely to execute its payload after Jane, an employee, has left the company?
logic bombmalwareinsider threat - Question #755Threats, vulnerabilities, and mitigations
Which of the following application security principles involves inputting random data into a program?
fuzzingapplication testingsoftware security - Question #756Security operations
Which of the following is an important step in the initial stages of deploying a host-based firewall?
host-based firewallfirewall rulesexception management - Question #757Security operations
Identifying a list of all approved software on a system is a step in which of the following practices?
software baselinehost hardeningapplication inventory - Question #758General security concepts
Which of the following BEST describes using a smart card and typing in a PIN to gain access to a system?
multifactor authenticationsmart cardPINauthentication factors - Question #759Threats, vulnerabilities, and mitigations
An administrator has advised against the use of Bluetooth phones due to bluesnarfing concerns. Which of the following is an example of this threat?
bluesnarfingBluetoothwireless attackunauthorized access - Question #760General security concepts
Which of the following is the difference between identification and authentication of a user?
identificationauthenticationaccess control - Question #761Threats, vulnerabilities, and mitigations
The marketing department wants to distribute pens with embedded USB drives to clients. In the past this client has been victimized by social engineering attacks which led to a loss...
USB securitysocial engineeringdata exfiltrationremovable media