SY0-301 Exam Questions
901 real SY0-301 exam questions with expert-verified answers and explanations. Page 9 of 19.
- Question #403General security concepts
Which of the following provides a static record of all certificates that are no longer valid?
CRLPKIcertificate revocationcertificate management - Question #404General security concepts
A company requires that a user's credentials include providing something they know and something they are in order to gain access to the network. Which of the following types of au...
two-factor authenticationauthentication factorsbiometricssomething you are - Question #405General security concepts
A company wants to ensure that all credentials for various systems are saved within a central database so that users only have to login once for access to all systems. Which of the...
Single Sign-OnSSOidentity managementcentralized authentication - Question #406Threats, vulnerabilities, and mitigations
A server with the IP address of 10.10.2.4 has been having intermittent connection issues. The logs show repeated connection attempts from the following IP: 10.10.3.23 These attempt...
DoSdenial of serviceconnection floodsingle-source attack - Question #407Threats, vulnerabilities, and mitigations
Physical documents must be incinerated after a set retention period is reached. Which of the following attacks does this action remediate?
dumpster divingdocument destructiondata disposalphysical security - Question #408Threats, vulnerabilities, and mitigations
All executive officers have changed their monitor location so it cannot be easily viewed when passing by their offices. Which of the following attacks does this action remediate?
shoulder surfingvisual eavesdroppingphysical securitymonitor positioning - Question #409Threats, vulnerabilities, and mitigations
Which of the following protocols is vulnerable to man-in-the-middle attacks by NOT using end to end TLS encryption?
WPAman-in-the-middlewireless securityTLS encryption - Question #410Security architecture
A security administrator has been tasked with setting up a new internal wireless network that must use end to end TLS. Which of the following may be used to meet this objective?
WPA2wireless securityTLSnetwork configuration - Question #411Threats, vulnerabilities, and mitigations
After viewing wireless traffic, an attacker notices the following networks are being broadcasted by local access points: Corpnet Coffeeshop FreePublicWifi Using this information th...
evil twinpacket sniffingrogue access pointwireless attack - Question #412Threats, vulnerabilities, and mitigations
A server administrator notes that a legacy application often stops running due to a memory error. When reviewing the debugging logs, they notice code being run calling an internal...
buffer overflowmemory exploitcode executionapplication vulnerability - Question #413Security architecture
Key cards at a bank are not tied to individuals, but rather to organizational roles. After a break in, it becomes apparent that extra efforts must be taken to successfully pinpoint...
video surveillancephysical access controlaccountabilityphysical security - Question #414Security architecture
After running into the data center with a vehicle, attackers were able to enter through the hole in the building and steal several key servers in the ensuing chaos. Which of the fo...
bollardsvehicle barriersperimeter securityphysical security - Question #415General security concepts
Which of the following ciphers would be BEST used to encrypt streaming video?
RC4stream ciphersymmetric encryptionstreaming data encryption - Question #416Security operations
A CA is compromised and attacks start distributing maliciously signed software updates. Which of the following can be used to warn users about the malicious activity?
CRLcertificate revocationCA compromisePKI response - Question #417Security operations
After encrypting all laptop hard drives, an executive officer's laptop has trouble booting to the operating system. Now that it is successfully encrypted the helpdesk cannot retrie...
recovery agentdisk encryptionkey recoveryPKI - Question #418Security architecture
Which of the following devices is MOST likely being used when processing the following? 1 PERMIT IP ANY ANY EQ 80 2 DENY IP ANY ANY
firewallACLaccess control listpacket filtering - Question #419Security operations
The security administrator at ABC company received the following log information from an external party: 10:45:01 EST, SRC 10.4.3.7:3056, DST 8.4.2.1:80, ALERT, Directory traversal...
PATNATnetwork address translationlog analysis - Question #420General security concepts
A user attempting to log on to a workstation for the first time is prompted for the following information before being granted access: username, password, and a four-digit security...
single-factor authenticationauthentication factorspasswordPIN - Question #421Security operations
The security administrator is implementing a malware storage system to archive all malware seen by the company into a central database. The malware must be categorized and stored b...
fuzzy hashingmalware analysisthreat intelligencehash similarity - Question #422General security concepts
The security administrator installed a newly generated SSL certificate onto the company web server. Due to a mis-configuration of the website, a downloadable file containing one of...
PKIpublic keySSL/TLScertificate management - Question #423Threats, vulnerabilities, and mitigations
After analyzing and correlating activity from multiple sensors, the security administrator has determined that a group of very well organized individuals from an enemy country is r...
APTnation-state threatstargeted attacksthreat actors - Question #424Threats, vulnerabilities, and mitigations
Which of the following was launched against a company based on the following IDS log? 122.41.15.252 - - [21/May/2012:00:17:20 +1200] "GET /index.php?username=AAAAAAAAAAAAAAAAAAAAAA...
buffer overflowIDS logsattack recognitionweb application attacks - Question #425Security operations
The security administrator is analyzing a user's history file on a Unix server to determine if the user was attempting to break out of a rootjail. Which of the following lines in t...
rootjail escapedirectory traversalUnix securitylog analysis - Question #426Security operations
A software development company has hired a programmer to develop a plug-in module to an existing proprietary application. After completing the module, the developer needs to test t...
gray box testingapplication security testingsoftware developmentvulnerability assessment - Question #427General security concepts
A security administrator must implement all requirements in the following corporate policy: Passwords shall be protected against offline password brute force attacks. Passwords sha...
password policyaccount lockoutbrute force protectionpassword complexity - Question #428General security concepts
Which of the following is a best practice for error and exception handling?
error handlingsecure codinginformation disclosureexception management - Question #429Security architecture
A merchant acquirer has the need to store credit card numbers in a transactional database in a high performance environment. Which of the following BEST protects the credit card da...
database field encryptionPCI DSSdata at restcredit card protection - Question #430Security operations
A team of firewall administrators have access to a `master password list' containing service account passwords. Which of the following BEST protects the master password list?
file encryptionpassword managementsensitive data protectionaccess control - Question #431Security architecture
An SSL/TLS private key is installed on a corporate web proxy in order to inspect HTTPS requests. Which of the following describes how this private key should be stored so that it i...
HSMprivate key protectionkey managementSSL/TLS - Question #432Security operations
An insurance company requires an account recovery process so that information created by an employee can be accessed after that employee is no longer with the firm. Which of the fo...
account recoveryaccess managementpassword resetdata accessibility - Question #433Security operations
A small company has a website that provides online customer support. The company requires an account recovery process so that customers who forget their passwords can regain access...
password recoverytemporary passwordsweb authenticationaccount management - Question #434General security concepts
A bank has a fleet of aging payment terminals used by merchants for transactional processing. The terminals currently support single DES but require an upgrade in order to be compl...
3DESsymmetric encryptionDES migrationcryptographic upgrade - Question #435Security architecture
A new MPLS network link has been established between a company and its business partner. The link provides logical isolation in order to prevent access from other business partners...
IPSec VPNMPLSdata in transitnetwork confidentiality - Question #436General security concepts
Which of the following authentication services should be replaced with a more secure alternative?
TACACSAAA protocolsauthentication servicesRADIUS - Question #437Security architecture
A financial company requires a new private network link with a business partner to cater for real- time and batched data flows. Which of the following activities should be performe...
design reviewnetwork securitythird-party connectivitysecurity assessment - Question #438General security concepts
A customer has provided an email address and password to a website as part of the login process. Which of the following BEST describes the email address?
identificationAAAauthentication vs identificationaccess control - Question #439Security architecture
Which of the following is designed to ensure high availability of web based applications?
load balancinghigh availabilityweb application resilienceredundancy - Question #440Security program management and oversight
After a number of highly publicized and embarrassing customer data leaks as a result of social engineering attacks by phone, the Chief Information Officer (CIO) has decided user tr...
security awareness trainingsocial engineeringvishingdata leakage prevention - Question #441Security program management and oversight
Human Resources (HR) would like executives to undergo only two specific security training programs a year. Which of the following provides the BEST level of security training for t...
executive security trainingphishing awarenesssecurity programtraining prioritization - Question #442Security architecture
Which of the following provides data the best fault tolerance at the LOWEST cost?
RAIDfault toleranceavailabilitydata redundancy - Question #443Security architecture
The librarian wants to secure the public Internet kiosk PCs at the back of the library. Which of the following would be the MOST appropriate? (Select TWO).
physical securityendpoint securitykiosk hardeningcable locks - Question #444General security concepts
Which of the following functions provides an output which cannot be reversed and converts data into a string of characters?
hashingone-way functioncryptographydata integrity - Question #445General security concepts
Which of the following encrypts data a single bit at a time?
stream cipherencryptioncryptographybit-level encryption - Question #446General security concepts
A system administrator wants to enable WPA2 CCMP. Which of the following is the only encryption used?
WPA2CCMPAESwireless encryption - Question #447General security concepts
Which of the following is used to verify data integrity?
SHAhashingdata integritycryptography - Question #448Threats, vulnerabilities, and mitigations
Two programmers write a new secure application for the human resources department to store personal identifiable information. The programmers make the application available to them...
backdoormalware typesinsider threatapplication security - Question #449Security program management and oversight
Everyone in the accounting department has the ability to print and sign checks. Internal audit has asked that only one group of employees may print checks while only two other empl...
separation of dutiesaccess controlinternal controlsleast privilege - Question #450General security concepts
The security department has implemented a new laptop encryption product in the environment. The product requires one user name and password at the time of boot up and also another...
single factor authenticationmultifactor authenticationauthentication typesdisk encryption - Question #451Security operations
The Human Resources department has a parent shared folder setup on the server. There are two groups that have access, one called managers and one called staff. There are many sub f...
implicit denypermissions inheritanceaccess control listsfile system permissions - Question #452General security concepts
The finance department works with a bank which has recently had a number of cyber attacks. The finance department is concerned that the banking website certificates have been compr...
CRLcertificate revocationPKIdigital certificates