SY0-501 Exam Questions
551 real SY0-501 exam questions with expert-verified answers and explanations. Page 10 of 12.
- Question #462Security operations
A company wants to ensure confidential data from storage media is sanitized in such a way that the drive cannot be reused. Which of the following method should the technician use?
media sanitizationdata destructionphysical destructiondrive disposal - Question #463Security operations
A forensic expert is given a hard drive from a crime scene and is asked to perform an investigation. Which of the following is the FIRST step the forensic expert needs to take the...
digital forensicschain of custodyevidence handlingincident documentation - Question #464Security operations
An incident response manager has started to gather all the facts related to a SIEM alert showing multiple systems may have been compromised. The manager has gathered these facts: T...
incident responseIRP phasesidentificationSIEM - Question #465Security architecture
A stock trading company had the budget for enhancing its secondary datacenter approved. Since the main site is a hurricane-affected area and the disaster recovery site is 100 mi (1...
disaster recoverybusiness continuitycloud DRsite availability - Question #466Security operations
A systems administrator is attempting to recover from a catastrophic failure in the datacenter. To recover the domain controller, the systems administrator needs to provide the dom...
account typesprivileged accountsdomain administratoraccess control - Question #467Security architecture
User from two organizations, each with its own PKI, need to begin working together on a joint project. Which of the following would allow the users of the separate PKIs to work tog...
PKItrust modelcross-certificationcertificate interoperability - Question #468Threats, vulnerabilities, and mitigations
A security analyst is migrating a pass-the-hash vulnerability on a Windows infrastructure. Given the requirement, which of the following should the security analyst do to MINIMIZE...
pass-the-hashNTLM authenticationcredential attacksWindows authentication - Question #470Security operations
A security analyst is reviewing an assessment report that includes software versions, running services, supported encryption algorithms, and permission settings. Which of the follo...
vulnerability scanningsecurity assessment toolsenumeration - Question #471Security program management and oversight
A Chief Information Officer (CIO) asks the company's security specialist if the company should spend any funds on malware protection for a specific server. Based on a risk assessme...
quantitative risk analysisALESLEARO - Question #472Security operations
The computer resource center issue smartphones to all first-level and above managers. The managers have the ability to install mobile tools. Which of the following tools should be...
mobile device managementapplication managementMAMMDM - Question #473Security operations
A systems administrator wants to provide for and enforce wireless access accountability during events where external speakers are invited to make presentations to a mixed audience...
guest accesswireless access controlidentity managementsponsored accounts - Question #474
A recent internal audit is forcing a company to review each internal business unit's VMs because the cluster they are installed on is in danger of running out of computer resources...
- Question #475Threats, vulnerabilities, and mitigations
A security analyst is attempting to identify vulnerabilities in a customer's web application without impacting the system or its data. Which of the following BEST describes the vul...
vulnerability scanningpassive scanningnon-intrusive assessment - Question #476General security concepts
Two users must encrypt and transmit large amounts of data between them. Which of the following should they use to encrypt and transmit the data?
symmetric encryptioncryptographybulk data encryptionalgorithm selection - Question #477Security program management and oversight
A new Chief Information Officer (CIO) has been reviewing the badging and decides to write a policy that all employees must have their badges rekeyed at least annually. Which of the...
administrative controlssecurity policyphysical access managementcontrol types - Question #478Threats, vulnerabilities, and mitigations
A software developer is concerned about DLL hijacking in an application being written. Which of the following is the MOST viable mitigation measure of this type of attack?
DLL hijackingapplication securitysecure codingWindows security - Question #479Security architecture
A security engineer wants to implement a site-to-site VPN that will require SSL certificates for mutual authentication. Which of the following should the engineer implement if the...
VPN protocolsSSL VPNnetwork tunnelingMAC address visibility - Question #480Threats, vulnerabilities, and mitigations
An application was recently compromised after some malformed data came in via web form. Which of the following would MOST likely have prevented this?
input validationweb application securityinjection preventionsecure coding - Question #481Security operations
While working on an incident, Joe, a technician, finished restoring the OS and applications on a workstation from the original media. Joe is about to begin copying the user's files...
incident responserecovery phasesystem restorationIRP phases - Question #482Threats, vulnerabilities, and mitigations
A systems administrator found a suspicious file in the root of the file system. The file contains URLs, usernames, passwords, and text from other documents being edited on the syst...
keyloggermalware classificationcredential theftdata exfiltration - Question #483Security operations
A computer emergency response team is called at midnight to investigate a case in which a mail server was restarted. After an initial investigation, it was discovered that email is...
incident responseemail exfiltrationforensic analysiscontainment - Question #484Threats, vulnerabilities, and mitigations
A remote intruder wants to take inventory of a network so exploits can be researched. The intruder is looking for information about software versions on the network. Which of the f...
banner grabbingreconnaissanceenumerationnetwork scanning - Question #485Threats, vulnerabilities, and mitigations
An analyst is reviewing a simple program for potential security vulnerabilities before being deployed to a Windows server. Given the following code: void foo (char *bar) { car rand...
buffer overflowcode reviewmemory corruptionapplication security - Question #486Security program management and oversight
A company has a data classification system with definitions for "Private" and "Public". the company's security policy outlines how data should be protected based on type. The compa...
data classificationsecurity policydata governanceproprietary data - Question #487Security operations
A security technician is configuring an access management system to track and record user actions. Which of the following functions should the technician configure?
AAAaccountingaudit loggingaccess management - Question #488Security operations
A security administrator installed a new network scanner that identifies new host systems on the network. Which of the following did the security administrator install?
rogue system detectionnetwork scanningasset discoveryhost inventory - Question #489Security program management and oversight
A Chief Information Officer (CIO) has decided it is not cost effective to implement safeguards against a known vulnerability. Which of the following risk responses does this BEST d...
risk acceptancerisk managementrisk responsecost-benefit analysis - Question #490Security architecture
A manager wants to distribute a report to several other managers within the company. Some of them reside in remote locations that are not connected to the domain but have a local s...
secure file transferSSHFTPSHTTPS - Question #491Threats, vulnerabilities, and mitigations
A technician is investigating a potentially compromised device with the following symptoms: Browser slowness Frequent browser crashes Hourglass stuck New search toolbar Increased m...
man-in-the-browsermalware identificationbrowser hijackingtrojan - Question #492General security concepts
A penetration tester has written an application that performs a bit-by-bit XOR 0xFF operation on binaries prior to transmission over untrusted media. Which of the following BEST de...
obfuscationXOR ciphercryptographydata encoding - Question #493Security architecture
An audit reported has identifies a weakness that could allow unauthorized personnel access to the facility at its main entrance and from there gain access to the network. Which of...
mantrapphysical securityaccess controltailgating prevention - Question #494General security concepts
When attempting to secure a mobile workstation, which of the following authentication technologies rely on the user's physical characteristics? (Select TWO)
biometricsauthentication factorsretina scanfingerprint - Question #495Security operations
Systems administrator and key support staff come together to simulate a hypothetical interruption of service. The team updates the disaster recovery processes and documentation aft...
tabletop exercisedisaster recoverybusiness continuityincident response - Question #496Security architecture
A company has two wireless networks utilizing captive portals. Some employees report getting a trust error in their browsers when connecting to one of the networks. Both captive po...
certificate chainingPKISSL/TLStrust chain - Question #497Security architecture
Company A has acquired Company
federationidentity managementcross-domain authenticationSSO - Question #498Security architecture
A technician is configuring a load balancer for the application team to accelerate the network performance of their applications. The applications are hosted on multiple servers an...
load balancinghigh availabilitylocality-basedredundancy - Question #499Security program management and oversight
Ann is the IS manager for several new systems in which the classifications of the systems' data are being decided. She is trying to determine the sensitivity level of the data bein...
data ownerdata classificationdata governanceroles and responsibilities - Question #500Security architecture
An organization's employees currently use three different sets of credentials to access multiple internal resources. Management wants to make this process less complex. Which of th...
single sign-onidentity managementauthenticationaccess management - Question #501Threats, vulnerabilities, and mitigations
An external attacker can modify the ARP cache of an internal computer. Which of the following types of attacks is described?
ARP spoofingARP poisoningnetwork attacksman-in-the-middle - Question #502Security operations
A systems administrator has isolated an infected system from the network and terminated the malicious process from executing. Which of the following should the administrator do NEX...
incident responserecovery phaseeradicationmalware remediation - Question #503Security operations
A new security administrator ran a vulnerability scanner for the first time and caused a system outage. Which of the following types of scans MOST likely caused the outage?
vulnerability scanningintrusive scannon-credentialed scansystem outage - Question #504Security architecture
A security analyst is hardening a WiFi infrastructure. The primary requirements are the following: The infrastructure must allow staff to authenticate using the most secure method....
WPA2 Enterprisecaptive portalwireless securityauthentication protocols - Question #505Threats, vulnerabilities, and mitigations
A security administrator is trying to eradicate a worm, which is spreading throughout the organization, using an old remote vulnerability in the SMB protocol. The worm uses Nmap to...
wormSMB vulnerabilityNIPSzero-day exploits - Question #506Security architecture
Which of the following is a deployment concept that can be used to ensure only the required OS access is exposed to software applications?
sandboxingapplication isolationOS access controldeployment concepts - Question #507Security program management and oversight
A procedure differs from a policy in that it:
policyproceduregovernancedocumentation - Question #508Security operations
Ann, a user, reports she is unable to access an application from her desktop. A security analyst verifies Ann's access and checks the SIEM for any errors. The security analyst revi...
log analysishost-based firewallSIEMnetwork traffic - Question #509Security operations
Which of the following types of penetration test will allow the tester to have access only to password hashes prior to the penetration test?
gray box testingpenetration testingpassword hashesreconnaissance - Question #510Threats, vulnerabilities, and mitigations
Which of the following threats has sufficient knowledge to cause the MOST danger to an organization?
insider threatthreat actorsprivileged accessorganizational risk - Question #511General security concepts
While troubleshooting a client application connecting to the network, the security administrator notices the following error: Certificate is not valid. Which of the following is th...
CRLPKIcertificate validationdigital certificates - Question #513Security program management and oversight
A business sector is highly competitive, and safeguarding trade secrets and critical information is paramount. On a seasonal basis, an organization employs temporary hires and cont...
account expirationtemporary accountscontractor accessidentity lifecycle