JK0-022 Exam Details

  • Exam Code
    :JK0-022
  • Exam Name
    :CompTIA Security+ Certification
  • Certification
    :CompTIA Security+
  • Vendor
    :CompTIA
  • Total Questions
    :1149 Q&As
  • Last Updated
    :Feb 05, 2025

CompTIA JK0-022 Online Questions & Answers

  • Question 421:

    An application developer has tested some of the known exploits within a new application. Which of the following should the administrator utilize to test for unidentified faults or memory leaks?

    A. XSRF Attacks
    B. Fuzzing
    C. Input Validations D. SQL Injections

  • Question 422:

    A security administrator wants to deploy a physical security control to limit an individual's access into a sensitive area. Which of the following should be implemented?

    A. Guards
    B. CCTV
    C. Bollards
    D. Spike strip

  • Question 423:

    A security administrator forgets their card to access the server room. The administrator asks a coworker if they could use their card for the day. Which of the following is the administrator using to gain access to the server room?

    A. Man-in-the-middle
    B. Tailgating
    C. Impersonation
    D. Spoofing

  • Question 424:

    Although a vulnerability scan report shows no vulnerabilities have been discovered, a subsequent penetration test reveals vulnerabilities on the network. Which of the following has been reported by the vulnerability scan?

    A. Passive scan
    B. Active scan
    C. False positive
    D. False negative

  • Question 425:

    A technician is reviewing the logical access control method an organization uses. One of the senior managers requests that the technician prevent staff members from logging on during nonworking days. Which of the following should the technician implement to meet managements request?

    A. Enforce Kerberos
    B. Deploy smart cards
    C. Time of day restrictions
    D. Access control lists

  • Question 426:

    A database administrator receives a call on an outside telephone line from a person who states that they work for a well-known database vendor. The caller states there have been problems applying the newly released vulnerability patch for

    their database system, and asks what version is being used so that they can assist.

    Which of the following is the BEST action for the administrator to take?

    A. Thank the caller, report the contact to the manager, and contact the vendor support line to verify any reported patch issues.
    B. Obtain the vendor's email and phone number and call them back after identifying the number of systems affected by the patch.
    C. Give the caller the database version and patch level so that they can receive help applying the patch.
    D. Call the police to report the contact about the database systems, and then check system logs for attack attempts.

  • Question 427:

    A network administrator noticed various chain messages have been received by the company.

    Which of the following security controls would need to be implemented to mitigate this issue?

    A. Anti-spam
    B. Antivirus
    C. Host-based firewalls
    D. Anti-spyware

  • Question 428:

    A user attempting to log on to a workstation for the first time is prompted for the following information before being granted access: username, password, and a four-digit security pin that was mailed to him during account registration. This is an example of which of the following?

    A. Dual-factor authentication
    B. Multifactor authentication
    C. Single factor authentication
    D. Biometric authentication

  • Question 429:

    A security administrator at a company which implements key escrow and symmetric encryption only, needs to decrypt an employee's file. The employee refuses to provide the decryption key to the file. Which of the following can the administrator do to decrypt the file?

    A. Use the employee's private key
    B. Use the CA private key
    C. Retrieve the encryption key
    D. Use the recovery agent

  • Question 430:

    Which of the following allows lower level domains to access resources in a separate Public Key Infrastructure?

    A. Trust Model
    B. Recovery Agent
    C. Public Key
    D. Private Key

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your JK0-022 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.