CompTIA JK0-022 Online Practice
Questions and Exam Preparation
JK0-022 Exam Details
Exam Code
:JK0-022
Exam Name
:CompTIA Security+ Certification
Certification
:CompTIA Security+
Vendor
:CompTIA
Total Questions
:1149 Q&As
Last Updated
:Feb 05, 2025
CompTIA JK0-022 Online Questions &
Answers
Question 471:
A company is looking to reduce the likelihood of employees in the finance department being involved with money laundering. Which of the following controls would BEST mitigate this risk?
A. Implement privacy policies B. Enforce mandatory vacations C. Implement a security policy D. Enforce time of day restrictions
B. Enforce mandatory vacations A mandatory vacation policy requires all users to take time away from work to refresh. And in the same time it also gives the company a chance to make sure that others can fill in any gaps in skills and satisfy the need to have replication or duplication at all levels in addition to affording the company an opportunity to discover fraud for when others do the same job in the absence of the regular staff member then there is transparency. Incorrect Answers: A: Privacy policies are used to define which controls are needed to implement and maintain sanctity/safety of data privacy. C: Security policies are used to define which controls are needed to implement and maintain the security of the company resources such as systems, users and networks. D: Time of day restrictions are used to configure when an account can have access to the system, this does not prevent anyone from laundering money. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 24 -25, 153
Question 472:
Visitors entering a building are required to close the back door before the front door of the same entry room is open. Which of the following is being described?
A. Tailgating B. Fencing C. Screening D. Mantrap
D. Mantrap Mantraps are designed to contain an unauthorized, potentially hostile person/individual physically until authorities arrive. Mantraps are typically manufactured with bulletproof glass, high-strength doors, and locks and to allow the minimal amount of individuals depending on its size. Some mantraps even include scales that will weigh the person. The doors are designed in such a way as to open only when the mantrap is occupied or empty and not in-between. This means that the backdoor must first close before the front door will open; exactly what is required in this scenario. Incorrect Answers: A: Tailgating is the term used for someone being so close to you when you enter a building that they are able to come in right behind you without needing to use a key, a card, or any other security device. B: Fencing is perimeter security to keep unauthorized people off your premises. C: Screening does not necessitate people to close or open doors. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, p 371
Question 473:
Which of the following is the term for a fix for a known software problem?
A. Skiff B. Patch C. Slipstream D. Upgrade
B. Patch Patch management is the process of maintaining the latest source code for applications and operating systems by applying the latest vendor updates. This helps protect a systems from newly discovered attacks and vulnerabilities. Incorrect Answers: A: A skiff is a small boat. C: Slipstreaming is the process of making an installation image of an operating system that includes the latest service packs and required applications. This is used to install new systems rather than fix software problems. D: Upgrades are replacement of the existing software with newer and better versions of the oftware. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 220 Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 231
Question 474:
When using PGP, which of the following should the end user protect from compromise? (Select TWO).
A. Private key B. CRL details C. Public key D. Key password E. Key escrow F. Recovery agent
A. Private key D. Key password A: In PGP only the private key belonging to the receiver can decrypt the session key. PGP combines symmetric-key encryption and public-key encryption. The message is encrypted using a symmetric encryption algorithm, which requires a symmetric key. Each symmetric key is used only once and is also called a session key. D: PGP uses a passphrase to encrypt your private key on your machine. Your private key is encrypted on your disk using a hash of your passphrase as the secret key. You use the passphrase to decrypt and use your private key. Incorrect Answers: B: A certificate revocation list (CRL) is a list of certificates. An end user of PGP does not have to be concerned with the CRL. C: The public key is available for everyone. It does need protection. E: Key escrow is not related to PGP. Key escrow is the process of storing keys or certificates for use by law enforcement. F: The recovery agent does not need to be protected by the end user. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 262, 272-273, 285
Question 475:
Joe, the system administrator, has been asked to calculate the Annual Loss Expectancy (ALE) for a $5,000 server, which often crashes. In the past year, the server has crashed 10 times, requiring a system reboot to recover with only 10% loss of data or function. Which of the following is the ALE of this server?
A. $500 B. $5,000 C. $25,000 D. $50,000
B. $5,000 SLE ARO = ALE, where SLE is equal to asset value (AV) times exposure factor (EF); and ARO is the annualized rate of occurrence. (5000 x 10) x 0.1 = 5000 Incorrect Answers: A: 500 is the sum of a single failure only and the question mentions that the failure occurs 10 times per year. C: 25000 would be the ALE if the server itself costs 10 times more than is stated or the system can be recovered with a 25% loss of data or function. D: 50000 would be the sum if the server cannot be recovered or the failure occurs 100 times per year. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 5-6 http://www.ciscopress.com/articles/article.asp?p=1998559andseqNum=2
Question 476:
A security administrator plans on replacing a critical business application in five years. Recently, there was a security flaw discovered in the application that will cause the IT department to manually re-enable user accounts each month at a cost of $2,000. Patching the application today would cost $140,000 and take two months to implement. Which of the following should the security administrator do in regards to the application?
A. Avoid the risk to the user base allowing them to re-enable their own accounts B. Mitigate the risk by patching the application to increase security and saving money C. Transfer the risk replacing the application now instead of in five years D. Accept the risk and continue to enable the accounts each month saving money
D. Accept the risk and continue to enable the accounts each month saving money This is a risk acceptance measure that has to be implemented since the cost of patching would be too high compared to the cost to keep the system going as is. Risk acceptance is often the choice you must make when the cost of implementing any of the other four choices (i.e. risk deterrence, mitigation, transference or avoidance) exceeds the value of the harm that would occur if the risk came to fruition. Incorrect Answers: A: This is a business critical function and cannot be avoided, least of all by having the user base re-enable their own user accounts. B: Patching the application amounts to risk mitigation methods and would be too costly. C: Replacing the application in five years' time would still cost more than a monthly cost of having the IT department manually re-enable the user accounts each month even over 60 months. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 9-10
Question 477:
Establishing a published chart of roles, responsibilities, and chain of command to be used during a disaster is an example of which of the following?
A. Fault tolerance B. Succession planning C. Business continuity testing D. Recovery point objectives
B. Succession planning Succession planning outlines those internal to the organization that has the ability to step into positions when they open. By identifying key roles that cannot be left unfilled and associating internal employees who can step into these roles, you can groom those employees to make sure that they are up to speed when it comes time for them to fill those positions. Incorrect Answers: A: Fault tolerance refers to the ability of a system to sustain operations in the event of a component failure. C: Business Continuity testing is mainly concerned with the processes, policies, and methods that an organization uses to minimize the impact any type of failure would have and to make sure that the business continues. D: Recovery point objectives define the point at which the system needs to be restored and usually matches the status quo prior to failure. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 33, 454
Question 478:
The security department has implemented a new laptop encryption product in the environment. The product requires one user name and password at the time of boot up and also another password after the operating system has finished loading. This setup is using which of the following authentication types?
A. Two-factor authentication B. Single sign-on C. Multifactor authentication D. Single factor authentication
D. Single factor authentication Single-factor authentication is when only one authentication factor is used. In this case, Something you know is being used as an authentication factor. Username, password, and PIN form part of Something you know. Incorrect Answers: A: Two-factor authentication is when two different authentication factors are provided for authentication purposes. B: Single sign-on means that once a user (or other subject) is authenticated into a realm, re- authentication is not required for access to resources on any realm entity. C: Multifactor authentication requires a user to provide two or more different authentication factors for authentication purposes. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 280, 282, 284.
Question 479:
The main corporate website has a service level agreement that requires availability 100% of the time, even in the case of a disaster. Which of the following would be required to meet this demand?
A. Warm site implementation for the datacenter B. Geographically disparate site redundant datacenter C. Localized clustering of the datacenter D. Cold site implementation for the datacenter
B. Geographically disparate site redundant datacenter Data backups, redundant systems, and disaster recovery plans all support availability. AN in this case a geographically disparate site redundant datacenter represents 100% availability regardless of whether a disaster event occurs. Incorrect Answers: A: A warm site provides some of the capabilities of a hot site, but it requires the customer to do more work to become operational. Warm sites provide computer systems and compatible media capabilities. If a warm site is used, administrators and other staff will need to install and configure systems to resume operations. C: Anytime you connect multiple computers to work/act together as a single server, it is known as clustering. In this case localized clustering does not guarantee 100 % availability in the event of a disaster occurring. D: A cold site is a facility that isn't immediately ready to use. The organization using it must bring along its equipment and network. A cold site may provide network capability, but this isn't usually the case; the site provides a place for operations to resume, but it doesn't provide the infrastructure to support those operations. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 414, 444
Question 480:
A security administrator is auditing a database server to ensure the correct security measures are in place to protect the data. Some of the fields consist of people's first name, last name, home address, date of birth and mothers last name. Which of the following describes this type of data?
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only CompTIA exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your JK0-022 exam preparations
and CompTIA certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.