Font size
WorksheetsSY0-501 Practice Quiz 2
Total questions: 29
Worksheet time: 29mins
You are a security administrator for a company that has been contracted by a 'local government agency for a
data collection and reporting project Data must be stored locally to your organization and the company will
be ~ s suing weekly summary reports.
At some point, it may be necessary for the government agency to view the raw data, but only after receiving
proper authorization from its supervising agents or through a court order.. You need to ensure this, capability.
What should you do?
Prepare a CSR that can be submitted as necessary
Create user accounts for agency employees, and then disable the accounts
Designate agency employees as recovery agents
Set up a key escrow
A critical web server is compromised by a persistent XSS attack. Which two steps would you take as part of the containment process? (Choose Two)
Redirect traffic to a different web server
Create a forensic image of the server
Implement input validation
Review the web application logs
Re-image the server
A company is concerned that accessing data from an Active Directory domain is not secure, Which protocol should you implement?
LDAP over IPSec
FTP over SSL
FTP over IPSec
LDAP over SSL
You want to use a backup scheme that does not take too much time or require very high capacity tapes each right. Because you don not have to restore data that often, you do not care if the restore process is lengthier as a result, but you do not want it to take an unreasonable amount of time. Which of the following would be the best backup scheme to meet your goals?
Perform a full backup nightly
Perform a full backup weekly. Perform differential backups nightly
Perform full backup monthly. Perform incremental backups nightly
Perform full backup weekly. Perform incremental backups nightly
You receive a security bulletin that a patch is available for an application running on all network client computers. The application is a mission-critical application. You download the patch to a directory on a network server. What should you do next?
Deploy the patch immediately to all computers that are trunning the application
Test the patch on select isolated computers
Wait until client computers display the problem described in the security bulletin
Distribute copies of the patch on CD-ROM to all network users
All computers in your organization come with TPM installed. What type of data encryption most often uses keys generated from the TPM?
Full disk encryption
File encryption
Data in transit encryption
Database encryption
Which is BEST described as a type of compensating control?
Hot site
Anti-virus
IDS
Firewall
A company wants to open a new office. Both offices have a reliable link to the internet. The company has provided the following requirements for this project:
- All communication between the two sites has to be protected and secures using AES
- Implement a solution to prevent theft of company data from the inside
Which solution should you recommend?
GRE tunnel and DLP
VPN PPTP tunnel and DLP
VPN IPSec tunnel and DLP
GRE tunnel and IPS
Users report that an application is failing and displaying detailed messaging including stack traces, data dumps, and detailed codes. This results from what type of vulnerability?
Certificate mismanagement
Untrained users
Improper error handling
False positive
A company deploys a DLP system. A security officer wants to create a policy to match and block access to documents that include any linked PII. Which three of the following should be included?
Credit card numbers
E-mail addresses
Postcodes
Personal phone numbers
Salary information
A company wants to introduce EAP to secure all WLAN connections. The solution has to use mutual authentication and a valid certificate for the client and the server. Which protocol should the company implement to meet theses requirements?
EAP-FAST
EAP-TTLS
EAP-TLS
EAP-MD5
A company has a fully functional wireless network with a single SSID and two standalone access points using WPA2-PSK. The company wants to add a new SSID that will be isolated from the existing SSID. A new IP range will be introduced. Which solution BEST supports that deployment
DMZ
EAP
IPSec
VLAN
A company wants to install a VOIP system internally and between two branch offices. Which two technologies will assist in a secure deployment?
PPTP
TLS
L2TP
RTP
VLAN
What are two advantages of implementing a vendor diversity policy?
Improved network troubleshooting
Reduced equipment costs
Access to the most recent technologies
Layered defense strategies
Simplified administration requirements
Which two attacks are DoS attacks against a Wi-Fi network?
Replay
IV attack
WPS attack
Jamming
War driving
You want to deploy a centralized authentication structure that can be used to authenticate routers, servers, and switches. You want this structure to be as secure as possible. What should you use?
SAML
TACACS+
Kerberos
RADIUS
An organization has determined it can tolerate a maximum of three hours of downtime. Which of the following has been specified?
RTO
RPO
MTBF
MTTR
Which of the following types of keys is found in a key escrow?
Pubilc
Private
Shared
Session
A network administrator wants to implement a method of securing internal routing. Which of the following should the administrator implement?
DMZ
NAT
VPN
PAT
A security administrator is developing controls for creating audit trails and tracking if a PHI data breach is to occur. The administrator has been given the following
requirements:
-All access must be correlated to a user account.
-All user accounts must be assigned to a single individual.
-User access to the PHI data must be recorded.
-Anomalies in PHI data access must be reported.
-Logs and records cannot be deleted or modified.
Which of the following should the administrator implement to meet the above requirements? (Select three.)
Eliminate shared accounts
Create a standard naming convention
Implement usage auditing and review
Enable account lockout thresholds
Perform regular permission audits and reviews
Which of the following encryption methods does PKI typically use to securely project keys?
Eliptic curve
Digital signatures
Asymmetric
Obfuscation
A department head at a university resigned on the first day of the spring semester. It was subsequently determined that the department head deleted numerous files
and directories from the server-based home directory while the campus was closed. Which of the following policies or procedures could have prevented this from
occurring?
Time-of-day restrictions
Permission auditing and review
Offboarding
Account expiration
A security administrator has found a hash in the environment known to belong to malware. The administrator then finds this file to be in in the preupdate area of the
OS, which indicates it was pushed from the central patch system.
File: winx86_adobe_flash_upgrade.exe
Hash: 99ac28bede43ab869b853ba62c4ea243
The administrator pulls a report from the patch management system with the following output:
Given the above outputs, which of the following MOST likely happened?
The file was corrupted after it left the patch system
The file was infected when the patch manager downloaded it
The file was not approved in the application whitelist system
The file was embedded with a logic bomb to evade detection
A network administrator at a small office wants to simplify the configuration of mobile clients connecting to an encrypted wireless network. Which of the following
should be implemented in the administrator does not want to provide the wireless password or he certificate to the employees?
WPS
802.1x
WPA2-PSK
TKIP
When configuring settings in a mandatory access control environment, which of the following specifies the subjects that can access specific data objects?
Owner
System
Administrator
User
A high-security defense installation recently begun utilizing large guard dogs that bark very loudly and excitedly at the slightest provocation. Which of the following
types of controls does this BEST describe?
Deterent
Prevnetive
Detective
Compensating
A company’s user lockout policy is enabled after five unsuccessful login attempts. The help desk notices a user is repeatedly locked out over the course of a
workweek. Upon contacting the user, the help desk discovers the user is on vacation and does not have network access. Which of the following types of attacks are
MOST likely occurring? (Select two.)
Replay
Rainbow tables
Brute force
Pass the hash
Dictionary
A company performs information classification. What is the outcome of this process?
Appropriate access permissions are applied to data
The cost of protecting data from accidental or malicious disclosure is assessed
Data is categorized in terms of confidentiality, integrity, and availability requirements
Access to data is assigned on a need-to-know according to the user's role in the company
A server has failed four times in the past year. Which measurement is used to determine the amount of time the serer was operational?
MTTF
ARO
MTBF
ALE
