SY0-501 Exam Questions
551 real SY0-501 exam questions with expert-verified answers and explanations. Page 1 of 12.
- Question #1Introduction to Security
A high-security defense installation recently began utilizing large guard dogs that bark very loudly and excitedly at the slightest provocation. Which of the following types of con...
deterrent controlphysical securitysecurity controls - Question #2Endpoint Security
An incident responder receives a call from a user who reports a computer is exhibiting symptoms consistent with a malware infection. Which of the following steps should the respond...
incident responsemalwarefirst responsedocumentation - Question #3Endpoint Security
Multiple organizations operating in the same vertical want to provide seamless wireless access for their employees as they visit the other organizations. Which of the following sho...
RADIUS federation802.1xwireless authenticationidentity federation - Question #4Endpoint Security
An analyst wants to implement a more secure wifeless authentication for office access points. Which of the following technologies allows for encrypted authentication of wireless cl...
PEAPEAP-TLSwireless authenticationTLS - Question #5Security architecture
A security analyst is hardening an authentication server. One of the primary requirements is to ensure there is mutual authentication and delegation. Given these requirements, whic...
KerberosAuthentication protocolsMutual authenticationDelegation - Question #6Web Security
An organization wishes to provide better security for its name resolution services. Which of the following technologies BEST supports the deployment DNSSEC at the organization?
DNSSECDNS securityTLSname resolution - Question #7Endpoint Security
Ann, an employee in the payroll department, has contacted the help desk citing multiple issues with her device, including: Slow performance Word documents, PDFs, and images no long...
crypto-malwareransomwaremalware identificationemail threat - Question #8Data Loss Prevention
A department head at a university resigned on the first day of the spring semester. It was subsequently determined that the department head deleted numerous files and directories f...
offboardingaccount managementdata protectioninsider threat - Question #9Endpoint Security
A company is using a mobile device deployment model in which employees use their personal devices for work at their own discretion. Some of the problems the company is encountering...
COPEmobile device managementBYODMDM - Question #10Data Loss Prevention
A security administrator is developing controls for creating audit trails and tracking if a PHI data breach is to occur. The administrator has been given the following requirements...
PHIaudit loggingWORMaccess control - Question #11Introduction to Security
Which of the following can be provided to an AAA system for the identification phase?
AAAidentificationauthenticationaccess control - Question #12Messaging Security
Hotspot Question Select the appropriate attack from each drop down list to label the corresponding illustrated attack Instructions: Attacks may only be used once, and will disappea...
social engineeringphishingvishingpharming - Question #13Threats, vulnerabilities, and mitigations
Despite having implemented password policies, users continue to set the same weak passwords and reuse old passwords. Which of the following technical controls would help prevent th...
Password securityTechnical controlsAuthentication policies - Question #14Introduction to Security
A security analyst is reviewing the following output from an IPS: Given this output, which of the following can be concluded? (Select TWO).
IPSlog analysisintrusion detectionIGAP - Question #15Introduction to Security
An organization finds that most help desk calls ate regarding account lockout due to a variety of applications running on different systems. Manager is looking for a solution to re...
SSOaccount managementIAMauthentication - Question #16Introduction to Security
Which of the following threat actors is MOST likely to steal a company's proprietary information to gain a market edge and reduce time to market?
threat actorscorporate espionagecompetitorintellectual property - Question #17Endpoint Security
When trying to log onto a company's new ticketing system, some employees receive the following message: Access denied: too many concurrent sessions. The ticketing system was recent...
virtualizationconcurrent sessionsVM resourcessystem performance - Question #18Endpoint Security
A network administrator at a small office wants to simplify the configuration of mobile clients connecting to an encrypted wireless network. Which of the following should be implem...
WPSwireless configurationwireless security802.1x - Question #19Introduction to Security
A company is developing a new secure technology and requires computers being used for development to be isolated. Which of the following should be implemented to provide the MOST s...
air gapnetwork isolationphysical securitysecure environment - Question #20Introduction to Security
Which of the following explains why vendors publish MD5 values when they provide software patches for their customers to download over the Internet?
MD5integrityhashingsoftware verification - Question #21Security architecture
Drag and Drop Question A security administrator is given the security and availability profiles for servers that are being deployed. 1) Match each RAID type with the correct config...
RAIDData storageAvailabilityData integrity - Question #22Web Security
Refer to the following code: Which of the following vulnerabilities would occur if this is executed?
null pointermissing null checkcode vulnerabilitysecure coding - Question #23Security operations
A database backup schedule consists of weekly full backups performed on Saturday at 12:00 A.m. and daily differential backups also performed at 12:00 A.m. If the database is restor...
backup recoverydifferential backupfull backuprestore procedures - Question #24General security concepts
Which of the following technologies employ the use of SAML? (Select TWO).
SAMLSSOfederationidentity management - Question #25Security operations
An organization is using a tool to perform a source code review. Which of the following describes the case in which the tool incorrectly identifies the vulnerability?
false positivestatic analysisvulnerability scanningcode review - Question #26Security architecture
In a corporation where compute utilization spikes several times a year, the Chief Information Officer (CIO) has requested a cost-effective architecture to handle the variable capac...
ElasticityCloud architectureCapacity managementCost optimization - Question #27Security operations
A Security analyst is diagnosing an incident in which a system was compromised from an external IP address. The socket identified on the firewall was traced to 207.46.130.6666. Whi...
netstatincident responsenetwork forensicsactive connections - Question #28Security architecture
Which of the following BEST describes an important security advantage yielded by implementing vendor diversity?
vendor diversityresiliencysupply chainredundancy - Question #29CompTIA Security+ Domain 2: Architecture and Design - Summarize the importance of physical security controls and implementing security controls to meet organizational requirements
Drag and Drop Question You have been tasked with designing a security plan for your company. Drag and drop the appropriate security controls on the floor plan. Instructions: All ob...
Physical Security ControlsAccess ControlSecurity PlanningAsset Protection - Question #30General security concepts
Which of the following encryption methods does PKI typically use to securely protect keys?
PKIasymmetric encryptioncryptographykey management - Question #31Threats, vulnerabilities, and mitigations
Which of the following characteristics differentiate a rainbow table attack from a brute force attack? (Select TWO).
rainbow tablebrute forceprecomputed hashespassword hashing - Question #32Threats, vulnerabilities, and mitigations
Which of the following BEST describes a routine in which semicolons, dashes, quotes, and commas are removed from a string?
input validationSQL injectionsanitizationapplication security - Question #33Security operations
Which of the following is an important step to take BEFORE moving any installation packages from a test environment to production?
file integrityhash verificationchange managementsecure deployment - Question #34General security concepts
Which of the following cryptographic attacks would salting of passwords render ineffective?
password saltingdictionary attackcryptographic attackspassword security - Question #35Security architecture
A network administrator wants to implement a method of securing internal routing. Which of the following should the administrator implement?
VPNrouting securitynetwork designsecure communications - Question #36General security concepts
Which of the following types of keys is found in a key escrow?
key escrowprivate keycryptographykey management - Question #37Threats, vulnerabilities, and mitigations
A senior incident response manager receives a call about some external IPs communicating with internal computers during off hours. Which of the following types of malware is MOST l...
botnetC2 communicationmalwarenetwork traffic analysis - Question #38Security architecture
A company is currently using the following configuration: * IAS server with certificate-based EAP-PEAP and MSCHAP * Unencrypted authentication via PAP A security administrator need...
wireless authenticationPAPMSCHAPPEAP - Question #39General security concepts
A security administrator is trying to encrypt communication. For which of the following reasons should administrator take advantage of the Subject Alternative Name (SAM) attribute...
certificate SANPKImulti-domain certificatesHTTPS - Question #40Security operations
After a merger between two companies a security analyst has been asked to ensure that the organization's systems are secured against infiltration by any former employees that were...
access controlaccount managementoffboardingidentity management - Question #41Security program management and oversight
A new mobile application is being developed in-house. Security reviews did not pick up any major flaws, however vulnerability scanning results show fundamental issues at the very e...
SDLCcode reviewvulnerability detectionsecure development lifecycle - Question #42Security architecture
A security administrator is creating a subnet on one of the corporate firewall interfaces to use as a DMZ which is expected to accommodate at most 14 physical hosts. Which of the f...
subnettingDMZnetwork designCIDR notation - Question #43Security operations
A company has a security policy that specifies all endpoint computing devices should be assigned a unique identifier that can be tracked via an inventory management system. Recent...
MDMmobile device managementendpoint trackingasset management - Question #44Security operations
The security administrator receives an email on a non-company account from a coworker stating that some reports are not exporting correctly. Attached to the email was an example re...
DLPdata loss preventionemail securitysensitive data protection - Question #45Security operations
A technician is configuring a wireless guest network. After applying the most recent changes the technician finds the new devices can no longer find the wireless network by name bu...
Wireless securitySSID broadcastNetwork configurationGuest network - Question #46Security operations
A security administrator has been assigned to review the security posture of the standard corporate system image for virtual machines. The security administrator conducts a thoroug...
host hardeningVM securityaccount managementsystem hardening - Question #47Threats, vulnerabilities, and mitigations
Although a web enabled application appears to only allow letters in the comment field of a web form, malicious user was able to carry a SQL injection attack by sending special char...
SQL injectionserver-side validationinput validationweb application security - Question #48Threats, vulnerabilities, and mitigations
An attacker discovers a new vulnerability in an enterprise application. The attacker takes advantage of the vulnerability by developing new malware. After installing the malware th...
zero-day exploitmalwarevulnerability exploitationremote access - Question #49Security operations
A security administrator returning from a short vacation receives an account lock-out message when attempting to log into the computer. After getting the account unlocked the secur...
brute force attackcontinuous monitoringaccount lockoutintrusion detection - Question #50Security program management and oversight
A bank requires tellers to get manager approval when a customer wants to open a new account. A recent audit shows that there have been four cases in the previous year where tellers...
separation of dutiesaccess controladministrative controlsaccount creation