Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

2021 BEST SECURITY+ EXAM SY0-601 STUDY

Rating
-
Sold
-
Pages
45
Grade
A+
Uploaded on
01-04-2022
Written in
2021/2022

A Ans- A security administrator suspects an employee has been emailing proprietary information to a competitor. Company policy requires the administrator to capture an exact copy of the employee's hard disk. Which of the following should the administrator use? A. dd B. chmod C. dnsenum D. logger THIS IS THE ORDER AS FOLLOWS: ssh-keygen -t rsa ssh-copy-id -i ~/.ssh/id_ user@server chmod 644 ~/.ssh/id_rsa ssh root@server Ans- DRAG AND DROP SIMULATION (SEE IMAGE) Firewall 1:DNS Rule "" ANY -- ANY -- DNS -- PERMIT HTTPS Outbound "" 10.0.0.1/24 -- ANY -- HTTPS -- PERMIT Management "" ANY -- ANY -- SSH -- PERMIT HTTPS Inbound "" ANY -- ANY -- HTTPS -- PERMIT HTTP Inbound "" ANY -- ANY -- HTTP -- DENY Firewall 2: No changes should be made to this firewall Firewall 3:DNS Rule "" ANY -- ANY -- DNS -- PERMIT HTTPS Outbound "" 192.168.0.1/24 -- ANY -- HTTPS -- PERMIT Management "" ANY -- ANY -- SSH -- PERMIT HTTPS Inbound "" ANY -- ANY -- HTTPS -- PERMIT HTTP Inbound "" ANY -- ANY -- HTTP -- DENY Ans- DROP DOWN SIMULATION (SEE IMAGE) See IMAGE Ans- DRAG AND DROP SIMULATION (SEE ANSWERS IN IMAGE) DF Ans- Which of the following will MOST likely adversely impact the operations of unpatched traditional programmable-logic controllers, running a back-end LAMP server and OT systems with human-management interfaces that are accessible over the Internet via a web interface? (Choose two.) A. Cross-site scripting B. Data exfiltration C. Poor system logging D. Weak encryption E. SQL injection F. Server-side request forgery A Ans- A company recently transitioned to a strictly BYOD culture due to the cost of replacing lost or damaged corporate-owned mobile devices. Which of the following technologies would be BEST to balance the BYOD culture while also protecting the company's data? A. Containerization B. Geofencing C. Full-disk encryption D. Remote wipe D Ans- A Chief Security Office's (CSO's) key priorities are to improve preparation, response, and recovery practices to minimize system downtime and enhance organizational resilience to ransomware attacks. Which of the following would BEST meet the CSO's objectives? A. Use email-filtering software and centralized account management, patch high-risk systems, and restrict administration privileges on fileshares. B. Purchase cyber insurance from a reputable provider to reduce expenses during an incident. C. Invest in end-user awareness training to change the long-term culture and behavior of staff and executives, reducing the organization's susceptibility to phishing attacks. D. Implement application whitelisting and centralized event-log management, and perform regular testing and validation of full backups. AC Ans- A network engineer has been asked to investigate why several wireless barcode scanners and wireless computers in a warehouse have intermittent connectivity to the shipping server. The barcode scanners and computers are all on forklift trucks and move around the warehouse during their regular use. Which of the following should the engineer do to determine the issue? (Choose two.) A. Perform a site survey B. Deploy an FTK Imager C. Create a heat map D. Scan for rogue access points E. Upgrade the security protocols F. Install a captive portal C Ans- Which of the following is MOST likely to outline the roles and responsibilities of data controllers and data processors? A. SSAE SOC 2 B. PCI DSS C. GDPR D. ISO 31000 C Ans- Phishing and spear-phishing attacks have been occurring more frequently against a company's staff. Which of the following would MOST likely help mitigate this issue? A. DNSSEC and DMARC B. DNS query logging C. Exact mail exchanger records in the DNS D. The addition of DNS conditional forwarders EF Ans- On which of the following is the live acquisition of data for forensic analysis MOST dependent? (Choose two.) A. Data accessibility B. Legal hold C. Cryptographic or hash algorithm D. Data retention legislation E. Value and volatility of data F. Right-to-audit clauses B Ans- Which of the following incident response steps involves actions to protect critical systems while maintaining business operations? A. Investigation B. Containment C. Recovery D. Lessons learned B Ans- A security auditor is reviewing vulnerability scan data provided by an internal security team. Which of the following BEST indicates that valid credentials were used? A. The scan results show open ports, protocols, and services exposed on the target host B. The scan enumerated software versions of installed programs C. The scan produced a list of vulnerabilities on the target host D. The scan identified expired SSL certificates B Ans- Which of the following BEST explains the difference between a data owner and a data custodian? A. The data owner is responsible for adhering to the rules for using the data, while the data custodian is responsible for determining the corporate governance regarding the data B. The data owner is responsible for determining how the data may be used, while the data custodian is responsible for implementing the protection to the data C. The data owner is responsible for controlling the data, while the data custodian is responsible for maintaining the chain of custody when handling the data D. The data owner grants the technical permissions for data access, while the data custodian maintains the database access controls to the data D Ans- A network engineer needs to build a solution that will allow guests at the company's headquarters to access the Internet via WiFi. This solution should not allow access to the internal corporate network, but it should require guests to sign off on the acceptable use policy before accessing the Internet. Which of the following should the engineer employ to meet these requirements? A. Implement open PSK on the APs B. Deploy a WAF C. Configure WIPS on the APs D. Install a captive portal D Ans- Based on the analyst's findings, which of the following attacks is being executed? A. Credential harvesting B. Keylogger C. Brute-force D. Spraying C Ans- Which of the following cloud models provides clients with servers, storage, and networks but nothing else? A. SaaS B. PaaS C. IaaS D. DaaS AB Ans- A network administrator needs to build out a new datacenter, with a focus on resiliency and uptime. Which of the following would BEST meet this objective?(Choose two.) A. Dual power supply B. Off-site backups C. Automatic OS upgrades D. NIC teaming E. Scheduled penetration testing F. Network-attached storage C Ans- Which of the following network attacks is the researcher MOST likely experiencing? A. MAC cloning B. Evil twin C. Man-in-the-middle D. ARP poisoning BD Ans- An organization is developing an authentication service for use at the entry and exit ports of country borders. The service will use data feeds obtained from passport systems, passenger manifests, and high-definition video feeds from CCTV systems that are located at the ports. The service will incorporate machine-learning techniques to eliminate biometric enrollment processes while still allowing authorities to identify passengers with increasing accuracy over time. The more frequently passengers travel, the more accurately the service will identify them. Which of the following biometrics will MOST likely be used, without the need for enrollment? (Choose two.) A. Voice B. Gait C. Vein D. Facial E. Retina F. Fingerprint D Ans- An organization needs to implement more stringent controls over administrator/root credentials and service accounts. Requirements for the project include: Check-in/checkout of credentials The ability to use but not know the password Automated password changes Logging of access to credentials Which of the following solutions would meet the requirements? A. OAuth 2.0 B. Secure Enclave C. A privileged access management system D. An OpenID Connect authentication system A Ans- Several employees return to work the day after attending an industry trade show. That same day, the security manager notices several malware alerts coming from each of the employee's workstations. The security manager investigates but finds no signs of an attack on the perimeter firewall or the NIDS. Which of the following is MOST likely causing the malware alerts? A. A worm that has propagated itself across the intranet, which was initiated by presentation media B. A fileless virus that is contained on a vCard that is attempting to execute an attack C. A Trojan that has passed through and executed malicious code on the hosts D. A USB flash drive that is trying to run malicious code but is being blocked by the host firewall A Ans- After reading a security bulletin, a network security manager is concerned that a malicious actor may have breached the network using the same software flaw.The exploit code is publicly available and has been reported as being used against other industries in the same vertical. Which of the following should the network security manager consult FIRST to determine a priority list for forensic review? A. The vulnerability scan output B. The IDS logs C. The full packet capture data D. The SIEM alerts

Show more Read less
Institution
Course

Content preview

2021 BEST SECURITY+ EXAM SY0-601
STUDY

A Ans- A security administrator suspects an employee has been emailing proprietary
information to a competitor. Company policy requires the administrator to capture an
exact copy of the employee's hard disk.

Which of the following should the administrator use?

A. dd
B. chmod
C. dnsenum
D. logger

THIS IS THE ORDER AS FOLLOWS:
ssh-keygen -t rsa
ssh-copy-id -i ~/.ssh/id_rsa.pub user@server
chmod 644 ~/.ssh/id_rsa
ssh root@server Ans- DRAG AND DROP SIMULATION (SEE IMAGE)

Firewall 1:DNS Rule "" ANY --> ANY --> DNS --> PERMIT
HTTPS Outbound "" 10.0.0.1/24 --> ANY --> HTTPS --> PERMIT
Management "" ANY --> ANY --> SSH --> PERMIT
HTTPS Inbound "" ANY --> ANY --> HTTPS --> PERMIT
HTTP Inbound "" ANY --> ANY --> HTTP --> DENY

Firewall 2: No changes should be made to this firewall

Firewall 3:DNS Rule "" ANY --> ANY --> DNS --> PERMIT
HTTPS Outbound "" 192.168.0.1/24 --> ANY --> HTTPS --> PERMIT
Management "" ANY --> ANY --> SSH --> PERMIT
HTTPS Inbound "" ANY --> ANY --> HTTPS --> PERMIT
HTTP Inbound "" ANY --> ANY --> HTTP --> DENY Ans- DROP DOWN SIMULATION
(SEE IMAGE)

See IMAGE Ans- DRAG AND DROP SIMULATION (SEE ANSWERS IN IMAGE)

DF Ans- Which of the following will MOST likely adversely impact the operations of
unpatched traditional programmable-logic controllers, running a back-end LAMP server
and OT systems with human-management interfaces that are accessible over the
Internet via a web interface? (Choose two.)

,A. Cross-site scripting
B. Data exfiltration
C. Poor system logging
D. Weak encryption
E. SQL injection
F. Server-side request forgery

A Ans- A company recently transitioned to a strictly BYOD culture due to the cost of
replacing lost or damaged corporate-owned mobile devices.

Which of the following technologies would be BEST to balance the BYOD culture while
also protecting the company's data?

A. Containerization
B. Geofencing
C. Full-disk encryption
D. Remote wipe

D Ans- A Chief Security Office's (CSO's) key priorities are to improve preparation,
response, and recovery practices to minimize system downtime and enhance
organizational resilience to ransomware attacks.

Which of the following would BEST meet the CSO's objectives?

A. Use email-filtering software and centralized account management, patch high-risk
systems, and restrict administration privileges on fileshares.

B. Purchase cyber insurance from a reputable provider to reduce expenses during an
incident.

C. Invest in end-user awareness training to change the long-term culture and behavior
of staff and executives, reducing the organization's susceptibility to phishing attacks.

D. Implement application whitelisting and centralized event-log management, and
perform regular testing and validation of full backups.

AC Ans- A network engineer has been asked to investigate why several wireless
barcode scanners and wireless computers in a warehouse have intermittent connectivity
to the shipping server. The barcode scanners and computers are all on forklift trucks
and move around the warehouse during their regular use.

Which of the following should the engineer do to determine the issue? (Choose two.)

A. Perform a site survey
B. Deploy an FTK Imager
C. Create a heat map

,D. Scan for rogue access points
E. Upgrade the security protocols
F. Install a captive portal

C Ans- Which of the following is MOST likely to outline the roles and responsibilities of
data controllers and data processors?

A. SSAE SOC 2
B. PCI DSS
C. GDPR
D. ISO 31000

C Ans- Phishing and spear-phishing attacks have been occurring more frequently
against a company's staff.

Which of the following would MOST likely help mitigate this issue?

A. DNSSEC and DMARC
B. DNS query logging
C. Exact mail exchanger records in the DNS
D. The addition of DNS conditional forwarders

EF Ans- On which of the following is the live acquisition of data for forensic analysis
MOST dependent? (Choose two.)

A. Data accessibility
B. Legal hold
C. Cryptographic or hash algorithm
D. Data retention legislation
E. Value and volatility of data
F. Right-to-audit clauses

B Ans- Which of the following incident response steps involves actions to protect critical
systems while maintaining business operations?

A. Investigation
B. Containment
C. Recovery
D. Lessons learned

B Ans- A security auditor is reviewing vulnerability scan data provided by an internal
security team.

Which of the following BEST indicates that valid credentials were used?

, A. The scan results show open ports, protocols, and services exposed on the target
host
B. The scan enumerated software versions of installed programs
C. The scan produced a list of vulnerabilities on the target host
D. The scan identified expired SSL certificates

B Ans- Which of the following BEST explains the difference between a data owner and
a data custodian?

A. The data owner is responsible for adhering to the rules for using the data, while the
data custodian is responsible for determining the corporate governance regarding the
data

B. The data owner is responsible for determining how the data may be used, while the
data custodian is responsible for implementing the protection to the data

C. The data owner is responsible for controlling the data, while the data custodian is
responsible for maintaining the chain of custody when handling the data

D. The data owner grants the technical permissions for data access, while the data
custodian maintains the database access controls to the data

D Ans- A network engineer needs to build a solution that will allow guests at the
company's headquarters to access the Internet via WiFi. This solution should not allow
access to the internal corporate network, but it should require guests to sign off on the
acceptable use policy before accessing the Internet.

Which of the following should the engineer employ to meet these requirements?

A. Implement open PSK on the APs
B. Deploy a WAF
C. Configure WIPS on the APs
D. Install a captive portal

D Ans- Based on the analyst's findings, which of the following attacks is being
executed?

A. Credential harvesting
B. Keylogger
C. Brute-force
D. Spraying

C Ans- Which of the following cloud models provides clients with servers, storage, and
networks but nothing else?

A. SaaS

Written for

Course

Document information

Uploaded on
April 1, 2022
Number of pages
45
Written in
2021/2022
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$13.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
EvaTee Phoenix University
Follow You need to be logged in order to follow users or courses
Sold
5206
Member since
4 year
Number of followers
3567
Documents
55690
Last sold
1 day ago
TIGHT DEADLINE? I CAN HELP

Many students don\'t have the time to work on their academic papers due to balancing with other responsibilities, for example, part-time work. I can relate. kindly don\'t hesitate to contact me, my study guides, notes and exams or test banks, are 100% graded

3.8

947 reviews

5
451
4
167
3
171
2
48
1
110

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions