JK0-022 Exam Details

  • Exam Code
    :JK0-022
  • Exam Name
    :CompTIA Security+ Certification
  • Certification
    :CompTIA Security+
  • Vendor
    :CompTIA
  • Total Questions
    :1149 Q&As
  • Last Updated
    :Feb 05, 2025

CompTIA JK0-022 Online Questions & Answers

  • Question 321:

    Which of the following protocols is the security administrator observing in this packet capture?

    12:33:43, SRC 192.168.4.3:3389, DST 10.67.33.20:8080, SYN/ACK

    A. HTTPS
    B. RDP
    C. HTTP
    D. SFTP

  • Question 322:

    A security administrator develops a web page and limits input into the fields on the web page as well as filters special characters in output. The administrator is trying to prevent which of the following attacks?

    A. Spoofing
    B. XSS
    C. Fuzzing
    D. Pharming

  • Question 323:

    A company needs to receive data that contains personally identifiable information. The company requires both the transmission and data at rest to be encrypted. Which of the following achieves this goal? (Select TWO).

    A. SSH
    B. TFTP
    C. NTLM
    D. TKIP
    E. SMTP
    F. PGP/GPG

  • Question 324:

    Which of the following is the MOST secure protocol to transfer files?

    A. FTP
    B. FTPS
    C. SSH
    D. TELNET

  • Question 325:

    A company has several conference rooms with wired network jacks that are used by both employees and guests. Employees need access to internal resources and guests only need access to the Internet. Which of the following combinations is BEST to meet the requirements?

    A. NAT and DMZ
    B. VPN and IPSec
    C. Switches and a firewall
    D. 802.1x and VLANs

  • Question 326:

    An active directory setting restricts querying to only secure connections. Which of the following ports should be selected to establish a successful connection?

    A. 389
    B. 440
    C. 636
    D. 3286

  • Question 327:

    A security administrator looking through IDS logs notices the following entry: (where [email protected] and passwd= `or 1==1')

    Which of the following attacks had the administrator discovered?

    A. SQL injection
    B. XML injection
    C. Cross-site script
    D. Header manipulation

  • Question 328:

    The Chief Information Security Officer (CISO) has mandated that all IT systems with credit card data be segregated from the main corporate network to prevent unauthorized access and that access to the IT systems should be logged. Which of the following would BEST meet the CISO's requirements?

    A. Sniffers
    B. NIDS
    C. Firewalls
    D. Web proxies
    E. Layer 2 switches

  • Question 329:

    Which of the following controls should critical application servers implement to protect themselves from other potentially compromised application services?

    A. NIPS
    B. Content filter
    C. NIDS
    D. Host-based firewalls

  • Question 330:

    The incident response team has received the following email message.

    From: [email protected] To: [email protected] Subject: Copyright infringement

    A copyright infringement alert was triggered by IP address 13.10.66.5 at 09: 50: 01 GMT. After reviewing the following web logs for IP 13.10.66.5, the team is unable to correlate and identify the incident.

    09:

    45: 33 13.10.66.5 http: //remote.site.com/login.asp?user=john

    09:

    50: 22 13.10.66.5 http: //remote.site.com/logout.asp?user=anne

    10: 50: 01 13.10.66.5 http: //remote.site.com/access.asp?file=movie.mov

    11: 02: 45 13.10.65.5 http: //remote.site.com/download.asp?movie.mov=ok

    Which of the following is the MOST likely reason why the incident response team is unable to identify and correlate the incident?

    A. The logs are corrupt and no longer forensically sound.
    B. Traffic logs for the incident are unavailable.
    C. Chain of custody was not properly maintained.
    D. Incident time offsets were not accounted for.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your JK0-022 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.