Which of the following best describes the practice of preserving and documenting the handling of forensic evidence?
A. Acquisition of evidenceA company web server is initiating outbound traffic to a low-reputation, public IP on non-standard pat. The web server is used to present an unauthenticated page to clients who upload images the company. An analyst notices a suspicious process running on the server hat was not created by the company development team.
Which of the following is the most likely explanation for his security incident?
A. A web shell has been deployed to the server through the page.A systems administrator receives the following alert from a file integrity monitoring tool:
The hash of the cmd.exe file has changed.
The systems administrator checks the OS logs and notices that no patches were applied in the last two months.
Which of the following most likely occurred?
A. The end user changed the file permissions.To improve the security at a data center, a security administrator implements a CCTV system and posts several signs about the possibility of being filmed.
Which of the following best describe these types of controls?
(Select two).
A. PreventiveWhich of the following should be used to select a label for a file based on the file's value, sensitivity, or applicable regulations?
A. VerificationWhich of the following can best contribute to prioritizing patch applications?
A. CVSSWhile investigating a recent security breach an analyst finds that an attacker gained access by SOL infection through a company website.
Which of the following should the analyst recommend to the website developers to prevent this from reoccurring?
A. Secure cookiesAn administrator needs to protect user passwords and has been advised to hash the passwords.
Which of the following BEST describes what the administrator is being advised to do?
A. Perform a mathematical operation on the passwords that will convert them into unique strings.Which of the following involves an attempt to take advantage of database misconfigurations?
A. Buffer overflowA security analyst investigates an incident in which a PowerShell script was identified as a potential IoC.
Which of the following will best help the analyst identify an attempt to compromise the system?
A. SNMP logsNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-701 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.