CompTIA SY0-501 - CompTIA Security+ Exam

Question #11 (Topic: Single Topic)
A security analyst is hardening a server with the directory services role installed. The analyst must ensure LDAP traffic cannot be monitored or sniffed and
maintains compatibility with LDAP clients. Which of the following should the analyst implement to meet these requirements? (Choose two.)
A. Generate an X.509-compliant certificate that is signed by a trusted CA. B. Install and configure an SSH tunnel on the LDAP server. C. Ensure port 389 is open between the clients and the servers using the communication. D. Ensure port 636 is open between the clients and the servers using the communication. E. Remote the LDAP directory service role from the server.
Answer: AD
Question #12 (Topic: Single Topic)
Which of the following threat actors is MOST likely to steal a company's proprietary information to gain a market edge and reduce time to market?
A. Competitor B. Hacktivist C. Insider D. Organized crime.
Answer: A
Question #13 (Topic: Single Topic)
A penetration tester is crawling a target website that is available to the public. Which of the following represents the actions the penetration tester is performing?
A. URL hijacking B. Reconnaissance C. White box testing D. Escalation of privilege
Answer: B
Question #14 (Topic: Single Topic)
Which of the following characteristics differentiate a rainbow table attack from a brute force attack? (Choose two.)
A. Rainbow table attacks greatly reduce compute cycles at attack time. B. Rainbow tables must include precomputed hashes. C. Rainbow table attacks do not require access to hashed passwords. D. Rainbow table attacks must be performed on the network. E. Rainbow table attacks bypass maximum failed login restrictions.
Answer: BE
Question #15 (Topic: Single Topic)
Which of the following best describes routine in which semicolons, dashes, quotes, and commas are removed from a string?
A. Error handling to protect against program exploitation B. Exception handling to protect against XSRF attacks. C. Input validation to protect against SQL injection. D. Padding to protect against string buffer overflows.
Answer: C
Download Exam
Page: 3 / 227
Total 1132 questions