SY0-301 Exam Questions
901 real SY0-301 exam questions with expert-verified answers and explanations. Page 3 of 19.
- Question #101General security concepts
Which of the following protocols allows for secure transfer of files? (Select TWO).
secure file transferSFTPSCPnetwork protocols - Question #102General security concepts
Which of the following passwords is the LEAST complex?
password complexitypassword policyauthentication - Question #103Threats, vulnerabilities, and mitigations
During a penetration test from the Internet, Jane, the system administrator, was able to establish a connection to an internal router, but not successfully log in to it. Which port...
firewall portspenetration testingnetwork protocolsremote access - Question #104__DIAG_PROBE2__
Which of the following is an application security coding problem?
__diag2__ - Question #105Security architecture
An IT security technician needs to establish host based security for company workstations. Which of the following will BEST meet this requirement?
host hardeningGPOOS hardeningendpoint security - Question #106Security operations
Which of the following is the MOST specific plan for various problems that can arise within a system?
IT contingency planbusiness continuitydisaster recoveryincident response - Question #107Threats, vulnerabilities, and mitigations
Which of the following BEST describes the weakness in WEP encryption?
WEP weaknessRC4wireless encryptioninitialization vector - Question #108Security program management and oversight
Sara, the Chief Security Officer (CSO), has had four security breaches during the past two years. Each breach has cost the company $3,000. A third party vendor has offered to repai...
risk managementrisk transferALEcost-benefit analysis - Question #109General security concepts
Which of the following is an authentication and accounting service that uses TCP for connecting to routers and switches?
TACACS+AAA protocolsauthenticationnetwork access control - Question #110Threats, vulnerabilities, and mitigations
Which of the following can BEST help prevent cross-site scripting attacks and buffer overflows on a production system?
input validationXSSbuffer overflowapplication security - Question #111Security architecture
Pete, an IT Administrator, needs to secure his server room. Which of the following mitigation methods would provide the MOST physical protection?
physical securitymantrapserver roomaccess control - Question #112Security architecture
Which of the following should be connected to the fire alarm system in order to help prevent the spread of a fire in a server room without data loss to assist in an FM-200 deployme...
fire suppressionFM-200HVACdatacenter physical security - Question #113Security architecture
Matt, a security consultant, has been tasked with increasing server fault tolerance and has been given no budget to accomplish his task. Which of the following can Matt implement t...
RAIDfault tolerancehigh availabilityserver resilience - Question #114Security architecture
Which of the following fire suppression systems is MOST likely used in a datacenter?
FM-200fire suppressiondatacenterclean agent - Question #115General security concepts
A security administrator has installed a new KDC for the corporate environment. Which of the following authentication protocols is the security administrator planning to implement...
KerberosKDCauthentication protocolsActive Directory - Question #116Threats, vulnerabilities, and mitigations
While opening an email attachment, Pete, a customer, receives an error that the application has encountered an unexpected issue and must be shut down. This could be an example of w...
buffer overflowapplication crashexploitsoftware vulnerability - Question #117Security operations
Jane has recently implemented a new network design at her organization and wishes to passively identify security issues with the new network. Which of the following should Jane per...
vulnerability assessmentpassive scanningsecurity assessmentnetwork security - Question #118General security concepts
A security technician is working with the network firewall team to implement access controls at the company's demarc as part of the initiation of configuration management processes...
rule-based access controlfirewall ACLaccess control modelsnetwork security - Question #119General security concepts
Jane, a security administrator, has been tasked with explaining authentication services to the company's management team. The company runs an active directory infrastructure. Which...
KerberosActive Directoryhost authenticationAAA - Question #120Security architecture
Pete, the compliance manager, wants to meet regulations. Pete would like certain ports blocked only on all computers that do credit card transactions. Which of the following should...
host-based firewallPCI DSSport filteringendpoint security - Question #121Security architecture
Pete, the system administrator, wants to restrict access to advertisements, games, and gambling web sites. Which of the following devices would BEST achieve this goal?
URL content filteringweb filteringproxyaccess control - Question #122Security architecture
Pete, the system administrator, wishes to monitor and limit users' access to external websites. Which of the following would BEST address this?
proxy serverweb filteringnetwork monitoringport 80 - Question #123Security architecture
Sara, the security administrator, must configure the corporate firewall to allow all public IP addresses on the internal interface of the firewall to be translated to one public IP...
PATNATfirewallIP translation - Question #124General security concepts
Matt, a security analyst, needs to select an asymmetric encryption method that allows for the same level of encryption strength with a lower key length than is typically necessary....
ECCasymmetric encryptionkey lengthcryptography - Question #125Security program management and oversight
Sara, a security analyst, is trying to prove to management what costs they could incur if their customer database was breached. This database contains 250 records with PII. Studies...
ALEquantitative riskPIIrisk calculation - Question #126Threats, vulnerabilities, and mitigations
Methods to test the responses of software and web applications to unusual or unexpected inputs is known as:
fuzzinginput validationsoftware testingvulnerability testing - Question #127Security architecture
Pete needs to open ports on the firewall to allow for secure transmission of files. Which of the following ports should be opened on the firewall?
SSHSFTPTCP 22secure file transfer - Question #128Security architecture
Sara, a security architect, has developed a framework in which several authentication servers work together to increase processing power for an application. Which of the following...
clusteringhigh availabilityauthentication serversfault tolerance - Question #129Security operations
Which statement is TRUE about the operation of a packet sniffer?
packet snifferpromiscuous modenetwork monitoringEthernet - Question #130Security architecture
Which of the following firewall rules only denies DNS zone transfers?
DNS zone transferfirewall rulesTCP 53DNS security - Question #131General security concepts
Which of the following BEST explains the use of an HSM within the company servers?
HSMhardware encryptionperformancekey management - Question #132Security architecture
Which of the following technologies can store multi-tenant data with different security requirements?
cloud computingmulti-tenancydata segregationvirtualization - Question #133Security operations
Matt, a security analyst, needs to implement encryption for company data and also prevent theft of company data. Where and how should Matt meet this requirement?
DLPdatabase encryptiondata protectiondata loss prevention - Question #134General security concepts
Which of the following types of encryption will help in protecting files on a PED?
mobile device encryptionPEDdata at restfull disk encryption - Question #135General security concepts
Which of the following does full disk encryption prevent?
full disk encryptionclear text accessdata at restphysical security - Question #136Security program management and oversight
Pete, a security analyst, has been informed that the development team has plans to develop an application which does not meet the company's password policy. Which of the following...
password policysecurity policy enforcementcomplianceapplication development - Question #137Security operations
Sara, a security manager, has decided to force expiration of all company passwords by the close of business day. Which of the following BEST supports this reasoning?
password expirationcredential compromisesecurity breachaccount management - Question #138General security concepts
Which of the following presents the STRONGEST access control?
MACDACRBACaccess control models - Question #139Security program management and oversight
Which of the following encompasses application patch management?
configuration managementpatch managementchange controlsecurity baseline - Question #140Threats, vulnerabilities, and mitigations
Sara, an application developer, implemented error and exception handling alongside input validation. Which of the following does this help prevent?
buffer overflowinput validationerror handlingsecure coding - Question #141Security operations
Which of the following is the LEAST volatile when performing incident response procedures?
order of volatilityincident responsedigital forensicsvolatile data - Question #142Security operations
Pete, a developer, writes an application. Jane, the security analyst, knows some things about the overall application but does not have all the details. Jane needs to review the so...
gray box testingsoftware security reviewapplication testingpartial knowledge testing - Question #143Threats, vulnerabilities, and mitigations
The information security team does a presentation on social media and advises the participants not to provide too much personal information on social media web sites. This advice w...
social engineeringcognitive passwordssocial media securityinformation disclosure - Question #144Threats, vulnerabilities, and mitigations
Pete's corporation has outsourced help desk services to a large provider. Management has published a procedure that requires all users, when receiving support, to call a special nu...
impersonationsocial engineeringhelp desk securityidentity verification - Question #145Security architecture
Pete, the security engineer, would like to prevent wireless attacks on his network. Pete has implemented a security control to limit the connecting MAC addresses to a single port....
wireless securityrogue access pointMAC filteringport security - Question #146General security concepts
Which of the following can be implemented with multiple bit strength?
AESsymmetric encryptionkey lengthcryptography algorithms - Question #147Security operations
Pete, the system administrator, has blocked users from accessing social media web sites. In addition to protecting company information from being accidentally leaked, which additio...
web filteringmalware preventionbanner adscontent filtering - Question #148Security operations
Pete, the system administrator, is reviewing his disaster recovery plans. He wishes to limit the downtime in the event of a disaster, but does not have the budget approval to imple...
disaster recoverywarm sitebusiness continuityoffsite location - Question #149General security concepts
A network stream needs to be encrypted. Sara, the network administrator, has selected a cipher which will encrypt 8 bits at a time before sending the data across the network. Which...
block cipherstream cipherencryption modescryptography - Question #150Security architecture
Pete, a security auditor, has detected clear text passwords between the RADIUS server and the authenticator. Which of the following is configured in the RADIUS server and what tech...
RADIUSPAPMSCHAPv2authentication protocols