SY0-501 Exam Questions
551 real SY0-501 exam questions with expert-verified answers and explanations. Page 4 of 12.
- Question #151Threats, vulnerabilities, and mitigations
A user clicked an email link that led to a website that infected the workstation with a virus. The virus encrypted all the network shares to which the user had access. The virus wa...
zero-day attackransomwareover-privilegesecurity controls bypass - Question #152General security concepts
Which of the fallowing security controls does an iris scanner provide?
biometricsiris scannerphysical controlssecurity control types - Question #153Security operations
An auditor wants to test the security posture of an organization by running a tool that will display the following: Which of the following commands should be used?
nbtstatNetBIOSnetwork enumerationreconnaissance - Question #154Threats, vulnerabilities, and mitigations
Which of the following attacks specifically impacts data availability?
DDoSavailabilityCIA triaddenial of service - Question #155CompTIA Security+ Domain 1: Threats, Attacks and Vulnerabilities - specifically identifying types of social engineering attacks and distinguishing them from other attack categories
Drag and Drop Question Task: Determine the types of attacks below by selecting an option from the dropdown list. Answer:
Social EngineeringPhishing AttacksThreat VectorsSecurity Awareness - Question #156General security concepts
When connected to a secure WAP, which of the following encryption technologies is MOST likely to be configured when connecting to WPA2-PSK?
WPA2-PSKAESwireless encryptionsymmetric encryption - Question #157CompTIA Security+ Domain 2: Architecture and Design / Identity and Access Management - specifically authentication methods, multi-factor authentication implementation, and wireless security protocols (maps to SY0-701 objective 2.4: Summarize authentication and authorization design concepts, and 3.1: Compare and contrast security implications of different architecture models including physical security controls and WAP security configurations).
Lab Simulation You have just received some room and WiFi access control recommendations from a security consulting company. Click on each building to bring up available security co...
Multi-Factor AuthenticationAuthentication Factor CategoriesWireless Security (WPA)Physical Access Controls - Question #158Security operations
Which of the following network vulnerability scan indicators BEST validates a successful, active scan?
vulnerability scanningactive scanattack vectorsscan validation - Question #159Threats, vulnerabilities, and mitigations
Which of the following allows an auditor to test proprietary-software compiled code for security flaws?
fuzzingcompiled codecode security testingdynamic analysis - Question #160Security operations
An application team is performing a load-balancing test for a critical application during off- hours and has requested access to the load balancer to review. Which servers are up w...
least privilegeaccess controlload balancerseparation of duties - Question #161CompTIA Security+ Domain 3: Implementation - Implementing secure network architecture concepts including firewall rules, port/protocol management, and least-privilege network access control.
Lab Sim - Configure the Firewall Task: Configure the firewall (fill out the table) to allow these four rules: - Only allow the Accounting computer to have HTTPS access to the Admin...
Firewall ConfigurationNetwork SecurityAccess ControlPort and Protocol Mapping - Question #163General security concepts
Hotspot Question For each of the given items, select the appropriate authentication category from the dropdown choices. Instructions: When you have completed the simulation, please...
authentication factorssomething you aresomething you havesomething you know - Question #164Security operations
During a data breach cleanup it is discovered that not all of the sites involved have the necessary data wiping tools. The necessary tools are quickly distributed to the required t...
incident responselessons learneddata breachIR lifecycle - Question #165General security concepts
Hotspot Question For each of the given items, select the appropriate authentication category from the drop down choices. Select the appropriate authentication type for the followin...
biometric authenticationOTPmulti-factor authenticationPAP - Question #166Security operations
Simulation A security administrator discovers that an attack has been completed against a node on the corporate network. All available logs were collected and stored. You must revi...
Incident ResponseLog AnalysisDigital ForensicsEvidence Collection - Question #167Security architecture
Joe, a technician, is working remotely with his company provided laptop at the coffee shop near his home. Joe is concerned that another patron of the coffee shop may be trying to a...
host-based firewallendpoint securityremote workwireless security - Question #168Threats, vulnerabilities, and mitigations
An attacker uses a network sniffer to capture the packets of a transaction that adds $20 to a gift card. The attacker then user a function of the sniffer to push those packets back...
replay attackpacket sniffingnetwork attacksession hijacking - Question #169Security architecture
An organization is moving its human resources system to a cloud services provider. The company plans to continue using internal usernames and passwords with the service provider, b...
federated authenticationSSOcloud identitypassword management - Question #170Security operations
The data backup window has expanded into the morning hours and has begun to affect production users. The main bottleneck in the process is the time it takes to replicate the backup...
data deduplicationbackup optimizationstorage arraydata replication - Question #171Security operations
A penetration testing is preparing for a client engagement in which the tester must provide data that proves and validates the scanning tools' results. Which of the following is th...
penetration testingprotocol analyzerevidence collectionnetwork forensics - Question #172Security operations
Which of the following best describes the initial processing phase used in mobile device forensics?
mobile forensicsdigital forensicsevidence preservationforensic investigation - Question #173Security operations
Ann a security analyst is monitoring the IDS console and noticed multiple connections from an internal host to a suspicious call back domain. Which of the following tools would aid...
packet analyzerIDS monitoringnetwork trafficcallback domain - Question #174General security concepts
An administrator is testing the collision resistance of different hashing algorithms. Which of the following is the strongest collision resistance test?
hash collisioncollision resistancecryptographic hashinghash functions - Question #175Security architecture
The SSID broadcast for a wireless router has been disabled but a network administrator notices that unauthorized users are accessing the wireless network. The administor has determ...
wireless securitySSID broadcastprobe requestnetwork obscurity - Question #176General security concepts
Which of the following should be used to implement voice encryption?
SRTPvoice encryptionVoIP securityprotocol security - Question #177General security concepts
During an application design, the development team specifics a LDAP module for single sign-on communication with the company's access control database. This is an example of which...
LDAPSSOauthenticationdirectory services - Question #178Security program management and oversight
After a merger, it was determined that several individuals could perform the tasks of a network administrator in the merged organization. Which of the following should have been pe...
user rights reviewaccess managementmergerpermission review - Question #179Security program management and oversight
A company exchanges information with a business partner. An annual audit of the business partner is conducted against the SLA in order to verify:
SLA auditvendor managementthird-party assessmentservice metrics - Question #180Security program management and oversight
Which of the following is the proper way to quantify the total monetary damage resulting from an exploited vulnerability?
ALErisk quantificationrisk managementvulnerability assessment - Question #181Security operations
A security administrator needs to implement a system that detects possible intrusions based upon a vendor provided list. Which of the following BEST describes this type of IDS?
signature-based IDSintrusion detectionvendor signatures - Question #182Security program management and oversight
The chief Security Officer (CSO) has reported a rise in data loss but no break ins have occurred. By doing which of the following is the CSO most likely to reduce the number of inc...
security awareness trainingdata loss preventioninsider threathuman factor - Question #183Threats, vulnerabilities, and mitigations
Ann, a user, states that her machine has been behaving erratically over the past week. She has experienced slowness and input lag and found text files that appear to contain pieces...
keyloggermalware identificationendpoint securitydata exfiltration - Question #184Threats, vulnerabilities, and mitigations
An information security specialist is reviewing the following output from a Linux server. Based on the above information, which of the following types of malware was installed on t...
logic bombmalware analysisLinux securitycode execution - Question #185General security concepts
In terms of encrypting data, which of the following is BEST described as a way to safeguard password data by adding random data to it in storage?
password saltingcryptographypassword storagehashing - Question #186Security operations
A system administrator wants to provide for and enforce wireless access accountability during events where external speakers are invited to make presentations to a mixed audience o...
sponsored guest accesswireless accountabilityidentity managementaccess control - Question #187Security operations
Which of the following would MOST likely appear in an uncredentialed vulnerability scan?
vulnerability scanninguncredentialed scanself-signed certificatesnetwork assessment - Question #188Threats, vulnerabilities, and mitigations
A security analyst observes the following events in the logs of an employee workstation: Given the information provided, which of the following MOST likely occurred on the workstat...
Application whitelistingExploit preventionEndpoint security - Question #189Security program management and oversight
When identifying a company's most valuable assets as part of a BIA, which of the following should be the FIRST priority?
BIAbusiness impact analysisasset prioritizationlife safety - Question #190Security architecture
An organization needs to implement a large PKI. Network engineers are concerned that repeated transmission of the OCSP will impact network performance. Which of the following shoul...
PKIOCSPCRLcertificate management - Question #191Security program management and oversight
When considering a third-party cloud service provider, which of the following criteria would be the BEST to include in the security assessment process? (Select two.)
cloud securityvendor assessmentregulatory compliancedata retention - Question #192Threats, vulnerabilities, and mitigations
Which of the following occurs when the security of a web application relies on JavaScript for input validation?
input validationclient-side validationweb application securitydata integrity - Question #193Threats, vulnerabilities, and mitigations
An analyst is reviewing a simple program for potential security vulnerabilities before being deployed to a Windows server. Given the following code: Which of the following vulnerab...
buffer overflowsecure codingapplication vulnerabilitymemory management - Question #194Security operations
An organization's file server has been virtualized to reduce costs. Which of the following types of backups would be MOST appropriate for the particular file server?
backup strategiesvirtualizationincremental backupbusiness continuity - Question #195Security architecture
A wireless network uses a RADIUS server that is connected to an authenticator, which in turn connects to a supplicant. Which of the following represents the authentication architec...
802.1xRADIUSwireless authenticationnetwork access control - Question #196General security concepts
An employer requires that employees use a key-generating app on their smartphones to log into corporate applications. In terms of authentication of an individual, this type of acce...
authentication factorsMFAsomething you haveTOTP - Question #197General security concepts
Adhering to a layered security approach, a controlled access facility employs security guards who verify the authorization of all personnel entering the facility. Which of the foll...
security controlsadministrative controlsphysical securityaccess control - Question #198Security architecture
A security analyst is hardening a web server, which should allow a secure certificate-based session using the organization's PKI infrastructure. The web server should also utilize...
PKITLSX.509web server hardening - Question #199Security architecture
A manager wants to distribute a report to several other managers within the company. Some of them reside in remote locations that are not connected to the domain but have a local s...
secure file transferSSHFTPSHTTPS - Question #200Threats, vulnerabilities, and mitigations
An auditor is reviewing the following output from a password-cracking tool: User:1: Password1 User2: Recovery! User3: Alaskan10 User4: 4Private User5: PerForMance2 Which of the fol...
hybrid attackpassword crackingdictionary attackauthentication - Question #201Security operations
Which of the following must be intact for evidence to be admissible in court?
chain of custodydigital forensicsevidence handlingadmissibility