SY0-301 Exam Questions
901 real SY0-301 exam questions with expert-verified answers and explanations. Page 18 of 19.
- Question #865General security concepts
Which of the following protocols provides fast, unreliable file transfer?
TFTPfile transfer protocolsUDPprotocol comparison - Question #866General security concepts
Which of the following digital certificate management practices will ensure that a lost certificate is not compromised?
CRLPKIcertificate revocationcertificate management - Question #867General security concepts
Which of the following protocols operates at the HIGHEST level of the OSI model?
OSI modelnetwork protocolsapplication layerSCP - Question #868Security program management and oversight
Joe, the system administrator, has been asked to calculate the Annual Loss Expectancy (ALE) for a $5,000 server, which often crashes. In the past year, the server has crashed 10 ti...
ALErisk calculationSLEARO - Question #869Security architecture
Jane, a security administrator, needs to implement a secure wireless authentication method that uses a remote RADIUS server for authentication. Which of the following is an authent...
RADIUSLEAPwireless authentication802.1x - Question #870Security operations
Computer evidence at a crime scene is documented with a tag stating who had possession of the evidence at a given time. Which of the following does this illustrate?
chain of custodydigital forensicsevidence handling - Question #871Security program management and oversight
Which of the following is being tested when a company's payroll server is powered off for eight hours?
continuity of operationsCOOPbusiness continuitydisaster recovery - Question #872Security operations
A security manager must remain aware of the security posture of each system. Which of the following supports this requirement?
baseline reportingsecurity posturesecurity monitoring - Question #873General security concepts
Deploying a wildcard certificate is one strategy to:
wildcard certificatePKIcertificate management - Question #874Security architecture
The security administrator needs to manage traffic on a layer 3 device to support FTP from a new remote site. Which of the following would need to be implemented?
ACLaccess control listslayer 3network traffic management - Question #875Threats, vulnerabilities, and mitigations
A server with the IP address of 10.10.2.4 has been having intermittent connection issues. The logs show repeated connection attempts from the following IPs: 10.10.3.16 10.10.3.23 2...
DDoSdenial of servicenetwork attack - Question #876Security architecture
Which of the following is true about input validation in a client-server architecture, when data integrity is critical to the organization?
input validationserver-side validationsecure codingdata integrity - Question #877Security architecture
Which of the following is BEST at blocking attacks and providing security at layer 7 of the OSI model?
WAFweb application firewallOSI modelapplication layer - Question #878Security operations
Which of the following is BEST used to capture and analyze network traffic between hosts on the same network segment?
protocol analyzerpacket capturenetwork monitoring - Question #879Security architecture
A datacenter requires that staff be able to identify whether or not items have been removed from the facility. Which of the following controls will allow the organization to provid...
RFIDphysical securityasset trackingdatacenter - Question #880Security architecture
A malicious person gained access to a datacenter by ripping the proximity badge reader off the wall near the datacenter entrance. This caused the electronic locks on the datacenter...
fail openphysical access controlelectronic locksecurity design - Question #881General security concepts
The concept of rendering data passing between two points over an IP based network impervious to all but the most sophisticated advanced persistent threats is BEST categorized as wh...
transport encryptionin-transit encryptionnetwork securitycryptography - Question #882Security operations
On Monday, all company employees report being unable to connect to the corporate wireless network, which uses 802.1x with PEAP. A technician verifies that no configuration changes...
802.1xPEAPRADIUScertificate expiration - Question #883Threats, vulnerabilities, and mitigations
Which of the following would BEST deter an attacker trying to brute force 4-digit PIN numbers to access an account at a bank teller machine?
account lockoutbrute forcePIN securityauthentication controls - Question #884Security program management and oversight
An administrator discovers that many users have used their same passwords for years even though the network requires that the passwords be changed every six weeks. Which of the fol...
password historyminimum password agepassword policyauthentication - Question #885Security program management and oversight
A recent audit has discovered that at the time of password expiration clients are able to recycle the previous credentials for authentication. Which of the following controls shoul...
password agepassword historypassword policyauthentication - Question #886General security concepts
A system administrator is configuring UNIX accounts to authenticate against an external server. The configuration file asks for the following information DC=ServerName and DC=COM....
LDAPdirectory servicesauthenticationDC notation - Question #887General security concepts
In Kerberos, the Ticket Granting Ticket (TGT) is used for which of the following?
KerberosTGTauthenticationticket-based auth - Question #888Security architecture
When considering a vendor-specific vulnerability in critical industrial control systems which of the following techniques supports availability?
ICSavailabilityredundancysystem diversity - Question #889Security architecture
During the information gathering stage of a deploying role-based access control model, which of the following information is MOST likely required?
RBACrole definitionprivilege matrixaccess control - Question #890Security program management and oversight
The Chief Technical Officer (CTO) has been informed of a potential fraud committed by a database administrator performing several other job functions within the company. Which of t...
separation of dutiesinsider threatfraud preventionadministrative controls - Question #891Security operations
A recently installed application update caused a vital application to crash during the middle of the workday. The application remained down until a previous version could be reinst...
patch managementchange managementapplication updatesavailability - Question #892Security operations
A company is about to release a very large patch to its customers. An administrator is required to test patch installations several times prior to distributing them to customer PCs...
virtualizationsnapshotspatch testingsandbox - Question #893General security concepts
An auditing team has found that passwords do not meet best business practices. Which of the following will MOST increase the security of the passwords? (Select TWO).
password policypassword complexitypassword lengthauthentication - Question #894Threats, vulnerabilities, and mitigations
A vulnerability scan is reporting that patches are missing on a server. After a review, it is determined that the application requiring the patch does not exist on the operating sy...
vulnerability scanningfalse positivepatch managementscan results - Question #895General security concepts
Company A submitted a bid on a contract to do work for Company B via email. Company B was insistent that the bid did not come from Company A. Which of the following would have assu...
digital signaturesnon-repudiationPKIemail security - Question #896Security architecture
Ann, a sales manager, successfully connected her company-issued smartphone to the wireless network in her office without supplying a username/password combination. Upon disconnecti...
MAC filteringwireless securitynetwork access control802.11 - Question #897Security operations
A network technician is on the phone with the system administration team. Power to the server room was lost and servers need to be restarted. The DNS services must be the first to...
DNSBINDservice recoveryserver roles - Question #898Security program management and oversight
A security administrator is reviewing the company's continuity plan. The plan specifies an RTO of six hours and RPO of two days. Which of the following is the plan describing?
RTORPObusiness continuitydisaster recovery - Question #899Security operations
The incident response team has received the following email message. From: [email protected] To: [email protected] Subject: Copyright infringement A copyright infringement...
incident responselog analysistime synchronizationforensic investigation - Question #900Security operations
A server dedicated to the storage and processing of sensitive information was compromised with a rootkit and sensitive data was exfiltrated. Which of the following incident respons...
rootkitincident responseremediationOS reinstallation - Question #901Threats, vulnerabilities, and mitigations
Which of the following describes a type of malware which is difficult to reverse engineer in a virtual lab?
armored virusmalware analysisreverse engineeringobfuscation - Question #902Threats, vulnerabilities, and mitigations
Using a heuristic system to detect an anomaly in a computer's baseline, a system administrator was able to detect an attack even though the company signature based IDS and antiviru...
zero-day attackheuristic detectionprivilege escalationIDS - Question #903General security concepts
After copying a sensitive document from his desktop to a flash drive, Joe, a user, realizes that the document is no longer encrypted. Which of the following can a security technici...
file-level encryptionremovable mediadata protectionDLP - Question #904General security concepts
A security administrator must implement a system to allow clients to securely negotiate encryption keys with the company's server over a public unencrypted communication channel. W...
Diffie-HellmanECDHEkey exchangeasymmetric cryptography - Question #905Security program management and oversight
Acme Corp has selectively outsourced proprietary business processes to ABC Services. Due to some technical issues, ABC services wants to send some of Acme Corp's debug data to a th...
data ownershipNDAthird-party riskdata governance - Question #906General security concepts
An organization has introduced token-based authentication to system administrators due to risk of password compromise. The tokens have a set of numbers that automatically change ev...
TOTPmulti-factor authenticationtoken-based authenticationOTP - Question #907Security architecture
A security technician at a small business is worried about the Layer 2 switches in the network suffering from a DoS style attack caused by staff incorrectly cabling network connect...
spanning tree protocolLayer 2 securityDoS mitigationnetwork loops - Question #908Security architecture
An administrator wants to establish a WiFi network using a high gain directional antenna with a narrow radiation pattern to connect two buildings separated by a very long distance....
Yagi antennadirectional antennawireless networkingpoint-to-point - Question #909Threats, vulnerabilities, and mitigations
An attacker used an undocumented and unknown application exploit to gain access to a file server. Which of the following BEST describes this type of attack?
zero-day exploitapplication vulnerabilitiesunknown exploitattack types - Question #910General security concepts
Which of the following is an XML based open standard used in the exchange of authentication and authorization information between different parties?
SAMLfederated identitySSOXML authentication - Question #911Security operations
Which of the following ports and protocol types must be opened on a host with a host- based firewall to allow incoming SFTP connections?
SFTPport 22firewall rulesprotocol ports - Question #912Threats, vulnerabilities, and mitigations
A user, Ann, is reporting to the company IT support group that her workstation screen is blank other than a window with a message requesting payment or else her hard drive will be...
ransomwaremalware typesextortiondata destruction threat - Question #913Security operations
Which of the following controls can be implemented together to prevent data loss in the event of theft of a mobile device storing sensitive information? (Select TWO).
full device encryptionscreen lockmobile securitydata loss prevention - Question #914Threats, vulnerabilities, and mitigations
A security audit identifies a number of large email messages being sent by a specific user from their company email account to another address external to the company. These messag...
steganographydata exfiltrationinsider threatcovert channels