[Nov-2021] Verified SYO-501 dumps Q&As - SYO-501 dumps with Correct Answers [Q345-Q361]

Share

[Nov-2021] Verified SYO-501 dumps Q&As - SYO-501 dumps with Correct Answers

The Best Security+ Study Guide for the SYO-501 Exam

NEW QUESTION 345
While reviewing the wireless router, the systems administrator of a small business determines someone is spoofing the MAC address of an authorized device. Given the table below:

Which of the following should be the administrator's NEXT step to detect if there is a rogue system without impacting availability?

  • A. Apply MAC filtering.
  • B. Physically check each system.
  • C. Deny Internet access to the "UNKNOWN" hostname.
  • D. Conduct a ping sweep.

Answer: D

 

NEW QUESTION 346
The Chief Financial Officer (CFO) of an insurance company received an email from Ann, the company's Chief Executive Officer (CEO), requesting a transfer of $10,000 to an account. The email states Ann is on vacation and has lost her purse, containing cash and credit cards. Which of the following social-engineering techniques is the attacker using?

  • A. Phishing
  • B. Pharming
  • C. Typo squatting
  • D. Whaling

Answer: D

Explanation:
Whaling attack
A whaling attack is a method used by cybercriminals to masquerade as a senior player at an organization and directly target senior or other important individuals at an organization, with the aim of stealing money or sensitive information or gaining access to their computer systems for criminal purposes.
A whaling attack is essentially a spear-phishing attack but the targets are bigger - hence whale phishing. Where spear-phishing attacks may target any individual, whaling attacks are more specific in what type of person they target: focusing on one specific high level executive or influencer vs a broader group of potential victims.
Cybercriminals use whaling attacks to impersonate senior management in an organization, such as the CEO, CFO, or other executives, hoping to leverage their authority to gain access to sensitive data or money. They use the intelligence they find on the internet (and often social media) to trick employees - or another whale - into replying with financial or personal data.

 

NEW QUESTION 347
An incident response manager has started to gather all the facts related to a SIEM alert showing multiple systems may have been compromised. The manager has gathered these facts:
The breach is currently indicated on six user PCs

One service account is potentially compromised

Executive management has been notified

In which of the following phases of the IRP is the manager currently working?

  • A. Containment
  • B. Eradication
  • C. Recovery
  • D. Identification

Answer: D

 

NEW QUESTION 348
Drag and drop the correct protocol to its default port.

Answer:

Explanation:

Explanation

FTP uses TCP port 21. Telnet uses port 23.
SSH uses TCP port 22.
All protocols encrypted by SSH, including SFTP, SHTTP, SCP, SExec, and slogin, also use TCP port 22.
Secure Copy Protocol (SCP) is a secure file-transfer facility based on SSH and Remote Copy Protocol (RCP).
Secure FTP (SFTP) is a secured alternative to standard File Transfer Protocol (FTP). SMTP uses TCP port 25.
Port 69 is used by TFTP.
SNMP
makes use of UDP ports 161 and 162. http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers

 

NEW QUESTION 349
When backing up a database server to LTO tape drives, the following backup schedule is used. Backups take one hour to complete:

On Friday at 9:00 p.m., there is a RAID failure on the database server. The data must be restored from backup.
Which of the following is the number of backup tapes that will be needed to complete this operation?

  • A. 0
  • B. 1
  • C. 2
  • D. 3
  • E. 4

Answer: C

 

NEW QUESTION 350
As a security measure, an organization has disabled all external media from accessing the network. Since some users may have data that needs to be transferred to the network, which of the following would BEST assist a security administrator with transferring the data while keeping the internal network secure?

  • A. Upload the media in the DMZ
  • B. Contact the data custodian
  • C. Upload the data in a separate VLAN
  • D. Use a standalone scanning system

Answer: D

 

NEW QUESTION 351
DRAG DROP
A security administrator is given the security and availability profiles for servers that are being deployed.
Match each RAID type with the correct configuration and MINIMUM number of drives.
Review the server profiles and match them with the appropriate RAID type based on integrity, availability, I/O, storage requirements. Instructions:
All drive definitions can be dragged as many times as necessary
Not all placeholders may be filled in the RAID configuration boxes
If parity is required, please select the appropriate number of parity checkboxes
Server profiles may be dragged only once
Instructions: If at any time you would like to bring back the initial state of the simulation, please select the Reset button. When you have completed the simulation, please select the
Done button to submit. Once the simulation is submitted, please select the Next button to continue.

Answer:

Explanation:

Explanation:

RAID-0 is known as striping. It is not a fault tolerant solution but does improve disk performance for read/write operations. Striping requires a minimum of two disks and does not use parity. RAID-0 can be used where performance is required over fault tolerance, such as a media streaming server.
RAID-1 is known as mirroring because the same data is written to two disks so that the two disks have identical data. This is a fault tolerant solution that halves the storage space. A minimum of two disks are used in mirroring and does not use parity. RAID-1 can be used where fault tolerance is required over performance, such as on an authentication server.
RAID-5 is a fault tolerant solution that uses parity and striping. A minimum of three disks are required for RAID-5 with one disk's worth of space being used for parity information.
However, the parity information is distributed across all the disks. RAID-5 can recover from a sing disk failure.
RAID-6 is a fault tolerant solution that uses dual parity and striping. A minimum of four disks are required for RAID-6. Dual parity allows RAID-6 to recover from the simultaneous failure of up to two disks. Critical data should be stored on a RAID-6 system.
References:
Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, 6th Edition, Sybex,
Indianapolis, 2014, pp. 34-36, 234-235

 

NEW QUESTION 352
After being alerted to potential anomalous activity related to trivial DNS lookups, a security analyst looks at the following output of implemented firewall rules:

The analyst notices that the expected policy has no hit count for the day. Which of the following MOST likely occurred?

  • A. Data execution prevention is enabled
  • B. There is a policy violation for DNS lookups
  • C. The VLAN is not trunked properly
  • D. The firewall policy is misconfigured

Answer: D

 

NEW QUESTION 353
An administrator performs a workstation audit and finds one that has non-standard software installed. The administrator then requests a report to see if a change request was completed for the installed software. The report shows a request was completed. Which of the following has the administrator found?

  • A. Unauthorized software
  • B. An insider threat
  • C. A baseline deviation
  • D. A license compliance violation

Answer: C

 

NEW QUESTION 354
A new hire wants to use a personally owned phone to access company resources. The new hire expresses concern about what happens to the data on the phone when they leave the company.
Which of the following portions of the company's mobile device management configuration would allow the company data to be removed from the device without touching the new hire's data?

  • A. Asset control
  • B. Storage lock out
  • C. Storage segmentation
  • D. Device access control

Answer: C

 

NEW QUESTION 355
An organization wants to conduct secure transactions of large data files. Before encrypting and exchanging the data files, the organization wants to ensure a secure exchange of keys. Which of the following algorithms is appropriate for securing the key exchange?

  • A. 3DES
  • B. Blowfish
  • C. Diffie-Hellman
  • D. DES
  • E. DSA

Answer: C

 

NEW QUESTION 356
A security auditor is reviewing the following output from file integrity monitoring software installed on a very busy server at a large service provider. The server has not been updates since it was installed. Drag and drop the log entry that identifies the first instance of server compromise.

Answer:

Explanation:

Explanation
1/1/2017 3:30:00 7813a82384cbaeb45bd12943a9234df3

 

NEW QUESTION 357
A security auditor is reviewing the following output from file integrity monitoring software installed on a very busy server at a large service provider. The server has not been updates since it was installed. Drag and drop the log entry that identifies the first instance of server compromise.

Answer:

Explanation:

 

NEW QUESTION 358
A security administrator is given the security and availability profiles for servers that are being deployed.
* Match each RAID type with the correct configuration and MINIMUM number of drives.
* Review the server profiles and match them with the appropriate RAID type based on integrity, availability, I/O, storage requirements. Instructions:
* All drive definitions can be dragged as many times as necessary
* Not all placeholders may be filled in the RAID configuration boxes
* If parity is required, please select the appropriate number of parity checkboxes
* Server profiles may be dragged only once
If at any time you would like to bring back the initial state of the simulation, please select the Reset button.
When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.

Answer:

Explanation:

Explanation

RAID-0 is known as striping. It is not a fault tolerant solution but does improve disk performance for read/write operations. Striping requires a minimum of two disks and does not use parity.
RAID-0 can be used where performance is required over fault tolerance, such as a media streaming server.
RAID-1 is known as mirroring because the same data is written to two disks so that the two disks have identical data. This is a fault tolerant solution that halves the storage space. A minimum of two disks are used in mirroring and does not use parity. RAID-1 can be used where fault tolerance is required over performance, such as on an authentication server. RAID-5 is a fault tolerant solution that uses parity and striping. A minimum of three disks are required for RAID-5 with one disk's worth of space being used for parity information. However, the parity information is distributed across all the disks. RAID-5 can recover from a sing disk failure.
RAID-6 is a fault tolerant solution that uses dual parity and striping. A minimum of four disks are required for RAID-6. Dual parity allows RAID-6 to recover from the simultaneous failure of up to two disks. Critical data should be stored on a RAID-6 system.
http://www.adaptec.com/en-us/solutions/raid_levels.html

 

NEW QUESTION 359
A company is having issues with intellectual property being sent to a competitor from its system. The information being sent is not random but has an identifiable pattern Which of the following should be implemented in the system to stop the content from being sent?

  • A. IPS
  • B. DLP
  • C. Encryption
  • D. Hashing

Answer: B

 

NEW QUESTION 360
Which of the following is MOST likely happening?

  • A. A hacker attempted to pivot using the web server interface.
  • B. A potential hacker could be banner grabbing to determine what architecture is being used
  • C. The DNS is misconfigured for the server's IP address.
  • D. A server is experiencing DoS, and the request Is timing out.

Answer: A

 

NEW QUESTION 361
......


What Should You Know about SY0-501 Test Objectives?

The test details for every objective are highlighted below:

Cryptography and PKI

This topic will confirm if you can compare and contrast the most basic concepts of cryptography. Besides, it also covers the algorithms of cryptography and their features, the installation and configuration of wireless security settings, and the implementation of public key infrastructure. In particular, you will learn to deal with Hashing, Salt, IV, symmetric algorithms, cipher modes, wireless security settings, and Objects Identifiers (OID).

 

SYO-501 certification guide Q&A from Training Expert TestPDF: https://www.testpdf.com/SYO-501-exam-braindumps.html