SY0-501 Exam Question 166

A security analyst is testing both Windows and Linux systems for unauthorized DNS zone transfers within a LAN on comptia.org from example.org. Which of the following commands should the security analyst use? (Select two.)
  • SY0-501 Exam Question 167

    An information system owner has supplied a new requirement to the development team that calls for increased non-repudiation within the application. After undergoing several audits, the owner determined that current levels of non-repudiation were insufficient.
    Which of the following capabilities would be MOST appropriate to consider implementing is response to the new requirement?
  • SY0-501 Exam Question 168

    An organization's internal auditor discovers that large sums of money have recently been paid to a vendor that management does not recognize. The IT security department is asked to investigate the organizations the organization's ERP system to determine how the accounts payable module has been used to make these vendor payments.
    The IT security department finds the following security configuration for the accounts payable module:
    New Vendor Entry - Required Role: Accounts Payable Clerk
    New Vendor Approval - Required Role: Accounts Payable Clerk
    Which of the following changes to the security configuration of the accounts payable module would BEST mitigate the risk?
  • SY0-501 Exam Question 169

    Ann, a new employee, received an email from an unknown source indicating she needed to click on the provided link to update her company's profile. Once Ann clicked the link, a command prompt appeared with the following output:

    Which of the following types of malware was executed?
  • SY0-501 Exam Question 170

    A new network administrator is establishing network circuit monitoring guidelines to catch potentially malicious traffic. The administrator begins monitoring the NetFlow statistics tor the critical Internet circuit and notes the following data after two weeks.

    However, after checking the statistics from the weekend following the compiled statistics the administrator notices a spike in traffic to 250Mbps sustained for one hour The administrator is able to track the source of the spike to a server in the DMZ Which of the following is the next BEST course of action the administrator should take?