CompTIA JK0-022 Online Practice
Questions and Exam Preparation
JK0-022 Exam Details
Exam Code
:JK0-022
Exam Name
:CompTIA Security+ Certification
Certification
:CompTIA Security+
Vendor
:CompTIA
Total Questions
:1149 Q&As
Last Updated
:Feb 05, 2025
CompTIA JK0-022 Online Questions &
Answers
Question 461:
Matt, a forensic analyst, wants to obtain the digital fingerprint for a given message. The message is 160-bits long. Which of the following hashing methods would Matt have to use to obtain this digital fingerprint?
A. SHA1 B. MD2 C. MD4 D. MD5
A. SHA1 The Secure Hash Algorithm (SHA) was designed to ensure the integrity of a message. SHA is a one-way hash that provides a hash value that can be used with an encryption protocol. This algorithm produces a 160-bit hash value. SHA (1 or 2) is preferred over Message Digest Algorithm. Incorrect Answers: B: The Message Digest Algorithm (MD) also creates a hash value and uses a one-way hash. It produces a 128-bit hash. C: MD4 is another version of the Message Digest Algorithm and produces a 128-bit hash. D: MD5 is another version of the Message Digest Algorithm and produces a 128-bit hash. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 255-356
Question 462:
Which of the following should Joe, a security manager, implement to reduce the risk of employees working in collusion to embezzle funds from his company?
A. Privacy Policy B. Least Privilege C. Acceptable Use D. Mandatory Vacations
D. Mandatory Vacations When one person fills in for another, such as for mandatory vacations, it provides an opportunity to see what the person is doing and potentially uncover any fraud. Incorrect Answers: A: Privacy policies define what controls are required to implement and maintain the sanctity of data privacy in the work environment. Privacy policy is a legal document that outlines how data collected is secured. It should encompass information regarding the information the company collects, privacy choices you have based on your account, potential information sharing of your data with other parties, security measures in place, and enforcement. B: A least privilege policy should be used when assigning permissions. Give users only the permissions that they need to do their work and no more. C: Acceptable use policies (AUPs) describe how the employees in an organization can use company systems and resources, both software and hardware. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, p 25
Question 463:
A network inventory discovery application requires non-privileged access to all hosts on a network for inventory of installed applications. A service account is created by the network inventory discovery application for accessing all hosts. Which of the following is the MOST efficient method for granting the account non- privileged access to the hosts?
A. Implement Group Policy to add the account to the users group on the hosts B. Add the account to the Domain Administrator group C. Add the account to the Users group on the hosts D. Implement Group Policy to add the account to the Power Users group on the hosts.
A. Implement Group Policy to add the account to the users group on the hosts Group Policy is an infrastructure that allows you to implement specific configurations for users and computers. Group Policy settings are contained in Group Policy objects (GPOs), which are linked to the following Active Directory directory service containers: sites, domains, or organizational units (OUs). This means that if the GPO is linked to the domain, all Users groups in the domain will include the service account. Incorrect Answers: B: Adding the account to the Domain Administrator group will give the account full control of the domain. The account should have non-privileged access. C: This is a valid course of action, but would require accessing the Users group on each individual host. The question asks for the most efficient method. Group policy is more efficient that this option. D: In previous versions of Windows, the Power Users group gave users specific administrator rights and permissions to perform common system tasks.The account should have non-privileged access. References: https://technet.microsoft.com/en-us/windowsserver/bb310732.aspx https://technet.microsoft.com/en-us/library/cc756898(v=ws.10).aspx https:// technet.microsoft.com/en-us/library/cc771990.aspx
Question 464:
When creating a public / private key pair, for which of the following ciphers would a user need to specify the key strength?
A. SHA B. AES C. DES D. RSA
D. RSA RSA (an asymmetric algorithm) uses keys of a minimum length of 2048 bits. Incorrect Answers: A: The Secure Hash Algorithm (SHA) was designed to ensure the integrity of a message. SHA is a one-way hash that provides a hash value that can be used with an encryption protocol. This algorithm produces a 160-bit hash value. B: Advanced Encryption Standard (AES) has replaced DES as the current standard, and it uses the Rijndael algorithm. It was developed by Joan Daemen and Vincent Rijmen. AES is the current product used by U.S. governmental agencies. It supports key sizes of 128, 192, and 256 bits, with 128 bits being the default. C: The Data Encryption Standard (DES) has been used since the mid-1970s. It was the primary standard used in government and industry until it was replaced by AES. It's based on a 56-bit key and has several modes that offer security and integrity. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 250, 251, 255-256
Question 465:
Which of the following would Pete, a security administrator, MOST likely implement in order to allow employees to have secure remote access to certain internal network services such as file servers?
A. Packet filtering firewall B. VPN gateway C. Switch D. Router
B. VPN gateway VPNs are usually employed to allow remote access users to connect to and access the network, and offer connectivity between two or more private networks or LANs. A VPN gateway (VPN router) is a connection point that connects two LANs via a nonsecure network such as the Internet. Incorrect Answers: A: A packet filter firewall filters traffic based on basic identification items found in a network packet's header. These items include source and destination address, port numbers, and protocols used. C: Switches are often used to create virtual LANs (VLANs), which are used to logically segment a network without altering its physical topology. D: Routers allow traffic from one network segment to cross into another network segment. References: http://www.tech-faq.com/the-vpn-gateway.html Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 6, 21, 39.
Question 466:
A system administrator has been instructed by the head of security to protect their data at-rest. Which of the following would provide the strongest protection?
A. Prohibiting removable media B. Incorporating a full-disk encryption system C. Biometric controls on data center entry points D. A host-based intrusion detection system
B. Incorporating a full-disk encryption system Full disk encryption can be used to encrypt an entire volume with 128-bit encryption. When the entire volume is encrypted, the data is not accessible to someone who might boot another operating system in an attempt to bypass the computer's security. Full disk encryption is sometimes referred to as hard drive encryption. This would be best to protect data that is at rest. Incorrect Answers: A: Prohibiting removable media is not working with data at rest. C: Biometrics are used mainly as a physical security control and to control access to resources. Data at rest is best protected with a full-disk encryption system. D: Intrusion detection systems are used as a physical security measure and not a data protection measure. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, p 290
Question 467:
Which of the following are Data Loss Prevention (DLP) strategies that address data in transit issues? (Select TWO).
A. Scanning printing of documents. B. Scanning of outbound IM (Instance Messaging). C. Scanning copying of documents to USB. D. Scanning of SharePoint document library. E. Scanning of shared drives. F. Scanning of HTTP user traffic.
B. Scanning of outbound IM (Instance Messaging). F. Scanning of HTTP user traffic. DLP systems monitor the contents of systems (workstations, servers, networks) to make sure key content is not deleted or removed. They also monitor who is using the data (looking for unauthorized access) and transmitting the data. Outbound IM and HTTP user traffic refers to data over a network which falls within the DLP strategy. Incorrect Answers: A: Printing of documents will not necessarily result in data loss since it is a hard copy of the soft copy that is already there. C: Copying documents to USB amounts to duplicating data. D: A SharePoint document Library is a list of the documents and not the data itself. This is not a data in transit issue E: Shared drive scanning is not data in transit. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 236-237, 364
Question 468:
Which of the following application security principles involves inputting random data into a program?
A. Brute force attack B. Sniffing C. Fuzzing D. Buffer overflow
C. Fuzzing Fuzzing is a software testing technique that involves providing invalid, unexpected, or random data to as inputs to a computer program. The program is then monitored for exceptions such as crashes, or failed validation, or memory leaks. Incorrect Answers: A: A Brute force attack consists of systematically checking all possible keys or passwords until a match is found. B: A sniffer is a passive network monitoring tool that provides information of network traffic in real-time. They are used for troubleshooting purposes, but can also be used by attackers to determine what protocols and systems are running on a network. D: Buffer overflow is an exploit at programming error, bugs and flaws. It occurs when an application receives more data than it is programmed to handle. This may cause the application to terminate or to write data beyond the end of the allocated space in memory. The termination of the application may cause the system to send the data with temporary access to privileged levels in the system, while overwriting can cause important data to be lost. References: http://en.wikipedia.org/wiki/Fuzz_testing http://en.wikipedia.org/wiki/Brute-force_attack Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 66, 218, 257, 338 Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 18, 197, 229,
Question 469:
A network consists of various remote sites that connect back to two main locations. Pete, the security administrator, needs to block TELNET access into the network. Which of the following, by default, would be the BEST choice to accomplish this goal?
A. Block port 23 on the L2 switch at each remote site B. Block port 23 on the network firewall C. Block port 25 on the L2 switch at each remote site D. Block port 25 on the network firewall
B. Block port 23 on the network firewall Telnet is a terminal-emulation network application that supports remote connectivity for executing commands and running applications but doesn't support transfer of fi les. Telnet uses TCP port 23. Because it's a clear text protocol and service, it should be avoided and replaced with SSH. Incorrect Answers: A, C: L2 switches may interconnect a small number of devices in a home or the office. They are normally used for LANs. D: Port 25 is used by Simple Mail Transfer Protocol (SMTP) for e-mail routing between mail servers. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, p 51. http://en.wikipedia.org/wiki/Network_switch#Layer_2 http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers
Question 470:
Which of the following is where an unauthorized device is found allowing access to a network?
A. Bluesnarfing B. Rogue access point C. Honeypot D. IV attack
B. Rogue access point A rogue access point is a wireless access point that has either been installed on a secure company network without explicit authorization from a local network administrator, or has been created to allow a hacker to conduct a man-in-themiddle attack. Rogue access points of the first kind can pose a security threat to large organizations with many employees, because anyone with access to the premises can install (maliciously or non-maliciously) an inexpensive wireless router that can potentially allow access to a secure network to unauthorized parties. Rogue access points of the second kind target networks that do not employ mutual authentication (client-server server- client) and may be used in conjunction with a rogue RADIUS server, depending on security configuration of the target network. To prevent the installation of rogue access points, organizations can install wireless intrusion prevention systems to monitor the radio spectrum for unauthorized access points. Incorrect Answers: A: Bluesnarfing is the theft of information from a wireless device through a Bluetooth connection. Bluetooth is a high-speed but very short-range wireless technology for exchanging data between desktop and mobile computers, personal digital assistants (PDAs), and other devices. By exploiting a vulnerability in the way Bluetooth is implemented on a mobile phone, an attacker can access information -- such as the user's calendar, contact list and e-mail and text messages -- without leaving any evidence of the attack. Other devices that use Bluetooth, such as laptop computers, may also be vulnerable, although to a lesser extent, by virtue of their more complex systems. Operating in invisible mode protects some devices, but others are vulnerable as long as Bluetooth is enabled. This is not what is described in this question. Therefore, this answer is incorrect. C: A honeypot is a system whose purpose it is to be attacked. An administrator can watch and study the attack to research current attack methodologies. A Honeypot luring a hacker into a system has several main purposes: The administrator can watch the hacker exploit the vulnerabilities of the system, thereby learning where the system has weaknesses that need to be redesigned. The hacker can be caught and stopped while trying to obtain root access to the system. By studying the activities of hackers, designers can better create more secure systems that are potentially invulnerable to future hackers. This is not what is described in this question. Therefore, this answer is incorrect. D: An initialization vector is a random number used in combination with a secret key as a means to encrypt data. This number is sometimes referred to as a nonce, or "number occurring once," as an encryption program uses it only once per session. An initialization vector is used to avoid repetition during the data encryption process, making it impossible for hackers who use dictionary attack to decrypt the exchanged encrypted message by discovering a pattern. This is known as an IV attack. A particular binary sequence may be repeated more than once in a message, and the more it appears, the more the encryption method is discoverable. For example if a one-letter word exists in a message, it may be either "a" or "I" but it can't be "e" because the word "e" is non-sensical in English, while "a" has a meaning and "I" has a meaning. Repeating the words and letters makes it possible for software to apply a dictionary and discover the binary sequence corresponding to each letter. Using an initialization vector changes the binary sequence corresponding to each letter, enabling the letter "a" to be represented by a particular sequence in the first instance, and then represented by a completely different binary sequence in the second instance. This is not what is described in this question. Therefore, this answer is incorrect. References: http://en.wikipedia.org/wiki/Rogue_access_point http://searchmobilecomputing.techtarget.com/definition/bluesnarfing http://www.techopedia.com/definition/26858/initialization-vector
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only CompTIA exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your JK0-022 exam preparations
and CompTIA certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.