SY0-301 Exam Questions
901 real SY0-301 exam questions with expert-verified answers and explanations. Page 7 of 19.
- Question #303General security concepts
Which of the following would provide the STRONGEST encryption?
one-time padencryption strengthsymmetric encryptionkey length - Question #304Threats, vulnerabilities, and mitigations
During a server audit, a security administrator does not notice abnormal activity. However, a network security analyst notices connections to unauthorized ports from outside the co...
rootkitmalwarehidden processesnetwork anomaly - Question #305General security concepts
A security administrator wants to ensure that the message the administrator sends out to their Chief Financial Officer (CFO) does not get changed in route. Which of the following i...
data integrityCIA triadmessage integrity - Question #306Security program management and oversight
Which of the following can be performed when an element of the company policy cannot be enforced by technical means?
user trainingsecurity policyadministrative controlscompensating controls - Question #307Threats, vulnerabilities, and mitigations
Timestamps and sequence numbers act as countermeasures against which of the following types of attacks?
replay attacktimestampssequence numberscountermeasures - Question #308General security concepts
Which of the following would be used as a secure substitute for Telnet?
SSHTelnet replacementsecure remote accessprotocols - Question #309Threats, vulnerabilities, and mitigations
Which of the following is described as an attack against an application using a malicious file?
client-side attackmalicious fileapplication attack - Question #310Security operations
Which of the following assessment techniques would a security administrator implement to ensure that systems and software are developed properly?
design reviewsecure SDLCapplication security assessment - Question #311Security operations
Which of the following would a security administrator implement in order to identify a problem between two applications that are not communicating properly?
protocol analyzernetwork troubleshootingpacket capturediagnostic tools - Question #312Security operations
Which of the following would a security administrator implement in order to identify change from the standard configuration on a server?
baseline reviewconfiguration managementchange detection - Question #313Security operations
Which of the following tools would a security administrator use in order to identify all running services throughout an organization?
port scannernetwork discoveryservice enumeration - Question #314General security concepts
Which of the following protocols provides transport security for virtual terminal emulation?
SSHvirtual terminaltransport securityterminal emulation - Question #315Security operations
Based on information leaked to industry websites, business management is concerned that unauthorized employees are accessing critical project information for a major, well-known ne...
honeypotinsider threatdeception technologyunauthorized access detection - Question #316Threats, vulnerabilities, and mitigations
A set of standardized system images with a pre-defined set of applications is used to build end- user workstations. The security administrator has scanned every workstation to crea...
attack surfaceapplication inventoryvulnerability assessmenthardening - Question #317Security architecture
A perimeter survey finds that the wireless network within a facility is easily reachable outside of the physical perimeter. Which of the following should be adjusted to mitigate th...
wireless securitypower level controlsRF containmentperimeter security - Question #318Security operations
Which of the following would verify that a threat does exist and security controls can easily be bypassed without actively testing an application?
vulnerability scanpenetration testingpassive assessmentsecurity controls - Question #319General security concepts
Connections using point-to-point protocol authenticate using which of the following? (Select TWO).
PPPPAPCHAPauthentication protocols - Question #320Threats, vulnerabilities, and mitigations
Which of the following will help prevent smurf attacks?
smurf attackdirected broadcastDDoS mitigationrouter configuration - Question #321Security architecture
An advantage of virtualizing servers, databases, and office applications is:
virtualizationcentralized managementserver consolidation - Question #322Security architecture
A major security risk with co-mingling of hosts with different security requirements is:
network segmentationsecurity zoneshost isolationsecurity policy - Question #323Threats, vulnerabilities, and mitigations
Which of the following attacks targets high level executives to gain company information?
whalingsocial engineeringspear phishingexecutive targeting - Question #324Security operations
Which of the following can be used as an equipment theft deterrent?
physical securitycable lockstheft deterrentequipment security - Question #325Threats, vulnerabilities, and mitigations
At the outside break area, an employee, Ann, asked another employee to let her into the building because her badge is missing. Which of the following does this describe?
tailgatingsocial engineeringphysical access controlpiggybacking - Question #326Security program management and oversight
A company that has a mandatory vacation policy has implemented which of the following controls?
mandatory vacationadministrative controlsrisk controlseparation of duties - Question #327Security operations
Ann, a company's security officer, often receives reports of unauthorized personnel having access codes to the cipher locks of secure areas in the building. Ann should immediately...
security awareness trainingphysical access controlcipher locksinsider threat - Question #328Security operations
Which of the following is the MOST intrusive type of testing against a production system?
penetration testingvulnerability testingproduction systemssecurity testing - Question #329Security architecture
The IT department has installed new wireless access points but discovers that the signal extends far into the parking lot. Which of the following actions should be taken to correct...
wireless securityRF power levelsaccess point configurationsignal containment - Question #330Security operations
The helpdesk reports increased calls from clients reporting spikes in malware infections on their systems. Which of the following phases of incident response is MOST appropriate as...
incident responseidentification phasemalwareincident handling - Question #331General security concepts
Which of the following protocols would be used to verify connectivity between two remote devices at the HIGHEST level of the OSI model?
OSI modelprotocol layersSCPnetwork connectivity - Question #332Security architecture
Which of the following devices would be MOST useful to ensure availability when there are a large number of requests to a certain website?
load balanceravailabilityhigh availabilityweb servers - Question #333General security concepts
Which of the following uses port 22 by default? (Select THREE).
port numbersSSHSFTPSCP - Question #334Threats, vulnerabilities, and mitigations
Ann, a software developer, has installed some code to reactivate her account one week after her account has been disabled. Which of the following is this an example of? (Select TWO...
logic bombbackdoormalwareinsider threat - Question #335Threats, vulnerabilities, and mitigations
The string: ` or 1=1-- - represents which of the following?
SQL injectioninjection attacksweb application securityinput validation - Question #336Security operations
Joe, an administrator, installs a web server on the Internet that performs credit card transactions for customer payments. Joe also sets up a second web server that looks like the...
honeypotdeception technologyintrusion detectionfabricated data - Question #337Security operations
Which of the following can Joe, a security administrator, implement on his network to capture attack details that are occurring while also protecting his production network?
honeypotnetwork deceptionattack captureproduction protection - Question #338Security program management and oversight
Which of the following should Joe, a security manager, implement to reduce the risk of employees working in collusion to embezzle funds from his company?
mandatory vacationcollusion preventionseparation of dutiesfraud mitigation - Question #339Security operations
Ann, a security technician, is reviewing the IDS log files. She notices a large number of alerts for multicast packets from the switches on the network. After investigation, she di...
IDSfalse positiveslog analysisintrusion detection - Question #340Security program management and oversight
Joe, a security analyst, asks each employee of an organization to sign a statement saying that they understand how their activities may be monitored. Which of the following BEST de...
acceptable use policyprivacy policyuser monitoringsecurity policies - Question #341Security operations
A process in which the functionality of an application is tested without any knowledge of the internal mechanisms of the application is known as:
black box testingapplication testingsecurity assessmentpenetration testing - Question #342Security operations
Which of the following tools would allow Ann, the security administrator, to be able to BEST quantify all traffic on her network?
protocol analyzernetwork traffic analysisnetwork monitoringsecurity tools - Question #343Security operations
Which of the following should an administrator implement to research current attack methodologies?
honeypotattack researchthreat intelligencedeception technology - Question #344Threats, vulnerabilities, and mitigations
Which of the following consists of peer assessments that help identify security threats and vulnerabilities?
code reviewpeer assessmentvulnerability identificationsecure development - Question #345Security program management and oversight
Ann is starting a disaster recovery program. She has gathered specifics and team members for a meeting on site. Which of the following types of tests is this?
disaster recoverystructured walk-throughBCP testingDR test types - Question #346General security concepts
An internal auditing team would like to strengthen the password policy to support special characters. Which of the following types of password controls would achieve this goal?
password complexitypassword policyspecial charactersauthentication controls - Question #347Security architecture
Which of the following can be implemented in hardware or software to protect a web server from cross-site scripting attacks?
WAFcross-site scriptingweb application securityXSS mitigation - Question #348Threats, vulnerabilities, and mitigations
Ann, the software security engineer, works for a major software vendor. Which of the following practices should be implemented to help prevent race conditions, buffer overflows, an...
code reviewbuffer overflowrace conditionsecure development - Question #349Security operations
Ann, a security analyst, is preparing for an upcoming security audit. To ensure that she identifies unapplied security controls and patches without attacking or compromising the sy...
vulnerability scanningsecurity auditnon-intrusive testingunapplied patches - Question #350Security operations
Ann, the security administrator, received a report from the security technician, that an unauthorized new user account was added to the server over two weeks ago. Which of the foll...
log auditingaccount managementunauthorized accessmonitoring - Question #351General security concepts
Which of the following ports should be opened on a firewall to allow for NetBIOS communication? (Select TWO).
NetBIOSnetwork portsfirewall rulesport 137 port 139 - Question #352Security architecture
Joe, the systems administrator, is setting up a wireless network for his team's laptops only and needs to prevent other employees from accessing it. Which of the following would BE...
MAC filteringwireless securityaccess controlnetwork access restriction