CompTIA SY0-601 Exam Preparation Guide and PDF Download [Q127-Q144]

Share

CompTIA SY0-601 Exam Preparation Guide and PDF Download

Verified & Correct SY0-601 Practice Test Reliable Source Aug 25, 2023 Updated

NEW QUESTION # 127
A security analyst is investigating a vulnerability in which a default file permission was set incorrectly. The company uses non-credentialed scanning for vulnerability management. Which of the following tools can the analyst use to verify the permissions?

  • A. chmod
  • B. nessus
  • C. ls
  • D. ssh
  • E. nc
  • F. setuid

Answer: C


NEW QUESTION # 128
An attacker has successfully exfiltrated several non-salted password hashes from an online system. Given the logs below:

Which of the following BEST describes the type of password attack the attacker is performing?

  • A. Brute-force
  • B. Password spraying
  • C. Dictionary
  • D. Pass-the-hash

Answer: C


NEW QUESTION # 129
Security analysts are conducting an investigation of an attack that occurred inside the organization's network.
An attacker was able to connect network traffic between workstation throughout the network. The analysts review the following logs:

The layer 2 address table has hundred of entries similar to the ones above. Which of the following attacks has MOST likely occurred?

  • A. SQL injection
  • B. ARP poisoning
  • C. DNS spoofing
  • D. MAC flooding

Answer: B


NEW QUESTION # 130
A small business just recovered from a ransomware attack against its file servers by purchasing the decryption keys from the attackers. The issue was triggered by a phishing email and the IT administrator wants to ensure it does not happen again. Which of the following should the IT administrator do FIRST after recovery?

  • A. Restrict administrative privileges and patch all systems and applications.
  • B. Rebuild all workstations and install new antivirus software.
  • C. Scan the NAS for residual or dormant malware and take new daily backups that are tested on a frequent basis.
  • D. Implement application whitelisting and perform user application hardening.

Answer: C

Explanation:
The reason the company had to pay the ransom is because they did not have valid backups, otherwise they would have just restored their data. If your company just had to pay ransom and your boss says, "Don't let this happen again", what is the first thing you are going to do. The only action after a ransomware attack is "restore from backup".


NEW QUESTION # 131
A security engineer is setting up passwordless authentication for the first time.
INSTRUCTIONS
Use the minimum set of commands to set this up and verify that it works. Commands cannot be reused.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Answer:

Explanation:

Explanation
A screenshot of a computer Description automatically generated with medium confidence


NEW QUESTION # 132
The findings in a consultant's report indicate the most critical risk to the security posture from an incident response perspective is a lack of workstation and server investigation capabilities. Which of the following should be implemented to remediate this risk?

  • A. NGFW
  • B. EDR
  • C. HIDS
  • D. FDE

Answer: B

Explanation:
EDR solutions are designed to detect and respond to malicious activity on workstations and servers, and they provide a detailed analysis of the incident, allowing organizations to quickly remediate the threat. According to the CompTIA Security+ SY0-601 Official Text Book, EDR solutions can be used to detect malicious activity on endpoints, investigate the incident, and contain the threat. EDR solutions can also provide real-time monitoring and alerting for potential security events, as well as detailed forensic analysis for security incidents. Additionally, the text book recommends that organizations also implement a host-based intrusion detection system (HIDS) to alert them to malicious activity on their workstations and servers.


NEW QUESTION # 133
While researching a data exfiltration event, the security team discovers that a large amount of data was transferred to a file storage site on the internet. Which of the following controls would work best to reduce the risk of further exfiltration using this method?

  • A. File integrity monitoring
  • B. Blocking IP traffic at the firewall
  • C. Data loss prevention
  • D. Containerization

Answer: C

Explanation:
Data loss prevention (DLP) is a set of tools and processes that aim to prevent unauthorized access, use, or transfer of sensitive data. DLP can help reduce the risk of further exfiltration using file storage sites on the internet by monitoring and controlling data flows across endpoints, networks, and cloud services. DLP can also detect and block attempts to copy, upload, or download sensitive data to or from file storage sites based on predefined policies and rules.


NEW QUESTION # 134
A security analyst is reviewing the following attack log output:

Which of the following types of attacks does this MOST likely represent?

  • A. Brute-force
  • B. Password-spraying
  • C. Dictionary
  • D. Rainbow table

Answer: B

Explanation:
Explanation
Password spraying is a type of brute-force attack in which a malicious actor uses a single password against targeted user accounts before moving on to attempt a second password, and so on. This technique allows the actor to remain undetected by avoiding rapid or frequent account lockouts.
https://us-cert.cisa.gov/ncas/current-activity/2019/08/08/acsc-releases-advisory-password-spraying-attacks#:~:tex


NEW QUESTION # 135
A remote user recently took a two-week vacation abroad and brought along a corporate-owned laptop. Upon returning to work, the user has been unable to connect the laptop to the VPN.
Which of the following is the MOST likely reason for the user's inability to connect the laptop to the VPN? (Select TWO).

  • A. The VPN client was blacklisted.
  • B. The user's laptop was quarantined because it missed the latest patch update.
  • C. The user in unable to authenticate because they are outside of the organization's mobile geofencing configuration.
  • D. Due to foreign travel, the user's laptop was isolated from the network.
  • E. The user's account was put on a legal hold.
  • F. The laptop is still configured to connect to an international mobile network operator.

Answer: B,D


NEW QUESTION # 136
A security engineer is hardening existing solutions to reduce application vulnerabilities. Which of the following solutions should the engineer implement FIRST? (Select TWO)

  • A. HTTP headers
  • B. Sandboxing
  • C. Third-party updates
  • D. Secure cookies
  • E. Hardware encryption
  • F. Auto-update
  • G. Full disk encryption

Answer: B,F

Explanation:
Explanation
Auto-update can help keep the app up-to-date with the latest security fixes and enhancements, and reduce the risk of exploitation by attackers who target outdated or vulnerable versions of the app.
Sandboxing can help isolate the app from other processes and resources on the system, and limit its access and permissions to only what is necessary. Sandboxing can help prevent the app from being affected by or affecting other applications or system components, and contain any potential damage in case of a breach.


NEW QUESTION # 137
An attacker is attempting, to harvest user credentials on a client's website. A security analyst notices multiple attempts of random usernames and passwords. When the analyst types in a random username and password.
the logon screen displays the following message:
Which of the following should the analyst recommend be enabled?

  • A. Username lockout
  • B. Obfuscation
  • C. Input validation
  • D. Error handling

Answer: B


NEW QUESTION # 138
Which of the following must be in place before implementing a BCP?

  • A. NDA
  • B. SLA
  • C. BIA
  • D. AUP

Answer: C

Explanation:
To create an effective business continuity plan, a firm should take these five steps:
Step 1: Risk Assessment
This phase includes:
Evaluation of the company's risks and exposures
Assessment of the potential impact of various business disruption scenarios
Determination of the most likely threat scenarios
Assessment of telecommunication recovery options and communication plans
Prioritization of findings and development of a roadmap
Step 2: Business Impact Analysis (BIA)
During this phase we collect information on:
Recovery assumptions, including Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO)
Critical business processes and workflows as well as the supporting production applications
Interdependencies, both internal and external
Critical staff including backups, skill sets, primary and secondary contacts
Future endeavors that may impact recovery
Special circumstances
Pro tip: Compiling your BIA into a master list can be helpful from a wholistic standpoint, as well as helpful in identifying pain points throughout the organization.
Step 3: Business Continuity Plan Development
This phase includes:
Obtaining executive sign-off of Business Impact Analysis
Synthesizing the Risk Assessment and BIA findings to create an actionable and thorough plan
Developing department, division and site level plans
Reviewing plan with key stakeholders to finalize and distribute
Step 4: Strategy and Plan Development
Validate that the recovery times that you have stated in your plan are obtainable and meet the objectives that are stated in the BIA. They should easily be available and readily accessible to staff, especially if and when a disaster were to happen. In the development phase, it's important to incorporate many perspectives from various staff and all departments to help map the overall company feel and organizational focus. Once the plan is developed, we recommend that you have an executive or management team review and sign off on the overall plan.
Step 5: Plan Testing & Maintenance
The final critical element of a business continuity plan is to ensure that it is tested and maintained on a regular basis. This includes:
Conducting periodic table top and simulation exercises to ensure key stakeholders are comfortable with the plan steps
Executing bi-annual plan reviews
Performing annual Business Impact Assessments


NEW QUESTION # 139
The Chief Executive Officer (CEO) of an organization would like staff members to have the flexibility to work from home anytime during business hours, incident during a pandemic or crisis, However, the CEO is concerned that some staff members may take advantage of the of the flexibility and work from high-risk countries while on holidays work to a third-party organization in another country. The Chief information Officer (CIO) believes the company can implement some basic to mitigate the majority of the risk.
Which of the following would be BEST to mitigate CEO's concern? (Select TWO).

  • A. Tokens
  • B. Role-based access controls
  • C. Certificates
  • D. Geotagging
  • E. Geolocation
  • F. Time-of-day restrictions

Answer: E,F


NEW QUESTION # 140
A startup company is using multiple SaaS and IaaS platform to stand up a corporate infrastructure and build out a customer-facing web application. Which of the following solutions would be BEST to provide security, manageability, and visibility into the platforms?

  • A. SWG
  • B. DLP
  • C. CASB
  • D. SIEM

Answer: C

Explanation:
A cloud access security broker is on-premises or cloud based software that sits between cloud service users and cloud applications, and monitors all activity and enforces security policies A CASB has a separate, and more distinctive role. Differing from the use case for SWG, which focuses on the broader filtering and protection against inbound threats and filtering illegitimate web traffic, a CASB is more deeply integrated and has control over your cloud application usage. It can be tied into an applications API to scan data at rest or can be used with a proxy based deployment to enforce inline policies for more real time protection.


NEW QUESTION # 141
A company recently experienced an attack during which its main website was Directed to the attacker's web server, allowing the attacker to harvest credentials from unsuspecting customers, Which of the following should the company implement to prevent this type of attack from occurring In the future?

  • A. IPsec
  • B. ONSSEC
  • C. SMIME
  • D. SSL/TLS

Answer: D

Explanation:
To prevent attacks where the main website is directed to the attacker's web server and allowing the attacker to harvest credentials from unsuspecting customers, the company should implement SSL/TLS (Secure Sockets Layer/Transport Layer Security) to encrypt the communication between the web server and the clients. This will prevent attackers from intercepting and tampering with the communication, and will also help to verify the identity of the web server to the clients.


NEW QUESTION # 142
Which of the following types of controls is a turnstile?

  • A. Physical
  • B. Technical
  • C. Corrective
  • D. Detective

Answer: A


NEW QUESTION # 143
A manufacturer creates designs for very high security products that are required to be protected and controlled by the government regulations. These designs are not accessible by corporate networks or the Internet. Which of the following is the BEST solution to protect these designs?

  • A. A demilitarized zone
  • B. A Faraday cage
  • C. A shielded cable
  • D. An air gap

Answer: D

Explanation:
Explanation


NEW QUESTION # 144
......

Pass CompTIA SY0-601 exam Dumps 100 Pass Guarantee With Latest Demo: https://www.prepawayexam.com/CompTIA/braindumps.SY0-601.ete.file.html

Free CompTIA SY0-601 Exam Files Downloaded Instantly: https://drive.google.com/open?id=1HTwMMjU1DWialBa17KPZfz-wGiF2Rbna