[Dec 02, 2021] SY0-501 Test Engine files, SY0-501 Dumps PDF [Q186-Q210]

Share

[Dec 02, 2021] SY0-501 Test Engine files, SY0-501 Dumps PDF 

Latest CompTIA SY0-501 PDF and Dumps (2021) Free Exam Questions Answers


Where Does Security+ Lie on Professional CompTIA Certification Ladder?

In terms of cybersecurity certificates, this is the first certification that you should obtain to become a cybersecurity specialist. But if you squint hard enough, you will realize the new Security+ training is more than just an entry-level certificate, because it also qualifies learners for intermediate-level jobs in IT. Therefore, the CompTIA Security+ is among the most popular certificates that the vendor has to offer today. So, to earn it, you must pass only one exam - SY0-501 exam.


Our SY0-501 practice test will include those topics:

  • Cryptography and PKI 12%
  • Risk Management 14%
  • Threats, Attacks and Vulnerabilities 21%
  • Technologies and Tools 22%
  • Identity and Access Management 16%

For more info visit: CompTIA Security

 

NEW QUESTION 186
While testing a new application, a developer discovers that the inclusion of an apostrophe in a username cause the application to crash. Which of the following secure coding techniques would be MOST useful to avoid this problem?

  • A. Obfuscation
  • B. Input validation
  • C. Encryption
  • D. Code signing

Answer: B

 

NEW QUESTION 187
Which of the following techniques can be bypass a user or computer's web browser privacy settings?
(Select Two)

  • A. SQL injection
  • B. Locally shared objects
  • C. LDAP injection
  • D. Cross-site scripting
  • E. Session hijacking

Answer: D,E

 

NEW QUESTION 188
A director of IR is reviewing a report regarding several recent breaches. The director compiles the following statistic's
-Initial IR engagement time frame
-Length of time before an executive management notice went out
-Average IR phase completion
The director wants to use the data to shorten the response time. Which of the following would accomplish this?

  • A. Containment phase
  • B. Tabletop exercise
  • C. CSIRT
  • D. Escalation notifications

Answer: B

 

NEW QUESTION 189
A user suspects someone has been accessing a home network without permission by spoofing the MAC address of an authorized system. While attempting to determine if an authorized user is logged into the home network, the user reviews the wireless router, which shows the following table for systems that are currently on the home network.

Which of the following should be the NEXT step to determine if there is an unauthorized user on the network?

  • A. Physically check each of the authorized systems to determine if they are logged onto the network.
  • B. Apply MAC filtering and see if the router drops any of the systems.
  • C. Deny the "unknown" host because the hostname is not known and MAC filtering is not applied to this host.
  • D. Conduct a ping sweep of each of the authorized systems and see if an echo response is received.

Answer: C

 

NEW QUESTION 190
A security analyst receives the following output

Which of the following MOST likely occurred to produce this output?

  • A. The firewall prevented an incoming malware-infected file
  • B. The host-based firewall prevented an attack from a Trojan horse
  • C. The host DLP prevented a file from being moved off a computer
  • D. USB-OTG prevented a file from being uploaded to a mobile device

Answer: B

 

NEW QUESTION 191
A penetration tester finds that a company's login credentials for the email client were being sent in clear text. Which of the following should be done to provide encrypted logins to the email server?

  • A. Enable an SSL certificate for IMAP services.
  • B. Enable MIME services and POP3.
  • C. Enable IPSec and configure SMTP.
  • D. Enable SSH and LDAP credentials.

Answer: A

 

NEW QUESTION 192
Which of the following is the GREATEST risk to a company by allowing employees to physically bring their
personal smartphones to work?

  • A. Taking pictures of proprietary information and equipment in restricted areas.
  • B. Increases the attack surface by having more target devices on the company's campus
  • C. Company cannot automate patch management on personally-owned devices.
  • D. Installing soft token software to connect to the company's wireless network.

Answer: A

 

NEW QUESTION 193
A company has three divisions, each with its own networks and services. The company decides to make its secure web portal accessible to all employees utilizing their existing usernames and passwords, The security administrator has elected to use SAML to support authentication. In this scenario, which of the following will occur when users try to authenticate to the portal? (Select TWO)

  • A. The back-end networks will verify the assertion token issued by the portal functioning as the identity provider
  • B. The back-end networks will function as an identity provider and issue an authentication assertion
  • C. The portal will function as an identity provider and issue an authentication assertion
  • D. The back-end networks will request authentication tickets from the portal, which will act as the third-party service provider authentication store
  • E. The portal will request an authentication ticket from each network that is transitively trusted

Answer: B

 

NEW QUESTION 194
A hacker has a packet capture that contains:

Which of the following tools will the hacker use against this type of capture?

  • A. Password cracker
  • B. Fuzzer
  • C. Vulnerability scanner
  • D. DLP scanner

Answer: A

 

NEW QUESTION 195
A copy of a highly confidential salary report was recently found on a printer in the IT department. The human resources department does not have this specific printer mapped to its devices, and it is suspected that an employee in the IT department browsed to the share where the report was located and printed it without
authorization. Which of the following technical controls would be the BEST choice to immediately prevent this from happening again?

  • A. Implement a DLP solution and classify the report as confidential, restricting access only to human resources staff
  • B. Place the human resources computers on a restricted VLAN and configure the ACL to prevent access from the IT department
  • C. Restrict access to the share where the report resides to only human resources employees and enable auditing
  • D. Have all members of the IT department review and sign the AUP and disciplinary policies

Answer: C

 

NEW QUESTION 196
A security consultant is analyzing data from a recent compromise. The following data points are documented
* Access to data on share drives and certain networked hosts was lost after an employee logged in to an interactive session as a privileged user.
* The data was unreadable by any known commercial software.
* The issue spread through the enterprise via SMB only when certain users accessed data.
* Removal instructions were not available from any major antivirus vendor.
Which of the following types of malware is this example of'?

  • A. Keylogger
  • B. Worm
  • C. Backdoor
  • D. Ransomware
  • E. RAT

Answer: E

 

NEW QUESTION 197
A security administrator wants to implement a company-wide policy to empower data owners to manage and enforce access control rules on various resources.
Which of the following should be implemented?

  • A. Discretionary access control
  • B. Role based access control
  • C. Mandatory access control
  • D. Rule-based access control

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 198
When considering a third-party cloud service provider, which of the following criteria would be the BEST to include in the security assessment process? (Choose two.)

  • A. Data retention policies
  • B. Use of performance analytics
  • C. Size of the corporation
  • D. Adherence to regulatory compliance
  • E. Breadth of applications support

Answer: A,D

 

NEW QUESTION 199
Exploitation of a system using widely known credentials and network addresses that results in DoS is an example of:

  • A. untrained users
  • B. default configurations.
  • C. improper error handling.
  • D. lack of vendor support

Answer: B

 

NEW QUESTION 200
A supervisor in your organization was demoted on Friday afternoon. The supervisor had the ability to modify the contents of a confidential database, as well as other managerial permissions.
On Monday morning, the database administrator reported that log files indicated that several records were missing from the database.
Which of the following risk mitigation strategies should have been implemented when the supervisor was demoted?

  • A. IT governance
  • B. Routine auditing
  • C. Incident management
  • D. Monthly user rights reviews

Answer: B

Explanation:
The right answer is Routine auditing because Routine auditing includes user rights review and/or disabling unused accounts.
https://www.youtube.com/watch?v=HvMJRFYn7Ik - Professor Messer about User Access Reviews and Monitoring.

 

NEW QUESTION 201
A security program manager wants to actively test the security posture of a system. The system is not yet in production and has no uptime requirement or active user base.
Which of the following methods will produce a report which shows vulnerabilities that were actually exploited?

  • A. Penetration testing
  • B. Peer review
  • C. Vulnerability testing
  • D. Component testing

Answer: A

Explanation:
A penetration test, or pen test, is an attempt to evaluate the security of an IT infrastructure by safely trying to exploit vulnerabilities.

 

NEW QUESTION 202
The SOC is reviewing processes and procedures after a recent incident. The review indicates it took more than 30 minutes to determine that quarantining an infected host was the best course of action. This allowed the malware to spread to additional hosts before it was contained. Which of the following would be BEST to improve the incident response process?

  • A. Dividing the network into trusted and untrusted zones
  • B. Updating the playbooks with better decision points
  • C. Providing additional end-user training on acceptable use
  • D. Implementing manual quarantining of infected hosts

Answer: C

 

NEW QUESTION 203
A website administrator has received an alert from an application designed to check the integrity of the company's website. The alert indicated that the hash value for a particular MPEG file has changed. Upon further investigation, the media appears to be the same as it was before the alert. Which of the following methods has MOST likely been used?

  • A. Cryptography
  • B. Covert timing
  • C. Steganography
  • D. Time of check/time of use
  • E. Man in the middle

Answer: C

 

NEW QUESTION 204
Refer to the following code:

Which of the following vulnerabilities would occur if this is executed?

  • A. NullPointerException
  • B. Pointer deference
  • C. Page exception
  • D. Missing null check

Answer: D

 

NEW QUESTION 205
While working on an incident, Joe, a technician, finished restoring the OS and applications on a workstation from the original medi Joe is about to begin copying the user's files back onto the hard drive. Which of the following incident response steps is Joe working on now?

  • A. Containment
  • B. Recovery
  • C. Identification
  • D. Eradication

Answer: B

 

NEW QUESTION 206
A security analyst is determining the point of compromise after a company was hacked. The analyst checks the server logs and sees that a user account was logged in at night, and several large compressed files were exfiltrated. The analyst then discovers the user last logged in four years ago and was terminated. Which of the following should the security analyst recommend to prevent this type of attack in the future? (Choose two.)

  • A. Restrict the compromised user account
  • B. Disable all user accounts that are not logged in to for 180 days
  • C. Enable a login banner prohibiting unauthorized use
  • D. Create a honeypot to catch the hacker
  • E. Perform an audit of all company user accounts
  • F. Review and update the firewall settings

Answer: A,E

 

NEW QUESTION 207
A systems administrator has been assigned to create accounts for summer interns. The interns are only authorized to be in the facility and operate computers under close supervision. They must also leave the facility at designated times each day. However, the interns can access intern file folders without supervision. Which of the following represents the BEST way to configure the accounts? (Select TWO.)

  • A. Modify archived data.
  • B. Enforce least privilege.
  • C. Implement time-of-day restrictions.
  • D. Create privileged accounts.
  • E. Access executive shared portals.

Answer: C,D

 

NEW QUESTION 208
A user suspects someone has been accessing a home network without permission by spoofing the MAC address of an authorized system. While attempting to determine if an authorized user is logged into the home network, the user reviews the wireless router, which shows the following table for systems that are currently on the home network.

Which of the following should be the NEXT step to determine if there is an unauthorized user on the network?

  • A. Physically check each of the authorized systems to determine if they are logged onto the network.
  • B. Apply MAC filtering and see if the router drops any of the systems.
  • C. Deny the "unknown" host because the hostname is not known and MAC filtering is not applied to this host.
  • D. Conduct a ping sweep of each of the authorized systems and see if an echo response is received.

Answer: C

 

NEW QUESTION 209
Which of the following are used to increase the computing time it takes to brute force a password using an offline attack? (Select TWO)

  • A. bcrypt
  • B. RIPEMD
  • C. HMAC
  • D. PBKDF2
  • E. XOR

Answer: A,D

 

NEW QUESTION 210
......


Which Skills Will You Obtain from CompTIA Security+ Certification?

You will earn 5 core skills from the Security+ certification including the following:

  • Attacks, threats, and vulnerabilities;
  • Operations and incident response;
  • Architecture and design;
  • Implementation;
  • Governance, risk, and compliance.

 

Pass Your Security+ SY0-501 Exam on Dec 02, 2021 with 715 Questions: https://www.passleadervce.com/Security/reliable-SY0-501-exam-learning-guide.html