SY0-701 Flashcards
Threat Actors
Nation-state actors are most likely to be hired by a foreign government to attack critical systems because they possess large financial resources.
Hashing
A salt is used to add extra complexity before using a one-way data transformation algorithm.
Phishing
An employee clicking a link in an email from a payment website asking to update contact information is an example of phishing.
DNS Traffic Limitation
The correct firewall ACL to limit outbound DNS traffic originating from an internal network, allowing it only from device with IP address 10.50.10.25, is:
Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
Authentication for SaaS Applications
To reduce the number of authentication prompts for a SaaS application, a data administrator can configure Single Sign-On (SSO).
Business Email Compromise (BEC)
A possible business email compromise attack involves an employee receiving a gift card request in an email that has an executive's name in the display field of the email.
Database Administrator Access
A company prevented direct access from database administrators' workstations to the network segment, indicating a security measure.
Buffer Overflow
An organization's internet-facing website was compromised due to an attacker exploiting a buffer overflow.
Multifactor Authentication (MFA)
To prevent users logging in from suspicious IP addresses, implement multifactor authentication.
Smishing
An employee receiving a text message that appears to have been sent by the payroll department is an example of smishing.
Best responses to a fraudulent text message from someone claiming to be the CEO asking for gift cards:
Add a smishing exercise to the annual company training.
Issue a general email warning to the company.
Certified Hardware
A company is required to use certified hardware when building networks to ensure compliance and security standards are met.
Penetration Testing
A penetration tester begins an engagement by performing port and service scans against the client's systems to gather information about potential vulnerabilities.
Restore Process Management
Proper documentation is required for an organization to properly manage its restore process in the event of data loss or system failure.
Software Vulnerabilities
Installing software outside of a manufacturer's official channels can lead to vulnerabilities.
Password Spraying Attack
The attack most likely occurring in the provided logs is password spraying.
Zero Trust Principles
An analyst is evaluating the implementation of Zero Trust principles within the data plane to ensure least privilege access and continuous verification.
Unauthorized Access Prevention
To prevent unauthorized access, an engineer needs to find a solution that creates an added layer of security, such as multi-factor authentication.
Web Filter Configuration
A company's web filter is configured to scan URLs for strings and deny access when matches are found, which is a basic form of content filtering.
Firewall Rule for Malicious IP
To block a malicious IP address (10.1.4.9) from accessing the organization's network, create an inbound firewall rule that denies traffic from that IP address.
The correct access list is:
access-list inbound deny ip source 10.1.4.9/32 destination 0.0.0.0/0
Administrative Access and Traffic Minimization
A company needs to provide administrative access to internal resources while minimizing the traffic allowed, often achieved through network segmentation and access controls.
SIEM Alerts and Malicious Network Traffic
A security analyst reviews alerts in the SIEM related to potential malicious network traffic to identify and respond to security incidents.
New Tactic by Malicious Actors
A cyber operations team informs a security analyst about a new tactic malicious actors are using to remain informed and update security measures.
Cyber Insurance
A company purchased cyber insurance to address items listed on the risk register, indicating a risk transfer strategy.
Data Protection on Laptops
A security administrator would like to protect data on employees' laptops using full disk encryption (FDE).
Acceptable Use Policy (AUP)
An acceptable use policy represents a administrative security control type.
Access Control
An IT manager informs the help desk staff that only the IT manager and the help desk lead will have elevated privileges, illustrating role-based access control.
Risk Management Documentation
A risk register is the most likely tool used to document risks, responsible parties, and thresholds.
Firewall Rules
When setting up a new set of firewall rules, a security administrator should adhere to the principle of least privilege, allowing only necessary traffic.
Threat Surface Program
A company is expanding its threat surface program and allowing individuals to security test the company's systems, indicating a bug bounty or vulnerability disclosure program.
Threat Actors and Financial Resources
Nation-state actors are the most likely to use large financial resources to attack critical systems located in other countries.
Input Field Exploitation
Exploiting an input field to run commands that can view or manipulate data is known as SQL injection.
Training for R&D Units
Employees in research and development receive extensive training to ensure they understand security protocols and protect sensitive information.
Asset Inventory Stickers
Security benefits of labeling all laptops with asset inventory stickers and associating them with employee IDs:
If a security incident occurs on the device, the correct employee can be notified.
Company data can be accounted for when the employee leaves the organization.
Improving User Awareness
To improve the situational and environmental awareness of existing users, a technician could implement security awareness training.
Board Member Cybersecurity Knowledge
A newly appointed board member with cybersecurity knowledge wants the board of directors to receive a cyber risk briefing.
File Integrity Monitoring Tool
If a systems administrator receives an alert from a file integrity monitoring tool that the hash of cmd.exe has changed, and no patches were applied, likely a rootkit was deployed.
Project Documentation
A document outlining the project, the cost, and the completion date is a statement of work (SOW).
Cross-Site Scripting (XSS) Prevention
To prevent cross-site scripting vulnerabilities, implement input validation.
High-Availability Network Design
When designing a high-availability network, consider redundancy and failover mechanisms.
Patching Production Systems
When applying a high-priority patch to a production system, test it in a non-production environment first.
PCI DSS Compliance Failure
If a large bank fails an internal PCI DSS compliance, the most likely outcome is financial penalties and restrictions on processing credit card transactions.
Business Continuity Strategy
When developing a business continuity strategy, determine how many staff members are essential for critical operations.
Sensitive Documents in SaaS
A company's legal department drafted sensitive documents in a SaaS application and wants to ensure the confidentiality and integrity of those documents.
Firewall Configuration Troubleshooting
While troubleshooting a firewall configuration, if a deny any policy causes servers to become unreachable, test the policy in a non-production environment before enabling it in the production network.
Backup Data Center Requirements
When building a new backup data center with cost-benefit as the primary requirement and RTO (Recovery Time Objective) as a key consideration, prioritize cost-effective solutions that minimize downtime.
Securely Wiping Hard Drives
A company requires hard drives to be securely wiped before sending decommissioned systems to recycling to prevent data breaches.
Patient Data Security
A systems administrator working for a local hospital needs to ensure patient data is protected and secure, adhering to HIPAA regulations.
Expanding Data Centers Internationally
When a U.S.-based cloud-hosting provider wants to expand its data centers to new international locations, they must consider local laws and regulations related to data privacy and security.
Blocking Unknown Programs
The best way to block unknown programs from executing is to use application whitelisting.
Offensive Security Assessment
A company hired a consultant to perform an offensive security assessment covering penetration testing and vulnerability assessments.
Code Authenticity
To ensure the authenticity of code created by the company, perform code signing on company-developed software.
Identifying Attacker Activities
A honeypot can be used to identify potential attacker activities without affecting production systems.
Incident Source
During an investigation, an incident response team attempts to understand the source of an incident, often through log analysis and forensic investigation.
Vulnerability Assessment
A security practitioner completes a vulnerability assessment on a company’s network and finds several critical vulnerabilities.
Unauthorized Data Copying
When an administrator is notified that a user logged in remotely after hours and copied large amounts of data, it is important to investigate for potential data exfiltration.
Message Attribution
Digital signatures allow for the attribution of messages to individuals.
Security Settings Consistency
The best way to consistently determine on a daily basis whether security settings have drifted from the baseline is a configuration compliance scanner.
Input Validation Security Technique
The security technique adopted by including regular expressions in source code to remove special characters from variables set by forms in a web application is input validation.
Phishing Campaign Performance Review
If the user click-through rate exceeded the acceptable risk threshold, update the EDR policies to block automatic execution of downloaded programs.
Host-Based Firewall Implementation
When a host-based firewall on a legacy Linux system allows only necessary ports and services, it demonstrates the principle of least privilege.
Account Access Management
If new accounts set up manually do not always have correct access, implement role-based access control.
SIEM System Setup
When setting up a SIEM (Security Information and Event Management) system, assign an analyst to review the logs on a weekly basis.
Low-Cost Application-Hosting Solution
A systems administrator looking for a low-cost application-hosting solution that is cloud-based should consider Platform as a Service (PaaS).
Malicious Activity Determination
When a security operations center determines that the malicious activity detected on a server is normal, it is classified as a false positive.
Domain Activity Logs Review
If a security analyst reviews domain activity logs and notices numerous failed login attempts for a user, an attacker is attempting to brute force the user's account.
Server Room Weather Damage
A company concerned about weather events causing damage to the server room and downtime should consider using geographically diverse data centers.
BYOD Program Security Concern
The primary security concern for a company setting up a BYOD (Bring Your Own Device) program involves data leakage.
Cyber Insurance Policy
A company decided to reduce the cost of its annual cyber insurance policy by removing the coverage for business interruption.
Security Awareness Program
Reporting phishing attempts or other suspicious activities, is most likely to be included as an element of communication in a security awareness program.
Incident Response Process
The phase in the incident response process when a security analyst reviews roles and responsibilities is preparation.
Router Hardening
After a recent vulnerability scan, a security engineer needs to harden the routers within the corporate network by updating firmware and disabling unnecessary services.
Data Security
A security administrator needs a method to secure data in an environment that includes some form of checks and balances which can be provided by digital signature.
Server Security Logs
Multiple invalid user attempts captured in the log file best describes a brute-force attack.
FDE Implementation
The most essential consideration for a security engineer implementing Full Disk Encryption (FDE) for all laptops in an organization is managing recovery keys.
Public Network Security
The best course of action is to setting up a VPN and placing the jump server inside the firewall.
Browser Version Exploitation
The best control is to implement patch management since vulnerabilities are in old code.
Data Center Security
Physical security is to protect life in the event of a fire.
Response to Attacks
Behavior is to implement anomaly based response.
Ensuring Evidence
Chain of custody to make sure there is evidence in the system.
Updating Wire Transfers
Standardizing Security Incidence reporting.
Preventing Errors
Code review and testing which can be achieved through documentation/scripts.
Collecting Data
Data Classification (labeling) to determine the classification of the data.
Levels of Accepted Risk
Risk appetite refers to the maximum amount of accepted risk.
unusual DNS Queries
Infected system to look for unusual DNS queries.
ports on firewall for SaaS
Documenting justification for each open port.
Time Savings
Solution to use for saving time and prevent human error is automation.
Security threat
Database Misconfiguration.
Certificates
The proper means of validating a certificate when it is presented to a user is through a Certificate Authority (CA).
Recommendation
Security Bulletin sent by vendor for BIOS update. It is critical that software/hardware are up to date to ensure that systems are not exposed to vulnerabilities. As a solution the organization must upgrade the hardware BIOS.
Assessing Criticality
CVSS (Common Vulnerability Scoring System) is used to quantitatively measure the criticality of a vulnerability.
Ensuring work stations
Ensue systems meet certain standards using group policy.
VPN Protecting
Data in transit is what the VPN is protecting.
Allowing Unauthorized Entry
False Acceptance would allow an unauthorized user to access and compromise the system.
Handling data
Following and consulting GDPR when handling data.
Exploitation
When a interactive process is exploited to gain access to resources is called Privilege escalation.
Resiliency
Geographic dispersal is the consideration that is important to the organization.
Enabling Risk
Transference enables risk to a third party.
Report areas of improvements.
Lessons Learned will determine the possible improvements.
Preventing Social Message Sharing
Hoaxes would be the risk which this action would prevent.
Application Alerts
DDoS most likely explains this issue.
Cryptography Increase
Increase cryptography security you need increase high data entropy.
Zero-day Exploits Described
Zero-day Exploits Undetectable And No Patch Exists.
DLP is first performed.
Classification should be performed before DL.
Software Delvelopment
Agile Described Software Delivery Method.
Company Account Compromises
Enforce Multi Factor Authentication when an account request reaches a risk threshold.
Threat Intelligence Sharing
Implement a TAXII server.
Greatest Security Concern.
Unknown Backdoor.
Prioritize
Low FRR, the goal is prioritize.
Frameworks For Security Config
NIST sets frameworks and controls.
Instructions used secretly. Harmful instruction.
Logic Bomb.
Analysis Next Step
Quarantine Affected Host, which is contain incident.
Exploit Stages. Chain Kill
The Adversary operating stage is Command and Control.
Identify a Breach
SIEM will identify an intrusion.
A New cloud service
The new service they are using is called Hybrid.
Security Analyst solution being implemented
User Behavior Analysis. (UDA)
Data Exfiltration
Directory Traversal Explains.
Conduct Analysis Most Likely
Malicious Script, is the answer to MOST likely.
Unusual Text Message. Technique Message
SMiShing Described. Using link provided in a text.
Improved Incident Process.
Train Team to identify the difference between events, & incidents.
Block attack layer 7
NIPS and WAF
WAF and NIPS can block Layer 7 attacks.
Business Questions
Best Virtual Machine migration to mitigate managers concern.
The Action Best To Prevent Infection
Blocking port 3389 inbound, because that an RDP Port.
The Use SAML for Authentication
Federation.
Solutions Should Consider.
Utilizing a SOAR platform.
Trusted Validation Between Partners
The best solution to adopt would be PKI.
Cyber Security The Security Analyst Need To Take.
VDI solution.
Sensitive To The Organization
Proprietary
Locating Unsecure Web Server
nmap -p 80 10.10.10.0 /24 is used for locating secure servers.
Reasons to Publish HASH
Hashing can be used to validate a file.
The best solution is TPM can check file and protect during boot process from virus.
User Screen Prompts
This shows Password Complexity requirement.
Hidden file Source Code
Stermography can identify code
Describe best what administrator is working on.
Unique String
New File Transfer Solution Description
Secure Shell best protects file transfer.
Which used by a tool
Hashing can Identify credential
Preventative measures
RFID tag can be used
Prevent theft. from network.
DLP can prevent exfiltration from network
Implement The Company Implement.
For that they are using Wild Card.
Report Was Deliver CISO
This should be MFA
Types Of Data Has Hosted.
Classify The Data.
The Source breach occurred.
SQL Injection.
From Accessing Unauthorized removable media. The Best Method.
USB Data Blocker
Which Best Control
IPS Would have effective control against zero-day environment issues.
Simulate the team after detection.
Conduct forensics on the compromised system
Secure Coding
Secure Coding first should be practiced in development
How is the code be Deployed
Production is were the code is deployed
Build the System
You have to Purchase from Different Vendors
Protect from cyber issues
Is casb, ng-swg
Implement Models Roll Out
VDI model is important
Users compromise
Keylagger is the reason that user are compromised
backup use
Snapshot use to preserve the stage 1
return the conference
*Direct access
Remote managing
Use the SSH remote connection
The value for known vulnerabilities organization can prioritize mitigation.
CVSS solution
The BEST meet needed for the requirements
Community
Prove Data hasn't been altered Use Most.
Checksum Use Hashing Algorithm
The passwords Used
Password History
fingerprint the tools
curl --head 192.168.0.10
Nmap for Pivoting
Which meets Mobile
Mobile Device Management
Risk before Incidence.
The Solution Should Be Preventive
Defended performance on Virtual setting.
Memory Leak
Memory Leak is Best option to mitigate.
Risk Strategy To maintain Legacy System.
Risk - Acceptance
Incidence Response. Best Action.Central repository - Publish Document Organization. 200. Designing Appropriate Controls
Desired Laptop Budget. Best Meeting Low For The Requirement.
Deterrent.
The Best to migrate require. Least support. - SaaS
Security Responsible. - DPO 307.The passwords are not match
Is Due to Salting
Shell access network
Pivoting Technique
The Most credential can find is
OSINT, dark web because these provide information on individuals not organizations.
Can't get from organizations because they are very vague and are not transparent. C:
New one tool Best Abilit
SIEM = Event, Correlation best support to combine traffic/information and make correlations from multiple sources, all in on the UI console.
Which the following Mostly occurring ?
Injection = SQLi
Best Which components best cloud Multiple Firewall?
Ans = Transit
# The DPO report several hadives we removed.
Logic BOOM Attack to cause attack *Digital Signature.
Use sender private message private and use with sender public key