📘 Free SYO-701 Sample Questions
A user is attempting to navigate to a website from inside the company network using a desktop. When the user types in the URL, https://www.site.com, the user is presented with a certificate mismatch warning from the browser. The user does not receive a warning when visiting http://www.anothersite.com. Which of the following describes this attack?
A
On-path
B
Domain hijacking
C
DNS poisoning
D
Evil twin
Correct Answer:
C. DNS poisoning
Explanation:
C is the correct answer. By the way, there is a course in north Carolina and they are receiving $4000 in advance and showing you 6-hour pre-recorded videos every Saturday. There is no human intervention and no update over time. They are lying and giving you fake promises before signing up to course and then there is no contact after you became member. Be careful because they are completely SCAMMER.
Which of the following tools is effective in preventing a user from accessing unauthorized removable media?
A
USB data blocker
B
Faraday cage
C
Proximity reader
D
Cable lock
Correct Answer:
A. USB data blocker
Explanation:
A USB data blocker, also known as a “USB condom” (really, no kidding!), is a device that allows you to plug into USB charging ports including charging kiosks, and USB ports on gadgets owned by other people.
The main purpose of using one is to eliminate the risk of infecting your phone or tablet with malware, and even prevent hackers to install/execute any malicious code to access your data.
A Chief Security Officer is looking for a solution that can provide increased scalability and flexibility for back-end infrastructure, allowing it to be updated and modified without disruption to services. The security architect would like the solution selected to reduce the back-end server resources and has highlighted that session persistence is not important for the applications running on the back-end servers. Which of the following would BEST meet the requirements?
A
Reverse proxy
B
Automated patch management
C
Snapshots
D
NIC teaming
Correct Answer:
A. Reverse proxy
Explanation:
its the way to distribute load across different servers, at the same time you can remove from the cluster each server that you want to update.
In computer networks, a reverse proxy is the application that sits in front of back-end applications and forwards client requests to those applications. Reverse proxies help increase scalability, performance, resilience and security
Which of the following describes a social engineering technique that seeks to exploit a person's sense of urgency?
A
A phishing email stating a cash settlement has been awarded but will expire soon
B
A smishing message stating a package is scheduled for pickup
C
A vishing call that requests a donation be made to a local charity
D
A SPIM notification claiming to be undercover law enforcement investigating a cybercrime
Correct Answer:
A. A phishing email stating a cash settlement has been awarded but will expire soon
Explanation:
Keyword is "will expire" which is something that creates a sense of urgency.
A security analyst is reviewing application logs to determine the source of a breach and locates the following log: https://www.comptia.com/login.php?id='%20or%20'1'1='1
Which of the following has been observed?
A
DLL Injection
B
API attack
C
SQLi
D
XSS
Correct Answer:
C. SQLi
Explanation:
SQL Injection (SQLi) is a type of an injection attack that makes it possible to execute malicious SQL statements. These statements control a database server behind a web application. Attackers can use SQL Injection vulnerabilities to bypass application security measures.
An audit identified PII being utilized in the development environment of a critical application. The Chief Privacy Officer (CPO) is adamant that this data must be removed; however, the developers are concerned that without real data they cannot perform functionality tests and search for specific data. Which of the following should a security professional implement to BEST satisfy both the CPO's and the development team's requirements?
A
Data anonymization
B
Data encryption
C
Data masking
D
Data tokenization
Correct Answer:
A. Data anonymization
Explanation:
Data anonymization is the alteration process of personally identifiable information (PII) in a dataset, to protect individual identification. This way the data can be used and still be protected.
A network engineer has been asked to investigate why several wireless barcode scanners and wireless computers in a warehouse have intermittent connectivity to the shipping server. The barcode scanners and computers are all on forklift trucks and move around the warehouse during their regular use. Which of the following should the engineer do to determine the issue? (Choose two.)
A
Perform a site survey
B
Deploy an FTK Imager
C
Create a heat map
D
Scan for rogue access points
E
Upgrade the security protocols
F
Install a captive portal
Correct Answer:
A. Perform a site survey
Explanation:
WiFi heatmap is a map of wireless signal coverage and strength. Typically, a WiFi heatmap shows a real map of a room, floor, or even a city overlaid by a graphical representation of a wireless signal.
Heat map and site survey will provide the wifi strength and identify the weakness areas..this will give the opportunity if we need to increase WiFI strength or give suggestion to the forklift drivers about the movement
A forensics investigator is examining a number of unauthorized payments that were reported on the company's website. Some unusual log entries show users received an email for an unwanted mailing list and clicked on a link to attempt to unsubscribe. One of the users reported the email to the phishing team, and the forwarded email revealed the link to be:
Click here to unsubscribeWhich of the following will the forensics investigator MOST likely determine has occurred?
A
SQL injection
B
Broken authentication
C
XSS
D
XSRF
Correct Answer:
D. XSRF
Explanation:
Funds out of a bank account in most cases indicates CSRF.
An attacker crafts code to create an HTTP request that, if it were run in the browser of a logged in user, would do something dangerous such as transfer money or delete data. The attacker then finds a way—typically through email—to get the malicious code into a victim’s browser. Depending on your definition of "Broken Authentication" that could work, I just don't see this as the authentication as broken as the attacker never logged in. Ref: https://www.stackhawk.com/blog/what-is-cross-site-request-forgery-csrf/
A report delivered to the Chief Information Security Officer (CISO) shows that some user credentials could be exfiltrated. The report also indicates that users tend to choose the same credentials on different systems and applications. Which of the following policies should the CISO use to prevent someone from using the exfiltrated credentials?
A
MFA
B
Lockout
C
Time-based logins
D
Password history
Correct Answer:
A. MFA
Explanation:
MFA is the only one that obligate to have more info than a password to login in the system
A company wants to simplify the certificate management process. The company has a single domain with several dozen subdomains, all of which are publicly accessible on the internet. Which of the following BEST describes the type of certificate the company should implement?
A
Subject alternative name
B
Wildcard
C
Self-signed
D
Domain validation
Correct Answer:
B. Wildcard
Explanation:
B- Wildcard SSL(Secure Sockets Layer) Certificate: Wildcard SSL certificates are for a single domain and all its subdomains.
www.cloudfare.com
Questions: 1-10 out of 754
Continue Full Practice..
GET ALL 754 QUESTIONS