A Ans- A security administrator suspects an employee has been emailing proprietary information to a competitor. Company policy requires the administrator to capture an exact copy of the employee's hard disk.
Which of the following should the administrator use?
A. dd
B. chmod
C. dnsenum
D....
a ans a security administrator suspects an employee has been emailing proprietary information to a competitor company policy requires the administrator to capt
Geschreven voor
2021 BEST SECURITY
Alle documenten voor dit vak (3)
Verkoper
Volgen
EvaTee
Ontvangen beoordelingen
Voorbeeld van de inhoud
2021 BEST SECURITY+ EXAM SY0-601
STUDY
A Ans- A security administrator suspects an employee has been emailing proprietary
information to a competitor. Company policy requires the administrator to capture an
exact copy of the employee's hard disk.
Which of the following should the administrator use?
A. dd
B. chmod
C. dnsenum
D. logger
THIS IS THE ORDER AS FOLLOWS:
ssh-keygen -t rsa
ssh-copy-id -i ~/.ssh/id_rsa.pub user@server
chmod 644 ~/.ssh/id_rsa
ssh root@server Ans- DRAG AND DROP SIMULATION (SEE IMAGE)
Firewall 1:DNS Rule "" ANY --> ANY --> DNS --> PERMIT
HTTPS Outbound "" 10.0.0.1/24 --> ANY --> HTTPS --> PERMIT
Management "" ANY --> ANY --> SSH --> PERMIT
HTTPS Inbound "" ANY --> ANY --> HTTPS --> PERMIT
HTTP Inbound "" ANY --> ANY --> HTTP --> DENY
Firewall 2: No changes should be made to this firewall
Firewall 3:DNS Rule "" ANY --> ANY --> DNS --> PERMIT
HTTPS Outbound "" 192.168.0.1/24 --> ANY --> HTTPS --> PERMIT
Management "" ANY --> ANY --> SSH --> PERMIT
HTTPS Inbound "" ANY --> ANY --> HTTPS --> PERMIT
HTTP Inbound "" ANY --> ANY --> HTTP --> DENY Ans- DROP DOWN SIMULATION
(SEE IMAGE)
See IMAGE Ans- DRAG AND DROP SIMULATION (SEE ANSWERS IN IMAGE)
DF Ans- Which of the following will MOST likely adversely impact the operations of
unpatched traditional programmable-logic controllers, running a back-end LAMP server
and OT systems with human-management interfaces that are accessible over the
Internet via a web interface? (Choose two.)
,A. Cross-site scripting
B. Data exfiltration
C. Poor system logging
D. Weak encryption
E. SQL injection
F. Server-side request forgery
A Ans- A company recently transitioned to a strictly BYOD culture due to the cost of
replacing lost or damaged corporate-owned mobile devices.
Which of the following technologies would be BEST to balance the BYOD culture while
also protecting the company's data?
A. Containerization
B. Geofencing
C. Full-disk encryption
D. Remote wipe
D Ans- A Chief Security Office's (CSO's) key priorities are to improve preparation,
response, and recovery practices to minimize system downtime and enhance
organizational resilience to ransomware attacks.
Which of the following would BEST meet the CSO's objectives?
A. Use email-filtering software and centralized account management, patch high-risk
systems, and restrict administration privileges on fileshares.
B. Purchase cyber insurance from a reputable provider to reduce expenses during an
incident.
C. Invest in end-user awareness training to change the long-term culture and behavior
of staff and executives, reducing the organization's susceptibility to phishing attacks.
D. Implement application whitelisting and centralized event-log management, and
perform regular testing and validation of full backups.
AC Ans- A network engineer has been asked to investigate why several wireless
barcode scanners and wireless computers in a warehouse have intermittent connectivity
to the shipping server. The barcode scanners and computers are all on forklift trucks
and move around the warehouse during their regular use.
Which of the following should the engineer do to determine the issue? (Choose two.)
A. Perform a site survey
B. Deploy an FTK Imager
C. Create a heat map
,D. Scan for rogue access points
E. Upgrade the security protocols
F. Install a captive portal
C Ans- Which of the following is MOST likely to outline the roles and responsibilities of
data controllers and data processors?
A. SSAE SOC 2
B. PCI DSS
C. GDPR
D. ISO 31000
C Ans- Phishing and spear-phishing attacks have been occurring more frequently
against a company's staff.
Which of the following would MOST likely help mitigate this issue?
A. DNSSEC and DMARC
B. DNS query logging
C. Exact mail exchanger records in the DNS
D. The addition of DNS conditional forwarders
EF Ans- On which of the following is the live acquisition of data for forensic analysis
MOST dependent? (Choose two.)
A. Data accessibility
B. Legal hold
C. Cryptographic or hash algorithm
D. Data retention legislation
E. Value and volatility of data
F. Right-to-audit clauses
B Ans- Which of the following incident response steps involves actions to protect critical
systems while maintaining business operations?
A. Investigation
B. Containment
C. Recovery
D. Lessons learned
B Ans- A security auditor is reviewing vulnerability scan data provided by an internal
security team.
Which of the following BEST indicates that valid credentials were used?
, A. The scan results show open ports, protocols, and services exposed on the target
host
B. The scan enumerated software versions of installed programs
C. The scan produced a list of vulnerabilities on the target host
D. The scan identified expired SSL certificates
B Ans- Which of the following BEST explains the difference between a data owner and
a data custodian?
A. The data owner is responsible for adhering to the rules for using the data, while the
data custodian is responsible for determining the corporate governance regarding the
data
B. The data owner is responsible for determining how the data may be used, while the
data custodian is responsible for implementing the protection to the data
C. The data owner is responsible for controlling the data, while the data custodian is
responsible for maintaining the chain of custody when handling the data
D. The data owner grants the technical permissions for data access, while the data
custodian maintains the database access controls to the data
D Ans- A network engineer needs to build a solution that will allow guests at the
company's headquarters to access the Internet via WiFi. This solution should not allow
access to the internal corporate network, but it should require guests to sign off on the
acceptable use policy before accessing the Internet.
Which of the following should the engineer employ to meet these requirements?
A. Implement open PSK on the APs
B. Deploy a WAF
C. Configure WIPS on the APs
D. Install a captive portal
D Ans- Based on the analyst's findings, which of the following attacks is being
executed?
A. Credential harvesting
B. Keylogger
C. Brute-force
D. Spraying
C Ans- Which of the following cloud models provides clients with servers, storage, and
networks but nothing else?
A. SaaS
Voordelen van het kopen van samenvattingen bij Stuvia op een rij:
Verzekerd van kwaliteit door reviews
Stuvia-klanten hebben meer dan 700.000 samenvattingen beoordeeld. Zo weet je zeker dat je de beste documenten koopt!
Snel en makkelijk kopen
Je betaalt supersnel en eenmalig met iDeal, creditcard of Stuvia-tegoed voor de samenvatting. Zonder lidmaatschap.
Focus op de essentie
Samenvattingen worden geschreven voor en door anderen. Daarom zijn de samenvattingen altijd betrouwbaar en actueel. Zo kom je snel tot de kern!
Veelgestelde vragen
Wat krijg ik als ik dit document koop?
Je krijgt een PDF, die direct beschikbaar is na je aankoop. Het gekochte document is altijd, overal en oneindig toegankelijk via je profiel.
Tevredenheidsgarantie: hoe werkt dat?
Onze tevredenheidsgarantie zorgt ervoor dat je altijd een studiedocument vindt dat goed bij je past. Je vult een formulier in en onze klantenservice regelt de rest.
Van wie koop ik deze samenvatting?
Stuvia is een marktplaats, je koop dit document dus niet van ons, maar van verkoper EvaTee. Stuvia faciliteert de betaling aan de verkoper.
Zit ik meteen vast aan een abonnement?
Nee, je koopt alleen deze samenvatting voor €12,20. Je zit daarna nergens aan vast.