SY0-501 Exam Question 196

A security administrator is reviewing the following report from an organization's patch management system that has only wired workstations which are utilized daily:

Which of the following is the GREATEST security concern for the administrator?
  • SY0-501 Exam Question 197

    A technician suspects that a desktop was compromised with a rootkit. After removing lhe hard drive from the desktop and running an offline le integrity check, the technician reviews the following output:

    Based on the above output, which of the following is the malicious file?
  • SY0-501 Exam Question 198

    Ann. An employee in the payroll department, has contacted the help desk citing multiple issues with her device, including:
    Ann states the issues began after she opened an invoice that a vendor emailed to her. Upon opening the invoice, she had to click several security warnings to view it in her word processor. With which of the following is the device MOST likely infected?
  • SY0-501 Exam Question 199

    A technician wants to configure a wireless router at a small office that manages a family-owned dry cleaning business. The router will support five laptops, potential smartphones, a wireless printer, and occasional guests.
    Which of the following wireless configuration is BEST implemented in this scenario?
  • SY0-501 Exam Question 200

    SIMULATION
    A security administrator discovers that an attack has been completed against a node on the corporate network. All available logs were collected and stored.
    You must review all network logs to discover the scope of the attack, check the box of the node(s) that have been compromised and drag and drop the appropriate actions to complete the incident response on the network. The environment is a critical production environment; perform the LEAST disruptive actions on the network, while still performing the appropriate incid3nt responses.
    Instructions: The web server, database server, IDS, and User PC are clickable. Check the box of the node(s) that have been compromised and drag and drop the appropriate actions to complete the incident response on the network. Not all actions may be used, and order is not important. If at any time you would like to bring back the initial state of the simulation, please select the Reset button. When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.