CompTIA JK0-022 Online Practice
Questions and Exam Preparation
JK0-022 Exam Details
Exam Code
:JK0-022
Exam Name
:CompTIA Security+ Certification
Certification
:CompTIA Security+
Vendor
:CompTIA
Total Questions
:1149 Q&As
Last Updated
:Feb 05, 2025
CompTIA JK0-022 Online Questions &
Answers
Question 401:
Which of the following protocols allows for the LARGEST address space?
A. IPX B. IPv4 C. IPv6 D. Appletalk
C. IPv6 The main advantage of IPv6 over IPv4 is its larger address space. The length of an IPv6 address is 128 bits, compared with 32 bits in IPv4. Incorrect Answers: A: A big advantage of IPX was a small memory footprint of the IPX driver, which was vital for MS-DOS and Microsoft Windows up to the version Windows 95 because of limited size of the conventional memory. B: IPv4 has 32-bit addresses, whereas IPv6 has 128 bit addresses. D: AppleTalk is a proprietary suite of networking protocols developed by Apple Inc. References: http://en.wikipedia.org/wiki/IPv6#Larger_address_space http://en.wikipedia.org/wiki/Internetwork_Packet_Exchange http://en.wikipedia.org/wiki/AppleTalk
Question 402:
When confidentiality is the primary concern, and a secure channel for key exchange is not available, which of the following should be used for transmitting company documents?
A. Digital Signature B. Symmetric C. Asymmetric D. Hashing
C. Asymmetric
Question 403:
A company has implemented PPTP as a VPN solution. Which of the following ports would need to be opened on the firewall in order for this VPN to function properly? (Select TWO).
A. UDP 1723 B. TCP 500 C. TCP 1723 D. UDP 47 E. TCP 47
C. TCP 1723 D. UDP 47 A PPTP tunnel is instantiated by communication to the peer on TCP port 1723. This TCP connection is then used to initiate and manage a second GRE tunnel to the same peer. The PPTP GRE packet format is non-standard, including an additional acknowledgement field replacing the typical routing field in the GRE header. However, as in a normal GRE connection, those modified GRE packets are directly encapsulated into IP packets, and seen as IP protocol number 47. Incorrect Answers: A, E: PPTP uses a control channel over TCP and a GRE tunnel operating to encapsulate PPP packets. B: TCP port 500 is used by the Internet Security Association and Key Management Protocol (ISAKMP) References: http://en.wikipedia.org/wiki/Point-to-Point_Tunneling_Protocol http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers
Question 404:
Which of the following attacks impact the availability of a system? (Select TWO).
A. Smurf B. Phishing C. Spim D. DDoS E. Spoofing
A. Smurf D. DDoS
Question 405:
Which of the following attacks targets high level executives to gain company information?
A. Phishing B. Whaling C. Vishing D. Spoofing
B. Whaling Whaling is a specific kind of malicious hacking within the more general category of phishing, which involves hunting for data that can be used by the hacker. In general, phishing efforts are focused on collecting personal data about users. In whaling, the targets are high-ranking bankers, executives or others in powerful positions or job titles. Hackers who engage in whaling often describe these efforts as "reeling in a big fish," applying a familiar metaphor to the process of scouring technologies for loopholes and opportunities for data theft. Those who are engaged in whaling may, for example, hack into specific networks where these powerful individuals work or store sensitive data. They may also set up keylogging or other malware on a work station associated with one of these executives. There are many ways that hackers can pursue whaling, leading C-level or top-level executives in business and government to stay vigilant about the possibility of cyber threats. Incorrect Answers: A: Phishing is the act of sending an email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. Phishing email will direct the user to visit a website where they are asked to update personal information, such as a password, credit card, social security, or bank account numbers, that the legitimate organization already has. The website, however, is bogus and set up only to steal the information the user enters on the page. Phishing emails are blindly sent to thousands, if not millions of recipients. By spamming large groups of people, the "phisher" counts on the email being read by a percentage of people who actually have an account with the legitimate company being spoofed in the email and corresponding webpage. Phishing, also referred to as brand spoofing or carding, is a variation on "fishing," the idea being that bait is thrown out with the hopes that while most will ignore the bait, some will be tempted into biting. Phishing is not specifically targeted toward high-level executives. Therefore, this answer is incorrect. C: Vishing (voice or VoIP phishing) is an electronic fraud tactic in which individuals are tricked into revealing critical financial or personal information to unauthorized entities. Vishing works like phishing but does not always occur over the Internet and is carried out using voice technology. A vishing attack can be conducted by voice email, VoIP (voice over IP), or landline or cellular telephone. The potential victim receives a message, often generated by speech synthesis, indicating that suspicious activity has taken place in a credit card account, bank account, mortgage account or other financial service in their name. The victim is told to call a specific telephone number and provide information to "verify identity" or to "ensure that fraud does not occur." If the attack is carried out by telephone, caller ID spoofing can cause the victim's set to indicate a legitimate source, such as a bank or a government agency. Vishing is not specifically targeted toward high-level executives. Therefore, this answer is incorrect. D: There are several kinds of spoofing including email, caller ID, MAC address, and uniform resource locator (URL) spoof attacks. All types of spoofing are designed to imitate something or someone. Email spoofing (or phishing), used by dishonest advertisers and outright thieves, occurs when email is sent with falsified "From:" entry to try and trick victims that the message is from a friend, their bank, or some other legitimate source. Any email that claims it requires your password or any personal information could be a trick. Spoofing is not specifically targeted toward high-level executives. Therefore, this answer is incorrect. References: http://www.webopedia.com/TERM/P/phishing.html http://searchunifiedcommunications.techtarget.com/definition/vishing
Question 406:
Simulation
A security administrator discovers that an attack has been completed against a node on the corporate network. All available logs were collected and stored.
You must review all network logs to discover the scope of the attack, check the box of the node(s) that have been compromised and drag and drop the appropriate actions to complete the incident response on the network. The environment is
a critical production environment; perform the LEAST disruptive actions on the network, while still performing the appropriate incid3nt responses.
Instructions: The web server, database server, IDS, and User PC are clickable. Check the box of the node(s) that have been compromised and drag and drop the appropriate actions to complete the incident response on the network. Not all
actions may be used, and order is not important. If at anytime you would like to bring back the initial state of the simulation, please select the Reset button. When you have completed the simulation, please select the Done button to submit.
Once the simulation is submitted, please select the Next button to continue.
Correct Answer.
Database server was attacked, actions should be to capture network traffic and Chain of Custody.
Database server was attacked, actions should be to capture network traffic and Chain of Custody.
IDS Server Log:
Web Server Log:
Database Server Log:
Users PC Log:
Question 407:
Use of group accounts should be minimized to ensure which of the following?
A. Password security B. Regular auditing C. Baseline management D. Individual accountability
D. Individual accountability Holding users accountable for their actions is part of security, and can only be achieved by users having their own user accounts. To adequately provide accountability, the use of shared or group accounts should be discouraged. Incorrect Answers: A: Password length and password complexity combined increases ensures password security. B: Regular auditing will help determine whether users have been doing their work properly or if they have successfully or unsuccessfully attempted to contravene company policies or the law. C: A baseline is a distinct starting point from where implementation begins, improvement is judged, or comparison is made. Baseline management is the administration of this starting point. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 293, 294. http://www.businessdictionary.com/definition/baseline-management.html
Question 408:
Which of the following types of security services are used to support authentication for remote users and devices?
A. Biometrics B. HSM C. RADIUS D. TACACS
C. RADIUS RADIUS authentication phase takes place when a network client connects to a network access server (NAS) and provides authentication credentials. The NAS will then make use of the authentication credentials to issue a RADIUS authentication request to the RADIUS server, which will then exchange RADIUS authentication messages with the NAS. Incorrect Answers: A: Biometrics refers to a collection of physical attributes of the human body that can be used as identification or an authentication factor. Devices cannot use this. B: HSM is a physical computing device that protects and oversees digital keys for strong authentication and provides cryptoprocessing. It is not used for the authentication of remote users and devices? D: TACACS was used for communicating with an authentication server, not the actual authentication. References: http://cloudessa.com/products/cloudessa-radius-service/what-is-a-radius-server/ Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, p 285. http://en.wikipedia.org/wiki/Hardware_security_module http://en.wikipedia.org/wiki/TACACS
Question 409:
The security administrator installed a newly generated SSL certificate onto the company web server. Due to a misconfiguration of the website, a downloadable file containing one of the pieces of the key was available to the public. It was verified that the disclosure did not require a reissue of the certificate. Which of the following was MOST likely compromised?
A. The file containing the recovery agent's keys. B. The file containing the public key. C. The file containing the private key. D. The file containing the server's encrypted passwords.
B. The file containing the public key. The public key can be made available to everyone. There is no need to reissue the certificate. Incorrect Answers: A: The recovery agent has no key. C: The private key must be secret. If the private key is made available to a third party, then the key must be revoked. D: Encrypted passwords would not be a security risk. It would be hard to decrypt them. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 279-285
Question 410:
Which of the following ports should be opened on a firewall to allow for NetBIOS communication? (Select TWO).
A. 110 B. 137 C. 139 D. 143 E. 161 F. 443
B. 137 C. 139 NetBIOS provides four distinct services: Name service for name registration and resolution (port: 137/udp) Name service for name registration and resolution (port: 137/tcp) Datagram distribution service for connectionless communication (port: 138/udp) Session service for connection-oriented communication (port: 139/tcp) Incorrect Answers: A: POP3 uses port 110. NetBIOS does not use port 110. D: IMAP uses port 143. NetBIOS does not use port 143. E: SNM
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only CompTIA exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your JK0-022 exam preparations
and CompTIA certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.