SY0-501 Exam Questions
551 real SY0-501 exam questions with expert-verified answers and explanations. Page 11 of 12.
- Question #514Security operations
Which of the following locations contain the MOST volatile data?
data volatilitycache memorydigital forensicsmemory hierarchy - Question #515Threats, vulnerabilities, and mitigations
Ann, a customer, is reporting that several important files are missing from her workstation. She recently received communication from an unknown party who is requesting funds to re...
ransomwaremalwareextortionfile encryption - Question #516Security operations
Every morning, a systems administrator monitors failed login attempts on the company's log management server. The administrator notices the DBAdmin account has five failed username...
honeypotdeception technologyintrusion detectiondummy accounts - Question #517Security operations
Joe, a user, has been trying to send Ann, a different user, an encrypted document via email. Ann has not received the attachment but is able to receive the header information. Whic...
email securityauthenticationencrypted emailattachment delivery - Question #518Security architecture
A systems administrator is configuring a system that uses data classification labels. Which of the following will the administrator need to implement to enforce access control?
mandatory access controldata classificationaccess control modelssecurity labels - Question #519Threats, vulnerabilities, and mitigations
An analyst is using a vulnerability scanner to look for common security misconfigurations on devices. Which of the following might be identified by the scanner? (Select TWO).
vulnerability scanningsecurity misconfigurationdefault credentialsfirewall configuration - Question #520Security operations
A security analyst is reviewing patches on servers. One of the servers is reporting the following error message in the WSUS management console: The computer has not reported status...
WSUSpatch managementsoftware updatesWindows Update - Question #521General security concepts
Two users must encrypt and transmit large amount of data between them. Which of the following should they use to encrypt and transmit the data?
symmetric encryptioncryptographybulk data encryptionalgorithm selection - Question #522Threats, vulnerabilities, and mitigations
A security administrator is reviewing the following PowerShell script referenced in the Task Scheduler on a database server: $members = GetADGroupMemeber -Identity "Domain Admins"...
logic bombmalware analysisPowerShellscheduled tasks - Question #523Security architecture
A bank is experiencing a DoS attack against an application designed to handle 500IP-based sessions. in addition, the perimeter router can only handle 1Gbps of traffic. Which of the...
DoS mitigationredundancyhigh availabilitynetwork resilience - Question #524Threats, vulnerabilities, and mitigations
A malicious system continuously sends an extremely large number of SYN packets to a server. Which of the following BEST describes the resulting effect?
SYN floodDoS attackTCP handshakehalf-open connections - Question #525Security architecture
A systems administrator is deploying a new mission essential server into a virtual environment. Which of the following is BEST mitigated by the environment's rapid elasticity chara...
cloud computingrapid elasticityvirtualizationDoS mitigation - Question #526General security concepts
Which of the following is the proper order for logging a user into a system from the first step to the last step?
identificationauthenticationauthorizationaccess control - Question #527Threats, vulnerabilities, and mitigations
A company stores highly sensitive data files used by the accounting system on a server file share. The accounting system uses a service account named accounting-svc to access the f...
full disk encryptionlocal console accessdata protectionaccess controls - Question #528Security architecture
A bank uses a wireless network to transmit credit card purchases to a billing system. Which of the following would be MOST appropriate to protect credit card information from being...
Faraday cagewireless securityphysical securityEMI shielding - Question #529Security program management and oversight
Joe, a salesman, was assigned to a new project that requires him to travel to a client site. While waiting for a flight, Joe decides to connect to the airport wireless network with...
acceptable use policyVPNwireless securitypolicy violation - Question #530Threats, vulnerabilities, and mitigations
A help desk technician receives a phone call from an individual claiming to be an employee of the organization and requesting assistance to access a locked account. The help desk t...
social engineeringimpersonationvishingidentity verification - Question #531General security concepts
Confidential emails from an organization were posted to a website without the organization's knowledge. Upon investigation, it was determined that the emails were obtained from an...
S/MIMESMTPSemail securityencryption protocols - Question #532Security architecture
A company wants to implement an access management solution that allows employees to use the same usernames and passwords for multiple applications without having to keep multiple c...
SSOfederationidentity managementaccess management - Question #533Security program management and oversight
An external auditor visits the human resources department and performs a physical security assessment. The auditor observed documents on printers that are unclaimed. A closer look...
PIIprivacy policydata handlingclean desk policy - Question #534General security concepts
Which of the following authentication concepts is a gait analysis MOST closely associated?
biometricsbehavioral authenticationgait analysissomething you do - Question #535Security program management and oversight
Which of the following metrics are used to calculate the SLE? (Select TWO)
SLEALEAROrisk quantification - Question #536Security operations
Due to regulatory requirements, server in a global organization must use time synchronization. Which of the following represents the MOST secure method of time synchronization?
NTPtime synchronizationStratumnetwork security - Question #537General security concepts
When sending messages using symmetric encryption, which of the following must happen FIRST?
symmetric encryptionkey exchangeencryption methodscryptography - Question #538General security concepts
Which of the following scenarios BEST describes an implementation of non-repudiation?
non-repudiationdigital signaturesemail securitycryptography - Question #539Security program management and oversight
An office manager found a folder that included documents with various types of data relating to corporate clients. The office manager notified the data included dates of birth, add...
PIIdata classificationprivacycompliance - Question #540General security concepts
Which of the following is an asymmetric function that generates a new and separate key every time it runs?
Diffie-Hellman ephemeralasymmetric cryptographykey exchangeforward secrecy - Question #541General security concepts
Which of the following would be considered multifactor authentication?
multifactor authenticationauthentication factorsbiometricssomething you know - Question #542Security operations
Users report the following message appear when browsing to the company's secure site: This website Which of the following actions should a security analyst take to resolve these ca...
digital certificatesPKIcertificate trustroot certificate - Question #543Threats, vulnerabilities, and mitigations
A user receives an email from ISP indicating malicious traffic coming from the user's home network is detected. The traffic appears to be Linux-based, and it is targeting a website...
botnetIoT securityDDoSmalware - Question #544Threats, vulnerabilities, and mitigations
A security auditor is testing perimeter security in a building that is protected by badge readers. Which of the following types of attacks would MOST likely gain access?
tailgatingphysical securitysocial engineeringperimeter access - Question #546Security program management and oversight
A department head at a university resigned on the first day of spring semester. It was subsequently determined that the department head deleted numerous files and directories from...
offboardinginsider threataccess revocationdata destruction - Question #547Security operations
An organization wants to upgrade its enterprise-wide desktop computer solution. The organization currently has 500 PCs active on the network. the Chief Information Security Officer...
desktop imagingbaseline configurationconfiguration managementsecure deployment - Question #549Security architecture
An organization has implemented an IPSec VPN access for remote users. Which of the following IPSec modes would be the MOST secure for this organization to implement?
IPSecVPNtunnel modetransport mode - Question #550Security architecture
A security engineer is configuring a wireless network with EAP-TLS. Which of the following activities is a requirement for this configuration?
EAP-TLS802.1xPKI certificateswireless authentication - Question #551Threats, vulnerabilities, and mitigations
Several workstations on a network are found to be on OS versions that are vulnerable to a specific attack. Which of the following is considered to be a corrective action to combat...
patch managementvulnerability remediationcorrective controlsOS patching - Question #552Security operations
An external contractor, who has not been given information about the software or network architecture, is conducting a penetration test. Which of the following BEST describes the t...
black box testingpenetration testingzero knowledgeexternal assessment - Question #553Security operations
A security analyst has set up a network tap to monitor network traffic for vulnerabilities. Which of the following techniques would BEST describe the approach the analyst has taken...
passive vulnerability scanningnetwork taptraffic analysisvulnerability assessment - Question #554Security architecture
Due to regulatory requirements, a security analyst must implement full drive encryption on a Windows file server. Which of the following should the analyst implement on the system...
BitLockerTPMfull disk encryptionregulatory compliance - Question #555Security architecture
A company's loss control department identifies theft as a recurring loss type over the past year. Based on the department's report, the Chief Information Officer (CIO) wants to det...
motion detectionphysical securitydatacenter controlstheft prevention - Question #556Security operations
Which of the following penetration testing concepts is being used when an attacker uses public Internet databases to enumerate and learn more about a target?
OSINTpassive reconnaissanceopen source intelligencepenetration testing - Question #557Security operations
While performing a penetration test, the technicians want their efforts to go unnoticed for as long as possible while they gather useful data about the network they are assessing....
packet sniffingpassive reconnaissancestealth testingtraffic capture - Question #558Security operations
A security analyst captures forensic evidence from a potentially compromised system for further investigation. The evidence is documented and securely stored to FIRST:
digital forensicsevidence preservationchain of custodyincident response - Question #559Threats, vulnerabilities, and mitigations
A security analyst is investigating a security breach. Upon inspection of the audit an access logs, the analyst notices the host was accessed and the /etc/passwd file was modified...
backdoorprivilege escalationforensic analysisnetstat - Question #560Security architecture
A systems administrator wants to provide balance between the security of a wireless network and usability. The administrator is concerned with wireless encryption compatibility of...
WPAwireless securitypreshared keybackward compatibility - Question #561Security program management and oversight
A company recently replaced its unsecure email server with a cloud-based email and collaboration solution that is managed and insured by a third party. Which of the following actio...
risk transferencecloud servicesthird-party riskrisk management - Question #562Threats, vulnerabilities, and mitigations
A security administrator is reviewing the following network capture: Which of the following malware is MOST likely to generate the above information?
keyloggermalware analysisnetwork capturetraffic analysis - Question #563Network Security / Infrastructure Security - Configuring and troubleshooting Access Control Lists (ACLs) to control traffic based on source/destination IP addresses and port numbers (CompTIA Network+ or CCNA Security domain)
A network administrator adds an ACL to allow only HTTPS connections form host 192.168.2.3 to web server 192.168.5.2. After applying the rule, the host is unable to access the serve...
ACL ConfigurationNetwork SecurityPort NumbersAccess Control Lists - Question #564Security architecture
A datacenter recently experienced a breach. When access was gained, an RF device was used to access an air-gapped and locked server rack. Which of the following would BEST prevent...
Faraday cageRF shieldingair gap securityphysical security - Question #565General security concepts
A security analyst is working on a project that requires the implementation of a stream cipher. Which of the following should the analyst use?
stream ciphersymmetric encryptioncryptographycipher types