nerdexam
CompTIA

SY0-501 · Question #96

A security analyst is hardening a server with the directory services role installed. The analyst must ensure LDAP traffic cannot be monitored or sniffed and maintains compatibility with LDAP clients.

Sign in or unlock SY0-501 to reveal the answer and full explanation for question #96. The question stem and answer options stay visible for context.

Submitted by takeshi77· Mar 4, 2026Security architecture

Question

A security analyst is hardening a server with the directory services role installed. The analyst must ensure LDAP traffic cannot be monitored or sniffed and maintains compatibility with LDAP clients. Which of the following should the analyst implement to meet these requirements? (Select TWO).

Options

  • AGenerate an X 509-complaint certificate that is signed by a trusted CA.
  • BInstall and configure an SSH tunnel on the LDAP server.
  • CEnsure port 389 is open between the clients and the servers using the communication.
  • DEnsure port 636 is open between the clients and the servers using the communication.
  • ERemove the LDAP directory service role from the server.

Unlock SY0-501 to see the answer

You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#LDAPS#port 636#X.509 certificates#directory services hardening
Full SY0-501 Practice