Brooks Thornhill
Test por , creado hace más de 1 año

Questions 1 - 50

12
0
0
Brooks Thornhill
Creado por Brooks Thornhill hace casi 8 años
Cerrar

SY0-301 Part 1

Pregunta 1 de 50

1

Which of the following elements of PKI are found in a browser's trusted root CA?

Selecciona una de las siguientes respuestas posibles:

  • Private key

  • Symmetric key

  • Recovery key

  • Public key

Explicación

Pregunta 2 de 50

1

Which of the following protocols only encrypts password packets from client to server?

Selecciona una de las siguientes respuestas posibles:

  • XTACACS

  • TACACS

  • RADIUS

  • TACACS+

Explicación

Pregunta 3 de 50

1

Where are revoked certificates stored?

Selecciona una de las siguientes respuestas posibles:

  • Recovery agent

  • Registration

  • Key escrow

  • CRL

Explicación

Pregunta 4 de 50

1

DRPs should contain which of the following?

Selecciona una de las siguientes respuestas posibles:

  • Hierarchical list of non-critical personnel

  • Hierarchical list of critical systems

  • Hierarchical access control lists

  • Identification of single points of failure

Explicación

Pregunta 5 de 50

1

A system administrator could have a user level account and an administrator account to prevent:

Selecciona una de las siguientes respuestas posibles:

  • password sharing

  • escalation of privileges

  • implicit deny

  • administrative account lockout

Explicación

Pregunta 6 de 50

1

Which of the following is the BEST way to mitigate data loss if a portable device is compromised?

Selecciona una de las siguientes respuestas posibles:

  • Full disk encryption

  • Common access card

  • Strong password complexity

  • Biometric authentication

Explicación

Pregunta 7 de 50

1

Which of the following protocols should be blocked at the network perimeter to prevent host enumeration by
sweep devices?

Selecciona una de las siguientes respuestas posibles:

  • HTTPS

  • SSH

  • IPv4

  • ICMP

Explicación

Pregunta 8 de 50

1

Which of the following is specific to a buffer overflow attack?

Selecciona una de las siguientes respuestas posibles:

  • Memory addressing

  • Directory traversal

  • Initialization vector

  • Session cookies

Explicación

Pregunta 9 de 50

1

Which of the following asymmetric encryption keys is used to encrypt data to ensure only the intended recipient
can decrypt the ciphertext?

Selecciona una de las siguientes respuestas posibles:

  • Private

  • Escrow

  • Public

  • Preshared

Explicación

Pregunta 10 de 50

1

Which of the following should a security administrator implement to prevent users from disrupting network
connectivity, if a user connects both ends of a network cable to different switch ports?

Selecciona una de las siguientes respuestas posibles:

  • VLAN separation

  • Access control

  • Loop protection

  • DMZ

Explicación

Pregunta 11 de 50

1

A new enterprise solution is currently being evaluated due to its potential to increase the company's profit
margins. The security administrator has been asked to review its security implications. While evaluating the
product, various vulnerability scans were performed. It was determined that the product is not a threat but has
the potential to introduce additional vulnerabilities. Which of the following assessment types should the security
administrator also take into consideration while evaluating this product?

Selecciona una de las siguientes respuestas posibles:

  • Threat assessment

  • Vulnerability assessment

  • Code assessment

  • Risk assessment

Explicación

Pregunta 12 de 50

1

Which of the following requires special handling and explicit policies for data retention and data distribution?

Selecciona una de las siguientes respuestas posibles:

  • Personally identifiable information

  • Phishing attacks

  • Zero day exploits

  • Personal electronic devices

Explicación

Pregunta 13 de 50

1

Centrally authenticating multiple systems and applications against a federated user database is an example of:

Selecciona una de las siguientes respuestas posibles:

  • smart card

  • common access card

  • single sign-on

  • access control list

Explicación

Pregunta 14 de 50

1

WEP is seen as an unsecure protocol based on its improper implementation and use of which of the following?

Selecciona una de las siguientes respuestas posibles:

  • RC6

  • RC4

  • 3DES

  • AES

Explicación

Pregunta 15 de 50

1

Which of the following should be performed if a smartphone is lost to ensure no data can be retrieved from it?

Selecciona una de las siguientes respuestas posibles:

  • Device encryption

  • Remote wipe

  • Screen lock

  • GPS tracking

Explicación

Pregunta 16 de 50

1

In an 802.11n network, which of the following provides the MOST secure method of both encryption and
authorization?

Selecciona una de las siguientes respuestas posibles:

  • WEP with 802.1x

  • WPA Enterprise

  • WPA2-PSK

  • WPA with TKIP

Explicación

Pregunta 17 de 50

1

Which of the following methods of access, authentication, and authorization is the MOST secure by default?

Selecciona una de las siguientes respuestas posibles:

  • Kerberos

  • TACACS

  • RADIUS

  • LDAP

Explicación

Pregunta 18 de 50

1

Which of the following facilitates computing for heavily utilized systems and networks?

Selecciona una de las siguientes respuestas posibles:

  • Remote access

  • Provider cloud

  • VPN concentrator

  • Telephony

Explicación

Pregunta 19 de 50

1

With which of the following is RAID MOST concerned?

Selecciona una de las siguientes respuestas posibles:

  • Integrity

  • Confidentiality

  • Availability

  • Baselining

Explicación

Pregunta 20 de 50

1

Which of the following reduces the likelihood of a single point of failure when a server fails?

Selecciona una de las siguientes respuestas posibles:

  • Clustering

  • Virtualization

  • RAID

  • Cold site

Explicación

Pregunta 21 de 50

1

A user downloads a keygen to install pirated software. After running the keygen, system performance is
extremely slow and numerous antivirus alerts are displayed. Which of the following BEST describes this type of
malware?

Selecciona una de las siguientes respuestas posibles:

  • Logic bomb

  • Worm

  • Trojan

  • Adware

Explicación

Pregunta 22 de 50

1

Which of the following is used in conjunction with PEAP to provide mutual authentication between peers?

Selecciona una de las siguientes respuestas posibles:

  • LEAP

  • MSCHAPv2

  • PPP

  • MSCHAPv1

Explicación

Pregunta 23 de 50

1

A targeted email attack sent to the company's Chief Executive Officer (CEO) is known as which of the
following?

Selecciona una de las siguientes respuestas posibles:

  • Whaling

  • Bluesnarfing

  • Vishing

  • Dumpster diving

Explicación

Pregunta 24 de 50

1

Which of the following uses TCP port 22 by default?

Selecciona una de las siguientes respuestas posibles:

  • SSL, SCP, and TFTP

  • SSH, SCP, and SFTP

  • HTTPS, SFTP, and TFTP

  • TLS, TELNET, and SCP

Explicación

Pregunta 25 de 50

1

Actively monitoring data streams in search of malicious code or behavior is an example of:

Selecciona una de las siguientes respuestas posibles:

  • load balancing

  • an Internet proxy

  • URL filtering

  • content inspection

Explicación

Pregunta 26 de 50

1

A user is no longer able to transfer files to the FTP server. The security administrator has verified the ports are
open on the network firewall. Which of the following should the security administrator check?

Selecciona una de las siguientes respuestas posibles:

  • Anti-virus software

  • ACLs

  • Anti-spam software

  • NIDS

Explicación

Pregunta 27 de 50

1

A Human Resource manager is assigning access to users in their specific department performing the same job
function. This is an example of:

Selecciona una de las siguientes respuestas posibles:

  • role-based access control

  • rule-based access control

  • centralized access control

  • mandatory access control

Explicación

Pregunta 28 de 50

1

Which of the following BEST describes the process of key escrow?

Selecciona una de las siguientes respuestas posibles:

  • Maintains a copy of a user's public key for the sole purpose of recovering messages if it is lost

  • Maintains a secured copy of a user's private key to recover the certificate revocation list

  • Maintains a secured copy of a user's private key for the sole purpose of recovering the key if it is lost

  • Maintains a secured copy of a user's public key in order to improve network performance

Explicación

Pregunta 29 de 50

1

Which of the following network devices would MOST likely be used to detect but not react to suspicious
behavior on the network?

Selecciona una de las siguientes respuestas posibles:

  • Firewall

  • NIDS

  • NIPS

  • HIDS

Explicación

Pregunta 30 de 50

1

Which of the following is an example of allowing a user to perform a self-service password reset?

Selecciona una de las siguientes respuestas posibles:

  • Password length

  • Password recovery

  • Password complexity

  • Password expiration

Explicación

Pregunta 31 de 50

1

Which of the following wireless attacks uses a counterfeit base station with the same SSID name as a nearby
intended wireless network?

Selecciona una de las siguientes respuestas posibles:

  • War driving

  • Evil twin

  • Rogue access point

  • War chalking

Explicación

Pregunta 32 de 50

1

A security administrator finished taking a forensic image of a computer's memory. Which of the following should
the administrator do to ensure image integrity?

Selecciona una de las siguientes respuestas posibles:

  • Run the image through AES128

  • Run the image through a symmetric encryption algorithm

  • Compress the image to a password protected archive

  • Run the image through SHA256

Explicación

Pregunta 33 de 50

1

Which of the following BEST explains the security benefit of a standardized server image?

Selecciona una de las siguientes respuestas posibles:

  • All current security updates for the operating system will have already been applied

  • Mandated security configurations have been made to the operating system

  • Anti-virus software will be installed and current

  • Operating system license use is easier to track

Explicación

Pregunta 34 de 50

1

Which of the following is the primary purpose of using a digital signature? (Select TWO)

Selecciona una o más de las siguientes respuestas posibles:

  • Encryption

  • Integrity

  • Confidentiality

  • Non-repudiation

  • Availability

Explicación

Pregunta 35 de 50

1

Which of the following must a security administrator do when the private key of a web server has been
compromised by an intruder?

Selecciona una de las siguientes respuestas posibles:

  • Submit the public key to the CRL

  • Use the recovery agent to revoke the key

  • Submit the private key to the CRL

  • Issue a new CA

Explicación

Pregunta 36 de 50

1

The security administrator often observes that an employee who entered the datacenter does not match the
owner of the PIN that was entered into the keypad. Which of the following would BEST prevent this situation?

Selecciona una de las siguientes respuestas posibles:

  • Multifactor authentication

  • Username and password

  • Mandatory access control

  • Biometrics

Explicación

Pregunta 37 de 50

1

A programmer allocates 16 bytes for a string variable, but does not adequately ensure that more than 16 bytes
cannot be copied into the variable. This program may be vulnerable to which of the following attacks?

Selecciona una de las siguientes respuestas posibles:

  • Buffer overflow

  • Cross-site scripting

  • Session hijacking

  • Directory traversal

Explicación

Pregunta 38 de 50

1

An administrator is updating firmware on routers throughout the company. Where should the administrator
document this work?

Selecciona una de las siguientes respuestas posibles:

  • Event Viewer

  • Router's System Log

  • Change Management System

  • Compliance Review System

Explicación

Pregunta 39 de 50

1

The fundamental difference between symmetric and asymmetric key cryptographic systems is that symmetric
key cryptography uses:

Selecciona una de las siguientes respuestas posibles:

  • multiple keys for non-repudiation of bulk data

  • different keys on both ends of the transport medium

  • bulk encryption for data transmission over fiber

  • the same key on each end of the transmission medium

Explicación

Pregunta 40 de 50

1

Which of the following allows a user to have a one-time password?

Selecciona una de las siguientes respuestas posibles:

  • Biometrics

  • SSO

  • PIV

  • Tokens

Explicación

Pregunta 41 de 50

1

Which of the following allows a security administrator to set device traps?

Selecciona una de las siguientes respuestas posibles:

  • SNMP

  • TLS

  • ICMP

  • SSH

Explicación

Pregunta 42 de 50

1

Which of the following is the BEST way to secure data for the purpose of retention?

Selecciona una de las siguientes respuestas posibles:

  • Off-site backup

  • RAID 5 on-site backup

  • On-site clustering

  • Virtualization

Explicación

Pregunta 43 de 50

1

In which of the following locations would a forensic analyst look to find a hooked process?

Selecciona una de las siguientes respuestas posibles:

  • BIOS

  • Slack space

  • RAM

  • Rootkit

Explicación

Pregunta 44 de 50

1

Several classified mobile devices have been stolen. Which of the following would BEST reduce the data
leakage threat?

Selecciona una de las siguientes respuestas posibles:

  • Use GPS tracking to find the devices

  • Use stronger encryption algorithms

  • Immediately inform local law enforcement

  • Remotely sanitize the devices

Explicación

Pregunta 45 de 50

1

Which of the following is an example of requiring users to have a password of 16 characters or more?

Selecciona una de las siguientes respuestas posibles:

  • Password recovery requirements

  • Password complexity requirements

  • Password expiration requirements

  • Password length requirements

Explicación

Pregunta 46 de 50

1

Which of the following devices provides storage for RSA or asymmetric keys and may assist in user
authentication? (Select TWO)

Selecciona una o más de las siguientes respuestas posibles:

  • Trusted platform module

  • Hardware security module

  • Facial recognition scanner

  • Full disk encryption

  • Encrypted USB

Explicación

Pregunta 47 de 50

1

A small company needs to invest in a new expensive database. The company's budget does not include the
purchase of additional servers or personnel. Which of the following solutions would allow the small company to
save money on hiring additional personnel and minimize the footprint in their current datacenter?

Selecciona una de las siguientes respuestas posibles:

  • Allow users to telecommute

  • Setup a load balancer

  • Infrastructure as a Service

  • Software as a Service

Explicación

Pregunta 48 de 50

1

A security administrator needs to implement a site-to-site VPN tunnel between the main office and a remote
branch. Which of the following protocols should be used for the tunnel?

Selecciona una de las siguientes respuestas posibles:

  • RTP

  • SNMP

  • IPSec

  • 802.1X

Explicación

Pregunta 49 de 50

1

When examining HTTP server logs the security administrator notices that the company's online store crashes
after a particular search string is executed by a single external user. Which of the following BEST describes this
type of attack?

Selecciona una de las siguientes respuestas posibles:

  • Spim

  • DDoS

  • Spoofing

  • DoS

Explicación

Pregunta 50 de 50

1

Which of the following MUST a programmer implement to prevent cross-site scripting?

Selecciona una de las siguientes respuestas posibles:

  • Validate input to remove shell scripts

  • Validate input to remove hypertext

  • Validate input to remove batch files

  • Validate input to remove Java bit code

Explicación