Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SYO-601 Practice Questions 42-82

Total questions: 41

Worksheet time: 21mins

Name
Class
Date
1.

An organization is tuning SIEM rules based off of threat intelligence

reports. Which of the following phases of the incident response process

does this scenario represent?

a)

Eradication

b)

Preparation

c)

Lessons Learned

d)

Recovery

2.

A network manager is concerned that business may be negatively

impacted if the firewall in its datacenter goes offline. The manager would

like to implement a high availability pair to:

a)

decrease the mean time between failures

b)

cut dawn the mean time to repair.

c)

remove the single point of failure.

d)

reduce the recovery time objective.

3.

A host was infected with malware. During the incident response, Joe, a

user, reported that he did not receive any emails with links, but he had

been browsing the Internet all day. Which of the following would MOST likely show where the malware originated?

a)

The DNS logs

b)

The SIP traffic logs

c)

The web server logs

d)

The SNMP logs

4.

Which of the following would MOST likely be identified by a Points

credentialed scan but would be missed by an uncredentialed scan?

a)

Vulnerabilities with a CVSS score greater than 6.9.

b)

CVEs related to nan-Microsoft systems such as printers and switches.

c)

Critical infrastructure vulnerabilities on non-lP protocols.

d)

Missing patches for third-party software on Windows workstations and

servers.

5.

A recent phishing campaign resulted in several compromised user

accounts. The security incident response team has been tasked with

reducing the manual labor ot filtering through all the phishing emails as

they arrive and blocking the sender's email address, along with other

time-consuming mitigation actions. Which of the following can be configured to streamline those tasks?

a)

SOAR playbook

b)

Firewall rules

c)

MOM policy

d)

URLfilter

e)

SIEM data collection

6.

Which of the following is a reason to publish files' hashes?

a)

To validate the integrity af the files

b)

To use the hash as a software activation ke

c)

To verify if the software was digitally signed

d)

To use the hash as a decryption passphrase

7.

A security analyst is tasked with classifying data to be stored on company

servers. Which of the following should be classified as proprietary?

a)

Customers dates af birth

b)

Marketing strategies

c)

Customers email addresses

d)

Employee salaries

8.

Which of the following are requirements that must be configured for PCI

OSS compliance? (Choose two.)

a)

Testing security systems and processes regularly

b)

Assigning a unique 10 to each person with computer access

c)

Installing and maintaining a web proxy to protect cardholder data

d)

Encrypting transmission of cardholder data across private networks

e)

Benchmarking security awareness training far contractors

9.

Which of the following can be used by a monitoring tool to compare

values and detect password leaks without providing the actual

credentials?

a)

hashing

b)

masking

c)

tokenization

d)

Encryption

10.

An organization would like to give remote workers the ability to use

applications hosted inside the corporate network. Users will be allowed to

use their personal computers, or they will be provided organization

assets. Either way, no data or applications will be installed locally on any

user systems. Which of the following mobile solutions would accomplish these

goals?

a)

VDI

b)

COPE

c)

MDM

d)

UTM

11.

Which of the following explains why RTO is included in a BlA?

a)

It identifies the amount of allowable downtime for an application or system.

b)

It monetizes the loss of an asset and determines a break-even point for risk

mitigation.

c)

It prioritizes risks so the organization can allocate resources appropriately.

d)

It informs the backup approach so that the organization can recover data ta

a known time.

12.

Against the recommendation ot the IT security analyst, a company set all

user passwords on a server as F@55w0rD. upon review of the

/etc/passwd file, an attacker found the following:

Upon review of the /etc/passwd file, an attacker found the following: alice:a8df3b6c4fd75f0617431fd248f35191df8d237f bob:2d250c5b2976b03d757f324ebd59340df96aa05e chris:ea981ec3285421d014108089f3f3f997ce0f4150

Which of the following BEST explains why the encrypted passwords do not match?

a)

Perfect forward secrecy

b)

Salting

c)

Key stretching

d)

Hashing

13.

Which of the following would be the BEST way to analyze diskless

malware that has infected a VDI?

a)

Run a full on-demand scan of the root volume.

b)

Take a memory snapshot of the running system.

c)

Shut down the VOI and copy off the event logs.

d)

Use NetFlow to identify command-and-control IPs.

14.

An attacker browses a company's online job board attempting to find any

relevant information regarding the technologies the company uses.

Which of the following BEST describes this social engineering

technique?

a)

Hoax

b)

Impersonation

c)

Reconnaissance

d)

Pretexting

15.

An organization is building backup server rooms in geographically diverse

locations. The Chief Information Security Officer implemented a

requirement on the project that states the new hardware cannot be

susceptible to the same vulnerabilities in the existing server room.

Which of the following should the systems engineer consider?

a)

Purchasing hardware from different vendors

b)

Implementing a robust patch management solution

c)

Migrating workloads to public cloud infrastructure

d)

Designing new detective security controls

16.

While investigating a recent security incident, a security analyst decided

to view all network connections on a particular server.

Which of the following would provide the desired information?

a)

nslookup

b)

nmap

c)

netstat

d)

arp

17.

A Chief Information Security Officer (CISO) has defined resiliency

requirements for a new data center architecture The requirements are as follows:

• Critical file shares will remain accessible during and after a natural disaster

• Five percent of hard disks can fail at any given time without impacting the data.

• Systems will be forced to shut down gracefully when battery levels are below 20%.

Which of the following are required to BEST meet these objectives? (Select THREE)

a)

RAID

b)

NAS

c)

high availability

d)

UPS

18.

While investigating a recent security incident, a security analyst decided

to view all network connections on a particular server.

Which of the following would provide the desired information?

a)

nslookup

b)

netstat

c)

arp

d)

nmap

19.

A security analyst is reviewing the following command-line output:

a)

ICMP spoofing

b)

MAC address cloning

c)

URL redirection

d)

DNS poisoning

20.

A company is required to continue using legacy software to support a

critical service.

Which of the following BEST explains a risk of this practice?

a)

Default system configuration

b)

Lack of vendor support

c)

Unsecure protocols

d)

Weak encryption

21.

A major political party experienced a server breach. The hacker then

publicly posted stolen internal communications concerning campaign

strategies to give the opposition party an advantage.

Which of the following BEST describes these threat actors?

a)

Semi-authorized hackers

b)

Script kiddies

c)

State actors

d)

Advanced persistent threats

22.

While reviewing the wireless router, a systems administrator of a small

business determines someone is spoofing the MAC address of an

authorized device. Given the table ABOVE

Which of the following should be the administrators NEXT step to detect if there is a rogue system without impacting availability?

a)

Conduct a ping sweep

b)

Deny Internet access to the "UNKNOWN" hostname.

c)

Physically check each system.

d)

Apply MAC filtering

23.

A forensics investigator is examining a number ot unauthorized payments

that were reported on the company's website. Some unusual log entries

show users received an email for an unwanted mailing attempt to

unsubscribe. One of the users reported the email to the phishing team,

and the forwarded email revealed the link to be:

<a href="https://www.company.com/payto.do?routing=00001111&acct=22223334&amount=250">Click here to unsubscribe</a>

Which of the following will the forensics investigator MOST likely determine has occurred?

a)

SQL Injection

b)

XSS

c)

Broken authentication

d)

XSRF

24.

Which of the following is a risk that is specifically associated with hosting

applications in the public cloud?

a)

Unsecured root accounts

b)

Shared tenancy

c)

Zero-day

d)

Insider threat

25.

While checking logs, a security engineer notices a number of end users

suddenly downloading files with the .tar.gz extension. Closer examination

of the files reveals they are PE32 files. The end users state they did not

initiate any of the downloads. Further investigation reveals the end users

all clicked on an external email containing an infected MHT file with an

href link a week prior.

Which of the following is MOST likely occurring?

a)

A RAT was installed and is transferring additional exploit tools.

b)

A logic bomb was executed and is responsible for the data transfers.

c)

The workstations are beaconing to a command-and-control server.

d)

A fireless virus is spreading in the local network environment.

26.

A worldwide manufacturing company has been experiencing email

account compromises. In one incident, a user logged in from the

corporate office in France, but then seconds later, the same user account

attempted a login from Brazil.

Which of the following account policies would BEST prevent this type of

attack?

a)

Network location

b)

Geolocation

c)

Impossible travel time

d)

Geofencing

27.

After segmenting the network, the network manager wants to control the

traffic between the segments.

Which of the following should the manager use to control the

network traffic?

a)

A DMZ

b)

A VLAN

c)

A VPN

d)

An ACL

28.

Which of the following uses SAML for authentication?

a)

HOTP

b)

TOTP

c)

Federation

d)

Kerberos

29.

While reviewing pcap data, a network security analyst is able to locate

plaintext usernames and passwords being sent from workstations to

network switches.

Which of the following is the security analyst MOST likely observing?

a)

SNMP traps

b)

An SSH connection

c)

A Telnet session

d)

SFTP traffic

30.

The manager who is responsible for a data set has asked a security

engineer to apply encryption to the data on a hard disk. The security

engineer is an example of a:

a)

data controller.

b)

data custodian

c)

data owner

d)

data processor

31.

A cybersecurity analyst reviews the log files trom a web server and sees a

series of files that indicate a directory-traversal attack has occurred.

Which of the following is the analyst MOST likely seeing?

a)

http://sample.url.com/<script>Please-Visit-Our-Phishing-Site</script>

b)

http://sample.url.com/someotherpageonsite/../../../etc/shadow

32.

Under GOPR, which of the following is MOST responsible for the

protection of privacy and website user rights?

a)

The data protection officer

b)

The data owner

c)

The data processor

d)

The data controller

33.

A security administrator is analyzing the corporate wireless network. The

network only has two access points running on channels 1 and 11. While

using airodumping. the administrator notices other access points are

running with the same corporate ESSID on all available channels and with

the same BSSlD of one of the legitimate access points.

Which of the following attacks is happening on the corporate network?

a)

Man in the middle

b)

Jamming

c)

Evil twin

d)

Rogue access point

e)

Disassociation

34.

The IT depaäment's on-site developer has been WI•th the team for many

years. Each time an application is released, the security team is able to

identify multiple vulnerabilities.

Which of the following would BEST help the team ensure the application

is ready to be released to production?

a)

Limit the use of third-pady libraries

b)

Obfuscate the source code

c)

Prevent data exposure queries.

d)

Submit the application to

before releasing it

35.

A user received an SMS on a mobile phone that asked for bank details.

Which of the following social-engineering techniques was used in this

case?

a)

SPIM

b)

Spear phishing

c)

Vishing

d)

Smishing

36.

A company recently experienced a data breach and the source was

determined to be an executive who was charging a phone in a public

area.

Which of the following would MOST likely have prevented this breach?

a)

A firewall

b)

A

data blocker

c)

A device pin

d)

Biometrics

37.

A company is adopting a BYOD policy and is looking for a comprehensive

solution to protect company information on user devices.

Which of the following solutions would BEST support the policy?

a)

Mobile device management

b)

Remote wipe

c)

Full-device encryption

d)

Biometrics

38.

A security analyst is investigating multiple hosts that are communicating

to external IP addresses during the hours of 2.00 am - 4:00 am. The

malware has evaded detection by traditional antivirus software.

Which of the following types of malware is MOST likely infecting the

hosts?

a)

Ransomware

b)

Polymorphic

c)

A worm

d)

A RAT

39.

A security administrator suspects there may be unnecessary services

running on a server. Which of the following tools will the administrator

MOST likely use to confirm the suspicions?

a)

Nmap

b)

Autopsy

c)

Wireshark

d)

DNSEnum

40.

An organization is concerned about hackers potentially entering a facility

and plugging in a remotely accessible Kali Linux box.

Which of the following should be the first lines of defense against

such an attack? (Choose two.)

a)

MAC filtering

b)

Zero Trust segmentation

c)

Network access control

d)

Access control vestibules

e)

Guards

41.

Ann, a customer, received a notification from her mortgage company

stating her PII may be shared with partners, affiliates, and associates to

maintain day-to-day business operations.

Which of the following documents did Ann receive?

a)

An annual privacy notice

b)

A privileged•user agreement

c)

A non-disclosure agreement

d)

memorandum of understandng