CompTIA JK0-022 Online Practice
Questions and Exam Preparation
JK0-022 Exam Details
Exam Code
:JK0-022
Exam Name
:CompTIA Security+ Certification
Certification
:CompTIA Security+
Vendor
:CompTIA
Total Questions
:1149 Q&As
Last Updated
:Feb 05, 2025
CompTIA JK0-022 Online Questions &
Answers
Question 421:
An application developer has tested some of the known exploits within a new application. Which of the following should the administrator utilize to test for unidentified faults or memory leaks?
A. XSRF Attacks B. Fuzzing C. Input Validations D. SQL Injections
B. Fuzzing
Question 422:
A security administrator wants to deploy a physical security control to limit an individual's access into a sensitive area. Which of the following should be implemented?
A. Guards B. CCTV C. Bollards D. Spike strip
A. Guards A guard can be intimidating and respond to a situation and in a case where you want to limit an individual's access to a sensitive area a guard would be the most effective. Incorrect Answers: B: CCTV will only serve to record the perimeter breach and is not as intimidating as placing a guard to limit the individual's access. C: Bollards are designed to keep big objects from breaching a perimeter and not individuals who can still slip through between the bollards. D: A spike strip will only immobilize vehicles trying to breach a perimeter and will not keep individuals out. Individuals can just step over the spike strips and still gain access. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 372-373
Question 423:
A security administrator forgets their card to access the server room. The administrator asks a coworker if they could use their card for the day. Which of the following is the administrator using to gain access to the server room?
A. Man-in-the-middle B. Tailgating C. Impersonation D. Spoofing
C. Impersonation Impersonation is where a person, computer, software application or service pretends to be someone or something it's not. Impersonation is commonly non- maliciously used in client/server applications. However, it can also be used as a security threat. In this question, by using the coworker's card, the security administrator is `impersonating' the coworker. The server room locking system and any logging systems will `think' that the coworker has entered the server room. Incorrect Answers: A: In cryptography and computer security, a man-in-the-middle attack is an attack where the attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other. One example is active eavesdropping, in which the attacker makes independent connections with the victims and relays messages between them to make them believe they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker. The attacker must be able to intercept all relevant messages passing between the two victims and inject new ones. This is straightforward in many circumstances; for example, an attacker within reception range of an unencrypted Wi-Fi wireless access point, can insert himself as a man-in-the-middle. This is not what is described in this question. Therefore, this answer is incorrect. B: Just as a driver can tailgate another driver's car by following too closely, in the security sense, tailgating means to compromise physical security by following somebody through a door meant to keep out intruders. Tailgating is actually a form of social engineering, whereby someone who is not authorized to enter a particular area does so by following closely behind someone who is authorized. If the security administrator had followed the co-worker into the server room, that would be an example of tailgating. However, borrowing the co-worker's card is not tailgating. Therefore, this answer is incorrect. D: There are several kinds of spoofing including email, caller ID, MAC address, and uniform resource locator (URL) spoof attacks. All types of spoofing are designed to imitate something or someone. Email spoofing (or phishing), used by dishonest advertisers and outright thieves, occurs when email is sent with falsified "From:" entry to try and trick victims that the message is from a friend, their bank, or some other legitimate source. Any email that claims it requires your password or any personal information could be a trick. If the security administrator had created a card the same as the co-worker's card, that could be an example of spoofing. However, borrowing the coworker's card is not spoofing. Therefore, this answer is incorrect. References: http://en.wikipedia.org/wiki/Man-in-the-middle_attack http://www.yourdictionary.com/tailgating
Question 424:
Although a vulnerability scan report shows no vulnerabilities have been discovered, a subsequent penetration test reveals vulnerabilities on the network. Which of the following has been reported by the vulnerability scan?
A. Passive scan B. Active scan C. False positive D. False negative
D. False negative
Question 425:
A technician is reviewing the logical access control method an organization uses. One of the senior managers requests that the technician prevent staff members from logging on during nonworking days. Which of the following should the technician implement to meet managements request?
A. Enforce Kerberos B. Deploy smart cards C. Time of day restrictions D. Access control lists
C. Time of day restrictions Time of day restrictions limit when users can access specific systems based on the time of day or week. It can limit access to sensitive environments to normal business hours. Incorrect Answers: A: Kerberos makes use of encryption keys as tickets with time stamps to prove identity and grant access to resources. It will not prevent staff members from logging on during nonworking days. B: Smart cards are credit-card-sized IDs, badges, or security passes with an embedded integrated circuit chip that allows you to physically access secure facilities. It will not prevent staff members from logging on during nonworking days. D: Access Control List (ACL) specifies which users are allowed or refused the different types of available access based on the object type. It will not prevent staff members from logging on during nonworking days. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 24, 271, 280, 282.
Question 426:
A database administrator receives a call on an outside telephone line from a person who states that they work for a well-known database vendor. The caller states there have been problems applying the newly released vulnerability patch for
their database system, and asks what version is being used so that they can assist.
Which of the following is the BEST action for the administrator to take?
A. Thank the caller, report the contact to the manager, and contact the vendor support line to verify any reported patch issues. B. Obtain the vendor's email and phone number and call them back after identifying the number of systems affected by the patch. C. Give the caller the database version and patch level so that they can receive help applying the patch. D. Call the police to report the contact about the database systems, and then check system logs for attack attempts.
A. Thank the caller, report the contact to the manager, and contact the vendor support line to verify any reported patch issues. Impersonation is where a person, computer, software application or service pretends to be someone or something it's not. Impersonation is commonly non- maliciously used in client/server applications. However, it can also be used as a security threat. In this question, the person making the call may be impersonating someone who works for a well-known database vendor. The actions described in this answer would mitigate the risk. By not divulging information about your database system and contacting the vendor directly, you can be sure that you are talking to the right people. Incorrect Answers: B: Identifying the number of systems affected by the patch would involve divulging the version number to the caller without being able to verify his identity. Therefore, this answer is incorrect. C: Giving the caller the database version and patch level so that they can receive help applying the patch would be divulging potentially sensitive information to someone without being able to verify their identity. The version information could then be used for malicious purposes later especially if that version of software has known vulnerabilities. Therefore, this answer is incorrect. D: Calling the police to report the contact about the database systems, and then checking system logs for attack attempts may be overkill. You don't know that the caller is malicious. He may well be from the vendor company. You just need a way to verify his identity. Therefore, this answer is incorrect.
Question 427:
A network administrator noticed various chain messages have been received by the company.
Which of the following security controls would need to be implemented to mitigate this issue?
A. Anti-spam B. Antivirus C. Host-based firewalls D. Anti-spyware
A. Anti-spam A spam filter is a software or hardware solution used to identify and block, filter, or remove unwanted messages sent via email or instant messaging (IM). Incorrect Answers: B: Antivirus software is used to protect systems against viruses, which are a form of malicious code designed to spread from one system to another. C: A host-based firewall is installed on a client system and is used to protect the client system from the activities of the user as well as from communication from the network or Internet. It does not block email messages or instant messaging (IM) messages. D: Spyware monitors a user's activity and uses network protocols to reports it to a third party without the user's knowledge. This is usually accomplished using a tracking cookie. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 18-19, 161-162, 300 Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 246
Question 428:
A user attempting to log on to a workstation for the first time is prompted for the following information before being granted access: username, password, and a four-digit security pin that was mailed to him during account registration. This is an example of which of the following?
A. Dual-factor authentication B. Multifactor authentication C. Single factor authentication D. Biometric authentication
C. Single factor authentication Multi-factor authentication (MFA) is a method of computer access control which a user can pass by successfully presenting authentication factors from at least two of the three categories: knowledge factors ("things only the user knows"), such as passwords possession factors ("things only the user has"), such as ATM cards inherence factors ("things only the user is"), such as biometrics In this question a username, password, and a four-digit security pin knowledge are all knowledge factors (something the user knows). Therefore, this is single- factor authentication. Incorrect Answers: A: Dual factor authentication uses two factors of authentication. There are three main factors of authentication: knowledge factors, possession factors and inherence factors. In this question, only one factor (knowledge factor) is being used. B: Multi-factor authentication uses more than one factor of authentication. There are three main factors of authentication: knowledge factors, possession factors and inherence factors. In this question, only one factor (knowledge factor) is being used. D: Biometric authentication is an inherence factor something specific to the user such as a fingerprint or a retina scan. Neither are being used in this question. References: http://en.wikipedia.org/wiki/Multi-factor_authentication
Question 429:
A security administrator at a company which implements key escrow and symmetric encryption only, needs to decrypt an employee's file. The employee refuses to provide the decryption key to the file. Which of the following can the administrator do to decrypt the file?
A. Use the employee's private key B. Use the CA private key C. Retrieve the encryption key D. Use the recovery agent
C. Retrieve the encryption key
Question 430:
Which of the following allows lower level domains to access resources in a separate Public Key Infrastructure?
A. Trust Model B. Recovery Agent C. Public Key D. Private Key
A. Trust Model In a bridge trust model allows lower level domains to access resources in a separate PKI through the root CA. A trust Model is collection of rules that informs application on how to decide the legitimacy of a Digital Certificate. In a bridge trust model, a peer-to-peer relationship exists among the root CAs. The root CAs can communicate with one another, allowing cross certification. This arrangement allows a certification process to be established between organizations or departments. Each intermediate CA trusts only the CAs above and below it, but the CA structure can be expanded without creating additional layers of CAs. Incorrect Answers: B: A recovery agent cannot be used to bridge trust between PKIs. A key recovery agent is an entity that has the ability to recover a key, key components, or plaintext messages as needed. As opposed to escrow, recovery agents are typically used to access information that is encrypted with older keys. C: A public key is available to everyone. A public key cannot be used to bridge trust between PKIs. D: A private key is a secret key. It cannot be used to bridge trust between PKIs. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 262, 279-285, 285-289
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only CompTIA exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your JK0-022 exam preparations
and CompTIA certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.