https://www.newpassleader.com/CompTIA/SYO-501-exam-preparation-materials.html (351 Q&As Dumps, 30%OFF Special Discount: 30free )
NEW QUESTION NO: 1
A company hires a third-party firm to conduct an assessment of
vulnerabilities exposed to the Internet. The firm informs the
company that an exploit exists for an FTP server that had a version
installed from eight years ago. The company has decided to keep the
system online anyway, as no upgrade exists form the vendor. Which
of the following BEST describes the reason why the vulnerability
exists?
A. End-of-life system
B. Zero-day threats
C. Default configuration
D. Weak cipher suite
Answer: A
NEW QUESTION NO: 2
An organization is comparing and contrasting migration from its
standard desktop configuration to the newest version of the
platform. Before this can happen, the Chief Information Security
Officer (CISO) voices the need to evaluate the functionality of the
newer desktop platform to ensure interoperability with existing software in use by the organization. In which of the following principles of architecture and design is the CISO engaging?
A. Waterfalling
B. Baselining
C. Change management
D. Dynamic analysis
Answer: C
NEW QUESTION NO: 3
Which of the following types of attacks precedes the installation of a rootkit on a server?
A. Privilege escalation
B. DoS
C. Pharming
D. DDoS
Answer: A
NEW QUESTION NO: 4
A security analyst wants to harden the company's VoIP PBX. The
analyst is worried that credentials may be intercepted and
compromised when IP phones authenticate with the BPX. Which of the
following would best prevent this from occurring?
A. Implement SRTP between the phones and the PBX.
B. Require SIPS on connections to the PBX.
C. Restrict the phone connections to the PBX.
D. Place the phones and PBX in their own VLAN.
Answer: B
NEW QUESTION NO: 5
A development team has adopted a new approach to projects in
which feedback is iterative and multiple iterations of deployments
are provided within an application's full life cycle. Which of the
following software development methodologies is the development
team using?
A. Extreme
B. Rapid
C. Agile
D. Waterfall
Answer: C
NEW QUESTION NO: 6
Joe, a user, wants to send Ann, another user, a confidential
document electronically. Which of the following should Joe do to
ensure the document is protected from eavesdropping?
A. Encrypt it with Ann's private key.
B. Encrypt it with Joe's public key.
C. Encrypt it with Joe's private key.
D. Encrypt it with Ann's public key.
Answer: D
NEW QUESTION NO: 7
A director of IR is reviewing a report regarding several recent
breaches. The director compiles the following statistic's:
-
Initial IR engagement time frame
-
Length of time before an executive management notice went out
-
Average IR phase completion
The director wants to use the data to shorten the response time.
Which of the following would accomplish this?
A. Tabletop exercise
B. Containment phase
C. Escalation notifications
D. CSIRT
Answer: A
NEW QUESTION NO: 8
A security administrator is configuring a new network segment,
which contains devices that will be accessed by external users, such
as web and FTP server. Which of the following represents the MOST
seTchueresewgamyetnotcsohnofuigldurbeethpelancewd onnetawsoerkpasreagtme eVnLtA?N, and the firewall rules should be configured to allow extern

traffic.
The segment should be placed in the existing internal VLAN to allow internal traffic only.
The segment should be placed on an intranet, and the firewall rules should be configured to allow external traff The segment should be placed on an extranet, and the firewall rules should be configured to allow both internal external traffic.
Answer:
A
NEW QUESTION NO: 9
A security analyst receives an alert from a WAF with the following payload:
var data= "<test test test>" ++ <../../../../../../etc/passwd>"
Which of the following types of attacks is this?
A. Cross-site request forgery
B. Buffer overflow
C. Firewall evasion scipt
D. SQL injection
E. JavaScript data insertion
Answer: E
NEW QUESTION NO: 10
An organization uses SSO authentication for employee access to
network resources. When an employee resigns, as per the
organization's security policy, the employee's access to all network
resources is terminated immediately. Two weeks later, the former
employee sends an email to the help desk for a password reset to
access payroll information from the human resources server.
Which of the following represents the BEST course of action?

Approve the former employee's request, as a password reset would give the former employee access to only t human resources server.
Deny the former employee's request, since the password reset request came from an external email address.
Deny the former employee's request, as a password reset would give the employee access to all network resources.
Approve the former employee's request, as there would not be a security issue with the former employee gaini access to network.
Answer:
C