The Best CompTIA SY0-501 Study Guides and Dumps of 2021
Top CompTIA SY0-501 Exam Audio Study Guide! Practice Questions Edition
Exam SY0-501 earns you the CompTIA Security+ certificate, which is among the core certifications that validate foundational IT skills and technical knowledge. This certificate is the globally accepted benchmark for IT best practices, specifically on operational security and computer network.
NEW QUESTION 54
Select the appropriate attack from each drop down list to label the corresponding illustrated attack.
Instructions: Attacks may only be used once, and will disappear from drop down list if selected. When you have completed the simulation, please select the Done button to submit.
Answer:
Explanation:
Explanation
1: Spear phishing is an e-mail spoofing fraud attempt that targets a specific organization, seeking unauthorized access to confidential data. As with the e-mail messages used in regular phishing expeditions, spear phishing messages appear to come from a trusted source. Phishing messages usually appear to come from a large and well-known company or Web site with a broad membership base, such as eBay or PayPal. In the case of spear phishing, however, the apparent source of the e-mail is likely to be an individual within the recipient's own company and generally someone in a position of authority.
2: The Hoax in this question is designed to make people believe that the fake AV (anti- virus) software is genuine.
3: Vishing is the act of using the telephone in an attempt to scam the user into surrendering private information that will be used for identity theft. The scammer usually pretends to be a legitimate business, and fools the victim into thinking he or she will profit.
4: Phishing is the act of sending an email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft.
Phishing email will direct the user to visit a website where they are asked to update personal information, such as a password, credit card, social security, or bank account numbers, that the legitimate organization already has. The website, however, is bogus and set up only to steal the information the user enters on the page.
5: Similar in nature to e-mail phishing, pharming seeks to obtain personal or private (usually financial related) information through domain spoofing. Rather than being spammed with malicious and mischievous e-mail requests for you to visit spoof Web sites which appear legitimate, pharming 'poisons' a DNS server by infusing false information into the DNS server, resulting in a user's request being redirected elsewhere. Your browser, however will show you are at the correct Web site, which makes pharming a bit more serious and more difficult to detect. Phishing attempts to scam people one at a time with an e-mail while pharming allows the scammers to target large groups of people at one time through domain spoofing.
References:
http://searchsecurity.techtarget.com/definition/spear-phishing
http://www.webopedia.com/TERM/V/vishing.html http://www.webopedia.com/TERM/P/phishing.html
http://www.webopedia.com/TERM/P/pharming.html
NEW QUESTION 55
An attacker exploited a vulnerability on a mail server using the code below.
Which of the following BEST explains what the attacker is doing?
- A. The attacker is deleting a cookie.
- B. The attacker is stealing a document.
- C. The attacker is replacing a document.
- D. The attacker is replacing a cookie.
Answer: C
NEW QUESTION 56
The computer resource center issued smartphones to all first-level and above managers. The managers
have the ability to install mobile tools. Which of the following tools should be implemented to control the
types of tools the managers install?
- A. Download manager
- B. Segmentation manager
- C. Application manager
- D. Content manager
Answer: C
NEW QUESTION 57
DRAG DROP
Drag and drop the correct protocol to its default port.
Answer:
Explanation:
Explanation:
FTP uses TCP port 21.
Telnet uses port 23.
SSH uses TCP port 22. All protocols encrypted by SSH, including SFTP, SHTTP, SCP, SExec, and slogin, also use TCP port 22. Secure Copy Protocol (SCP) is a secure file-transfer facility based on SSH and Remote Copy Protocol (RCP). Secure FTP (SFTP) is a secured alternative to standard File Transfer Protocol (FTP).
SMTP uses TCP port 25.
Port 69 is used by TFTP.
SNMP makes use of UDP ports 161 and 162.
References:
Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp. 42, 45, 51
http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers
NEW QUESTION 58
Which of the following authentication concepts is a gait analysis MOST closely associated?
- A. Something you are
- B. Something you know
- C. Something you do
- D. Somewhere you are
Answer: C
NEW QUESTION 59
Which of the following Is a resiliency strategy that allows a system to automatically adapt to workload changes?
- A. High availability
- B. Elasticity
- C. Fault tolerance
- D. Redundancy
Answer: B
NEW QUESTION 60
A security engineer must install the same x.509 certificate on three different servers. The client application that connects to the server performs a check to ensure the certificate matches the host name. Which of the following should the security engineer use?
- A. Certificate chaining
- B. Extended validation certificate
- C. Certificate utilizing the SAN file
:
SAN = Subject Alternate Names - D. Wildcard certificate
Answer: C
NEW QUESTION 61
A technician is installing a new SIEM and is configuring the system to count the number of times an event occurs at a specific logical location before the system takes action. Which of the following BEST describes the feature being configured by the technician?
- A. Correlation
- B. Aggregation
- C. Flood guard
- D. Event deduplication
Answer: A
NEW QUESTION 62
Confidential emails from an organization were posted to a website without the organization's knowledge. Upon investigation, it was determined that the emails were obtained from an internal actor who sniffed the emails in plain text.
Which of the following protocols, if properly implemented, would have MOST likely prevented the emails from being sniffed? (Select TWO)
- A. HTTPS
- B. DNSSEC
- C. Secure IMAP
- D. SMTPS
- E. S/MIME
Answer: D,E
NEW QUESTION 63
A company is terminating an employee for misbehavior.
Which of the following steps is MOST important in the process of disengagement from this employee?
- A. Generate a report on outstanding projects the employee handled
- B. Have the employee sign an NDA before departing
- C. Obtain a list of passwords used by the employee.
- D. Have the employee surrender company identification.
Answer: D
Explanation:
NDA is signed prior hiring, reports are not the most important. Neither is obtain passwords because admin should be able to reset the passwords anyway.
NEW QUESTION 64
An actor downloads and runs a program against a corporate login page. The program imports a list of usernames and passwords, looking for a successful attempt. Which of the following terms BEST describes the actor in this situation?
- A. Script kiddie
- B. Security auditor
- C. Hacktivist
- D. Cryptologist
Answer: A
NEW QUESTION 65
A security administrator is trying to eradicate a worm, which is spreading throughout the organization, using an old remote vulnerability in the SMB protocol. The worm uses Nmap to identify target hosts within the company. The administrator wants to implement a solution that will eradicate the current worm and any future attacks that may be using zero-day vulnerabilities.
Which of the following would BEST meet the requirements when implemented?
- A. Enterprise patch management system
- B. Network-based intrusion prevention system
- C. File integrity checking
- D. Application blacklisting
- E. Host-based firewall
Answer: B
NEW QUESTION 66
Which of the following would enhance the security of accessing data stored in the cloud? (Select TWO)
- A. Block level encryption
- B. Transport encryption
- C. SAML authentication
- D. Predefined challenge question
- E. Multifactor authentication
- F. Hashing
Answer: C,E
NEW QUESTION 67
A forensic analyst is asked to respond to an ongoing network attack on a server. Place the items in the list below in the correct order in which the forensic analyst should preserve them.
Answer:
Explanation:
Explanation
When dealing with multiple issues, address them in order of volatility (OOV); always deal with the most volatile first. Volatility can be thought of as the amount of time that you have to collect certain data before a window of opportunity is gone. Naturally, in an investigation you want to collect everything, but some data will exist longer than others, and you cannot possibly collect all of it once. As an example, the OOV in an investigation may be RAM, hard drive data, CDs/DVDs, and printouts.
Order of volatility: Capture system images as a snapshot of what exists, look at network traffic and logs, capture any relevant video/screenshots/hashes, record time offset on the systems, talk to witnesses, and track total man-hours and expenses associated with the investigation.
NEW QUESTION 68
A user suspects someone has been accessing a home network without permission by spoofing the MAC address of an authorized system. While attempting to determine if an authorized user is logged into the home network, the user reviews the wireless router, which shows the following table for systems that are currently on the home network.
Which of the following should be the NEXT step to determine if there is an unauthorized user on the network?
- A. Deny the "unknown" host because the hostname is not known and MAC filtering is not applied to this host.
- B. Apply MAC filtering and see if the router drops any of the systems.
- C. Physically check each of the authorized systems to determine if they are logged onto the network.
- D. Conduct a ping sweep of each of the authorized systems and see if an echo response is received.
Answer: A
NEW QUESTION 69
After deploying an antivirus solution on some network-isolated industrial computers, the service desk team received a trouble ticket about the following message being displayed on then computer's screen:
Which of the following would be the SAFEST next step to address the issue?
- A. Centrally activate a full scan for the entire set of industrial computers, looking for new threats
- B. Check the antivirus vendor's documentation about the security modules, incompatibilities, and software whitelisting.
- C. Immediately delete the detected file from the quarantine to secure the environment and clear the alert from the antivirus console
- D. Perform a manual antivirus signature update directly from the antivirus vendor's cloud
Answer: B
NEW QUESTION 70
Which of the following methods minimizes the system interaction when gathering information to conduct a vulnerability assessment of a router?
- A. Change the routing to bypass the router.
- B. Conduct the assessmenet during downtime
- C. Run a credentialed scan.
- D. Download the configuration
Answer: D
NEW QUESTION 71
A security auditor is reviewing the following output from file integrity monitoring software installed on a very busy server at a large service provider. The server has not been updates since it was installed. Drag and drop the log entry that identifies the first instance of server compromise.
Answer:
Explanation:
Explanation
NEW QUESTION 72
Which of the following are disadvantages of full backups? (Select THREE)
- A. They are impossible in virtual environments
- B. They require the most storage.
- C. They rely on other backups tor recovery
- D. They have the slowest recovery time
- E. They demand the most bandwidth.
- F. They are time-consuming to complete.
- G. They require on-site storage.
Answer: B,E,F
NEW QUESTION 73
Task: Configure the firewall (fill out the table) to allow these four rules:
* Only allow the Accounting computer to have HTTPS access to the Administrative server.
* Only allow the HR computer to be able to communicate with the Server 2 System over SCP.
* Allow the IT computer to have access to both the Administrative Server 1 and Administrative Server 2

- A. Use the following answer for this simulation task.
Below table has all the answers required for this question.
Firewall rules act like ACLs, and they are used to dictate what traffic can pass between the firewall and the internal network. Three possible actions can be taken based on the rule's criteria:
Block the connection Allow the connection
Allow the connection only if it is secured
TCP is responsible for providing a reliable, one-to-one, connection-oriented session. TCP establishes a connection and ensures that the other end receives any packets sent.
Two hosts communicate packet results with each other. TCP also ensures that packets are decoded and sequenced properly. This connection is persistent during the session.
When the session ends, the connection is torn down.
UDP provides an unreliable connectionless communication method between hosts. UDP is considered a best-effort protocol, but it's considerably faster than TCP.
The sessions don't establish a synchronized session like the kind used in TCP, and UDP doesn't guarantee error-free communications.
The primary purpose of UDP is to send small packets of information.
The application is responsible for acknowledging the correct reception of the data. Port 22 is used by both SSH and SCP with UDP.
Port 443 is used for secure web connections? HTTPS and is a TCP port.
Thus to make sure only the Accounting computer has HTTPS access to the Administrative server you should use TCP port 443 and set the rule to allow communication between 10.4.255.10/24 (Accounting) and 10.4.255.101 (Administrative server1) Thus to make sure that only the HR computer has access to Server2 over SCP you need use of TCP port 22 and set the rule to allow communication between 10.4.255.10/23 (HR) and 10.4.255.2 (server2) Thus to make sure that the IT computer can access both the Administrative servers you need to use a port and accompanying port number and set the rule to allow communication between: 10.4.255.10.25 (IT computer) and 10.4.255.101 (Administrative server1)
10.4.255.10.25 (IT computer) and 10.4.255.102 (Administrative server2) - B. Use the following answer for this simulation task.
Below table has all the answers required for this question.
Firewall rules act like ACLs, and they are used to dictate what traffic can pass between the firewall and the internal network. Three possible actions can be taken based on the rule's criteria:
Block the connection Allow the connection
Allow the connection only if it is secured
TCP is responsible for providing a reliable, one-to-one, connection-oriented session. TCP establishes a connection and ensures that the other end receives any packets sent.
Two hosts communicate packet results with each other. TCP also ensures that packets are decoded and sequenced properly. This connection is persistent during the session.
When the session ends, the connection is torn down.
UDP provides an unreliable connectionless communication method between hosts. UDP is considered a best-effort protocol, but it's considerably faster than TCP.
Thus to make sure that the IT computer can access both the Administrative servers you need to use a port and accompanying port number and set the rule to allow communication between: 10.4.255.10.25 (IT computer) and 10.4.255.101 (Administrative server1)
10.4.255.10.25 (IT computer) and 10.4.255.102 (Administrative server2)
Answer: A
NEW QUESTION 74
Ann, a user, states that her machine has been behaving erratically over the past week. She has
experienced slowness and input lag and found text files that appear to contain pieces of her emails or
online conversations with coworkers. The technician runs a standard virus scan but detects nothing.
Which of the following types of malware has infected the machine?
- A. Rootkit
- B. Ransomware
- C. Backdoor
- D. Keylogger
Answer: D
NEW QUESTION 75
......
Valid SY0-501 Exam Updates - 2021 Study Guide: https://www.dumpsreview.com/SY0-501-exam-dumps-review.html

