http://https://www.lead1pass.com/CompTIA/SY0-501-practice-exam-dumps.html (351 Q&As Dumps, 30%OFF Special Discount: 30free )
NEW QUESTION NO: 10
A company is deploying a new VoIP phone system. They require 99.999% uptime for their phone service and are concerned about their existing data network interfering with the VoIP phone system.
The core switches in the existing data network are almost fully saturated. Which of the following options will pro-vide the best performance and availability for both the VoIP traffic, as well as the traffic on the existing data network?
A. Put the VoIP network into a different VLAN than the existing data network.
B. Implement flood guards on the data network.
C. Upgrade the edge switches from 10/100/1000 to improve network speed.
D. Physically separate the VoIP phones from the data network.
Answer: A
NEW QUESTION NO: 11
A company is investigating a data compromise where data exfiltration occurred. Prior to the investigation, the supervisor terminates an employee as a result of the suspected data loss. During the investigation, the supervisor is absent for the interview, and little evidence can be provided form the role-based authentication system in use by the company. The situation can be identified for future mitigation as which of the following?
A. Job rotation
B. Insider threat
C. Log failure
D. Lack of training
Answer: C
NEW QUESTION NO: 12
Company XYZ has decided to make use of a cloud-based service that requires mutual, certificate- based authentication with its users. The company uses SSL-inspecting IDS at its network boundary and is concerned about the confidentiality of the mutual authentication. Which of the following model prevents the IDS from capturing credentials used to authenticate users to the new service or keys to decrypt that communication?
A. Use of a third-party, SAML-based authentication service for attestation.
B. Use of active directory federation between the company and the cloud-based service.
C. Use of OATH between the user and the service and attestation from the company domain.
D. Use of smartcards that store x.509 keys, signed by a global CA.
Answer: B
NEW QUESTION NO: 13
Which of the following can be used to control specific commands that can be executed on a network infrastructure device?
A. LDAP
B. SAML
C. Kerberos
D. TACACS+
Answer: D
NEW QUESTION NO: 14
A network technician is trying to determine the source of an ongoing network based attack. Which of the following should the technician use to view IPv4 packet data on a particular internal network segment?
A. Firewall
B. Proxy
C. Protocol analyzer
D. Switch
Answer: C
NEW QUESTION NO: 15
An administrator is replacing a wireless router. The configuration of the old wireless router was not documented before it stopped functioning. The equipment connecting to the wireless network uses older legacy equipment that was manufactured prior to the release of the 802.11i standard. Which of the following configuration options should the administrator select for the new wireless router?
A. WPA+TWP
B. WPA2+CCMP
C. WPA2+TWP
D. WPA+CCMP
Answer: C
NEW QUESTION NO: 16
The security administrator has noticed cars parking just outside of the building fence line. Which of the following security measures can the administrator use to help protect the company's WiFi network against war driving? (Select TWO.)
A. Create a honeynet
B. Add false SSIDs
C. Adjust power level controls
D. Change antenna placement
E. Reduce beacon rate
F. Implement a warning banner
Answer: C,D
NEW QUESTION NO: 17
An auditor wants to test the security posture of an organization by running a tool that will display the following:
Which of the following commands should be used?
A. arp
B. nc
C. nbtstat
D. ipconfig
Answer: C
NEW QUESTION NO: 18
The help desk is receiving numerous password change alerts from users in the accounting department. These alerts occur multiple times on the same day for each of the affected users' accounts. Which of the following controls should be implemented to curtail this activity?
A. Password Complexity
B. Password Minimum Age
C. Password History
D. Password Reuse
Answer: B
NEW QUESTION NO: 19
A security administrator needs an external vendor to correct an urgent issue with an organization's physical access control system (PACS). The PACS does not currently have internet access because it is running a legacy operation system. Which of the following methods should the security administrator select the best balances security and efficiency?
A. Set up VPN concentrator for the vendor and restrict access to the PACS using desktop sharing.
B. Have the external vendor come onsite and provide access to the PACS directly.
C. Set up a web conference on the administrator's pc; then remotely connect to the pacs.
D. Temporarily permit outbound internet access for the pacs so desktop sharing can be set up.
Answer: A
NEW QUESTION NO: 20
An application team is performing a load-balancing test for a critical application during off-hours and has requested access to the load balancer to review. Which servers are up without having the administrator on call. The security analyst is hesitant to give the application team full access due to other critical applications running on the road balancer. Which of the following is the BEST solution for the security analyst to process the request?
A. Share the account with the application team.
B. Give the application team read-only access.
C. Give the application team administrator access during off hours.
D. Disable other critical applications before granting the team access.
Answer: C