SY0-501 Exam Questions
551 real SY0-501 exam questions with expert-verified answers and explanations. Page 9 of 12.
- Question #407Security operations
After attempting to harden a web server, a security analyst needs to determine if an application remains vulnerable to SQL injection attacks. Which of the following would BEST assi...
SQL injectionfuzzingweb application securityvulnerability testing - Question #408Security architecture
A company is allowing a BYOD policy for its staff. Which of the following is a best practice that can decrease the risk of users jailbreaking mobile devices?
BYODmobile securityjailbreakingMDM - Question #409Threats, vulnerabilities, and mitigations
Which of the following describes the key difference between vishing and phishing attacks?
vishingphishingsocial engineeringtelephony attacks - Question #410Security operations
Which of the following should a security analyst perform FIRST to determine the vulnerabilities of a legacy system?
vulnerability scanningpassive scanlegacy systemsassessment methodology - Question #411Threats, vulnerabilities, and mitigations
Which of the following components of printers and MFDs are MOST likely to be used as vectors of compromise if they are improperly configured?
printer securityembedded web serverMFD vulnerabilitiesnetwork devices - Question #412Threats, vulnerabilities, and mitigations
A hacker has a packet capture that contains: ....Joe Smith.........E289F21CD33E4F57890DDEA5CF267ED2.. ...Jane.Doe...........AD1FAB10D33E4F57890DDEA5CF267ED2.. ....John.Key............
password crackingpassword hashescredential thefthacking tools - Question #413Threats, vulnerabilities, and mitigations
A user downloads and installs an MP3 converter, and runs the application. Upon running the application, the antivirus detects a new port in a listening state. Which of the followin...
RATmalwareport listeningtrojan - Question #414Threats, vulnerabilities, and mitigations
An attacker exploited a vulnerability on a mail server using the code below. <HTML><body onload=document.location.replace "URL:" +"document.location) ; /> </body> </HTML> Which of...
XSSJavaScript injectionweb attackHTML manipulation - Question #415Security architecture
A security analyst is securing smartphones and laptops for a highly mobile workforce. Priorities include: Remote wipe capabilities Geolocation services Patch management and reporti...
MDMmobile device managementremote wipeendpoint security - Question #416Security operations
A technician receives a device with the following anomalies: Frequent pop-up ads Show response-time switching between active programs Unresponsive peripherals The technician review...
file integrity monitoringMD5 hashmalware detectionlog analysis - Question #417Security operations
A systems administrator is attempting to recover from a catastrophic failure in the datacenter. To recover the domain controller, the systems administrator needs to provide the dom...
domain administratoraccount typesprivileged accessidentity management - Question #418General security concepts
An organization plans to implement multifactor authentication techniques within the enterprise network architecture. Each authentication factor is expected to be a unique control....
multifactor authenticationauthentication factorssomething you havesomething you are - Question #420Threats, vulnerabilities, and mitigations
Upon entering an incorrect password, the logon screen displays a message informing the user that the password does not match the username provided and is not the required length of...
error handlinginformation disclosuresecure codingverbose errors - Question #421Security architecture
Which of the following s the BEST reason to run an untested application is a sandbox?
sandboxapplication isolationprivilege escalation preventionsecurity controls - Question #422Security architecture
An administrator is replacing a wireless router. The configuration of the old wireless router was not documented before it stopped functioning. The equipment connecting to the wire...
WPATKIPwireless securitylegacy compatibility - Question #425Threats, vulnerabilities, and mitigations
Which of the following specifically describes the exploitation of an interactive process to access otherwise restricted areas of the OS?
privilege escalationOS exploitationinteractive processaccess control - Question #427Security operations
A security analyst observes the following events in the logs of an employee workstation: 1/23 1:07:16 865 Access to C:\Users\user\temp\oasdfkh.hta has been restricted by your admin...
application whitelistingHTA fileexploit payloadSRP - Question #428Security operations
A security technician has been receiving alerts from several servers that indicate load balancers have had a significant increase in traffic. The technician initiates a system scan...
log analysisdisk spaceDDoSanomaly detection - Question #429Threats, vulnerabilities, and mitigations
A security administrator is diagnosing a server where the CPU utilization is at 100% for 24 hours. The main culprit of CPU utilization is the antivirus program. Which of the follow...
resource exhaustionDoSCPU utilizationantivirus - Question #430General security concepts
Which of the following is used to validate the integrity of data?
hashingMD5data integritycryptography - Question #431Security architecture
A user typically works remotely over the holidays using a web-based VPN to access corporate resources. The user reports getting untrusted host errors and being unable to connect. W...
SSL certificatecertificate expirationVPNPKI - Question #432Security architecture
When it comes to cloud computing, if one of the requirements for a project is to have the most control over the systems in the cloud, which of the following is a service model that...
IaaScloud service modelscloud controlinfrastructure - Question #433Security architecture
A company was recently audited by a third party. The audit revealed the company's network devices were transferring files in the clear. Which of the following protocols should the...
SCPsecure file transferencryption in transitprotocol selection - Question #434Security operations
A security analyst is acquiring data from a potential network incident. Which of the following evidence is the analyst MOST likely to obtain to determine the incident?
network forensicsincident responsepacket capturelog analysis - Question #435Security operations
A cybersecurity analyst is looking into the payload of a random packet capture file that was selected for analysis. The analyst notices that an internal host had a socket establish...
netcatnetwork socketnon-standard portcommand history analysis - Question #436Security architecture
A security administrator has written a script that will automatically upload binary and text-based configuration files onto a remote server using a scheduled task. The configuratio...
SCPcertificate-based authenticationsecure file transfersensitive data protection - Question #437Security operations
A security analyst conducts a manual scan on a known hardened host that identifies many non- compliant items. Which of the following BEST describe why this has occurred? (Select TW...
vulnerability scanningcompliance scanningaudit filesfalse positives - Question #438Security architecture
Which of the following solutions should an administrator use to reduce the risk from an unknown vulnerability in a third-party software application?
sandboxingzero-dayapplication isolationthird-party risk - Question #439Security architecture
A network administrator needs to allocate a new network for the R&D group. The network must not be accessible from the Internet regardless of the network firewall or other external...
network isolationprotected portsswitch configurationnetwork segmentation - Question #440Security program management and oversight
To help prevent one job role from having sufficient access to create, modify, and approve payroll data, which of the following practices should be employed?
separation of dutiesaccess controlleast privilegepayroll security - Question #441Threats, vulnerabilities, and mitigations
When attackers use a compromised host as a platform for launching attacks deeper into a company's network, it is said that they are:
pivotinglateral movementattack techniquesnetwork compromise - Question #442Security operations
The help desk received a call after hours from an employee who was attempting to log into the payroll server remotely. When the help desk returned the call the next morning, the em...
time-of-day restrictionsaccess controlaccount managementauthentication - Question #443Security architecture
An analyst receives an alert from the SIEM showing an IP address that does not belong to the assigned network can be seen sending packets to the wrong gateway. Which of the followi...
VLANswitch misconfigurationnetwork troubleshootingaccess ports - Question #444Threats, vulnerabilities, and mitigations
A home invasion occurred recently in which an intruder compromised a home network and accessed a WiFI- enabled baby monitor while the baby's parents were sleeping. Which of the fol...
IoT securitydefault configurationdefault credentialshome network - Question #445General security concepts
A security engineer must install the same x.509 certificate on three different servers. The client application that connects to the server performs a check to ensure the certificat...
X.509 certificatesSANPKITLS - Question #446Security operations
Which of the following refers to the term used to restore a system to its operational state?
MTTRrecovery metricsavailabilitybusiness continuity - Question #447Security operations
A Chief Information Officer (CIO) recently saw on the news that a significant security flaws exists with a specific version of a technology the company uses to support many critica...
penetration testingvulnerability assessmentrisk assessmentsecurity testing - Question #448Security architecture
An organization is expanding its network team. Currently, it has local accounts on all network devices, but with growth, it wants to move to centrally managed authentication. Which...
TACACS+RADIUSAAAcentralized authentication - Question #449Security architecture
An active/passive configuration has an impact on:
high availabilityactive/passivefailoverCIA triad - Question #450Threats, vulnerabilities, and mitigations
Which of the following attack types BEST describes a client-side attack that is used to manipulate an HTML iframe with JavaScript code via a web browser?
XSScross-site scriptingclient-side attacksweb security - Question #451General security concepts
Which of the following would provide additional security by adding another factor to a smart card?
multi-factor authenticationsmart cardPINauthentication factors - Question #452Security architecture
A systems administrator wants to implement a wireless protocol that will allow the organization to authenticate mobile devices prior to providing the user with a captive portal log...
Wireless securityAuthentication protocolsRADIUSNetwork Access Control - Question #453Threats, vulnerabilities, and mitigations
Which of the following uses precomputed hashes to guess passwords?
rainbow tablespassword crackinghash attackscryptography - Question #454
A systems administrator wants to provide balance between the security of a wireless network and usability. The administrator is concerned with wireless encryption compatibility of...
- Question #455Security operations
In determining when it may be necessary to perform a credentialed scan against a system instead of a non- credentialed scan, which of the following requirements is MOST likely to i...
credentialed scanningvulnerability scanningfile system permissionssecurity assessment - Question #456Security operations
A security administrator receives an alert from a third-party vendor that indicates a certificate that was installed in the browser has been hijacked at the root of a small public...
CRLcertificate revocationPKICA - Question #458Security program management and oversight
A company has noticed multiple instances of proprietary information on public websites. It has also observed an increase in the number of email messages sent to random employees co...
phishingsocial media policyemail securitydata leakage - Question #459Security operations
A security analyst is investigating a potential reach. Upon gathering, documenting, and securing the evidence, which of the following actions is the NEXT step to minimize the busin...
incident responseevidence handlingmalware removalbusiness continuity - Question #460Security program management and oversight
Joe, a salesman, was assigned to a new project that requires him to travel to a client site. While waiting for a flight, Joe, decides to connect to the airport wireless network wit...
acceptable use policywireless securityVPNdata breach - Question #461Security program management and oversight
A company is performing an analysis of the corporate enterprise network with the intent of identifying what will cause losses in revenue, referrals, and/or reputation when out of c...
Business Impact Analysis (BIA)Critical systems identificationBusiness continuity planningRisk assessment