[Mar 19, 2022] Valid SYO-501 Test Answers & CompTIA SYO-501 Exam PDF [Q233-Q258]

Share

[Mar 19, 2022] Valid SYO-501 Test Answers & CompTIA SYO-501 Exam PDF

Realistic SYO-501 Exam Dumps with Accurate & Updated Questions


Which Skills Will You Obtain from CompTIA Security+ Certification?

You will earn 5 core skills from the Security+ certification including the following:

  • Architecture and design;
  • Operations and incident response;
  • Attacks, threats, and vulnerabilities;
  • Implementation;
  • Governance, risk, and compliance.

 

NEW QUESTION 233
A security analyst runs a monthly file integrity check on the main web server. When analyzing the logs, the analyst observed the following entry:

No OS patches were applied to this server during this period. Considering the log output, which of the following is the BEST conclusion?

  • A. The cmd.exe was updated on the scanned server. An incident ticket should be created
  • B. The iexplore.exe was executed on the scanned server between the two dates. An incident ticket should be created.
  • C. The iexplore.exe was updated on the scanned server. An incident ticket should be created.
  • D. The cmd.exe was executed on the scanned server between the two dates. An incident ticket should be created

Answer: A

 

NEW QUESTION 234
A security administrator is reviewing the following network capture:
192.168.20.43:2043 -> 10.234.66.21:80
POST "192.168.20.43 https://www.banksite.com<ENTER>JoeUsr<BackSPACE>erPassword<ENTER>"
Which of the following malware is MOST likely to generate the above information?

  • A. Keylogger
  • B. Ransomware
  • C. adware
  • D. Logic bomb

Answer: B

 

NEW QUESTION 235
A security analyst believes an employee's workstation has been compromised. The analyst reviews the system logs, but does not find any attempted logins. The analyst then runs the diff command, comparing the C:\Windows\System32 directory and the installed cache directory. The analyst finds a series of files that look suspicious.
One of the files contains the following commands:

Which of the following types of malware was used?

  • A. Backdoor
  • B. Spyware
  • C. Logic bomb
  • D. Worm

Answer: A

 

NEW QUESTION 236
An auditor is reviewing the following output from a password-cracking tool:
User:1: Password1
User2: Recovery!
User3: Alaskan10
User4: 4Private
User5: PerForMance2
Which of the following methods did the author MOST likely use?

  • A. Dictionary
  • B. Hybrid
  • C. Brute force
  • D. Rainbow table

Answer: B

 

NEW QUESTION 237
A security administrator has found a hash in the environment known to belong to malware. The administrator then finds this file to be in in the preupdate area of the OS, which indicates it was pushed from the central patch system.
File: winx86_adobe_flash_upgrade.exe
Hash: 99ac28bede43ab869b853ba62c4ea243
The administrator pulls a report from the patch management system with the following output:

Given the above outputs, which of the following MOST likely happened?

  • A. The file was corrupted after it left the patch system.
  • B. The file was not approved in the application whitelist system.
  • C. The file was embedded with a logic bomb to evade detection.
  • D. The file was infected when the patch manager downloaded it.

Answer: C

 

NEW QUESTION 238
A security analyst has received several reports of an issue on an internal web application. Users state they are having to provide their credentials twice to log in. The analyst checks with the application team and notes this is not an expected behavior. After looking at several logs, the analyst decides to run some commands on the gateway and obtains the following output:

Which of the following BEST describes the attack the company is experiencing?

  • A. URL redirection
  • B. DNS hijacking
  • C. MAC flooding
  • D. ARP poisoning

Answer: D

Explanation:
Explanation
ARP Poisoning (also known as ARP Spoofing) is a type of cyber attack carried out over a Local Area Network (LAN) that involves sending malicious packets to a default gateway on a LAN in order to change the pairings in its IP to MAC address table. Protocol translates IP addresses into MAC addresses.

 

NEW QUESTION 239
An auditor has identified an access control system that can incorrectly accept an access attempt from an unauthorized user. Which of the following authentication systems has the auditor reviewed?

  • A. Location-based
  • B. Certificate-based
  • C. Biometric-based
  • D. Password-based

Answer: C

Explanation:
Explanation

 

NEW QUESTION 240
An analyst is concerned about data leaks and wants to restrict access to Internet services to authorized users only. The analyst also wants to control the actions each user can perform on each service Which of the following would be the BEST technology for me analyst to consider implementing?

  • A. DLP
  • B. VPC
  • C. ACL
  • D. CASB

Answer: A

 

NEW QUESTION 241
An audit reported has identifies a weakness that could allow unauthorized personnel access to the facility
at its main entrance and from there gain access to the network. Which of the following would BEST resolve
the vulnerability?

  • A. Faraday cage
  • B. Bollards
  • C. Mantrap
  • D. Air gap

Answer: C

 

NEW QUESTION 242
A company is investigating a data compromise where data exfiltration occurred. Prior to the investigation, the supervisor terminates an employee as a result of the suspected data loss.
During the investigation, the supervisor is absent for the interview, and little evidence can be provided form the role-based authentication system in use by the company. The situation can be identified for future mitigation as which of the following?

  • A. Log failure
  • B. Job rotation
  • C. Lack of training
  • D. Insider threat

Answer: A

 

NEW QUESTION 243
An employee workstation with an IP address of 204 211.38.211/24 reports it is unable to submit print jobs to a network printer at 204.211.38.52/24 after a firewall upgrade. The active firewall rules are as follows:

Assuming port numbers have not been changed from their defaults, which of the following should be modified to allow printing to the network printer?

  • A. The permit statement for 204.211.38.52/24 should be changed to TCP port 631 instead of UDP.
  • B. The permit statement for 204.211.38 211/24 should be changed to TCP port 631 only instead of ALL
  • C. The deny statement for 204 211.38.52/24 should be changed to a permit statement
  • D. The permit statement for 204.211.38.52/24 should be changed to UDP port 443 instead of 631

Answer: A

 

NEW QUESTION 244
A security program manager wants to actively test the security posture of a system. The system is not yet in production and has no uptime requirement or active user base.
Which of the following methods will produce a report which shows vulnerabilities that were actually exploited?

  • A. Penetration testing
  • B. Component testing
  • C. Vulnerability testing
  • D. Peer review

Answer: A

Explanation:
Explanation/Reference:
Explanation:
A penetration test, or pen test, is an attempt to evaluate the security of an IT infrastructure by safely trying to exploit vulnerabilities.

 

NEW QUESTION 245
Which of the following implements two-factor authentication?

  • A. A computer requiring username and password
  • B. A datacenter mantrap requiring fingerprint and iris scan
  • C. At ATM requiring a credit card and PIN
  • D. A phone system requiring a PIN to make a call

Answer: C

 

NEW QUESTION 246
A member of the human resources department is searching for candidate resumes and encounters the following error message when attempting to access popular job search websites:

Which of the following would resolve this issue without compromising the company's security policies?

  • A. Add the employee to a less restrictive group on the content filter
  • B. Remove the proxy settings from the employee's web browser
  • C. Create an exception for the job search sites in the host-based firewall on the employee's computer
  • D. Renew the DNS settings and IP address on the employee's computer

Answer: A

 

NEW QUESTION 247
An auditor is reviewing the following output from a password-cracking tool:

Which of the following methods did the auditor MOST likely use?

  • A. Dictionary
  • B. Hybrid
  • C. Brute force
  • D. Rainbow table

Answer: B

 

NEW QUESTION 248
An office recently completed digitizing all its paper records. Joe, the data custodian, has been tasked with the disposal of the paper files, which include:
* Intellectual property
* Payroll records
* Financial information
* Drug screening results
Which of the following is the BEST way to dispose of these items?

  • A. Recycling
  • B. Deidentifying
  • C. Shredding
  • D. Pulping

Answer: D

 

NEW QUESTION 249
A systems administrator is attempting to recover from a catastrophic failure in the datacenter. To recover the domain controller, the systems administrator needs to provide the domain administrator credentials.
Which of the following account types is the systems administrator using?

  • A. User account
  • B. Service account
  • C. Shared account
  • D. Guest account

Answer: A

 

NEW QUESTION 250
A security analyst observes the following events in the logs of an employee workstation:

Given the information provided, which of the following MOST likely occurred on the workstation?

  • A. Application whitelisting controls blocked an exploit payload from executing.
  • B. Automatic updates were initiated but failed because they had not been approved.
  • C. Antivirus software found and quarantined three malware files.
  • D. The SIEM log agent was not tuned properly and reported a false positive.

Answer: A

 

NEW QUESTION 251
Which of the following are used to substantially increase the computation time required to crack a password?
(Choose two.)

  • A. PBKDF2
  • B. BCRYPT
  • C. Substitution cipher
  • D. ECDHE
  • E. Diffie-Hellman

Answer: A,B

 

NEW QUESTION 252
An analyst wants to implement a more secure wireless authentication for office access points. Which of the following technologies allows for encrypted authentication of wireless clients over TLS?

  • A. EAP
  • B. RADIUS
  • C. WPA2
  • D. PEAP

Answer: D

Explanation:
EAP by itself is only an authentication framework.
PEAP (Protected Extensible Authentication Protocol) fully encapsulates EAP and is designed to work within a TLS (Transport Layer Security) tunnel that may be encrypted but is authenticated. The primary motivation behind the creation of PEAP was to help correct the deficiencies discovered within EAP since that protocol assumes that the communications channel is protected. As a result, when EAP messages are able to be discovered in the "clear" they do not provide the protection that was assumed when the protocol was originally authored.
PEAP, EAP-TTLS, and EAP-TLS "protect" inner EAP authentication within SSL/TLS sessions.

 

NEW QUESTION 253
Joe, a user, wants to send Ann, another user, a confidential document electronically. Which of the
following should Joe do to ensure the document is protected from eavesdropping?

  • A. Encrypt it with Ann's private key
  • B. Encrypt it with Joe's public key
  • C. Encrypt it with Joe's private key
  • D. Encrypt it with Ann's public key

Answer: D

 

NEW QUESTION 254
An organization relies heavily on an application that has a high frequency of security updates. At present, the security team only updates the application on the first Monday of each month, even though the security updates are released as often as twice a week. Which of the following would be the BEST method of updating this application?

  • A. Configure a sandbox for testing patches before the scheduled monthly update.
  • B. Configure security control testing for the application.
  • C. Configure testing and automate patch management for the application.
  • D. Manually apply updates for the application when they are released.

Answer: C

 

NEW QUESTION 255
The Chief Technology Officer (CTO) of a company, Ann, is putting together a hardware budget for the next 10 years. She is asking for the average lifespan of each hardware device so that she is able to calculate when she will have to replace each device. Which of the following categories BEST describes what she is looking for?

  • A. MTTF
  • B. ALE
  • C. MTTR
  • D. MTBF

Answer: A

 

NEW QUESTION 256
You have been tasked with designing a security plan for your company. Drag and drop the appropriate security controls on the floor plan.
Instructions: All objects must be used and all place holders must be filled. Order does not matter. When you have completed the simulation, please select the Done button to submit.

Answer:

Explanation:

Explanation
Cable locks - Adding a cable lock between a laptop and a desk prevents someone from picking it up and walking away Proximity badge + reader Safe is a hardware/physical security measure Mantrap can be used to control access to sensitive areas. CCTV can be used as video surveillance.
Biometric reader can be used to control and prevent unauthorized access. Locking cabinets can be used to protect backup media, documentation and other physical artifacts.

 

NEW QUESTION 257
A company has migrated to two-factor authentication for accessing the corporate network, VPN, and SSO.
Several legacy applications cannot support multifactor authentication and must continue to use usernames and passwords. Which of the following should be implemented to ensure the legacy applications are as secure as possible while ensuring functionality? (Choose two.)

  • A. Password reuse restrictions
  • B. Password recovery
  • C. Password complexity requirements
  • D. Priveleged accounts
  • E. Account disablement

Answer: C,E

 

NEW QUESTION 258
......

SYO-501 Exam Dumps - PDF Questions and Testing Engine: https://www.dumpsvalid.com/SYO-501-still-valid-exam.html