It is more faster and easier to pass the by using . Immediate access to the and find the same core area with professionally verified answers, then PASS your exam with a high score now.
Free demo questions for CompTIA SY0-501 Exam Dumps Below:
NEW QUESTION 1
A security analyst is inspecting the results of a recent internal vulnerability scan that was performed against intranet services. The scan reports include the following critical-rated vulnerability:
Title: Remote Command Execution vulnerability in web server Rating: Critical (CVSS 10.0) Threat actor: any remote user of the web server
Confidence: certain
Recommendation: apply vendor patches
Which of the following actions should the security analyst perform FIRST?
- A. Escalate the issue to senior management.
- B. Apply organizational context to the risk rating.
- C. Organize for urgent out-of-cycle patching.
- D. Exploit the server to check whether it is a false positive.
Answer: B
NEW QUESTION 2
A security administrator is trying to encrypt communication. For which of the following reasons should administrator take advantage of the Subject Alternative Name (SAM) attribute of a certificate?
- A. It can protect multiple domains
- B. It provides extended site validation
- C. It does not require a trusted certificate authority
- D. It protects unlimited subdomains
Answer: B
NEW QUESTION 3
A systems administrator wants to provide balance between the security of a wireless network and usability. The administrator is concerned with wireless encryption compatibility of older devices used by some employees. Which of the following would provide strong security and backward compatibility when accessing the wireless network?
- A. Open wireless network and SSL VPN
- B. WPA using a preshared key
- C. WPA2 using a RADIUS back-end for 802.1x authentication
- D. WEP with a 40-bit key
Answer: A
NEW QUESTION 4
Recently several employees were victims of a phishing email that appeared to originate from the company president. The email claimed the employees would be disciplined if they did not click on a malicious link in the message. Which of the following principles of social engineering made this attack successful?
- A. Authority
- B. Spamming
- C. Social proof
- D. Scarcity
Answer: A
NEW QUESTION 5
In an effort to reduce data storage requirements, some company devices to hash every file and eliminate duplicates. The data processing routines are time sensitive so the hashing algorithm is fast and supported on a wide range of systems. Which of the following algorithms is BEST suited for this purpose?
- A. MD5
- B. SHA
- C. RIPEMD
- D. AES
Answer: B
NEW QUESTION 6
A company recently replaced its unsecure email server with a cloud-based email and collaboration solution that is managed and insured by a third party. Which of the following actions did the company take regarding risks related to its email and collaboration services?
- A. Transference
- B. Acceptance
- C. Mitigation
- D. Deterrence
Answer: A
NEW QUESTION 7
A supervisor in your organization was demoted on Friday afternoon. The supervisor had the ability to modify the contents of a confidential database, as well as other managerial permissions. On Monday morning, the database administrator reported that log files indicated that several records were missing from the database. Which of the following risk mitigation strategies should have been implemented when the supervisor was demoted?
- A. Incident management
- B. Routine auditing
- C. IT governance
- D. Monthly user rights reviews
Answer: D
NEW QUESTION 8
An administrator discovers the following log entry on a server: Nov 12 2013 00:23:45 httpd[2342]:
GET/app2/prod/proc/process.php?input=change;cd%20../../../etc;cat%20shadow
Which of the following attacks is being attempted?
- A. Command injection
- B. Password attack
- C. Buffer overflow
- D. Cross-site scripting
Answer: B
NEW QUESTION 9
Joe a website administrator believes he owns the intellectual property for a company invention and has been replacing image files on the company's public facing website in the DMZ. Joe is using steganography to hide stolen data. Which of the following controls can be implemented to mitigate this type of inside threat?
- A. Digital signatures
- B. File integrity monitoring
- C. Access controls
- D. Change management
- E. Stateful inspection firewall
Answer: B
NEW QUESTION 10
An incident response manager has started to gather all the facts related to a SIEM alert showing multiple systems may have been compromised.
The manager has gathered these facts:
The breach is currently indicated on six user PCs One service account is potentially compromised Executive management has been notified
In which of the following phases of the IRP is the manager currently working?
- A. Recovery
- B. Eradication
- C. Containment
- D. Identification
Answer: D
NEW QUESTION 11
Which of the following is an important step to take BEFORE moving any installation packages from a test environment to production?
- A. Roll back changes in the test environment
- B. Verify the hashes of files
- C. Archive and compress the files
- D. Update the secure baseline
Answer: B
NEW QUESTION 12
An auditor has identified an access control system that can incorrectly accept an access attempt from an unauthorized user. Which of the following authentication systems has the auditor reviewed?
- A. Password-based
- B. Biometric-based
- C. Location-based
- D. Certificate-based
Answer: B
NEW QUESTION 13
Which of the following allows an application to securely authenticate a user by receiving credentials from a web domain?
- A. TACACS+
- B. RADIUS
- C. Kerberos
- D. SAML
Answer: D
NEW QUESTION 14
A security analyst is reviewing patches on servers. One of the servers is reporting the following error message in the WSUS management console:
The computer has not reported status in 30 days.
Given this scenario, which of the following statements BEST represents the issue with the output above?
- A. The computer in QUESTION NO: has not pulled the latest ACL policies for the firewall.
- B. The computer in QUESTION NO: has not pulled the latest GPO policies from the management server.
- C. The computer in QUESTION NO: has not pulled the latest antivirus definitions from the antivirus program.
- D. The computer in QUESTION NO: has not pulled the latest application software updates.
Answer: D
NEW QUESTION 15
A technician must configure a firewall to block external DNS traffic from entering a network. Which of the following ports should they block on the firewall?
- A. 53
- B. 110
- C. 143
- D. 443
Answer: A
NEW QUESTION 16
An administrator thinks the UNIX systems may be compromised, but a review of system log files provides no useful information. After discussing the situation with the security team, the administrator suspects that the attacker may be altering the log files and removing evidence of intrusion activity. Which of the following actions will help detect attacker attempts to further alter log files?
- A. Enable verbose system logging
- B. Change the permissions on the user's home directory
- C. Implement remote syslog
- D. Set the bash_history log file to "read only"
Answer: C
Recommend!! Get the Full SY0-501 dumps in VCE and PDF From Certleader, Welcome to Download: https://www.certleader.com/SY0-501-dumps.html (New 540 Q&As Version)