SY0-501 Exam Questions
551 real SY0-501 exam questions with expert-verified answers and explanations. Page 7 of 12.
- Question #302Security operations
A network technician is trying to determine the source of an ongoing network based attack. Which of the following should the technician use to view IPv4 packet data on a particular...
protocol analyzerpacket capturenetwork monitoringnetwork forensics - Question #303Security architecture
The security administrator has noticed cars parking just outside of the building fence line. Which of the following security measures can the administrator use to help protect the...
war drivingwireless securityantenna placementRF power control - Question #304Security operations
A security administrator suspects that data on a server has been exhilarated as a result of un- authorized remote access. Which of the following would assist the administrator in c...
DLPlog analysisdata exfiltrationincident investigation - Question #305Security architecture
A company is deploying a new VoIP phone system. They require 99.999% uptime for their phone service and are concerned about their existing data network interfering with the VoIP ph...
VLAN segmentationVoIP securitynetwork performancenetwork isolation - Question #306Security architecture
A server administrator needs to administer a server remotely using RDP, but the specified port is closed on the outbound firewall on the network. The access the server using RDP on...
RDPTLS tunnelingfirewall traversalport configuration - Question #307Security architecture
Which of the following can be used to control specific commands that can be executed on a network infrastructure device?
TACACS+command authorizationAAAnetwork device access - Question #308Security architecture
Company XYZ has decided to make use of a cloud-based service that requires mutual, certificate- based authentication with its users. The company uses SSL-inspecting IDS at its netw...
AD federationmutual authenticationSSL inspectioncertificate-based auth - Question #309Security program management and oversight
Six months into development, the core team assigned to implement a new internal piece of software must convene to discuss a new requirement with the stake holders. A stakeholder id...
SDLCrequirements analysissecure software developmentstakeholder review - Question #310Security operations
A company is investigating a data compromise where data exfiltration occurred. Prior to the investigation, the supervisor terminates an employee as a result of the suspected data l...
log managementincident investigationaudit loggingdata exfiltration - Question #311Security architecture
A security administrator needs an external vendor to correct an urgent issue with an organization's physical access control system (PACS). The PACS does not currently have internet...
VPNthird-party vendor accessremote accessphysical access control - Question #312Security operations
A datacenter manager has been asked to prioritize critical system recovery priorities. Which of the following is the MOST critical for immediate recovery?
Disaster RecoveryRecovery PrioritizationSystem DependenciesOperating Systems - Question #313Threats, vulnerabilities, and mitigations
Which of the following techniques can be bypass a user or computer's web browser privacy settings? (Select Two)
session hijackingcross-site scriptingbrowser securityweb attacks - Question #314Security architecture
When designing a web based client server application with single application server and database cluster backend, input validation should be performed:
input validationweb application securityapplication serversecure design - Question #315Security operations
Which of the following delineates why it is important to perform egress filtering and monitoring on Internet connected security zones of interfaces on a firewall?
egress filteringbotnet detectionnetwork monitoringfirewall policy - Question #316General security concepts
The help desk is receiving numerous password change alerts from users in the accounting department. These alerts occur multiple times on the same day for each of the affected users...
password policypassword minimum ageaccount managementIAM - Question #317Security architecture
Which of the following would enhance the security of accessing data stored in the cloud? (Select TWO)
cloud securitySAMLmultifactor authenticationaccess control - Question #318Security operations
A remote user (User1) is unable to reach a newly provisioned corporate windows workstation. The system administrator has been given the following log files from the VPN, corporate...
host firewallremote desktoplog analysisVPN troubleshooting - Question #320Security program management and oversight
During a third-party audit, it is determined that a member of the firewall team can request, approve, and implement a new rule-set on the firewall. Which of the following will the...
separation of dutiesfirewall managementchange controlaudit findings - Question #321Security architecture
Which of the following is the appropriate network structure used to protect servers and services that must be provided to external clients without completely eliminating access for...
DMZnetwork segmentationperimeter securityserver placement - Question #322Security operations
An administrator has configured a new Linux server with the FTP service. Upon verifying that the service was configured correctly, the administrator has several users test the FTP...
ACLFTP permissionsLinux file accessservice hardening - Question #323Security operations
An administrator thinks the UNIX systems may be compromised, but a review of system log files provides no useful information. After discussing the situation with the security team,...
remote sysloglog integrityintrusion detectionlog management - Question #324Threats, vulnerabilities, and mitigations
A global gaming console manufacturer is launching a new gaming platform to its customers. Which of the following controls reduces the risk created by malicious gaming customers att...
firmware securityautomatic updatesendpoint hardeningpatch management - Question #325Security program management and oversight
An audit has revealed that database administrators are also responsible for auditing database changes and backup logs. Which of the following access control methodologies would BES...
separation of dutiesdatabase securityaudit controlsaccess control - Question #326Threats, vulnerabilities, and mitigations
Ann, a security administrator, has been instructed to perform fuzz-based testing on the company's applications. Which of the following best describes what she will do?
fuzzingvulnerability testingapplication securityinput validation - Question #327General security concepts
An organization requires users to provide their fingerprints to access an application. To improve security, the application developers intend to implement multifactor authenticatio...
multifactor authenticationbiometricsauthentication factorssomething you are - Question #328Security architecture
A network technician is setting up a segmented network that will utilize a separate ISP to provide wireless access to the public area for a company. Which of the following wireless...
captive portalwireless securitynetwork segmentationpublic network access - Question #329Security operations
After a routine audit, a company discovers that engineering documents have been leaving the network on a particular port. The company must allow outbound traffic on this port, as i...
data loss preventiondata exfiltrationnetwork controlsDLP - Question #330Threats, vulnerabilities, and mitigations
A security analyst has received the following alert snippet from the HIDS appliance: Given the above logs, which of the following is the cause of the attack?
TCP flagspacket analysisHIDSnetwork attack detection - Question #331General security concepts
A security analyst reviews the following output: The analyst loads the hash into the SIEM to discover if this hash is seen in other parts of the network. After inspecting a large n...
MD5hash collisionscryptographic hashingSIEM analysis - Question #332Security program management and oversight
A company's AUP requires: - Passwords must meet complexity requirements. - Passwords are changed at least once every six months. - Passwords must be at least eight characters long....
password policypassword expirationAUP enforcementaccount management - Question #333Security program management and oversight
An organization's primary datacenter is experiencing a two-day outage due to an HVAC malfunction. The node located in the datacenter has lost power and is no longer operational, im...
single point of failureBIAbusiness continuitydatacenter resilience - Question #334Security operations
A security analyst notices anomalous activity coming from several workstations in the organizations. Upon identifying and containing the issue, which of the following should the se...
incident responseafter-action reportlessons learnedIR lifecycle - Question #335Threats, vulnerabilities, and mitigations
An employee receives an email, which appears to be from the Chief Executive Officer (CEO), asking for a report of security credentials for all users. Which of the following types o...
spear phishingsocial engineeringemail impersonationphishing types - Question #336Security program management and oversight
An information security analyst needs to work with an employee who can answer questions about how data for a specific system is used in the business. The analyst should seek out an...
data ownerdata governanceroles and responsibilitiesdata classification - Question #337Security architecture
A group of non-profit agencies wants to implement a cloud service to share resources with each other and minimize costs. Which of the following cloud deployment models BEST describ...
community cloudcloud deployment modelsresource sharingcloud computing - Question #338Security operations
A director of IR is reviewing a report regarding several recent breaches. The director complies the following statistics: - Initial IR engagement time frame - Length of time before...
tabletop exerciseincident response metricsIR improvementbusiness continuity - Question #339Security operations
A copy of a highly confidential salary report was recently found on a printer in the IT department. The human resources department does not have this specific printer mapped to its...
least privilegeaccess controldata protectionnetwork share permissions - Question #340General security concepts
A company is developing a new system that will unlock a computer automatically when an authorized user sits in front of it, and then lock the computer when the user leaves. The use...
facial recognitionbiometricsphysical access controlbehavioral authentication - Question #341Threats, vulnerabilities, and mitigations
A security analyst accesses corporate web pages and inputs random data in the forms. The response received includes the type of database used and SQL commands that the database acc...
input validationSQL injectionweb application securityerror handling - Question #342General security concepts
Which of the following differentiates a collision attack from a rainbow table attack?
hash collisionrainbow table attackcryptographic attackspassword cracking - Question #343General security concepts
A help desk is troubleshooting user reports that the corporate website is presenting untrusted certificate errors to employees and customers when they visit the website. Which of t...
PKIdigital certificatescertificate revocationTLS/SSL - Question #344Security operations
A security analyst is investigating a suspected security breach and discovers the following in the logs of the potentially compromised server: Which of the following would be the B...
account lockoutbrute force preventionlog analysisauthentication controls - Question #345Threats, vulnerabilities, and mitigations
A security administrator wants to implement a logon script that will prevent MITM attacks on the local LAN. Which of the following commands should the security administrator implem...
ARP poisoningMITM preventionstatic ARP entryLAN security - Question #346General security concepts
Which of the following is the BEST reason for salting a password hash before it is stored in a database?
password saltingcryptographic hashingrainbow table preventionpassword storage - Question #347Threats, vulnerabilities, and mitigations
An actor downloads and runs a program against a corporate login page. The program imports a list of usernames and passwords, looking for a successful attempt. Which of the followin...
threat actorsscript kiddiecredential stuffingattack tools - Question #348Security architecture
An organization wants to utilize a common, Internet-based third-party provider for authorization and authentication. The provider uses a technology based on OAuth 2.0 to provide re...
OpenID ConnectOAuth 2.0identity federationauthentication protocols - Question #349Threats, vulnerabilities, and mitigations
A penetration tester harvests potential usernames from a social networking site. The penetration tester then uses social engineering to attempt to obtain associated passwords to ga...
active reconnaissancesocial engineeringcredential harvestingpenetration testing - Question #350Security architecture
Which of the following could occur when both strong and weak ciphers are configured on a VPN concentrator? (Select TWO)
downgrade attackcipher negotiationVPN concentratordata integrity - Question #351General security concepts
Which of the following is the BEST choice for a security control that represents a preventive and corrective logical control at the same time?
security controlsantiviruspreventive controlcorrective control - Question #352Security architecture
A web developers improves client access to the company's REST API. Authentication needs to be tokenized but not expose the client's password. Which of the following methods would B...
OAuthREST APItoken-based authenticationAPI security