SYO-501 Exam Question 71
An incident response manager has started to gather all the facts related to a SIEM alert showing multiple systems may have been compromised. The manager has gathered these facts:
The breach is currently indicated on six user PCs

One service account is potentially compromised

Executive management has been notified

In which of the following phases of the IRP is the manager currently working?
The breach is currently indicated on six user PCs

One service account is potentially compromised

Executive management has been notified

In which of the following phases of the IRP is the manager currently working?
SYO-501 Exam Question 72
A company is currently using the following configuration:
IAS server with certificate-based EAP-PEAP and MSCHAP
Unencrypted authentication via PAP
A security administrator needs to configure a new wireless setup with the following configurations:
PAP authentication method
PEAP and EAP provide two-factor authentication
Which of the following forms of authentication are being used? (Select two.)
IAS server with certificate-based EAP-PEAP and MSCHAP
Unencrypted authentication via PAP
A security administrator needs to configure a new wireless setup with the following configurations:
PAP authentication method
PEAP and EAP provide two-factor authentication
Which of the following forms of authentication are being used? (Select two.)
SYO-501 Exam Question 73
An organization finds that most help desk calls are regarding account lockout due to a variety of applications running on different systems. Management is looking for a solution to reduce the number of account lockouts while improving security. Which of the following is the BEST solution for this organization?
SYO-501 Exam Question 74
An auditor is reviewing the following output from a password-cracking tool:

Which of the following methods did the auditor MOST likely use?

Which of the following methods did the auditor MOST likely use?
SYO-501 Exam Question 75
A company hired a third-party firm to conduct as assessment of vulnerabilities exposed to the Internet. The firm informs the company that an exploit exists for an FTP server that has a version installed from eight years ago. The company has decided to keep the system online anyway, as no upgrade exists from the vendor. Which of the following BEST describes the reason why the vulnerability exists?
