SY0-701 Flashcards

Threat Actors

  • Nation-state actors are most likely to be hired by a foreign government to attack critical systems because they possess large financial resources.

Hashing

  • A salt is used to add extra complexity before using a one-way data transformation algorithm.

Phishing

  • An employee clicking a link in an email from a payment website asking to update contact information is an example of phishing.

DNS Traffic Limitation

  • The correct firewall ACL to limit outbound DNS traffic originating from an internal network, allowing it only from device with IP address 10.50.10.25, is:

    • Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53

    • Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53

Authentication for SaaS Applications

  • To reduce the number of authentication prompts for a SaaS application, a data administrator can configure Single Sign-On (SSO).

Business Email Compromise (BEC)

  • A possible business email compromise attack involves an employee receiving a gift card request in an email that has an executive's name in the display field of the email.

Database Administrator Access

  • A company prevented direct access from database administrators' workstations to the network segment, indicating a security measure.

Buffer Overflow

  • An organization's internet-facing website was compromised due to an attacker exploiting a buffer overflow.

Multifactor Authentication (MFA)

  • To prevent users logging in from suspicious IP addresses, implement multifactor authentication.

Smishing

  • An employee receiving a text message that appears to have been sent by the payroll department is an example of smishing.

  • Best responses to a fraudulent text message from someone claiming to be the CEO asking for gift cards:

    • Add a smishing exercise to the annual company training.

    • Issue a general email warning to the company.

Certified Hardware

  • A company is required to use certified hardware when building networks to ensure compliance and security standards are met.

Penetration Testing

  • A penetration tester begins an engagement by performing port and service scans against the client's systems to gather information about potential vulnerabilities.

Restore Process Management

  • Proper documentation is required for an organization to properly manage its restore process in the event of data loss or system failure.

Software Vulnerabilities

  • Installing software outside of a manufacturer's official channels can lead to vulnerabilities.

Password Spraying Attack

  • The attack most likely occurring in the provided logs is password spraying.

Zero Trust Principles

  • An analyst is evaluating the implementation of Zero Trust principles within the data plane to ensure least privilege access and continuous verification.

Unauthorized Access Prevention

  • To prevent unauthorized access, an engineer needs to find a solution that creates an added layer of security, such as multi-factor authentication.

Web Filter Configuration

  • A company's web filter is configured to scan URLs for strings and deny access when matches are found, which is a basic form of content filtering.

Firewall Rule for Malicious IP

  • To block a malicious IP address (10.1.4.9) from accessing the organization's network, create an inbound firewall rule that denies traffic from that IP address.

  • The correct access list is: access-list inbound deny ip source 10.1.4.9/32 destination 0.0.0.0/0

Administrative Access and Traffic Minimization

  • A company needs to provide administrative access to internal resources while minimizing the traffic allowed, often achieved through network segmentation and access controls.

SIEM Alerts and Malicious Network Traffic

  • A security analyst reviews alerts in the SIEM related to potential malicious network traffic to identify and respond to security incidents.

New Tactic by Malicious Actors

  • A cyber operations team informs a security analyst about a new tactic malicious actors are using to remain informed and update security measures.

Cyber Insurance

  • A company purchased cyber insurance to address items listed on the risk register, indicating a risk transfer strategy.

Data Protection on Laptops

  • A security administrator would like to protect data on employees' laptops using full disk encryption (FDE).

Acceptable Use Policy (AUP)

  • An acceptable use policy represents a administrative security control type.

Access Control

  • An IT manager informs the help desk staff that only the IT manager and the help desk lead will have elevated privileges, illustrating role-based access control.

Risk Management Documentation

  • A risk register is the most likely tool used to document risks, responsible parties, and thresholds.

Firewall Rules

  • When setting up a new set of firewall rules, a security administrator should adhere to the principle of least privilege, allowing only necessary traffic.

Threat Surface Program

  • A company is expanding its threat surface program and allowing individuals to security test the company's systems, indicating a bug bounty or vulnerability disclosure program.

Threat Actors and Financial Resources

  • Nation-state actors are the most likely to use large financial resources to attack critical systems located in other countries.

Input Field Exploitation

  • Exploiting an input field to run commands that can view or manipulate data is known as SQL injection.

Training for R&D Units

  • Employees in research and development receive extensive training to ensure they understand security protocols and protect sensitive information.

Asset Inventory Stickers

  • Security benefits of labeling all laptops with asset inventory stickers and associating them with employee IDs:

    • If a security incident occurs on the device, the correct employee can be notified.

    • Company data can be accounted for when the employee leaves the organization.

Improving User Awareness

  • To improve the situational and environmental awareness of existing users, a technician could implement security awareness training.

Board Member Cybersecurity Knowledge

  • A newly appointed board member with cybersecurity knowledge wants the board of directors to receive a cyber risk briefing.

File Integrity Monitoring Tool

  • If a systems administrator receives an alert from a file integrity monitoring tool that the hash of cmd.exe has changed, and no patches were applied, likely a rootkit was deployed.

Project Documentation

  • A document outlining the project, the cost, and the completion date is a statement of work (SOW).

Cross-Site Scripting (XSS) Prevention

  • To prevent cross-site scripting vulnerabilities, implement input validation.

High-Availability Network Design

  • When designing a high-availability network, consider redundancy and failover mechanisms.

Patching Production Systems

  • When applying a high-priority patch to a production system, test it in a non-production environment first.

PCI DSS Compliance Failure

  • If a large bank fails an internal PCI DSS compliance, the most likely outcome is financial penalties and restrictions on processing credit card transactions.

Business Continuity Strategy

  • When developing a business continuity strategy, determine how many staff members are essential for critical operations.

Sensitive Documents in SaaS

  • A company's legal department drafted sensitive documents in a SaaS application and wants to ensure the confidentiality and integrity of those documents.

Firewall Configuration Troubleshooting

  • While troubleshooting a firewall configuration, if a deny any policy causes servers to become unreachable, test the policy in a non-production environment before enabling it in the production network.

Backup Data Center Requirements

  • When building a new backup data center with cost-benefit as the primary requirement and RTO (Recovery Time Objective) as a key consideration, prioritize cost-effective solutions that minimize downtime.

Securely Wiping Hard Drives

  • A company requires hard drives to be securely wiped before sending decommissioned systems to recycling to prevent data breaches.

Patient Data Security

  • A systems administrator working for a local hospital needs to ensure patient data is protected and secure, adhering to HIPAA regulations.

Expanding Data Centers Internationally

  • When a U.S.-based cloud-hosting provider wants to expand its data centers to new international locations, they must consider local laws and regulations related to data privacy and security.

Blocking Unknown Programs

  • The best way to block unknown programs from executing is to use application whitelisting.

Offensive Security Assessment

  • A company hired a consultant to perform an offensive security assessment covering penetration testing and vulnerability assessments.

Code Authenticity

  • To ensure the authenticity of code created by the company, perform code signing on company-developed software.

Identifying Attacker Activities

  • A honeypot can be used to identify potential attacker activities without affecting production systems.

Incident Source

  • During an investigation, an incident response team attempts to understand the source of an incident, often through log analysis and forensic investigation.

Vulnerability Assessment

  • A security practitioner completes a vulnerability assessment on a company’s network and finds several critical vulnerabilities.

Unauthorized Data Copying

  • When an administrator is notified that a user logged in remotely after hours and copied large amounts of data, it is important to investigate for potential data exfiltration.

Message Attribution

  • Digital signatures allow for the attribution of messages to individuals.

Security Settings Consistency

  • The best way to consistently determine on a daily basis whether security settings have drifted from the baseline is a configuration compliance scanner.

Input Validation Security Technique

  • The security technique adopted by including regular expressions in source code to remove special characters from variables set by forms in a web application is input validation.

Phishing Campaign Performance Review

  • If the user click-through rate exceeded the acceptable risk threshold, update the EDR policies to block automatic execution of downloaded programs.

Host-Based Firewall Implementation

  • When a host-based firewall on a legacy Linux system allows only necessary ports and services, it demonstrates the principle of least privilege.

Account Access Management

  • If new accounts set up manually do not always have correct access, implement role-based access control.

SIEM System Setup

  • When setting up a SIEM (Security Information and Event Management) system, assign an analyst to review the logs on a weekly basis.

Low-Cost Application-Hosting Solution

  • A systems administrator looking for a low-cost application-hosting solution that is cloud-based should consider Platform as a Service (PaaS).

Malicious Activity Determination

  • When a security operations center determines that the malicious activity detected on a server is normal, it is classified as a false positive.

Domain Activity Logs Review

  • If a security analyst reviews domain activity logs and notices numerous failed login attempts for a user, an attacker is attempting to brute force the user's account.

Server Room Weather Damage

  • A company concerned about weather events causing damage to the server room and downtime should consider using geographically diverse data centers.

BYOD Program Security Concern

  • The primary security concern for a company setting up a BYOD (Bring Your Own Device) program involves data leakage.

Cyber Insurance Policy

  • A company decided to reduce the cost of its annual cyber insurance policy by removing the coverage for business interruption.

Security Awareness Program

  • Reporting phishing attempts or other suspicious activities, is most likely to be included as an element of communication in a security awareness program.

Incident Response Process

  • The phase in the incident response process when a security analyst reviews roles and responsibilities is preparation.

Router Hardening

  • After a recent vulnerability scan, a security engineer needs to harden the routers within the corporate network by updating firmware and disabling unnecessary services.

Data Security

  • A security administrator needs a method to secure data in an environment that includes some form of checks and balances which can be provided by digital signature.

Server Security Logs

  • Multiple invalid user attempts captured in the log file best describes a brute-force attack.

FDE Implementation

  • The most essential consideration for a security engineer implementing Full Disk Encryption (FDE) for all laptops in an organization is managing recovery keys.

Public Network Security

  • The best course of action is to setting up a VPN and placing the jump server inside the firewall.

Browser Version Exploitation

  • The best control is to implement patch management since vulnerabilities are in old code.

Data Center Security

  • Physical security is to protect life in the event of a fire.

Response to Attacks

  • Behavior is to implement anomaly based response.

Ensuring Evidence

  • Chain of custody to make sure there is evidence in the system.

Updating Wire Transfers

  • Standardizing Security Incidence reporting.

Preventing Errors

  • Code review and testing which can be achieved through documentation/scripts.

Collecting Data

  • Data Classification (labeling) to determine the classification of the data.

Levels of Accepted Risk

  • Risk appetite refers to the maximum amount of accepted risk.

unusual DNS Queries

  • Infected system to look for unusual DNS queries.

ports on firewall for SaaS

  • Documenting justification for each open port.

Time Savings

  • Solution to use for saving time and prevent human error is automation.

Security threat

  • Database Misconfiguration.

Certificates

  • The proper means of validating a certificate when it is presented to a user is through a Certificate Authority (CA).

Recommendation

  • Security Bulletin sent by vendor for BIOS update. It is critical that software/hardware are up to date to ensure that systems are not exposed to vulnerabilities. As a solution the organization must upgrade the hardware BIOS.

Assessing Criticality

  • CVSS (Common Vulnerability Scoring System) is used to quantitatively measure the criticality of a vulnerability.

Ensuring work stations

  • Ensue systems meet certain standards using group policy.

VPN Protecting

  • Data in transit is what the VPN is protecting.

Allowing Unauthorized Entry

  • False Acceptance would allow an unauthorized user to access and compromise the system.

Handling data

  • Following and consulting GDPR when handling data.

Exploitation

  • When a interactive process is exploited to gain access to resources is called Privilege escalation.

Resiliency

  • Geographic dispersal is the consideration that is important to the organization.

Enabling Risk

  • Transference enables risk to a third party.

Report areas of improvements.

  • Lessons Learned will determine the possible improvements.

Preventing Social Message Sharing

  • Hoaxes would be the risk which this action would prevent.

Application Alerts

  • DDoS most likely explains this issue.

Cryptography Increase

  • Increase cryptography security you need increase high data entropy.

Zero-day Exploits Described

  • Zero-day Exploits Undetectable And No Patch Exists.

DLP is first performed.

  • Classification should be performed before DL.

Software Delvelopment

  • Agile Described Software Delivery Method.

Company Account Compromises

  • Enforce Multi Factor Authentication when an account request reaches a risk threshold.

Threat Intelligence Sharing

  • Implement a TAXII server.

Greatest Security Concern.

  • Unknown Backdoor.

Prioritize

  • Low FRR, the goal is prioritize.

Frameworks For Security Config

  • NIST sets frameworks and controls.

Instructions used secretly. Harmful instruction.

  • Logic Bomb.

Analysis Next Step

  • Quarantine Affected Host, which is contain incident.

Exploit Stages. Chain Kill

  • The Adversary operating stage is Command and Control.

Identify a Breach

  • SIEM will identify an intrusion.

A New cloud service

  • The new service they are using is called Hybrid.

Security Analyst solution being implemented

  • User Behavior Analysis. (UDA)

Data Exfiltration

  • Directory Traversal Explains.

Conduct Analysis Most Likely

  • Malicious Script, is the answer to MOST likely.

Unusual Text Message. Technique Message

  • SMiShing Described. Using link provided in a text.

Improved Incident Process.

  • Train Team to identify the difference between events, & incidents.

  • Block attack layer 7

NIPS and WAF

  • WAF and NIPS can block Layer 7 attacks.

Business Questions

  • Best Virtual Machine migration to mitigate managers concern.

The Action Best To Prevent Infection

  • Blocking port 3389 inbound, because that an RDP Port.

The Use SAML for Authentication

  • Federation.

Solutions Should Consider.

  • Utilizing a SOAR platform.

Trusted Validation Between Partners

  • The best solution to adopt would be PKI.

Cyber Security The Security Analyst Need To Take.

  • VDI solution.

Sensitive To The Organization

  • Proprietary

Locating Unsecure Web Server

  • nmap -p 80 10.10.10.0 /24 is used for locating secure servers.

Reasons to Publish HASH

  • Hashing can be used to validate a file.

  • The best solution is TPM can check file and protect during boot process from virus.

    User Screen Prompts

  • This shows Password Complexity requirement.

Hidden file Source Code

  • Stermography can identify code

Describe best what administrator is working on.

  • Unique String

New File Transfer Solution Description

  • Secure Shell best protects file transfer.

Which used by a tool

  • Hashing can Identify credential

Preventative measures

  • RFID tag can be used

Prevent theft. from network.

  • DLP can prevent exfiltration from network

Implement The Company Implement.

  • For that they are using Wild Card.

Report Was Deliver CISO

  • This should be MFA

Types Of Data Has Hosted.

  • Classify The Data.

The Source breach occurred.

  • SQL Injection.

From Accessing Unauthorized removable media. The Best Method.

  • USB Data Blocker

Which Best Control

  • IPS Would have effective control against zero-day environment issues.

Simulate the team after detection.

  • Conduct forensics on the compromised system

Secure Coding

  • Secure Coding first should be practiced in development

How is the code be Deployed

  • Production is were the code is deployed

Build the System

  • You have to Purchase from Different Vendors

Protect from cyber issues

  • Is casb, ng-swg

Implement Models Roll Out

  • VDI model is important

Users compromise

  • Keylagger is the reason that user are compromised

backup use

  • Snapshot use to preserve the stage 1

return the conference

*Direct access

Remote managing

  • Use the SSH remote connection

The value for known vulnerabilities organization can prioritize mitigation.

CVSS solution

The BEST meet needed for the requirements

  • Community

Prove Data hasn't been altered Use Most.

  • Checksum Use Hashing Algorithm

  • The passwords Used

    Password History

fingerprint the tools

  • curl --head 192.168.0.10

  • Nmap for Pivoting

Which meets Mobile

  • Mobile Device Management

Risk before Incidence.

  • The Solution Should Be Preventive
    Defended performance on Virtual setting.

Memory Leak

  • Memory Leak is Best option to mitigate.

Risk Strategy To maintain Legacy System.

  • Risk - Acceptance
    Incidence Response. Best Action.

  • Central repository - Publish Document Organization. 200. Designing Appropriate Controls

Desired Laptop Budget. Best Meeting Low For The Requirement.

  • Deterrent.
    The Best to migrate require. Least support. - SaaS
    Security Responsible. - DPO 307.

    The passwords are not match

  • Is Due to Salting

Shell access network

  • Pivoting Technique

    The Most credential can find is

  • OSINT, dark web because these provide information on individuals not organizations.
    Can't get from organizations because they are very vague and are not transparent. C:

New one tool Best Abilit

  • SIEM = Event, Correlation best support to combine traffic/information and make correlations from multiple sources, all in on the UI console.

Which the following Mostly occurring ?

Injection = SQLi

Best Which components best cloud Multiple Firewall?

Ans = Transit

# The DPO report several hadives we removed.

  • Logic BOOM Attack to cause attack *Digital Signature.

    • Use sender private message private and use with sender public key