We provide in two formats. Download PDF & Practice Tests. Pass CompTIA SY0-501 Exam quickly & easily. The SY0-501 PDF type is available for reading and printing. You can print more and practice many times. With the help of our product and material, you can easily pass the SY0-501 exam.

Free SY0-501 Demo Online For Microsoft Certifitcation:

NEW QUESTION 1
The help desk is receiving numerous password change alerts from users in the accounting department. These alerts occur multiple times on the same day for each of the affected users' accounts. Which of the following controls should be implemented to curtail this activity?

  • A. Password Reuse
  • B. Password complexity
  • C. Password History
  • D. Password Minimum age

Answer: D

NEW QUESTION 2
When designing a web based client server application with single application server and database cluster backend, input validation should be performed:

  • A. On the client
  • B. Using database stored procedures
  • C. On the application server
  • D. Using HTTPS

Answer: C

NEW QUESTION 3
Every morning, a systems administrator monitors failed login attempts on the company's log management server. The administrator notices the DBAdmin account has five failed username and/or password alerts during a ten-minute window. The systems administrator determines the user account is a dummy account used to attract attackers. Which of the following techniques should the systems administrator implement?

  • A. Role-based access control
  • B. Honeypot
  • C. Rule-based access control
  • D. Password cracker

Answer: B

NEW QUESTION 4
A global gaming console manufacturer is launching a new gaming platform to its customers. Which of the following controls reduces the risk created by malicious gaming customers attempting to circumvent control by way of modifying consoles?

  • A. Firmware version control
  • B. Manual software upgrades
  • C. Vulnerability scanning
  • D. Automatic updates
  • E. Network segmentation
  • F. Application firewalls

Answer: AD

NEW QUESTION 5
The firewall administrator is adding a new certificate for the company's remote access solution. The solution requires that the uploaded file contain the entire certificate chain for the certificate to load properly. The administrator loads the company certificate and the root CA certificate into the file. The file upload is rejected. Which of the following is required to complete the certificate chain?

  • A. Certificate revocation list
  • B. Intermediate authority
  • C. Recovery agent
  • D. Root of trust

Answer: B

NEW QUESTION 6
A security administrator needs to address the following audit recommendations for a public-facing SFTP server:
Users should be restricted to upload and download files to their own home directories only. Users should not be allowed to use interactive shell login.
Which of the following configuration parameters should be implemented? (Select TWO).

  • A. PermitTunnel
  • B. ChrootDirectory
  • C. PermitTTY
  • D. AllowTcpForwarding
  • E. IgnoreRhosts

Answer: BC

NEW QUESTION 7
A system administrator wants to implement an internal communication system that will allow employees to send encrypted messages to each other. The system must also support non- repudiation. Which of the following implements all these requirements?

  • A. Bcrypt
  • B. Blowfish
  • C. PGP
  • D. SHA

Answer: C

NEW QUESTION 8
Which of the following best describes routine in which semicolons, dashes, quotes, and commas are removed from a string?

  • A. Error handling to protect against program exploitation
  • B. Exception handling to protect against XSRF attacks.
  • C. Input validation to protect against SQL injection.
  • D. Padding to protect against string buffer overflows.

Answer: C

NEW QUESTION 9
An office manager found a folder that included documents with various types of data relating to corporate clients. The office manager notified the data included dates of birth, addresses, and phone numbers for the clients. The office manager then reported this finding to the security compliance officer. Which of the following portions of the policy would the security officer need to consult to determine if a breach has occurred?

  • A. Public
  • B. Private
  • C. PHI
  • D. PII

Answer: D

NEW QUESTION 10
A security administrator is configuring a new network segment, which contains devices that will be accessed by external users, such as web and FTP server. Which of the following represents the MOST secure way to
configure the new network segment?

  • A. The segment should be placed on a separate VLAN, and the firewall rules should be configured to allow external traffic.
  • B. The segment should be placed in the existing internal VLAN to allow internal traffic only.
  • C. The segment should be placed on an intranet, and the firewall rules should be configured to allow external traffic.
  • D. The segment should be placed on an extranet, and the firewall rules should be configured to allow both internal and external traffic.

Answer: A

NEW QUESTION 11
An administrator has configured a new Linux server with the FTP service. Upon verifying that the service was configured correctly, the administrator has several users test the FTP service. Users report that they are able to connect to the FTP service and download their personal files, however, they cannot transfer new files to the server. Which of the following will most likely fix the uploading issue for the users?

  • A. Create an ACL to allow the FTP service write access to user directories
  • B. Set the Boolean selinux value to allow FTP home directory uploads
  • C. Reconfigure the ftp daemon to operate without utilizing the PSAV mode
  • D. Configure the FTP daemon to utilize PAM authentication pass through user permissions

Answer: A

NEW QUESTION 12
Which of the following are methods to implement HA in a web application server environment? (Select two.)

  • A. Load balancers
  • B. Application layer firewalls
  • C. Reverse proxies
  • D. VPN concentrators
  • E. Routers

Answer: AB

NEW QUESTION 13
Which of the following best describes the initial processing phase used in mobile device forensics?

  • A. The phone should be powered down and the battery removed to preserve the state of data on any internal or removable storage utilized by the mobile device
  • B. The removable data storage cards should be processed first to prevent data alteration when examining the mobile device
  • C. The mobile device should be examined first, then removable storage and lastly the phone without removable storage should be examined again
  • D. The phone and storage cards should be examined as a complete unit after examining the removable storage cards separately.

Answer: D

NEW QUESTION 14
A security analyst is reviewing the following packet capture of an attack directed at a company's server located in the DMZ:
SY0-501 dumps exhibit
Which of the following ACLs provides the BEST protection against the above attack and any further attacks from the same IP, while minimizing service interruption?

  • A. DENY TCO From ANY to 172.31.64.4
  • B. Deny UDP from 192.168.1.0/24 to 172.31.67.0/24
  • C. Deny IP from 192.168.1.10/32 to 0.0.0.0/0
  • D. Deny TCP from 192.168.1.10 to 172.31.67.4

Answer: D

NEW QUESTION 15
A business has recently deployed laptops to all sales employees. The laptops will be used primarily from home offices and while traveling, and a high amount of wireless mobile use is expected. To protect the laptops while connected to untrusted wireless networks, which of the following would be the BEST method for reducing the risk of having the laptops compromised?

  • A. MAC filtering
  • B. Virtualization
  • C. OS hardening
  • D. Application white-listing

Answer: C

NEW QUESTION 16
A security administrator determined that users within the company are installing unapproved software. Company policy dictates that only certain applications may be installed or ran on the user's computers without exception. Which of the following should the administrator do to prevent all unapproved software from running on the user's computer?

  • A. Deploy antivirus software and configure it to detect and remove pirated software
  • B. Configure the firewall to prevent the downloading of executable files
  • C. Create an application whitelist and use OS controls to enforce it
  • D. Prevent users from running as administrator so they cannot install software.

Answer: C

P.S. Easily pass SY0-501 Exam with 540 Q&As Surepassexam Dumps & pdf Version, Welcome to Download the Newest Surepassexam SY0-501 Dumps: https://www.surepassexam.com/SY0-501-exam-dumps.html (540 New Questions)