Valid CompTIA Security+ SY0-501 Dumps with VCE and PDF for Free (Question 31 – Question 45)

PassLeader released the NEWEST CompTIA SY0-501 exam dumps recently! Both SY0-501 VCE dumps and SY0-501 PDF dumps are available on PassLeader, either SY0-501 VCE dumps or SY0-501 PDF dumps have the NEWEST SY0-501 exam questions in it, they will help you passing CompTIA SY0-501 exam easily! You can download the valid SY0-501 dumps VCE and PDF from PassLeader here: https://www.passleader.com/sy0-501.html (182 Q&As Dumps –> 250 Q&As Dumps –> 594 Q&As Dumps –> 694 Q&As Dumps) (Wrong Answers Have Been Corrected!!!)

Also, previewing the NEWEST PassLeader SY0-501 dumps online for free on Google Drive: https://drive.google.com/open?id=1Ei1CtZKTLawI_2jpkecHaVbM_kXPMZAu

QUESTION 31
Which of the following characteristics differentiate a rainbow table attack from a brute force attack? (Select TWO.)

A.    Rainbow table attacks greatly reduce compute cycles at attack time.
B.    Rainbow tables must include precompiled hashes.
C.    Rainbow table attacks do not require access to hashed passwords.
D.    Rainbow table attacks must be performed on the network.
E.    Rainbow table attacks bypass maximum failed login restrictions.

Answer: BE

QUESTION 32
Which of the following BEST describes a routine in which semicolons, dashes, quotes, and commas are removed from a string?

A.    Error handling to protect against program exploitation.
B.    Exception handling to protect against XSRF attacks.
C.    Input validation to protect against SQL injection.
D.    Padding to protect against string buffer overflows.

Answer: C

QUESTION 33
Which of the following is an important step to take BEFORE moving any installation packages from a test environment to production?

A.    Roll back changes in the test environment.
B.    Verify the hashes of files.
C.    Archive and compress the files.
D.    Update the secure baseline.

Answer: A

QUESTION 34
Which of the following cryptographic attacks would salting of passwords render ineffective?

A.    Brute force
B.    Dictionary
C.    Rainbow tables
D.    Birthday

Answer: B

QUESTION 35
A network administrator wants to implement a method of securing internal routing. Which of the following should the administrator implement?

A.    DMZ
B.    NAT
C.    VPN
D.    PAT

Answer: C

QUESTION 36
Which of the following types of keys is found in a key escrow?

A.    Public
B.    Private
C.    Shared
D.    Session

Answer: D

QUESTION 37
A senior incident response manager receives a call about some external IPs communicating with internal computers during off hours. Which of the following types of malware is MOST likely causing this issue?

A.    Botnet
B.    Ransomware
C.    Polymorphic malware
D.    Armored virus

Answer: A

QUESTION 38
A company is currently using the following configuration:
– IAS server with certificate-based EAP-PEAP and MSCHAP.
– Unencrypted authentication via PAP.
A security administrator needs to configure a new wireless setup with the following configurations:
– PAP authentication method.
– PEAP and EAP provide two-factor authentication.
Which of the following forms of authentication are being used? (Select TWO.)

A.    PAP
B.    PEAP
C.    MSCHAP
D.    PEAP-MSCHAP
E.    EAP
F.    EAP-PEAP

Answer: AF

QUESTION 39
A security administrator is trying to encrypt communication. For which of the following reasons should administrator take advantage of the Subject Alternative Name (SAM) attribute of a certificate?

A.    It can protect multiple domains.
B.    It provides extended site validation.
C.    It does not require a trusted certificate authority.
D.    It protects unlimited subdomains.

Answer: B

QUESTION 40
After a merger between two companies a security analyst has been asked to ensure that the organization’s systems are secured against infiltration by any former employees that were terminated during the transition. Which of the following actions are MOST appropriate to harden applications against infiltration by former employees? (Select TWO.)

A.    Monitor VPN client access
B.    Reduce failed login out settings
C.    Develop and implement updated access control policies
D.    Review and address invalid login attempts
E.    Increase password complexity requirements
F.    Assess and eliminate inactive accounts

Answer: CF

QUESTION 41
A new mobile application is being developed in-house. Security reviews did not pick up any major flaws, however vulnerability scanning results show fundamental issues at the very end of the project cycle. Which of the following security activities should also have been performed to discover vulnerabilities earlier in the lifecycle?

A.    Architecture review
B.    Risk assessment
C.    Protocol analysis
D.    Code review

Answer: D

QUESTION 42
A security administrator is creating a subnet on one of the corporate firewall interfaces to use as a DMZ which is expected to accommodate at most 14 physical hosts. Which of the following subnets would BEST meet the requirements?

A.    192.168.0.16
255.25.255.248
B.    192.168.0.16/28
C.    192.168.1.50
255.255.25.240
D.    192.168.2.32/27

Answer: B

QUESTION 43
A company has a security policy that specifies all endpoint computing devices should be assigned a unique identifier that can be tracked via an inventory management system. Recent changes to airline security regulations have cause many executives in the company to travel with mini tablet devices instead of laptops. These tablet devices are difficult to tag and track. An RDP application is used from the tablet to connect into the company network. Which of the following should be implemented in order to meet the security policy requirements?

A.    Virtual desktop infrastructure (IDI)
B.    WS-security and geo-fencing
C.    A hardware security module (HSM)
D.    RFID tagging system
E.    MDM software
F.    Security Requirements Traceability Matrix (SRTM)

Answer: E

QUESTION 44
The security administrator receives an email on a non-company account from a coworker stating that some reports are not exporting correctly. Attached to the email was an example report file with several customers’ names and credit card numbers with the PIN. Which of the following is the BEST technical controls that will help mitigate this risk of disclosing sensitive data?

A.    Configure the mail server to require TLS connections for every email to ensure all transport data is encrypted.
B.    Create a user training program to identify the correct use of email and perform regular audits to ensure compliance.
C.    Implement a DLP solution on the email gateway to scan email and remove sensitive data or files.
D.    Classify all data according to its sensitivity and inform the users of data that is prohibited to share.

Answer: C

QUESTION 45
A technician is configuring a wireless guest network. After applying the most recent changes the technician finds the new devices can no longer find the wireless network by name but existing devices are still able to use the wireless network. Which of the following security measures did the technician MOST likely implement to cause this Scenario?

A.    Deactivation of SSID broadcast
B.    Reduction of WAP signal output power
C.    Activation of 802.1X with RADIUS
D.    Implementation of MAC filtering
E.    Beacon interval was decreased

Answer: A


Welcome to choose PassLeader SY0-501 dumps for 100% passing CompTIA SY0-501 exam: https://www.passleader.com/sy0-501.html (182 Q&As VCE Dumps and PDF Dumps –> 250 Q&As Now! –> 594 Q&As Now! –> 694 Q&As Now!) (Wrong Answers Have Been Corrected!!!)

Also, previewing the NEWEST PassLeader SY0-501 dumps online for free on Google Drive: https://drive.google.com/open?id=1Ei1CtZKTLawI_2jpkecHaVbM_kXPMZAu