Log in
Sign up for FREE
arrow_back
Library

SY0-701 Practice A

star
star
star
star
star
Last updated about 2 years ago
106 questions
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
Question 1
1.

Question 2
2.

Question 3
3.

Question 4
4.

Question 5
5.

Question 6
6.

Question 7
7.

Question 8
8.

Question 9
9.

Question 10
10.

Question 11
11.

Question 12
12.

Question 13
13.

Question 14
14.

Question 15
15.

Question 16
16.

Question 17
17.

Question 18
18.

Question 19
19.

Question 20
20.

Question 21
21.

Question 22
22.

Question 23
23.

Question 24
24.

Question 25
25.

Question 26
26.

Question 27
27.

Question 28
28.

Question 29
29.

Question 30
30.

Question 31
31.

Question 32
32.

Question 33
33.

Question 34
34.

Question 35
35.

Question 36
36.

Question 37
37.

Question 38
38.

Question 39
39.

Question 40
40.

Question 41
41.

Question 42
42.

Question 43
43.

Question 44
44.

Question 45
45.

Question 46
46.

Question 47
47.

Question 48
48.

Question 49
49.

Question 50
50.

Question 51
51.

Question 52
52.

Question 53
53.

Question 54
54.

Question 55
55.

Question 56
56.

Question 57
57.

Question 58
58.

Question 59
59.

Question 60
60.

Question 61
61.

Question 62
62.

Question 63
63.

Question 64
64.

Question 65
65.

Question 66
66.

Question 67
67.

Question 68
68.

Question 69
69.

Question 70
70.

Question 71
71.

Question 72
72.

Question 73
73.

Question 74
74.

Question 75
75.

Question 76
76.

Question 77
77.

Question 78
78.

Question 79
79.

Question 80
80.

Question 81
81.

Question 82
82.

Question 83
83.

Question 84
84.

Question 85
85.

Question 86
86.

Question 87
87.

Question 88
88.

Question 89
89.

Question 90
90.

Question 91
91.

Question 92
92.

Question 93
93.

Question 94
94.

Question 95
95.

Question 96
96.

Question 97
97.

Question 98
98.

Question 99
99.

Question 100
100.

Question 101
101.

Question 102
102.

Question 103
103.

Question 104
104.

Question 105
105.

Question 106
106.

Choose Attack Type: Attacker obtains bank account number and birth date by calling the victim.
Vishing
Injection
Keylogger
On-path
DDoS (Distributed Denial of Service)
Choose Attack Type: Attacker accesses a database directly from a web browser.
Injection
Vishing
DDoS (Distributed Denial of Service)
Keylogger
On-path
Choose Attack Type: Attacker intercepts all communication between a client and a web server.
Keylogger
Injection
DDoS (Distributed Denial of Service)
On-path
Vishing
Choose Attack Type: Multiple attackers overwhelm a web server.
On-path
DDoS (Distributed Denial of Service)
Keylogger
Injection
Vishing
Choose Attack Type: Attacker obtains a list of all login credentials used over the last 24 hours.
On-path
Keylogger
Vishing
DDoS (Distributed Denial of Service)
Injection
The security team at a manufacturing company is creating a set of security standards for employees and visitors. Select the BEST security controls for: Outside Building (Parking and visitor drop-off).
Biometrics
Access Badge
Fencing
Lighting
Security Guard
The security team at a manufacturing company is creating a set of security standards for employees and visitors. Select the BEST security controls for: Reception (Building lobby).
Security Guard
Access Control Vestibule
Authentication Token
Biometrics
Access Badge
The security team at a manufacturing company is creating a set of security standards for employees and visitors. Select the BEST security controls for: Data Center Door (Entrance from inside building).
Lighting
Access Badge
Fencing
Access Control Vestibule
Biometrics
The security team at a manufacturing company is creating a set of security standards for employees and visitors. Select the BEST security control for: Server Administration (Authentication to server console in the data center).
Access Badge
Security Guard
Biometrics
Authentication Token
Lighting
Select the most appropriate category: A guard checks the identification of all visitors.
Managerial
Operational
Technical
Physical
Select the most appropriate category: All returns must be approved by a Vice President.
Operational
Managerial
Technical
Physical
Select the most appropriate category: A generator is used during a power outage.
Technical
Operational
Physical
Managerial
Select the most appropriate category: Building doors can be unlocked with an access card.
Physical
Operational
Technical
Managerial
Select the most appropriate category: System logs are transferred automatically to a SIEM.
Operational
Managerial
Physical
Technical
Select the most appropriate authentication factor: During the login process, your phone receives a text message with a one-time passcode.
Something you are
Somewhere you are
Something you know
Something you have
Select the most appropriate authentication factor: You enter your PIN to make a deposit into an ATM.
Somewhere you are
Something you have
Something you know
Something you are
Select the most appropriate authentication factor: You can use your finger to unlock the door to the data center.
Something you know
Something you have
Somewhere you are
Something you are
Select the most appropriate authentication factor: Your login will not work unless you are connected to the VPN.
Somewhere you are
Something you are
Something you have
Something you know
What Protocol and Port would be used to configure the following firewall rule: Block HTTP sessions between a web server and database server.
TCP/22
TCP/80
UDP/443
UDP/22
What Protocol and Port would be used to configure the following firewall rule: Allow a storage server to transfer files to a video server over HTTPS.
TCP/443
UDP/443
TCP/80
UDP/22
What Protocol and Port would be used to configure the following firewall rule: Allow a management server to use a secure terminal on a file server.
UDP/22
UDP/443
TCP/80
TCP/22
A company has hired a third-party to gather information about the company’s servers and data. This third-party will not have direct access to the company's internal network, but they can gather information from any other source. Which of the following would BEST describe this approach?
Regulatory Audit
Passive Reconnaissance
Supply Chain Analysis
Vulnerability Scanning
A company's email server has received an email from a third-party, but the origination server does not match the list of authorized devices. Which of the following would determine the disposition of this message?
DMARC (Domain-based Message Authentication Reporting and Conformance)
DKIM (Domain Keys Identified Mail)
NAC (Network Access Control)
SPF (Sender Policy Framework)
Which of these threat actors would be MOST likely to attack systems for direct financial gain?
Nation State
Hacktivist
Shadow IT
Organized Crime
A security administrator has examined a server recently compromised by an attacker, and has determined the system was exploited due to a known operating system vulnerability. Which of the following would BEST describe this finding?
Data Subject
E-discovery
Risk Appetite
Root Cause Analysis
A city is building an ambulance service network for emergency medical dispatching. Which of the following should have the highest priority?
Patch Availability
Power Usage
System Availability
Integration Costs
A system administrator receives a text alert when access rights are changed on a database containing private customer information. Which of the following would describe this alert?
Attestation and Acknowledgment
Maintenance Window
External Audit
Automation
A security administrator is concerned about the potential for data exfiltration using external storage drives. Which of the following would be the BEST way to prevent this method of data exfiltration?
Only allow applications that do not use removable media
Create an operating system security policy to block the use of removable media
Monitor removable media usage in host-based firewall logs
Define a removable media block rule in the UTM (Unified Threat Manage
r)undefined
A company creates a standard set of government reports each calendar quarter. Which of the following would describe this type of data?
Obfuscated
Regulated
Trade Secrets
Data In Use
An insurance company has created a set of policies to handle data breaches. The security team has been given this set of requirements based on these policies: • Access records from all devices must be saved and archived • Any data access outside of normal working hours must be immediately reported • Data access must only occur inside of the country • Access logs and audit reports must be created from a single database Which of the following should be implemented by the security team to meet these requirements? (Select THREE)
Restrict login access by IP address and GPS location
Require government-issued identification during the onboarding process
Conduct monthly permission auditing
Enable time-of-day restrictions on the authentication server
Consolidate all logs on a SIEM (Security Information and Event Manager)
A security engineer, is viewing this record from the firewall logs: UTC 04/05/2023 03:09:15809 AV Gateway Alert 136.127.92.171 80 -> 10.16.10.14 60818 Gateway Anti-Virus Alert: (Trojan) blocked. Which of the following can be observed from this log information?
The victim's IP address is 136.127.92.171
A botnet DDoS attack was blocked
The Trojan was blocked, but the file was not
A download was blocked from a web server
A user connects to a third-party website and receives this message: Your connection is not private. NET::ERR_CERT_INVALID Which of the following attacks would be the MOST likely reason for this message?
DoS (Denial of Service)
On-path
Brute Force
Deauthentication
Which of the following would be the BEST way to provide a website login using existing credentials from a third-party site?
802.1X
EAP (Extensible Authentication Protocol)
Federation
SSO (Single Sign-On)
A system administrator is working on a contract that will specify a minimum required uptime for a set of Internet-facing firewalls. The administrator needs to know how often the firewall hardware is expected to fail between repairs. Which of the following would BEST describe this information?
MTTR (Mean Time to Restore)
MTBF (Mean Time Between Failures)
RTO (Recovery Time Objectives)
RPO (Recovery Point Objective)
An attacker calls into a company’s help desk and pretends to be the director of the company’s manufacturing department. The attacker states that they have forgotten their password and they need to have the password reset quickly for an important meeting. What kind of attack would BEST describe this phone call?
Social Engineering
Watering Hole
On-path
Supply Chain
Two companies have been working together for a number of months, and they would now like to qualify their partnership with a broad formal agreement between both organizations. Which of the following would describe this agreement?
SOW (Statement of Work)
SLA (Service Level Agreement)
MOA (Memorandum of Agreement)
NDA (Non-Disclosure Agreement)
Which of the following would explain why a company would automatically add a digital signature to each outgoing email message?
Availability
Integrity
Authenticataion
Confidentiality
The embedded OS in a company’s time clock appliance is configured to reset the file system and reboot when a file system error occurs. On one of the time clocks, this file system error occurs during the startup process and causes the system to constantly reboot. Which of the following BEST describes this issue?
Memory Injection
Resource Consumption
Malicious Update
Race Condition
A recent audit has found that existing password policies do not include any restrictions on password attempts, and users are not required to periodically change their passwords. Which of the following would correct these policy issues? (Select TWO)
Password Expiration
Password Reuse
Account Lockout
Password Managers
Password Complexity
What kind of security control is associated with a login banner?
Directive
Corrective
Compensating
Preventative
Deterrent
An internal audit has discovered four servers that have not been updated in over a year, and it will take two weeks to test and deploy the latest patches. Which of the following would be the best way to quickly respond to this situation in the meantime?
Move the servers to a protected segment
Purchase cybersecurity insurance
Hire a third-party to perform an extensive audit
Implement an exception for all data center services
A business manager is documenting a set of steps for processing orders if the primary Internet connection fails. Which of these would BEST describe these steps?
Tabletop Exercise
Continuity of Operations
Cold Site Recovery
Platform Diversity
A company would like to examine the credentials of each individual entering the data center building. Which of the following would BEST facilitate this requirement?
Pressure Sensors
Bollards
Video Surveillance
Access Control Vestibule
A company stores some employee information in encrypted form, but other public details are stored as plaintext. Which of the following would BEST describe this encryption strategy?
Asymmetric
Key Escrow
Full-disk
Record
A company would like to minimize database corruption if power is lost to a server. Which of the following would be the BEST strategy to follow?
Off-site Backups
Journaling
Encryption
Replication
A company is creating a security policy for corporate mobile devices: • All mobile devices must be automatically locked after a predefined time period. • The location of each device needs to be traceable. • All of the user’s information should be completely separate from company data. Which of the following would be the BEST way to establish these security policy rules?
COPE (Corporately Owned and Personally Enabled)
Biometrics
MDM (Mobile Device Manager)
Segmentation
A security engineer runs a monthly vulnerability scan. The scan doesn’t list any vulnerabilities for Windows servers, but a significant vulnerability was announced last week and none of the servers are patched yet. Which of the following best describes this result?
Compensating Controls
Zero-day Attack
False Negative
Exploit
An IT help desk is using automation to improve the response time for security events. Which of the following use cases would apply to this process?
Guard Rails
Resource Provisioning
Escalation
Continuous Integration
A network administrator would like each user to authenticate with their corporate username and password when connecting to the company's wireless network. Which of the following should the network administrator configure on the wireless access points?
MFA (Multifactor Authentication)
802.1X
WPA3 (WiFi Protected Access 3)
PSK (Pre-Shared Key)
A company's VPN service performs a posture assessment during the login process. Which of the following mitigation techniques would this describe?
Least Privilege
Encryption
Configuration Enforcement
Decommissioning
A user has assigned individual rights and permissions to a file on their network drive. The user adds three additional individuals to have read-only access to the file. Which of the following would describe this access control model?
Mandatory
Role-based
Discretionary
Attribute-based
A remote user has received a text message with a link to login and confirm their upcoming work schedule. Which of the following would BEST describe this attack?
Smishing
Brute Force
Typosquatting
Watering Hole
A company is formalizing the design and deployment process used by their application programmers. Which of the following policies would apply?
Business Continuity
Development Lifecycle
Incident Response
Acceptable Use Policy
A security administrator has copied a suspected malware executable from a user's computer and is running the program in a sandbox. Which of the following would describe this part of the incident response process?
Eradication
Recovery
Preparation
Containment
A server administrator at a bank has noticed a decrease in the number of visitors to the bank's website. Additional research shows that users are being directed to a different IP address than the bank's web server. Which of the following would MOST likely describe this attack?
DDoS (Distributed Denial of Service)
Deauthentication
DNS Poisoning
Buffer Overflow
Which of the following considerations are MOST commonly associated with a hybrid cloud model?
Containerization Backups
Network Protection Mismatches
Microservice Outages
IoT (Internet of Things) Support
A company hires a large number of seasonal employees, and their system access should normally be disabled when the employee leaves the company. The security administrator would like to verify that their systems cannot be accessed by any of the former employees. Which of the following would be the BEST way to provide this verification?
Validate the account lockout policy
Validate the offboarding processes and procedures
Create a report that shows all authentications for a 24-hour period
Confirm that no unauthorized accounts have administrator access
Which of the following is used to describe how cautious an organization might be to taking a specific risk?
Risk Appetite
Risk Register
Risk Reporting
Risk Transfer
A technician is applying a series of patches to fifty web servers during a scheduled maintenance window. After patching and rebooting the first server, the web service fails with a critical error. Which of the following should the technician do NEXT?
Contact the stakeholders regarding the outage
Test the upgrade process in the lab
Evaluate the impact analysis associated with the change
Follow the steps listed in the backout plan
An attacker has discovered a way to disable a server by sending specially crafted packets from many remote devices to the operating system. When the packet is received, the system crashes and must be rebooted to restore normal operations. Which of the following would BEST describe this attack?
SQL (Structured Query Language) Injection
Replay Attack
DDoS (Distributed Denial of Service)
Privilege Escalation
A data breach has occurred in a large insurance company. A security administrator is building new servers and security systems to get all of the financial systems back online. Which part of the incident response process would BEST describe these actions?
Recovery
Lessons Learned
Analysis
Containment
A network team has installed new access points to support an application launch. In less than 24 hours, the wireless network was attacked and private company information was accessed. Which of the following would be the MOST likely reason for this breach?
Misconfiguration
Jailbreaking
Impersonation
Race Condition
An organization has identified a significant vulnerability in an Internet facing firewall. The firewall company has stated the firewall is no longer available for sale and there are no plans to create a patch for this vulnerability. Which of the following would BEST describe this issue?
Improper Input Handling
Incompatible OS
Improper Key Management
End-of-Life
A company has decided to perform a disaster recovery exercise during an annual meeting with the IT directors and senior directors. A simulated disaster will be presented, and the participants will discuss the logistics and processes required to resolve the disaster. Which of the following would BEST describe this exercise?
Business Impact Analysis
Tabletop Exercise
Continuity of Operations
Capacity Planning
A security administrator needs to block users from visiting websites hosting malicious software. Which of the following would be the BEST way to control this access?
Data Masking
Honeynet
DNS Filtering
Data Loss Prevention
A system administrator has been called to a system with a malware infection. As part of the incident response process, the administrator has imaged the operating system to a known-good version. Which of these incident response steps is the administrator following?
Containment
Lessons Learned
Detection
Recovery
A company has placed a SCADA system on a segmented network with limited access from the rest of the corporate network. Which of the following would describe this process?
Load Balancing
Data Retention
Least Privilege
Hardening
An administrator is viewing the following security log: Dec 30 08:40:03 web01 Failed password for root from 10.101.88.230 port 26244 ssh2 Dec 30 08:40:05 web01 Failed password for root from 10.101.88.230 port 26244 ssh2 Dec 30 08:40:09 web01 445 more authentication failures; rhost=10.101.88.230 user=root Which of the following would describe this attack?
Spraying
Downgrade
Brute Force
DDoS (Distributed Denial of Service)
During a morning login process, a user's laptop was moved to a private VLAN and a series of updates were automatically installed. Which of the following would describe this process?
Configuration Enforcement
Decommissioning
Account Lockout
Sideloading
Which of the following describes two-factor authentication?
A Windows Domain requires a password and smart card
The door to a building requires a fingerprint scan
A printer uses a password and a PIN
An application requires a pseudo-random code
A company is deploying a new application to all employees in the field. Some of the problems associated with this roll out include: • The company does not have a way to manage the devices in the field • Team members have many different kinds of mobile devices • The same device needs to be used for both corporate and private use Which of the following deployment models would address these concerns?
SSO (Single Sign-On)
BYOD (Bring Your Own Device)
COPE (Corporate-owned, Personally Enabled)
CYOD (Choose Your Own Device)
An organization is installing a UPS for their new data center. Which of the following would BEST describe this control type?
Compensating
Deterrent
Directive
Detective
A manufacturing company would like to track the progress of parts used on an assembly line. Which of the following technologies would be the BEST choice for this task?
Hashing
Secure Enclave
Asymmetric Encryption
Blockchain
A company's website has been compromised and the website content has been replaced with a political message. Which of the following threat actors would be the MOST likely culprit?
Insider
Organized Crime
Shadow IT
Hacktivist
A Linux administrator is downloading an updated version of her Linux distribution. The download site shows a link to the ISO and a SHA256 hash value. Which of these would describe the use of this hash value?
Verifies that the file was not corrupted during the file transfer
Provides a key for decrypting the ISO after download
Confirms that the file does not contain any malware
Authenticates the site as an official ISO distribution site
A company's security policy requires that login access should only be available if a person is physically within the same building as the server. Which of the following would be the BEST way to provide this requirement?
PIN
Biometric Scanner
USB Security Key
SMS (Short Message Service)
A development team has installed a new application and database to a cloud service. After running a vulnerability scanner on the application instance, a security administrator finds the database is available for anyone to query without providing any authentication. Which of these vulnerabilities is MOST associated with this issue?
Malicious Update
Legacy Software
Race Condition
Open Permissions
Employees of an organization have received an email with a link offering a cash bonus for completing an internal training course. Which of the following would BEST describe this email?
Phishing Campaign
Zero-Day
Watering Hole Attack
Cross-Site Scripting
Which of the following risk management strategies would include the purchase and installation of an NGFW?
Accept
Avoid
Transfer
Mitigate
An organization is implementing a security model where all application requests must be validated at a policy enforcement point. Which of the following would BEST describe this model?
Zero Trust
Federation
Discretionary Access Control
Public Key Infrastructure
A company is installing a new application in a public cloud. Which of the following determines the assignment of data security in this cloud infrastructure?
Playbook
Audit Committee
Right-to-Audit Clause
Responsibility Matrix
When decommissioning a device, a company documents the type and size of storage drive, the amount of RAM, and any installed adapter cards. Which of the following describes this process?
Enumeration
Certification
Destruction
Sanitization
An attacker has sent more information than expected in a single API call, and this has allowed the execution of arbitrary code. Which of the following would BEST describe this attack?
Cross-Site Scripting
Buffer Overflow
Replay Attack
DDoS (Distributed Denial of Service)
A company encourages users to encrypt all of their confidential materials on a central server. The organization would like to enable key escrow as a backup option. Which of these keys should the organization place into escrow?
Session
Public
Private
CA (Certificate Authority)
A company is in the process of configuring and enabling host-based firewalls on all user devices. Which of the following threats is the company addressing?
On-path
Vishing
Default Credentials
Instant Messaging
A manufacturing company would like to use an existing router to separate a corporate network from a manufacturing floor. Both networks use the same physical switch, and the company does not want to install any additional hardware. Which of the following would be the BEST choice for this segmentation?
Use host-based firewalls on each device
Connect the corporate network and the manufacturing floor with a VPN
Build an air gapped manufacturing floor network
Create separate VLANs for the corporate network and the manufacturing floor
An organization needs to provide a remote access solution for a newly deployed cloud-based application. This application is designed to be used by mobile field service technicians. Which of the following would be the best option for this requirement?
CRL (Certificate Revocation List)
SASE (Secure Access Service Edge)
RTOS (Real-time Operating System)
Zero-trust
A company is implementing a quarterly security awareness campaign. Which of the following would MOST likely be part of this campaign?
An itemized statement of work
An acceptable use policy document
An IaC (Infrastructure as Code) configuration file
Suspicious message reports from users
A recent report shows the return of a vulnerability that was previously patched four months ago. After researching this issue, the security team has found a recent patch has reintroduced this vulnerability on the servers. Which of the following should the security administrator implement to prevent this issue from occurring in the future?
Data Masking
802.1X
Containerization
Change management
A security manager would like to ensure that unique hashes are used with an application login process. Which of the following would be the BEST way to add random data when generating a set of stored password hashes?
Salting
Obfuscation
Key Stretching
Digital Signature
Which cryptographic method is used to add trust to a digital certificate?
Digital Signature
Symmetric Encryption
Steganography
Hash
A company is using SCAP as part of their security monitoring processes. Which of the following would BEST describe this implementation?
Present the results of an internal audit to the board
Identify and document authorized data center visitors
Train the user community to better identify phishing attempts
Automate the validation and patching of security issues
An organization maintains a large database of customer information for sales tracking and customer support. Which person in the organization would be responsible for managing the access rights to this data?
Data Processor
Data Custodian
Data Owner
Data Subject
An organization’s content management system currently labels files and documents as “Public” and “Restricted.” On a recent update, a new classification type of “Private” was added. Which of the following would be the MOST likely reason for this addition?
Minimized Attack Surface
Decreased Search Time
Simplified Categorization
Expanded Privacy Compliance
A corporate security team would like to consolidate and protect the private keys across all of their web servers. Which of these would be the BEST way to securely store these keys?
Use a TPM (Trusted Platform Module)
Upgrade the web servers to use a UEFI (Unified Extensible Firmware Interface) BIOS (Basic Input/Output System)
Implement full disk encryption on the web servers
Integrate an HSM (Hardware Security Module)
A security technician is reviewing this security log from an IPS: ALERT 2023-06-01 13:07:29 Cross-Site Scripting in JSON Data 222.43.112.74:3332 -> 64.235.145.35:80 - Method POST - Query String "-" User Agent: curl/7.21.3 (i386-redhat-linux-gnu) libcurl/7.21.3 NSS/3.13.1.0 zlib/1.2.5 libidn/1.19 libssh2/1.2.7 Detail: token="" Which of the following can be determined from this log information? (Select TWO)
The alert was generated from a malformed User Agent header
The alert was generated from an embedded script
The attacker's IP address is 222.43.112.74
The alert was generated due to an invalid client port number
The attacker's IP address is 64.235.145.35
Which of the following describes a monetary loss if one event occurs?
ALE (Annual Loss Expectancy)
ARO (Annualized Rate of Occurrence)
RTO (Recovery Time Objectives)
SLE (Single Loss Expectancy)
A user with restricted access has typed this text in a search field of an internal web-based application: USER77' OR '1'='1 After submitting this search request, all database records are displayed on the screen. Which of the following would BEST describe this search?
SSL Stripping
Buffer Overflow
SQL (Structured Query Language) Injection
Cross-Site Scripting
A user has opened a helpdesk ticket complaining of poor system performance, excessive pop up messages, and the cursor moving without anyone touching the mouse. This issue began after they opened a spreadsheet from a vendor containing part numbers and pricing information. Which of the following is MOST likely the cause of this user's issues?
On-path
Trojan Horse
Logic Bomb
Worm
A web-based manufacturing company processes monthly charges to credit card information saved in the customer's profile. All of the customer information is encrypted and protected with additional authentication factors. Which of the following would be the justification for these security controls?
Compliance Reporting
Password Vaulting
Sandboxing
Chain of Custody
A security manager has created a report showing intermittent network communication from certain workstations on the internal network to one external IP address. These traffic patterns occur at random times during the day. Which of the following would be the MOST likely reason for these traffic patterns?
On-path Attack
Replay Attack
Keylogger
Brute Force
The security policies in a manufacturing company prohibit the transmission of customer information. However, a security administrator has received an alert that credit card numbers were transmitted as an email attachment. Which of the following was the MOST likely source of this alert message?
IPsec (Internet Protocol Security)
RADIUS (Remote Authentication Dial-In User Service)
IPS (Intrusion Prevention System)
DLP (Data Loss Prevention)
A security administrator has configured a virtual machine in a screened subnet with a guest login account and no password. Which of the following would be the MOST likely reason for this configuration?
The server is a development sandbox for third party programming projects
The server is a honeypot for attracting potential attackers
The server will be used as a VPN concentrator
The server is a cloud storage service for remote users
A security administrator is configuring a DNS server with a SPF record. Which of the following would be the reason for this configuration?
Transmit all outgoing email over an encrypted tunnel
Digitally sign all outgoing email messages
List all servers authorized to send emails
Obtain disposition instructions for emails marked as spam
A company would like to securely deploy applications without the overhead of installing a virtual machine for each system. Which of the following would be the BEST way to deploy these applications?
Containerization
IoT (Internet of Things)
Proxy
RTOS (Real-Time Operating System)
A company has just purchased a new application server, and the security director wants to determine if the system is secure. The system is currently installed in a test environment and will not be available to users until the roll out to production next week. Which of the following would be the BEST way to determine if any part of the system can be exploited?
Tabletop Exercise
DDoS (Distributed Denial of Service)
Penetration Test
Vulnerability Scanner