Exam Details

  • Exam Code
    :JK0-022
  • Exam Name
    :CompTIA Security+ Certification
  • Certification
    :CompTIA Security+
  • Vendor
    :CompTIA
  • Total Questions
    :1149 Q&As
  • Last Updated
    :Feb 05, 2025

CompTIA CompTIA Security+ JK0-022 Questions & Answers

  • Question 121:

    A quality assurance analyst is reviewing a new software product for security, and has complete access to the code and data structures used by the developers. This is an example of which of the following types of testing?

    A. Black box

    B. Penetration

    C. Gray box

    D. White box

  • Question 122:

    Matt, the Chief Information Security Officer (CISO), tells the network administrator that a security company has been hired to perform a penetration test against his network. The security company asks Matt which type of testing would be most beneficial for him. Which of the following BEST describes what the security company might do during a black box test?

    A. The security company is provided with all network ranges, security devices in place, and logical maps of the network.

    B. The security company is provided with no information about the corporate network or physical locations.

    C. The security company is provided with limited information on the network, including all network diagrams.

    D. The security company is provided with limited information on the network, including some subnet ranges and logical network diagrams.

  • Question 123:

    The security consultant is assigned to test a client's new software for security, after logs show targeted attacks from the Internet. To determine the weaknesses, the consultant has no access to the application program interfaces, code, or data structures. This is an example of which of the following types of testing?

    A. Black box

    B. Penetration

    C. Gray box

    D. White box

  • Question 124:

    A process in which the functionality of an application is tested without any knowledge of the internal mechanisms of the application is known as:

    A. Black box testing

    B. White box testing

    C. Black hat testing

    D. Gray box testing

  • Question 125:

    The Quality Assurance team is testing a new third party developed application. The Quality team does not have any experience with the application. Which of the following is the team performing?

    A. Grey box testing

    B. Black box testing

    C. Penetration testing

    D. White box testing

  • Question 126:

    Joe a company's new security specialist is assigned a role to conduct monthly vulnerability scans across the network. He notices that the scanner is returning a large amount of false positives or failed audits. Which of the following should Joe recommend to remediate these issues?

    A. Ensure the vulnerability scanner is located in a segmented VLAN that has access to the company's servers

    B. Ensure the vulnerability scanner is configured to authenticate with a privileged account

    C. Ensure the vulnerability scanner is attempting to exploit the weaknesses it discovers

    D. Ensure the vulnerability scanner is conducting antivirus scanning

  • Question 127:

    Which of the following is an example of a false positive?

    A. Anti-virus identifies a benign application as malware.

    B. A biometric iris scanner rejects an authorized user wearing a new contact lens.

    C. A user account is locked out after the user mistypes the password too many times.

    D. The IDS does not identify a buffer overflow.

  • Question 128:

    Which of the following is BEST utilized to identify common misconfigurations throughout the enterprise?

    A. Vulnerability scanning

    B. Port scanning

    C. Penetration testing

    D. Black box

  • Question 129:

    A company is looking to improve their security posture by addressing risks uncovered by a recent penetration test. Which of the following risks is MOST likely to affect the business on a day-to-day basis?

    A. Insufficient encryption methods

    B. Large scale natural disasters

    C. Corporate espionage

    D. Lack of antivirus software

  • Question 130:

    Which of the following tests a number of security controls in the least invasive manner?

    A. Vulnerability scan

    B. Threat assessment

    C. Penetration test

    D. Ping sweep

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your JK0-022 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.