WorksheetsSYO-601 Practice Questions 42-82
Total questions: 41
Worksheet time: 21mins
An organization is tuning SIEM rules based off of threat intelligence
reports. Which of the following phases of the incident response process
does this scenario represent?
Eradication
Preparation
Lessons Learned
Recovery
A network manager is concerned that business may be negatively
impacted if the firewall in its datacenter goes offline. The manager would
like to implement a high availability pair to:
decrease the mean time between failures
cut dawn the mean time to repair.
remove the single point of failure.
reduce the recovery time objective.
A host was infected with malware. During the incident response, Joe, a
user, reported that he did not receive any emails with links, but he had
been browsing the Internet all day. Which of the following would MOST likely show where the malware originated?
The DNS logs
The SIP traffic logs
The web server logs
The SNMP logs
Which of the following would MOST likely be identified by a Points
credentialed scan but would be missed by an uncredentialed scan?
Vulnerabilities with a CVSS score greater than 6.9.
CVEs related to nan-Microsoft systems such as printers and switches.
Critical infrastructure vulnerabilities on non-lP protocols.
Missing patches for third-party software on Windows workstations and
servers.
A recent phishing campaign resulted in several compromised user
accounts. The security incident response team has been tasked with
reducing the manual labor ot filtering through all the phishing emails as
they arrive and blocking the sender's email address, along with other
time-consuming mitigation actions. Which of the following can be configured to streamline those tasks?
SOAR playbook
Firewall rules
MOM policy
URLfilter
SIEM data collection
Which of the following is a reason to publish files' hashes?
To validate the integrity af the files
To use the hash as a software activation ke
To verify if the software was digitally signed
To use the hash as a decryption passphrase
A security analyst is tasked with classifying data to be stored on company
servers. Which of the following should be classified as proprietary?
Customers dates af birth
Marketing strategies
Customers email addresses
Employee salaries
Which of the following are requirements that must be configured for PCI
OSS compliance? (Choose two.)
Testing security systems and processes regularly
Assigning a unique 10 to each person with computer access
Installing and maintaining a web proxy to protect cardholder data
Encrypting transmission of cardholder data across private networks
Benchmarking security awareness training far contractors
Which of the following can be used by a monitoring tool to compare
values and detect password leaks without providing the actual
credentials?
hashing
masking
tokenization
Encryption
An organization would like to give remote workers the ability to use
applications hosted inside the corporate network. Users will be allowed to
use their personal computers, or they will be provided organization
assets. Either way, no data or applications will be installed locally on any
user systems. Which of the following mobile solutions would accomplish these
goals?
VDI
COPE
MDM
UTM
Which of the following explains why RTO is included in a BlA?
It identifies the amount of allowable downtime for an application or system.
It monetizes the loss of an asset and determines a break-even point for risk
mitigation.
It prioritizes risks so the organization can allocate resources appropriately.
It informs the backup approach so that the organization can recover data ta
a known time.
Against the recommendation ot the IT security analyst, a company set all
user passwords on a server as F@55w0rD. upon review of the
/etc/passwd file, an attacker found the following:
Upon review of the /etc/passwd file, an attacker found the following: alice:a8df3b6c4fd75f0617431fd248f35191df8d237f bob:2d250c5b2976b03d757f324ebd59340df96aa05e chris:ea981ec3285421d014108089f3f3f997ce0f4150
Which of the following BEST explains why the encrypted passwords do not match?
Perfect forward secrecy
Salting
Key stretching
Hashing
Which of the following would be the BEST way to analyze diskless
malware that has infected a VDI?
Run a full on-demand scan of the root volume.
Take a memory snapshot of the running system.
Shut down the VOI and copy off the event logs.
Use NetFlow to identify command-and-control IPs.
An attacker browses a company's online job board attempting to find any
relevant information regarding the technologies the company uses.
Which of the following BEST describes this social engineering
technique?
Hoax
Impersonation
Reconnaissance
Pretexting
An organization is building backup server rooms in geographically diverse
locations. The Chief Information Security Officer implemented a
requirement on the project that states the new hardware cannot be
susceptible to the same vulnerabilities in the existing server room.
Which of the following should the systems engineer consider?
Purchasing hardware from different vendors
Implementing a robust patch management solution
Migrating workloads to public cloud infrastructure
Designing new detective security controls
While investigating a recent security incident, a security analyst decided
to view all network connections on a particular server.
Which of the following would provide the desired information?
nslookup
nmap
netstat
arp
A Chief Information Security Officer (CISO) has defined resiliency
requirements for a new data center architecture The requirements are as follows:
• Critical file shares will remain accessible during and after a natural disaster
• Five percent of hard disks can fail at any given time without impacting the data.
• Systems will be forced to shut down gracefully when battery levels are below 20%.
Which of the following are required to BEST meet these objectives? (Select THREE)
RAID
NAS
high availability
UPS
While investigating a recent security incident, a security analyst decided
to view all network connections on a particular server.
Which of the following would provide the desired information?
nslookup
netstat
arp
nmap
A security analyst is reviewing the following command-line output:
ICMP spoofing
MAC address cloning
URL redirection
DNS poisoning
A company is required to continue using legacy software to support a
critical service.
Which of the following BEST explains a risk of this practice?
Default system configuration
Lack of vendor support
Unsecure protocols
Weak encryption
A major political party experienced a server breach. The hacker then
publicly posted stolen internal communications concerning campaign
strategies to give the opposition party an advantage.
Which of the following BEST describes these threat actors?
Semi-authorized hackers
Script kiddies
State actors
Advanced persistent threats
While reviewing the wireless router, a systems administrator of a small
business determines someone is spoofing the MAC address of an
authorized device. Given the table ABOVE
Which of the following should be the administrators NEXT step to detect if there is a rogue system without impacting availability?
Conduct a ping sweep
Deny Internet access to the "UNKNOWN" hostname.
Physically check each system.
Apply MAC filtering
A forensics investigator is examining a number ot unauthorized payments
that were reported on the company's website. Some unusual log entries
show users received an email for an unwanted mailing attempt to
unsubscribe. One of the users reported the email to the phishing team,
and the forwarded email revealed the link to be:
<a href="https://www.company.com/payto.do?routing=00001111&acct=22223334&amount=250">Click here to unsubscribe</a>
Which of the following will the forensics investigator MOST likely determine has occurred?
SQL Injection
XSS
Broken authentication
XSRF
Which of the following is a risk that is specifically associated with hosting
applications in the public cloud?
Unsecured root accounts
Shared tenancy
Zero-day
Insider threat
While checking logs, a security engineer notices a number of end users
suddenly downloading files with the .tar.gz extension. Closer examination
of the files reveals they are PE32 files. The end users state they did not
initiate any of the downloads. Further investigation reveals the end users
all clicked on an external email containing an infected MHT file with an
href link a week prior.
Which of the following is MOST likely occurring?
A RAT was installed and is transferring additional exploit tools.
A logic bomb was executed and is responsible for the data transfers.
The workstations are beaconing to a command-and-control server.
A fireless virus is spreading in the local network environment.
A worldwide manufacturing company has been experiencing email
account compromises. In one incident, a user logged in from the
corporate office in France, but then seconds later, the same user account
attempted a login from Brazil.
Which of the following account policies would BEST prevent this type of
attack?
Network location
Geolocation
Impossible travel time
Geofencing
After segmenting the network, the network manager wants to control the
traffic between the segments.
Which of the following should the manager use to control the
network traffic?
A DMZ
A VLAN
A VPN
An ACL
Which of the following uses SAML for authentication?
HOTP
TOTP
Federation
Kerberos
While reviewing pcap data, a network security analyst is able to locate
plaintext usernames and passwords being sent from workstations to
network switches.
Which of the following is the security analyst MOST likely observing?
SNMP traps
An SSH connection
A Telnet session
SFTP traffic
The manager who is responsible for a data set has asked a security
engineer to apply encryption to the data on a hard disk. The security
engineer is an example of a:
data controller.
data custodian
data owner
data processor
A cybersecurity analyst reviews the log files trom a web server and sees a
series of files that indicate a directory-traversal attack has occurred.
Which of the following is the analyst MOST likely seeing?
http://sample.url.com/<script>Please-Visit-Our-Phishing-Site</script>
http://sample.url.com/someotherpageonsite/../../../etc/shadow
Under GOPR, which of the following is MOST responsible for the
protection of privacy and website user rights?
The data protection officer
The data owner
The data processor
The data controller
A security administrator is analyzing the corporate wireless network. The
network only has two access points running on channels 1 and 11. While
using airodumping. the administrator notices other access points are
running with the same corporate ESSID on all available channels and with
the same BSSlD of one of the legitimate access points.
Which of the following attacks is happening on the corporate network?
Man in the middle
Jamming
Evil twin
Rogue access point
Disassociation
The IT depaäment's on-site developer has been WI•th the team for many
years. Each time an application is released, the security team is able to
identify multiple vulnerabilities.
Which of the following would BEST help the team ensure the application
is ready to be released to production?
Limit the use of third-pady libraries
Obfuscate the source code
Prevent data exposure queries.
Submit the application to
before releasing it
A user received an SMS on a mobile phone that asked for bank details.
Which of the following social-engineering techniques was used in this
case?
SPIM
Spear phishing
Vishing
Smishing
A company recently experienced a data breach and the source was
determined to be an executive who was charging a phone in a public
area.
Which of the following would MOST likely have prevented this breach?
A firewall
A
data blocker
A device pin
Biometrics
A company is adopting a BYOD policy and is looking for a comprehensive
solution to protect company information on user devices.
Which of the following solutions would BEST support the policy?
Mobile device management
Remote wipe
Full-device encryption
Biometrics
A security analyst is investigating multiple hosts that are communicating
to external IP addresses during the hours of 2.00 am - 4:00 am. The
malware has evaded detection by traditional antivirus software.
Which of the following types of malware is MOST likely infecting the
hosts?
Ransomware
Polymorphic
A worm
A RAT
A security administrator suspects there may be unnecessary services
running on a server. Which of the following tools will the administrator
MOST likely use to confirm the suspicions?
Nmap
Autopsy
Wireshark
DNSEnum
An organization is concerned about hackers potentially entering a facility
and plugging in a remotely accessible Kali Linux box.
Which of the following should be the first lines of defense against
such an attack? (Choose two.)
MAC filtering
Zero Trust segmentation
Network access control
Access control vestibules
Guards
Ann, a customer, received a notification from her mortgage company
stating her PII may be shared with partners, affiliates, and associates to
maintain day-to-day business operations.
Which of the following documents did Ann receive?
An annual privacy notice
A privileged•user agreement
A non-disclosure agreement
memorandum of understandng
