SYO-501 Exam Question 177

An organization has air gapped a critical system.
Which of the following BEST describes the type of attacks that are prevented by this security measure?
  • SYO-501 Exam Question 178

    Joe is exchanging encrypted email with another party. Joe encrypts the initial email with a key. When Joe receives a response, he is unable to decrypt the response with the same key he used initially.
    Which of the following would explain the situation?
  • SYO-501 Exam Question 179

    A security administrator receives alerts from the perimeter UTM. Upon checking the logs, the administrator finds the following output:
    From Zone: Untrust
    To Zone: DMZ
    Attacker: externalip.com
    Victim: 172.16.0.20
    To Port: 80
    Action: Alert
    Severity: Critical
    When examining the PCAP associated with the event, the security administrator finds the following information:
    <script> alert ("Click here for important information regarding your account! http://externalip.com/account.php"); </script> Which of the following actions should the security administrator take?
  • SYO-501 Exam Question 180

    During a monthly vulnerability scan, a server was flagged for being vulnerable to an Apache Struts exploit.
    Upon further investigation, the developer responsible for the server informs the security team that Apache Struts is not installed on the server. Which of the following BEST describes how the security team should reach to this incident?
  • SYO-501 Exam Question 181

    An application developer has coded a new application with a module to examine all user entries for the graphical user interface. The module verifies that user entries match the allowed types for each field and that OS and database commands are rejected before entries are sent for further processing within the application. These are example of: