[Nov-2021] CompTIA SYO-501 Dumps - Secret To Pass in First Attempt [Q223-Q238]

Share

[Nov-2021] CompTIA SYO-501 Dumps - Secret To Pass in First Attempt

CompTIA SYO-501 Exam Dumps [2021] Practice Valid Exam Dumps Question

NEW QUESTION 223
An organization's IRP prioritizes containment over eradication. An incident has been discovered where an attacker outside of the organization has installed cryptocurrency mining software on the organization's web servers. Given the organization's stated priorities, which of the following would be the NEXT step?

  • A. Delete the malicious software and determine if the servers must be reimaged.
  • B. Review firewall and IDS logs to identify possible source IPs.
  • C. Identify and apply any missing operating system and software patches.
  • D. Remove the affected servers from the network.

Answer: D

Explanation:
Explanation
Now, since the organization top priority is more of containment over eradication, an outbreak code that is hostile as a can be suppressed effectively by removing the web server completely from the overall network facilities or infrastructure. Also, if the affected servers are not removed, it might affect the integrity, confidentiality of sensitive materials or documents which will be exposed to the outside world by the attacker.
Read more on Brainly.com - https://brainly.com/question/16835492#readmore

 

NEW QUESTION 224
The Chief Executive Officer (CEO) of a major defense contracting company a traveling overseas for a conference. The CEO will be taking a laptop.
Which of the following should the security administrator implement to ensure confidentiality of the data if the laptop were to be stolen or lost during the trip?

  • A. Remote wipe
  • B. BIOS password
  • C. Full device encryption
  • D. GPS tracking

Answer: C

Explanation:
Explanation

 

NEW QUESTION 225
The security administrator has installed a new firewall which implements an implicit DENY policy by default.
INSTRUCTIONS:
Click on the firewall and configure it to allow ONLY the following communication.
1. The Accounting workstation can ONLY access the web server on the public network over the default HTTPS port. The accounting workstation should not access other networks.
2. The HR workstation should be restricted to communicate with the Financial server ONLY, over the default SCP port
3. The Admin workstation should ONLY be able to access the servers on the secure network over the default TFTP port.
Instructions: The firewall will process the rules in a top-down manner in order as a first match The port number must be typed in and only one port number can be entered per rule Type ANY for all ports. The original firewall configuration can be reset at any time by pressing the reset button. Once you have met the simulation requirements, click save and then Done to submit.

Hot Area:

Answer:

Explanation:

Explanation


Section: Network Security
Implicit deny is the default security stance that says if you aren't specifically granted access or privileges for a resource, you're denied access by default.Rule #1 allows the Accounting workstation to ONLY access the web server on the public network over the default HTTPS port, which is TCP port 443.Rule #2 allows the HR workstation to ONLY communicate with the Financial server over the default SCP port, which is TCP Port
22Rule #3 & Rule #4 allow the Admin workstation to ONLY access the Financial and Purchasing servers located on the secure network over the default TFTP port, which is Port 69.
References:Stewart,
James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp. 26, 44
http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers

 

NEW QUESTION 226
A startup company is using multiple SaaS and laaS platforms to stand up a corporate infrastructure and build out a customer-facing web application. Which of the following solutions would be BEST to provide security, manageability, and visibility into the platforms?

  • A. DLP
  • B. CASB
  • C. SWG
  • D. SIEM

Answer: B

 

NEW QUESTION 227
Two users must encrypt and transmit large amount of data between them. Which of the following should they use to encrypt and transmit the data?

  • A. Hash function
  • B. Obfuscation
  • C. Digital signature
  • D. Symmetric algorithm

Answer: D

 

NEW QUESTION 228
An employee on the Internet facing part of a company's website submits a 20-character phrase in a small textbox on a web form. The website returns a message back to the browser stating.

Of which of the following is this an example?

  • A. Resources exhaustion
  • B. Buffer overflow
  • C. Improperly configured account
  • D. Improper error handling

Answer: D

 

NEW QUESTION 229
An incident response manager has started to gather all the facts related to a SIEM alert showing multiple systems may have been compromised.
The manager has gathered these facts:
The breach is currently indicated on six user PCs

One service account is potentially compromised

Executive management has been notified

In which of the following phases of the IRP is the manager currently working?

  • A. Containment
  • B. Eradication
  • C. Identification
  • D. Recovery

Answer: C

 

NEW QUESTION 230
During a code review a software developer discovers a security risk that may result in hundreds of hours of rework. The security team has classified these issues as low risk. Executive management has decided that the code will not be rewritten. This is an example of:

  • A. Risk transference
  • B. Risk mitigation
  • C. Risk avoidance
  • D. Risk acceptance

Answer: D

 

NEW QUESTION 231
A chief Financial Officer (CFO) has asked the Chief Information Officer (CISO) to provide responses to a recent audit report detailing deficiencies in the organization security controls. The CFO would like to know ways in which the organization can improve its authorization controls.
Given the request by the CFO, which of the following controls should the CISO focus on in the report? (Select Three)

  • A. Role-based permissions
  • B. Biometric systems
  • C. Lease privilege
  • D. Separation of duties
  • E. Hardware tokens
  • F. Multifactor authentication
  • G. Single sign-on
  • H. Password complexity policies
  • I. One time passwords

Answer: A,C,D

 

NEW QUESTION 232
A security auditor is reviewing the following output from file integrity monitoring software installed on a very busy server at a large service provider. The server has not been updates since it was installed. Drag and drop the log entry that identifies the first instance of server compromise.

Answer:

Explanation:

Explanation
1/1/2017 3:30:00 7813a82384cbaeb45bd12943a9234df3

 

NEW QUESTION 233
Which of the following is a component of multifactor authentication?

  • A. Transitive trust
  • B. OTP
  • C. SSO
  • D. RADIUS

Answer: D

 

NEW QUESTION 234
You have just received some room and WiFi access control recommendations from a security consulting company. Click on each building to bring up available security controls. Please implement the following requirements:
The Chief Executive Officer's (CEO) office had multiple redundant security measures installed on the door to the office. Remove unnecessary redundancies to deploy three-factor authentication, while retaining the expensive iris render.
The Public Cafe has wireless available to customers. You need to secure the WAP with WPA and place a passphrase on the customer receipts.
In the Data Center you need to include authentication from the "something you know" category and take advantage of the existing smartcard reader on the door.
In the Help Desk Office, you need to require single factor authentication through the use of physical tokens given to guests by the receptionist.
The PII Office has redundant security measures in place. You need to eliminate the redundancy while maintaining three-factor authentication and retaining the more expensive controls.

Instructions: The original security controls for each office can be reset at any time by selecting the Reset button. Once you have met the above requirements for each office, select the Save button. When you have completed the entire simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.




Answer:

Explanation:
See the solution below.
Explanation
Solution as




 

NEW QUESTION 235
A security technician has been assigned data destruction duties. The hard drives that are being disposed of contain highly sensitive information. Which of the following data destruction techniques is MOST appropriate?

  • A. Wiping
  • B. Degaussing
  • C. Purging
  • D. Shredding

Answer: D

 

NEW QUESTION 236
Malicious traffic from an internal network has been detected on an unauthorized port on an application server.
Which of the following network-based security controls should the engineer consider implementing?

  • A. NAT
  • B. ACLs
  • C. MAC filtering
  • D. HIPS

Answer: B

 

NEW QUESTION 237
A new security policy in an organization requires that all file transfers within the organization be completed using applications that provide secure transfer. Currently, the organization uses FTP and HTTP to transfer files.
Which of the following should the organization implement in order to be compliant with the new policy?

  • A. Replace FTP with FTPS and replaces HTTP with IPSec
  • B. Replace FTP with SFTP and replace HTTP with TLS
  • C. Replace FTP with FTPS and replaces HTTP with TFTP
  • D. Replace FTP with SFTP and replace HTTP with Telnet

Answer: C

 

NEW QUESTION 238
......


Risk Management

Risk management involves a wide range of issues related to plans, procedures, and policies of organizational security. It also addresses the concepts of business analysis, risk management, incident response procedures, control types, disaster recovery, and data privacy and security issues. Within this domain, you will get to know more about agreement types, SLA, ISA, NDA, mission-essential functions, and threat assessment.

 

SYO-501 Exam Dumps PDF Guaranteed Success  with Accurate & Updated Questions: https://www.pass4surequiz.com/SYO-501-exam-quiz.html

SYO-501 Dumps - Grab Out For [NEW-2021] CompTIA Exam: https://drive.google.com/open?id=1xTu2ITQHPiDQ6yhpv0qmzs5IdXTjKxz9