for CompTIA certification, Real Success Guaranteed with Updated . 100% PASS SY0-501 CompTIA Security+ Certification Exam exam Today!

CompTIA SY0-501 Free Dumps Questions Online, Read and Test Now.

NEW QUESTION 1
A company offers SaaS, maintaining all customers' credentials and authenticating locally. Many large customers have requested the company offer some form of federation with their existing authentication infrastructures. Which of the following would allow customers to manage authentication and authorizations from within their existing organizations?

  • A. Implement SAML so the company's services may accept assertions from the customers' authentication servers.
  • B. Provide customers with a constrained interface to manage only their users' accounts in the company'sactive directory server.
  • C. Provide a system for customers to replicate their users' passwords from their authentication service to the company's.
  • D. Use SOAP calls to support authentication between the company's product and the customers' authentication servers.

Answer: A

NEW QUESTION 2
A malicious attacker has intercepted HTTP traffic and inserted an ASCII line that sets the referrer URL. Which of the following is the attacker most likely utilizing?

  • A. Header manipulation
  • B. Cookie hijacking
  • C. Cross-site scripting
  • D. Xml injection

Answer: A

NEW QUESTION 3
A cybersecurity analyst is looking into the payload of a random packet capture file that was selected for analysis. The analyst notices that an internal host had a socket established with another internal host over a non-standard port.
Upon investigation, the origin host that initiated the socket shows this output:
SY0-501 dumps exhibit
Given the above output, which of the following commands would have established the questionable socket?

  • A. traceroute 8.8.8.8
  • B. ping -1 30 8.8.8.8 -a 600
  • C. nc -1 192.168.5.1 -p 9856
  • D. pskill pid 9487

Answer: C

NEW QUESTION 4
A database backup schedule consists of weekly full backups performed on Saturday at 12:00 a.m. and daily differential backups also performed at 12:00 a.m. If the database is restored on Tuesday afternoon, which of the following is the number of individual backups that would need to be applied to complete the database recovery?

  • A. 1
  • B. 2
  • C. 3
  • D. 4

Answer: B

NEW QUESTION 5
A security analyst observes the following events in the logs of an employee workstation:
SY0-501 dumps exhibit
Given the information provided, which of the following MOST likely occurred on the workstation?

  • A. Application whitelisting controls blocked an exploit payload from executing.
  • B. Antivirus software found and quarantined three malware files.
  • C. Automatic updates were initiated but failed because they had not been approved.
  • D. The SIEM log agent was not tuned properly and reported a false positive.

Answer: A

NEW QUESTION 6
An attacker discovers a new vulnerability in an enterprise application. The attacker takes advantage of the vulnerability by developing new malware. After installing the malware, the attacker is provided with access to the infected machine.
Which of the following is being described?

  • A. Zero-day exploit
  • B. Remote code execution
  • C. Session hijacking
  • D. Command injection

Answer: A

NEW QUESTION 7
Joe, a security administrator, needs to extend the organization’s remote access functionality to be used by staff while travelling. Joe needs to maintain separate access control functionalities for internal, external, and VOIP services. Which of the following represents the BEST access technology for Joe to use?

  • A. RADIUS
  • B. TACACS+
  • C. Diameter
  • D. Kerberos

Answer: B

NEW QUESTION 8
A company is deploying a new VoIP phone system. They require 99.999% uptime for their phone service and are concerned about their existing data network interfering with the VoIP phone system. The core switches in the existing data network are almost fully saturated. Which of the following options will pro-vide the best performance and availability for both the VoIP traffic, as well as the traffic on the existing data network?

  • A. Put the VoIP network into a different VLAN than the existing data network.
  • B. Upgrade the edge switches from 10/100/1000 to improve network speed
  • C. Physically separate the VoIP phones from the data network
  • D. Implement flood guards on the data network

Answer: A

NEW QUESTION 9
Multiple organizations operating in the same vertical want to provide seamless wireless access for their employees as they visit the other organizations. Which of the following should be implemented if all the organizations use the native 802.1x client on their mobile devices?

  • A. Shibboleth
  • B. RADIUS federation
  • C. SAML
  • D. OAuth
  • E. OpenID connect

Answer: B

Explanation: http://archive.oreilly.com/pub/a/wireless/2005/01/01/authentication.html

NEW QUESTION 10
A security administrator is trying to eradicate a worm, which is spreading throughout the organization, using an old remote vulnerability in the SMB protocol. The worm uses Nmap to identify target hosts within the company. The administrator wants to implement a solution that will eradicate the current worm and any future attacks that may be using zero-day vulnerabilities. Which of the following would BEST meet the requirements when implemented?

  • A. Host-based firewall
  • B. Enterprise patch management system
  • C. Network-based intrusion prevention system
  • D. Application blacklisting
  • E. File integrity checking

Answer: C

NEW QUESTION 11
Which of the following is an important step to take BEFORE moving any installation packages from a test environment to production?

  • A. Roll back changes in the test environment
  • B. Verify the hashes of files
  • C. Archive and compress the files
  • D. Update the secure baseline

Answer: B

NEW QUESTION 12
A company researched the root cause of a recent vulnerability in its software. It was determined that the vulnerability was the result of two updates made in the last release. Each update alone would not have resulted in the vulnerability. In order to prevent similar situations in the future, the company should improve which of the following?

  • A. Change management procedures
  • B. Job rotation policies
  • C. Incident response management
  • D. Least privilege access controls

Answer: A

NEW QUESTION 13
An organization uses SSO authentication for employee access to network resources. When an employee resigns, as per the organization’s security policy, the employee’s access to all network resources is terminated immediately. Two weeks later, the former employee sends an email to the help desk for a password reset to access payroll information from the human resources server. Which of the following represents the BEST course of action?

  • A. Approve the former employee’s request, as a password reset would give the former employee access to only the human resources server.
  • B. Deny the former employee’s request, since the password reset request came from an external email address.
  • C. Deny the former employee’s request, as a password reset would give the employee access to all network resources.
  • D. Approve the former employee’s request, as there would not be a security issue with the former employee gaining access to network resources.

Answer: C

NEW QUESTION 14
Select the appropriate attack from each drop down list to label the corresponding illustrated attack.
Instructions: Attacks may only be used once, and will disappear from drop down list if selected. When you have completed the simulation, please select the Done button to submit.
SY0-501 dumps exhibit

    Answer:

    Explanation: 1: Spear phishing is an e-mail spoofing fraud attempt that targets a specific organization, seeking unauthorized access to confidential data. As with the e-mail messages used in regular phishing expeditions, spear phishing messages appear to come from a trusted source. Phishing messages usually appear to come from a large and well-known company or Web site with a broad membership base, such as eBay or PayPal. In the case of spear phishing, however, the apparent source of the e-mail is likely to be an individual within the recipient's own company and generally someone in a position of authority.
    2: The Hoax in this question is designed to make people believe that the fake AV (anti- virus) software is genuine.
    3: Vishing is the act of using the telephone in an attempt to scam the user into surrendering private information that will be used for identity theft. The scammer usually pretends to be a legitimate business, and fools the victim into thinking he or she will profit.
    4: Phishing is the act of sending an email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft.
    Phishing email will direct the user to visit a website where they are asked to update personal information, such as a password, credit card, social security, or bank account numbers, that the legitimate organization already has. The website, however, is bogus and set up only to steal the information the user enters on the page.
    5: Similar in nature to e-mail phishing, pharming seeks to obtain personal or private (usually financial related) information through domain spoofing. Rather than being spammed with malicious and mischievous e-mail requests for you to visit spoof Web sites which appear legitimate, pharming 'poisons' a DNS server by infusing false information into the DNS server, resulting in a user's request being redirected elsewhere. Your browser, however will show you are at the correct Web site, which makes pharming a bit more serious and more difficult to detect. Phishing attempts to scam people one at a time with an e-mail while pharming allows the scammers to target large groups of people at one time through domain spoofing.
    References:
    http://searchsecurity.techtarget.com/definition/spear-phishing http://www.webopedia.com/TERM/V/vishing.html http://www.webopedia.com/TERM/P/phishing.html http://www.webopedia.com/TERM/P/pharming.html

    NEW QUESTION 15
    A security analyst wishes to increase the security of an FTP server. Currently, all traffic to the FTP server is unencrypted. Users connecting to the FTP server use a variety of modern FTP client software.
    The security analyst wants to keep the same port and protocol, while also still allowing unencrypted connections. Which of the following would BEST accomplish these goals?

    • A. Require the SFTP protocol to connect to the file server.
    • B. Use implicit TLS on the FTP server.
    • C. Use explicit FTPS for connections.
    • D. Use SSH tunneling to encrypt the FTP traffic.

    Answer: C

    NEW QUESTION 16
    Which of the following is the BEST reason to run an untested application is a sandbox?

    • A. To allow the application to take full advantage of the host system's resources and storage
    • B. To utilize the host systems antivirus and firewall applications instead of running it own protection
    • C. To prevent the application from acquiring escalated privileges and accessing its host system
    • D. To increase application processing speed so the host system can perform real-time logging

    Answer: C

    NEW QUESTION 17
    An audit reported has identifies a weakness that could allow unauthorized personnel access to the facility at its main entrance and from there gain access to the network. Which of the following would BEST resolve the vulnerability?

    • A. Faraday cage
    • B. Air gap
    • C. Mantrap
    • D. Bollards

    Answer: C

    NEW QUESTION 18
    Which of the following strategies should a systems architect use to minimize availability risks due to insufficient storage capacity?

    • A. High availability
    • B. Scalability
    • C. Distributive allocation
    • D. Load balancing

    Answer: B

    P.S. Easily pass SY0-501 Exam with 540 Q&As 2passeasy Dumps & pdf Version, Welcome to Download the Newest 2passeasy SY0-501 Dumps: https://www.2passeasy.com/dumps/SY0-501/ (540 New Questions)