SY0-301 Part 1

Beschreibung

Questions 1 - 50
Brooks Thornhill
Quiz von Brooks Thornhill, aktualisiert more than 1 year ago
Brooks Thornhill
Erstellt von Brooks Thornhill vor mehr als 7 Jahre
12
0

Zusammenfassung der Ressource

Frage 1

Frage
Which of the following elements of PKI are found in a browser's trusted root CA?
Antworten
  • Private key
  • Symmetric key
  • Recovery key
  • Public key

Frage 2

Frage
Which of the following protocols only encrypts password packets from client to server?
Antworten
  • XTACACS
  • TACACS
  • RADIUS
  • TACACS+

Frage 3

Frage
Where are revoked certificates stored?
Antworten
  • Recovery agent
  • Registration
  • Key escrow
  • CRL

Frage 4

Frage
DRPs should contain which of the following?
Antworten
  • Hierarchical list of non-critical personnel
  • Hierarchical list of critical systems
  • Hierarchical access control lists
  • Identification of single points of failure

Frage 5

Frage
A system administrator could have a user level account and an administrator account to prevent:
Antworten
  • password sharing
  • escalation of privileges
  • implicit deny
  • administrative account lockout

Frage 6

Frage
Which of the following is the BEST way to mitigate data loss if a portable device is compromised?
Antworten
  • Full disk encryption
  • Common access card
  • Strong password complexity
  • Biometric authentication

Frage 7

Frage
Which of the following protocols should be blocked at the network perimeter to prevent host enumeration by sweep devices?
Antworten
  • HTTPS
  • SSH
  • IPv4
  • ICMP

Frage 8

Frage
Which of the following is specific to a buffer overflow attack?
Antworten
  • Memory addressing
  • Directory traversal
  • Initialization vector
  • Session cookies

Frage 9

Frage
Which of the following asymmetric encryption keys is used to encrypt data to ensure only the intended recipient can decrypt the ciphertext?
Antworten
  • Private
  • Escrow
  • Public
  • Preshared

Frage 10

Frage
Which of the following should a security administrator implement to prevent users from disrupting network connectivity, if a user connects both ends of a network cable to different switch ports?
Antworten
  • VLAN separation
  • Access control
  • Loop protection
  • DMZ

Frage 11

Frage
A new enterprise solution is currently being evaluated due to its potential to increase the company's profit margins. The security administrator has been asked to review its security implications. While evaluating the product, various vulnerability scans were performed. It was determined that the product is not a threat but has the potential to introduce additional vulnerabilities. Which of the following assessment types should the security administrator also take into consideration while evaluating this product?
Antworten
  • Threat assessment
  • Vulnerability assessment
  • Code assessment
  • Risk assessment

Frage 12

Frage
Which of the following requires special handling and explicit policies for data retention and data distribution?
Antworten
  • Personally identifiable information
  • Phishing attacks
  • Zero day exploits
  • Personal electronic devices

Frage 13

Frage
Centrally authenticating multiple systems and applications against a federated user database is an example of:
Antworten
  • smart card
  • common access card
  • single sign-on
  • access control list

Frage 14

Frage
WEP is seen as an unsecure protocol based on its improper implementation and use of which of the following?
Antworten
  • RC6
  • RC4
  • 3DES
  • AES

Frage 15

Frage
Which of the following should be performed if a smartphone is lost to ensure no data can be retrieved from it?
Antworten
  • Device encryption
  • Remote wipe
  • Screen lock
  • GPS tracking

Frage 16

Frage
In an 802.11n network, which of the following provides the MOST secure method of both encryption and authorization?
Antworten
  • WEP with 802.1x
  • WPA Enterprise
  • WPA2-PSK
  • WPA with TKIP

Frage 17

Frage
Which of the following methods of access, authentication, and authorization is the MOST secure by default?
Antworten
  • Kerberos
  • TACACS
  • RADIUS
  • LDAP

Frage 18

Frage
Which of the following facilitates computing for heavily utilized systems and networks?
Antworten
  • Remote access
  • Provider cloud
  • VPN concentrator
  • Telephony

Frage 19

Frage
With which of the following is RAID MOST concerned?
Antworten
  • Integrity
  • Confidentiality
  • Availability
  • Baselining

Frage 20

Frage
Which of the following reduces the likelihood of a single point of failure when a server fails?
Antworten
  • Clustering
  • Virtualization
  • RAID
  • Cold site

Frage 21

Frage
A user downloads a keygen to install pirated software. After running the keygen, system performance is extremely slow and numerous antivirus alerts are displayed. Which of the following BEST describes this type of malware?
Antworten
  • Logic bomb
  • Worm
  • Trojan
  • Adware

Frage 22

Frage
Which of the following is used in conjunction with PEAP to provide mutual authentication between peers?
Antworten
  • LEAP
  • MSCHAPv2
  • PPP
  • MSCHAPv1

Frage 23

Frage
A targeted email attack sent to the company's Chief Executive Officer (CEO) is known as which of the following?
Antworten
  • Whaling
  • Bluesnarfing
  • Vishing
  • Dumpster diving

Frage 24

Frage
Which of the following uses TCP port 22 by default?
Antworten
  • SSL, SCP, and TFTP
  • SSH, SCP, and SFTP
  • HTTPS, SFTP, and TFTP
  • TLS, TELNET, and SCP

Frage 25

Frage
Actively monitoring data streams in search of malicious code or behavior is an example of:
Antworten
  • load balancing
  • an Internet proxy
  • URL filtering
  • content inspection

Frage 26

Frage
A user is no longer able to transfer files to the FTP server. The security administrator has verified the ports are open on the network firewall. Which of the following should the security administrator check?
Antworten
  • Anti-virus software
  • ACLs
  • Anti-spam software
  • NIDS

Frage 27

Frage
A Human Resource manager is assigning access to users in their specific department performing the same job function. This is an example of:
Antworten
  • role-based access control
  • rule-based access control
  • centralized access control
  • mandatory access control

Frage 28

Frage
Which of the following BEST describes the process of key escrow?
Antworten
  • Maintains a copy of a user's public key for the sole purpose of recovering messages if it is lost
  • Maintains a secured copy of a user's private key to recover the certificate revocation list
  • Maintains a secured copy of a user's private key for the sole purpose of recovering the key if it is lost
  • Maintains a secured copy of a user's public key in order to improve network performance

Frage 29

Frage
Which of the following network devices would MOST likely be used to detect but not react to suspicious behavior on the network?
Antworten
  • Firewall
  • NIDS
  • NIPS
  • HIDS

Frage 30

Frage
Which of the following is an example of allowing a user to perform a self-service password reset?
Antworten
  • Password length
  • Password recovery
  • Password complexity
  • Password expiration

Frage 31

Frage
Which of the following wireless attacks uses a counterfeit base station with the same SSID name as a nearby intended wireless network?
Antworten
  • War driving
  • Evil twin
  • Rogue access point
  • War chalking

Frage 32

Frage
A security administrator finished taking a forensic image of a computer's memory. Which of the following should the administrator do to ensure image integrity?
Antworten
  • Run the image through AES128
  • Run the image through a symmetric encryption algorithm
  • Compress the image to a password protected archive
  • Run the image through SHA256

Frage 33

Frage
Which of the following BEST explains the security benefit of a standardized server image?
Antworten
  • All current security updates for the operating system will have already been applied
  • Mandated security configurations have been made to the operating system
  • Anti-virus software will be installed and current
  • Operating system license use is easier to track

Frage 34

Frage
Which of the following is the primary purpose of using a digital signature? (Select TWO)
Antworten
  • Encryption
  • Integrity
  • Confidentiality
  • Non-repudiation
  • Availability

Frage 35

Frage
Which of the following must a security administrator do when the private key of a web server has been compromised by an intruder?
Antworten
  • Submit the public key to the CRL
  • Use the recovery agent to revoke the key
  • Submit the private key to the CRL
  • Issue a new CA

Frage 36

Frage
The security administrator often observes that an employee who entered the datacenter does not match the owner of the PIN that was entered into the keypad. Which of the following would BEST prevent this situation?
Antworten
  • Multifactor authentication
  • Username and password
  • Mandatory access control
  • Biometrics

Frage 37

Frage
A programmer allocates 16 bytes for a string variable, but does not adequately ensure that more than 16 bytes cannot be copied into the variable. This program may be vulnerable to which of the following attacks?
Antworten
  • Buffer overflow
  • Cross-site scripting
  • Session hijacking
  • Directory traversal

Frage 38

Frage
An administrator is updating firmware on routers throughout the company. Where should the administrator document this work?
Antworten
  • Event Viewer
  • Router's System Log
  • Change Management System
  • Compliance Review System

Frage 39

Frage
The fundamental difference between symmetric and asymmetric key cryptographic systems is that symmetric key cryptography uses:
Antworten
  • multiple keys for non-repudiation of bulk data
  • different keys on both ends of the transport medium
  • bulk encryption for data transmission over fiber
  • the same key on each end of the transmission medium

Frage 40

Frage
Which of the following allows a user to have a one-time password?
Antworten
  • Biometrics
  • SSO
  • PIV
  • Tokens

Frage 41

Frage
Which of the following allows a security administrator to set device traps?
Antworten
  • SNMP
  • TLS
  • ICMP
  • SSH

Frage 42

Frage
Which of the following is the BEST way to secure data for the purpose of retention?
Antworten
  • Off-site backup
  • RAID 5 on-site backup
  • On-site clustering
  • Virtualization

Frage 43

Frage
In which of the following locations would a forensic analyst look to find a hooked process?
Antworten
  • BIOS
  • Slack space
  • RAM
  • Rootkit

Frage 44

Frage
Several classified mobile devices have been stolen. Which of the following would BEST reduce the data leakage threat?
Antworten
  • Use GPS tracking to find the devices
  • Use stronger encryption algorithms
  • Immediately inform local law enforcement
  • Remotely sanitize the devices

Frage 45

Frage
Which of the following is an example of requiring users to have a password of 16 characters or more?
Antworten
  • Password recovery requirements
  • Password complexity requirements
  • Password expiration requirements
  • Password length requirements

Frage 46

Frage
Which of the following devices provides storage for RSA or asymmetric keys and may assist in user authentication? (Select TWO)
Antworten
  • Trusted platform module
  • Hardware security module
  • Facial recognition scanner
  • Full disk encryption
  • Encrypted USB

Frage 47

Frage
A small company needs to invest in a new expensive database. The company's budget does not include the purchase of additional servers or personnel. Which of the following solutions would allow the small company to save money on hiring additional personnel and minimize the footprint in their current datacenter?
Antworten
  • Allow users to telecommute
  • Setup a load balancer
  • Infrastructure as a Service
  • Software as a Service

Frage 48

Frage
A security administrator needs to implement a site-to-site VPN tunnel between the main office and a remote branch. Which of the following protocols should be used for the tunnel?
Antworten
  • RTP
  • SNMP
  • IPSec
  • 802.1X

Frage 49

Frage
When examining HTTP server logs the security administrator notices that the company's online store crashes after a particular search string is executed by a single external user. Which of the following BEST describes this type of attack?
Antworten
  • Spim
  • DDoS
  • Spoofing
  • DoS

Frage 50

Frage
Which of the following MUST a programmer implement to prevent cross-site scripting?
Antworten
  • Validate input to remove shell scripts
  • Validate input to remove hypertext
  • Validate input to remove batch files
  • Validate input to remove Java bit code
Zusammenfassung anzeigen Zusammenfassung ausblenden

ähnlicher Inhalt

Zeiten Englisch
Janine Egli
Teil B, Kapitel 3, Entscheidungsgrundlagen bei der Wahl der Rechtsform
Stefan Kurtenbach
Phyikum (Biologie/ Biochemie)
anna.grillborzer0656
PuKW Step 2 Neue Ausgearbeitete Fragen
Tim2015
The Commonwealth
Laura D
Grundlagen der Stochastik - Zusammenfassung
Flo Rian
Lf. 2 Büroprozesse gestalten und Arbeitsvorgänge organisieren
Sarah Schneider
WT1 Uni Due
Awash Kaul
Tierhaltung/-hygiene Klausur (Jahr unbekannt)
Kim Langner
Vetie - Klausur Tierhaltung und Tierhygiene 2018
E. König
Vetie - Innere Medzin 2018
Fioras Hu