CompTIA JK0-022 Online Practice
Questions and Exam Preparation
JK0-022 Exam Details
Exam Code
:JK0-022
Exam Name
:CompTIA Security+ Certification
Certification
:CompTIA Security+
Vendor
:CompTIA
Total Questions
:1149 Q&As
Last Updated
:Feb 05, 2025
CompTIA JK0-022 Online Questions &
Answers
Question 931:
Which of the following is a BEST practice when dealing with user accounts that will only need to be active for a limited time period?
A. When creating the account, set the account to not remember password history. B. When creating the account, set an expiration date on the account. C. When creating the account, set a password expiration date on the account. D. When creating the account, set the account to have time of day restrictions.
B. When creating the account, set an expiration date on the account. Disablement is a secure feature to employ on user accounts for temporary workers, interns, or consultants. It automatically disables a user account or causes the account to expire at a specific time and on a specific day. Incorrect Answers: A: Disabling password history will allow password reuse. The account will remain active. C: Password expiration compels users to change passwords after a specified period. The account will remain active. D: Time of day restrictions limit when users can access specific systems based on the time of day or week. The account will remain active. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 280, 292, 293.
Question 932:
Which of the following fire suppression systems is MOST likely used in a datacenter?
A. FM-200 B. Dry-pipe C. Wet-pipe D. Vacuum
A. FM-200 FM200 is a gas and the principle of a gas system is that it displaces the oxygen in the room, thereby removing this essential component of a fi re. in a data center is is the preferred choice of fire suppressant. Incorrect Answers: B: Dry-pipe fire suppression is not the optimal fire suppressant to be used. C: Wet-pipe fire suppression will douse a fire, but will also case extensive damage to electrical equipment. D: A vacuum suppression will also result in more damage to components in the area of the vacuum, whereas a gas system will just starve the fire of oxygen which is more preferable in a data center to use as a fire suppressant. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, p 380
Question 933:
Pete, a developer, writes an application. Jane, the security analyst, knows some things about the overall application but does not have all the details. Jane needs to review the software before it is released to production. Which of the following reviews should Jane conduct?
A. Gray Box Testing B. Black Box Testing C. Business Impact Analysis D. White Box Testing
A. Gray Box Testing Gray box testing, also called gray box analysis, is a strategy for software debugging in which the tester has limited knowledge of the internal details of the program. A gray box is a device, program or system whose workings are partially understood. Gray box testing can be contrasted with black box testing, a scenario in which the tester has no knowledge or access to the internal workings of a program, or white box testing, a scenario in which the internal particulars are fully known. Gray box testing is commonly used in penetration tests. Gray box testing is considered to be non-intrusive and unbiased because it does not require that the tester have access to the source code. With respect to internal processes, gray box testing treats a program as a black box that must be analyzed from the outside. During a gray box test, the person may know how the system components interact but not have detailed knowledge about internal program functions and operation. A clear distinction exists between the developer and the tester, thereby minimizing the risk of personnel conflicts. Incorrect Answers: B: Black-box testing is a method of software testing that examines the functionality of an application without peering into its internal structures or workings. This method of test can be applied to virtually every level of software testing: unit, integration, system and acceptance. It typically comprises most if not all higher level testing, but can also dominate unit testing as well. Specific knowledge of the application's code/internal structure and programming knowledge in general is not required. The tester is aware of what the software is supposed to do but is not aware of how it does it. For instance, the tester is aware that a particular input returns a certain, invariable output but is not aware of how the software produces the output in the first place. In this question, the tester has some knowledge of the application. Therefore, this answer is incorrect. C: A Business Impact Analysis is the analysis of the impact an event will have on the business. As an example in terms of IT, a Business Impact Analysis could describe the effect of a server failure. A Business Impact Analysis is not used to describe the testing of an application. Therefore, this answer is incorrect. D: White-box testing (also known as clear box testing, glass box testing, transparent box testing, and structural testing) is a method of testing software that tests internal structures or workings of an application, as opposed to its functionality (i.e. black-box testing). In white-box testing an internal perspective of the system, as well as programming skills, are used to design test cases. The tester chooses inputs to exercise paths through the code and determine the appropriate outputs. This is analogous to testing nodes in a circuit, e.g. in-circuit testing (ICT). White-box testing can be applied at the unit, integration and system levels of the software testing process. Although traditional testers tended to think of white-box testing as being done at the unit level, it is used for integration and system testing more frequently today. It can test paths within a unit, paths between units during integration, and between subsystems during a systemlevel test. In this question, the tester has some knowledge of the application but not the detailed knowledge required for a white-box test. Therefore, this answer is incorrect. References: http://searchsoftwarequality.techtarget.com/definition/gray-box http://en.wikipedia.org/wiki/Black-box_testing http://en.wikipedia.org/wiki/White-box_testing
Question 934:
Which of the following devices would be the MOST efficient way to filter external websites for staff on an internal network?
A. Protocol analyzer B. Switch C. Proxy D. Router
C. Proxy
Question 935:
A Human Resources user is issued a virtual desktop typically assigned to Accounting employees. A system administrator wants to disable certain services and remove the local accounting groups installed by default on this virtual machine. The system administrator is adhering to which of the following security best practices?
A. Black listing applications B. Operating System hardening C. Mandatory Access Control D. Patch Management
B. Operating System hardening
Question 936:
Which of the following assets is MOST likely considered for DLP?
A. Application server content B. USB mass storage devices C. Reverse proxy D. Print server
B. USB mass storage devices Data loss prevention (DLP) systems monitor the contents of systems (workstations, servers, and networks) to make sure that key content is not deleted or removed. They also monitor who is using the data (looking for unauthorized access) and transmitting the data. A USB presents the most likely device to be used to steal data because of its physical size. Incorrect Answers: A: Application server content would be hosting the software required by users to completet their tasks. Not likely to be DLP monitored. C: Reverse proxy firewalls can be set to perform proxy servers, and this can thus also be reversed this is not likely to be DLP monitored. D: A print server will most likely be used to make a printout of the data and this poses a paper trail and a physical, big piece or several pages of paper that must be used to steal data. Too obvious to be monitored using DLP. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, p 237
Question 937:
An administrator wants to establish a WiFi network using a high gain directional antenna with a narrow radiation pattern to connect two buildings separated by a very long distance. Which of the following antennas would be BEST for this situation?
A. Dipole B. Yagi C. Sector D. Omni
B. Yagi A Yagi-Uda antenna, commonly known simply as a Yagi antenna, is a directional antenna consisting of multiple parallel dipole elements in a line, usually made of metal rods. It consists of a single driven element connected to the transmitter or receiver with a transmission line, and additional parasitic elements: a so-called reflector and one or more directors. The reflector element is slightly longer than the driven dipole, whereas the directors are a little shorter. This design achieves a very substantial increase in the antenna's directionality and gain compared to a simple dipole. Incorrect Answers: A: The 15 cm long vertical element you see on most Wi-Fi equipment is actually a dipole antenna. It consists of two elements and is popular because of its omnidirectional radiation pattern. C: A sector antenna is a type of directional microwave antenna with a sector-shaped radiation pattern. The word "sector" is used in the geometric sense; some portion of the circumference of a circle measured in degrees of arc. 60? 90?and 120?designs are typical, often with a few degrees 'extra' to ensure overlap and mounted in multiples when wider or full-circle coverage is required. D: An omnidirectional antenna is designed to provide a 360-degree pattern and an even signal in all directions References: http://en.wikipedia.org/wiki/Yagi-Uda_antenna http://www.techrepublic.com/blog/data-center/80211-time-to-clear-up-some-antenna- misconceptions/ http://en.wikipedia.org/wiki/Sector_antenna#See_also Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, p 178.
Question 938:
Which of the following techniques can be used to prevent the disclosure of system information resulting from arbitrary inputs when implemented properly?
A. Fuzzing B. Patch management C. Error handling D. Strong passwords
C. Error handling Exception handling is an aspect of secure coding. When errors occur, the system should revert back to a secure state. This must be coded into the system by the programmer, and should capture errors and exceptions so that they could be handled by the application. Incorrect Answers: A: Fuzzing is a software testing technique that involves providing invalid, unexpected, or random data to as inputs to a computer program. The program is then monitored for exceptions such as crashes, or failed validation, or memory leaks. B: Patch management is the process of maintaining the latest source code for applications and operating systems. This helps protect a systems from known attacks and vulnerabilities. D: Passwords are used to control access to systems as part of a user authentication process. Strong passwords make it harder for attackers to guess or crack the passwords. References: http://en.wikipedia.org/wiki/Fuzz_testing Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, p 218, 220 Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 229, 230, 231-232
Question 939:
Which of the following is best practice to put at the end of an ACL?
A. Implicit deny B. Time of day restrictions C. Implicit allow D. SNMP string
A. Implicit deny An implicit deny clause is implied at the end of each ACL. This implies that if you aren't specifically granted access or privileges for a resource, you're denied access by default. The implicit deny clause is set by the system. Incorrect Answers: B: Time of day restrictions limit when users can access specific systems based on the time of day or week. They do not appear at the end of an ACL. C: Implicit allow does not appear at the end of an ACL. D: An SNMP string is similar to a user id or password that permits access to a router's or other device's statistics. They do not appear at the end of an ACL. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 26, 280. http://en.wikipedia.org/wiki/Simple_Network_Management_Protocol
Question 940:
Which of the following protocols uses TCP instead of UDP and is incompatible with all previous versions?
A. TACACS B. XTACACS C. RADIUS D. TACACS+
D. TACACS+ TACACS+ is not compatible with TACACS and XTACACS, and makes use of TCP. Incorrect Answers: A, B: TACACS and XTACACS make use of TCP and UDP. C: RADIUS makes use of UDP. References: http://en.wikipedia.org/wiki/TACACS
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only CompTIA exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your JK0-022 exam preparations
and CompTIA certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.