SY0-501 Exam Question 221

A security administrator is reviewing the following network capture:
192.168.20.43:2043 -> 10.234.66.21:80
POST "192.168.20.43
https://www.banksite.com<ENTER>JoeUsr<BackSPACE>erPassword<ENTER>"
Which of the following malware is MOST likely to generate the above information?
  • SY0-501 Exam Question 222

    After a user reports stow computer performance, a systems administrator detects a suspicious file, which was installed as part of a freeware software package.
    The systems administrator reviews the output below:

    Based on the above information, which of the following types of malware was installed on the user's computer?
  • SY0-501 Exam Question 223

    Which of the following is a risk that is specifically associated with hosting applications in the public cloud?
  • SY0-501 Exam Question 224

    A security administrator discovers that an attack has been completed against a node on the corporate network.
    All available logs were collected and stored.
    You must review all network logs to discover the scope of the attack, check the box of the node(s) that have been compromised and drag and drop the appropriate actions to complete the incident response on the network. The environment is a critical production environment; perform the LEAST disruptive actions on the network, while still performing the appropriate incid3nt responses.
    Instructions: The web server, database server, IDS, and User PC are clickable. Check the box of the node(s) that have been compromised and drag and drop the appropriate actions to complete the incident response on the network. Not all actions may be used, and order is not important. If at any time you would like to bring back the initial state of the simulation, please select the Reset button. When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.

    SY0-501 Exam Question 225

    A network administrator adds an ACL to allow only HTTPS connections form host 192.168.2.3 to web
    server 192.168.5.2. After applying the rule, the host is unable to access the server. The network
    administrator runs the output and notices the configuration below:

    Which of the following rules would be BEST to resolve the issue?
    A:

    B:

    C:

    D: