CompTIA SY0-501 Security+ Take Ten Challenge #2Step 1 of 1010%2-1: Which of the following would best describe data in-use? Encrypted data is stored in a SQL database A point of sale terminal encrypts a credit card number Customer information is transmitted across an IPsec tunnel A laptop drive is configured for whole disk encryption A switch forwards a frame to a router 2-2: An attacker has determined that they can intentionally overwrite an area of memory to perform an exploit. Which of these would best describe this exploitation method? Man in the middle Data injection Driver manipulation Cross-site request forgery Buffer overflow 2-3: A security administrator would like to limit internal users from directly communicating to external web sites. Which of these security technologies would be the best choice for this objective? IPS Proxy VPN concentrator Firewall Load balancer 2-4: Which of these best describes TPM functionality? Hardware root of trust Application blacklisting EAL4 Reverse proxy EMI prevention 2-5: Which of the following would be a disadvantage to using PAP during authentication? The passwords are stored as a salted hash The credentials are passed in the clear Must be used with a third-party trust The password hash is easy to brute force Only operates over dial-up lines 2-6: Which data label would be most associated with patient records from a medical doctor? PHI PCI PII DSS NDA 2-7: Which of the following would NOT commonly be associated with a server's certificate chain? Root CA certificate Server certificate Intermediate certificates Private key Root CA certificate hash 2-8: An attacker has infected a government healthcare reporting web site with malware in an effort to gain access to a hospital network. When the hospital visits the government site, the malware will attempt to infect the hospital computer. Which of the following would best describe this attack type? Data injection Watering hole Cross-site request forgery Man-in-the-middle Hoax 2-9: During a scheduled event, a security administrator was able to exploit a known vulnerability on a server to gain root access. Which of the following would best describe this event? DoS Penetration test Man-in-the-middle Vulnerability scan Spoofing 2-10: A security administrator needs to create a report each day that shows the number of invalid login attempts across all of their servers. Which of these would be the best way to provide this information? DLP Proxy SIEM NAC Firewall Take Ten Challenge #2 companion video with detailed answers: