SY0-301 Practice Questions
904 real SY0-301 exam questions with expert-verified answers and explanations. Page 3 of 19.
- Question #101
Which of the following protocols allows for secure transfer of files? (Select TWO).
- Question #102
Which of the following passwords is the LEAST complex?
- Question #103
During a penetration test from the Internet, Jane, the system administrator, was able to establish a connection to an internal router, but not successfully log in to it. Which port...
- Question #104
Which of the following is an application security coding problem?
- Question #105
An IT security technician needs to establish host based security for company workstations. Which of the following will BEST meet this requirement?
- Question #106
Which of the following is the MOST specific plan for various problems that can arise within a system?
- Question #107
Which of the following BEST describes the weakness in WEP encryption?
- Question #108
Sara, the Chief Security Officer (CSO), has had four security breaches during the past two years. Each breach has cost the company $3,000. A third party vendor has offered to repai...
- Question #109
Which of the following is an authentication and accounting service that uses TCP for connecting to routers and switches?
- Question #110
Which of the following can BEST help prevent cross-site scripting attacks and buffer overflows on a production system?
- Question #111
Pete, an IT Administrator, needs to secure his server room. Which of the following mitigation methods would provide the MOST physical protection?
- Question #112
Which of the following should be connected to the fire alarm system in order to help prevent the spread of a fire in a server room without data loss to assist in an FM-200 deployme...
- Question #113
Matt, a security consultant, has been tasked with increasing server fault tolerance and has been given no budget to accomplish his task. Which of the following can Matt implement t...
- Question #114
Which of the following fire suppression systems is MOST likely used in a datacenter?
- Question #115
A security administrator has installed a new KDC for the corporate environment. Which of the following authentication protocols is the security administrator planning to implement...
- Question #116
While opening an email attachment, Pete, a customer, receives an error that the application has encountered an unexpected issue and must be shut down. This could be an example of w...
- Question #117
Jane has recently implemented a new network design at her organization and wishes to passively identify security issues with the new network. Which of the following should Jane per...
- Question #118
A security technician is working with the network firewall team to implement access controls at the company's demarc as part of the initiation of configuration management processes...
- Question #119
Jane, a security administrator, has been tasked with explaining authentication services to the company's management team. The company runs an active directory infrastructure. Which...
- Question #120
Pete, the compliance manager, wants to meet regulations. Pete would like certain ports blocked only on all computers that do credit card transactions. Which of the following should...
- Question #121
Pete, the system administrator, wants to restrict access to advertisements, games, and gambling web sites. Which of the following devices would BEST achieve this goal?
- Question #122
Pete, the system administrator, wishes to monitor and limit users' access to external websites. Which of the following would BEST address this?
- Question #123
Sara, the security administrator, must configure the corporate firewall to allow all public IP addresses on the internal interface of the firewall to be translated to one public IP...
- Question #124
Matt, a security analyst, needs to select an asymmetric encryption method that allows for the same level of encryption strength with a lower key length than is typically necessary....
- Question #125
Sara, a security analyst, is trying to prove to management what costs they could incur if their customer database was breached. This database contains 250 records with PII. Studies...
- Question #126
Methods to test the responses of software and web applications to unusual or unexpected inputs is known as:
- Question #127
Pete needs to open ports on the firewall to allow for secure transmission of files. Which of the following ports should be opened on the firewall?
- Question #128
Sara, a security architect, has developed a framework in which several authentication servers work together to increase processing power for an application. Which of the following...
- Question #129
Which statement is TRUE about the operation of a packet sniffer?
- Question #130
Which of the following firewall rules only denies DNS zone transfers?
- Question #131
Which of the following BEST explains the use of an HSM within the company servers?
- Question #132
Which of the following technologies can store multi-tenant data with different security requirements?
- Question #133
Matt, a security analyst, needs to implement encryption for company data and also prevent theft of company data. Where and how should Matt meet this requirement?
- Question #134
Which of the following types of encryption will help in protecting files on a PED?
- Question #135
Which of the following does full disk encryption prevent?
- Question #136
Pete, a security analyst, has been informed that the development team has plans to develop an application which does not meet the company's password policy. Which of the following...
- Question #137
Sara, a security manager, has decided to force expiration of all company passwords by the close of business day. Which of the following BEST supports this reasoning?
- Question #138
Which of the following presents the STRONGEST access control?
- Question #139
Which of the following encompasses application patch management?
- Question #140
Sara, an application developer, implemented error and exception handling alongside input validation. Which of the following does this help prevent?
- Question #141
Which of the following is the LEAST volatile when performing incident response procedures?
- Question #142
Pete, a developer, writes an application. Jane, the security analyst, knows some things about the overall application but does not have all the details. Jane needs to review the so...
- Question #143
The information security team does a presentation on social media and advises the participants not to provide too much personal information on social media web sites. This advice w...
- Question #144
Pete's corporation has outsourced help desk services to a large provider. Management has published a procedure that requires all users, when receiving support, to call a special nu...
- Question #145
Pete, the security engineer, would like to prevent wireless attacks on his network. Pete has implemented a security control to limit the connecting MAC addresses to a single port....
- Question #146
Which of the following can be implemented with multiple bit strength?
- Question #147
Pete, the system administrator, has blocked users from accessing social media web sites. In addition to protecting company information from being accidentally leaked, which additio...
- Question #148
Pete, the system administrator, is reviewing his disaster recovery plans. He wishes to limit the downtime in the event of a disaster, but does not have the budget approval to imple...
- Question #149
A network stream needs to be encrypted. Sara, the network administrator, has selected a cipher which will encrypt 8 bits at a time before sending the data across the network. Which...
- Question #150
Pete, a security auditor, has detected clear text passwords between the RADIUS server and the authenticator. Which of the following is configured in the RADIUS server and what tech...