Exam Details

  • Exam Code
    :JK0-022
  • Exam Name
    :CompTIA Security+ Certification
  • Certification
    :CompTIA Security+
  • Vendor
    :CompTIA
  • Total Questions
    :1149 Q&As
  • Last Updated
    :Feb 05, 2025

CompTIA CompTIA Security+ JK0-022 Questions & Answers

  • Question 1041:

    Which of the following devices would be MOST useful to ensure availability when there are a large number of requests to a certain website?

    A. Protocol analyzer

    B. Load balancer

    C. VPN concentrator

    D. Web security gateway

  • Question 1042:

    Which of the following is a best practice when securing a switch from physical access?

    A. Disable unnecessary accounts

    B. Print baseline configuration

    C. Enable access lists

    D. Disable unused ports

  • Question 1043:

    Which of the following network design elements allows for many internal devices to share one public IP address?

    A. DNAT

    B. PAT

    C. DNS

    D. DMZ

  • Question 1044:

    The Chief Information Security Officer (CISO) has mandated that all IT systems with credit card data be segregated from the main corporate network to prevent unauthorized access and that access to the IT systems should be logged. Which of the following would BEST meet the CISO's requirements?

    A. Sniffers

    B. NIDS

    C. Firewalls

    D. Web proxies

    E. Layer 2 switches

  • Question 1045:

    Which of the following firewall types inspects Ethernet traffic at the MOST levels of the OSI model?

    A. Packet Filter Firewall

    B. Stateful Firewall

    C. Proxy Firewall

    D. Application Firewall

  • Question 1046:

    Which of the following security devices can be replicated on a Linux based computer using IP tables to inspect and properly handle network based traffic?

    A. Sniffer

    B. Router

    C. Firewall

    D. Switch

  • Question 1047:

    The security administrator at ABC company received the following log information from an external party:

    10:45:01 EST, SRC 10.4.3.7:3056, DST 8.4.2.1:80, ALERT, Directory traversal

    10:45:02 EST, SRC 10.4.3.7:3057, DST 8.4.2.1:80, ALERT, Account brute force

    10:45:03 EST, SRC 10.4.3.7:3058, DST 8.4.2.1:80, ALERT, Port scan

    The external party is reporting attacks coming from abc-company.com. Which of the following is the reason the ABC company's security administrator is unable to determine the origin of the attack?

    A. A NIDS was used in place of a NIPS.

    B. The log is not in UTC.

    C. The external party uses a firewall.

    D. ABC company uses PAT.

  • Question 1048:

    Which of the following devices is MOST likely being used when processing the following?

    1 PERMIT IP ANY ANY EQ 80 2 DENY IP ANY ANY

    A. Firewall

    B. NIPS

    C. Load balancer

    D. URL filter

  • Question 1049:

    Sara, the security administrator, must configure the corporate firewall to allow all public IP addresses on the internal interface of the firewall to be translated to one public IP address on the external interface of the same firewall. Which of the following should Sara configure?

    A. PAT

    B. NAP

    C. DNAT

    D. NAC

  • Question 1050:

    Separation of duties is often implemented between developers and administrators in order to separate which of the following?

    A. More experienced employees from less experienced employees

    B. Changes to program code and the ability to deploy to production

    C. Upper level management users from standard development employees

    D. The network access layer from the application access layer

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your JK0-022 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.