Free RC0-501 Exam Braindumps (page: 40)

Page 39 of 87

A security analyst has received the following alert snippet from the HIDS appliance:



Given the above logs, which of the following is the cause of the attack?

  1. The TCP ports on destination are all open
  2. FIN, URG, and PSH flags are set in the packet header
  3. TCP MSS is configured improperly
  4. There is improper Layer 2 segmentation

Answer(s): B



A security analyst reviews the following output:



The analyst loads the hash into the SIEM to discover if this hash is seen in other parts of the network.

After inspecting a large number of files, the security analyst reports the following:



Which of the following is the MOST likely cause of the hash being found in other areas?

  1. Jan Smith is an insider threat
  2. There are MD5 hash collisions
  3. The file is encrypted
  4. Shadow copies are present

Answer(s): B



A company's AUP requires:
Passwords must meet complexity requirements.
Passwords are changed at least once every six months.
Passwords must be at least eight characters long.
An auditor is reviewing the following report:



Which of the following controls should the auditor recommend to enforce the AUP?

  1. Account lockout thresholds
  2. Account recovery
  3. Password expiration
  4. Prohibit password reuse

Answer(s): C



An organization's primary datacenter is experiencing a two-day outage due to an HVAC malfunction. The node located in the datacenter has lost power and is no longer operational, impacting the ability of all users to connect to the alternate datacenter.
Which of the following BIA concepts BEST represents the risk described in this scenario?

  1. SPoF
  2. RTO
  3. MTBF
  4. MTTR

Answer(s): A






Post your Comments and Discuss CompTIA RC0-501 exam with other Community members:

RC0-501 Discussions & Posts