Unique Top-selling SYO-501 Exams - New 2021 CompTIA Pratice Exam
Security+ Dumps SYO-501 Exam for Full Questions - Exam Study Guide
NEW QUESTION 341
After a recent internal breach, a company decided to regenerate and reissue all certificates used in the transmission of confidential information. The company places the greatest importance on confidentiality and non-repudiation, and decided to generate dual key pairs for each client. Which of the following BEST describes how the company will use these certificates?
- A. One key pair will be used for encryption and decryption. The other will be used to digitally sign the data.
- B. Data will be encrypted once by each key, doubling the confidentiality and non-repudiation strength.
- C. One key pair will be used for internal communication, and the other will be used for external communication.
- D. One key pair will be used for encryption. The other key pair will provide extended validation.
Answer: A
NEW QUESTION 342
A systems administrator wants to protect data stored on mobile devices that are used to scan and record assets in a warehouse. The control must automatically destroy the secure container of mobile devices if they leave the warehouse. Which of the following should the administrator implement? (Choose two.)
- A. Remote wipe
- B. Geofencing
- C. Containerization
- D. Push notification services
- E. Near-field communication
Answer: B,C
NEW QUESTION 343
A security technician would like to obscure sensitive data within a file so that it can be transferred without causing suspicion.
Which of the following technologies would BEST be suited to accomplish this?
- A. Digital Signature
- B. Steganography
- C. Transport Encryption
- D. Stream Encryption
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Steganography is the process of hiding a message in another message so as to obfuscate its importance.
It is also the process of hiding a message in a medium such as a digital image, audio file, or other file. In theory, doing this prevents analysts from detecting the real message. You could encode your message in another file or message and use that file to hide your message.
NEW QUESTION 344
A company's loss control department identifies theft as a recurring loss type over the past year. Based on the department's report, the Chief Information Officer (CIO) wants to detect theft of datacenter equipment.
Which of the following controls should be implemented?
- A. Cameras
- B. Biometrics
- C. Mantraps
- D. Motion detectors
Answer: D
NEW QUESTION 345
A researcher has been analyzing large data sets for the last ten months. The researcher works with colleagues from other institutions and typically connects via SSH to retrieve additional data. Historically, this setup has worked without issue, but the researcher recently started getting the following message:
Which of the following network attacks Is the researcher MOST likely experiencing?
- A. MAC cloning
- B. Man-in-the-middle
- C. ARP poisoning
- D. Evil twin
Answer: B
Explanation:
Explanation
This is alarming because it could actually mean that you're connecting to a different server without knowing it.
If this new server is malicious then it would be able to view all data sent to and from your connection, which could be used by whoever set up the server. This is called a man-in-the-middle attack. This scenario is exactly what the "WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!" message is trying to warn you about.
NEW QUESTION 346
An employee finds a usb drive in the employee lunch room and plugs the drive into a shared workstation to determine who owns the drive. When the drive is inserted, a command prompt opens and a script begins to run. The employee notifies a technician who determines that data on a server have been compromised. This is an example of:
- A. Device removal
- B. Mitigation steps
- C. Data disclosure
- D. Incident identification
Answer: D
NEW QUESTION 347
Which of the following BEST describes a network-based attack that can allow an attacker to take full control of a vulnerable host?
- A. Man-in-the-middle
- B. Remote exploit
- C. Sniffing
- D. Amplification
Answer: C
NEW QUESTION 348
An organization has the following password policies:
* Passwords must be at least 16 characters long.
* A password cannot be the same as any previous 20 passwords.
* Three failed login attempts will lock the account for five minutes.
* Passwords must have one uppercase letter, one lowercase letter, and one non-alphanumeric symbol.
A database server was recently breached, and the incident response team suspects the passwords were compromised. Users with permission on that database server were forced to change their passwords for that server. Unauthorized and suspicious logins are now being detected on a completely separate server. Which of the following is MOST likely the issue and the best solution?
- A. Some users are reusing passwords for different systems; the organization should scan for password reuse across systems.
- B. User passwords are not sufficiently long or complex: the organization should increase the complexity and length requirements for passwords.
- C. The organization has improperly configured single sign-on; the organization should implement a RADIUS server to control account logins.
- D. The trust relationship between the two servers has been compromised: the organization should place each server on a separate VLAN.
Answer: A
NEW QUESTION 349
Which of the following should be implemented to stop an attacker from interacting with the hypervisor through another guest?
- A. Containers
- B. Virtual Desktop
- C. VM escape protection
- D. Security broker
Answer: A
NEW QUESTION 350
Which of the following would be MOST effective at stopping zero-day attacks on an endpoint? (Select TWO)
- A. Deploying antivirus and anti-malware system tools
- B. Installing a reverse proxy
- C. Implementing application whitelisting
- D. Removing administrator rights from users
- E. Deploying multivendor NGFWs
- F. Implementing a web application firewall
Answer: C,D
NEW QUESTION 351
A cyber security manager has scheduled biannual with the IT team and department leaders to discuss how they would respond hypothetical cyber attacks. During Developing an incident response plan these meetings, the manager presents a scenario and injects additional information throughout the session to replicate what might occur in a dynamic cyber security event involving the company, its facilities, its data , and its staff. Which of the following describes what the manager is doing?
- A. Building a disaster recovery plan
- B. Running a simulation exercise
- C. Developing an incident response plan
- D. Conducting a laptop exercise
Answer: D
NEW QUESTION 352
A security administrator discovers that an attack has been completed against a node on the corporate network.
All available logs were collected and stored.
You must review all network logs to discover the scope of the attack, check the box of the node(s) that have been compromised and drag and drop the appropriate actions to complete the incident response on the network. The environment is a critical production environment; perform the LEAST disruptive actions on the network, while still performing the appropriate incid3nt responses.
Instructions: The web server, database server, IDS, and User PC are clickable. Check the box of the node(s) that have been compromised and drag and drop the appropriate actions to complete the incident response on the network. Not all actions may be used, and order is not important. If at any time you would like to bring back the initial state of the simulation, please select the Reset button. When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.
Answer:
Explanation:
See the solution below.
Explanation
Database server was attacked, actions should be to capture network traffic and Chain of Custody.

IDS Server Log:
Web Server Log:

Database Server Log:
Users PC Log:
NEW QUESTION 353
For each of the given items, select the appropriate authentication category from the drop down choices.
Select the appropriate authentication type for the following items:
Answer:
Explanation:
Explanation:
NEW QUESTION 354
A security analyst is assessing a small company's internal servers against recommended security practices. Which of the following should the analyst do to conduct the assessment? (Select TWO).
- A. Compare configurations against platform benchmarks,
- B. Verify alignment with policy related to regulatory compliance
- C. Run an exploitation framework to confirm vulnerabilities
- D. Review the company's current security baseline,
- E. Confirm adherence to the company's industry-specific regulations.
Answer: C,D
NEW QUESTION 355
A member of the human resources department received the following email message after sending an email containing benefit and tax information to a candidate:
"Your message has been quarantined for the following policy violation: external_potential_Pll. Please contact the IT security administrator for further details." Which of the following BEST describes why this message was received?
- A. The mail gateway prevented the message from being sent to personal email addresses.
- B. The DLP system flagged the message
- C. The file integrity check failed for the attached files.
- D. The company firewall blocked the recipient's IP address.
Answer: B
NEW QUESTION 356
A coding error has been discovered on a customer-facing website. The error causes each request to return confidential PHI data for the incorrect organization. The IT department is unable to identify the specific customers who are affected. As a result at customers must be notified of the potential breach. Which of the following would allow the team to determine the scope of future incidents?
- A. Monthly vulnerability scans
- B. Database access monitoring
- C. Application fuzzing
- D. Intrusion detection system
Answer: C
NEW QUESTION 357
A security analyst has received the following alert snippet from the HIDS appliance:
Given the above logs, which of the following is the cause of the attack?
- A. The TCP ports on destination are all open
- B. There is improper Layer 2 segmentation
- C. FIN, URG, and PSH flags are set in the packet header
- D. TCP MSS is configured improperly
Answer: C
NEW QUESTION 358
......
Best way to practice test for CompTIA SYO-501: https://www.real4dumps.com/SYO-501_examcollection.html

