SY0-501 Exam Question 306

A security program manager wants to actively test the security posture of a system.
The system is not yet in production and has no uptime requirement or active user base.
Which of the following methods will produce a report which shows vulnerabilities that were actually exploited?
  • SY0-501 Exam Question 307

    An organization's Chief Executive Officer (CEO) directs a newly hired computer technician to install an OS on the CEO's: personal laptop. The technician performs the installation, and a software audit later in the month indicates a violation of the EULA occurred as a result. Which of the following would address this violation going forward?
  • SY0-501 Exam Question 308

    A security administrator found the following piece of code referenced on a domain controller's task scheduler:
    $var = GetDomainAdmins
    If $var != 'fabio'
    SetDomainAdmins = NULL
    With which of the following types of malware is the code associated?
  • SY0-501 Exam Question 309

    A business sector is highly competitive, and safeguarding trade secrets and critical information is paramount.
    On a seasonal basis, an organization employs temporary hires and contractor personnel to accomplish its mission objectives. The temporary and contract personnel require access to network resources only when on the clock.
    Which of the following account management practices are the BEST ways to manage these accounts?
  • SY0-501 Exam Question 310

    Which of the following development models entails several iterative and incremental software development methodologies such as Scrum?