CompTIA JK0-022 Online Practice
Questions and Exam Preparation
JK0-022 Exam Details
Exam Code
:JK0-022
Exam Name
:CompTIA Security+ Certification
Certification
:CompTIA Security+
Vendor
:CompTIA
Total Questions
:1149 Q&As
Last Updated
:Feb 05, 2025
CompTIA JK0-022 Online Questions &
Answers
Question 941:
Which of the following can a security administrator implement on mobile devices that will help prevent unwanted people from viewing the data if the device is left unattended?
A. Screen lock B. Voice encryption C. GPS tracking D. Device encryption
A. Screen lock Screen-lock is a security feature that requires the user to enter a PIN or a password after a short period of inactivity before they can access the system again. This feature ensures that if your device is left unattended or is lost or stolen, it will be difficult for anyone else to access your data or applications. Incorrect Answers: B: Voice encryption is used to protect audio (voice) transmission. It cannot secure data stored on a mobile device. C: Global Positioning System (GPS) tracking can be used to identify its location of a stolen device and can allow authorities to recover the device. However, for GPS tracking to work, the device must have an Internet connection or a wireless phone service over which to send its location information. D: Device encryption encrypts the data on the device. This feature ensures that the data on the device cannot be accessed in a useable form should the device be stolen. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 418-419 Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 237 https:// www.ukash.com/en-SI/mobile-device-security/
Question 942:
Establishing a method to erase or clear cluster tips is an example of securing which of the following?
A. Data in transit B. Data at rest C. Data in use D. Data in motion
B. Data at rest
Question 943:
After viewing wireless traffic, an attacker notices the following networks are being broadcasted by local access points:
Corpnet Coffeeshop FreePublicWifi
Using this information the attacker spoofs a response to make nearby laptops connect back to a malicious device. Which of the following has the attacker created?
A. Infrastructure as a Service B. Load balancer C. Evil twin D. Virtualized network
C. Evil twin In this question, the attacker has created another wireless network that is impersonating one of more of the three wireless networks listed in the question. This is known as an Evil Twin. An evil twin, in the context of network security, is a rogue or fake wireless access point (WAP) that appears as a genuine hotspot offered by a legitimate provider. In an evil twin attack, an eavesdropper or hacker fraudulently creates this rogue hotspot to collect the personal data of unsuspecting users. Sensitive data can be stolen by spying on a connection or using a phishing technique. For example, a hacker using an evil twin exploit may be positioned near an authentic Wi-Fi access point and discover the service set identifier (SSID) and frequency. The hacker may then send a radio signal using the exact same frequency and SSID. To end users, the rogue evil twin appears as their legitimate hotspot with the same name. In wireless transmissions, evil twins are not a new phenomenon. Historically, they were known as honeypots or base station clones. With the advancement of wireless technology and the use of wireless devices in public areas, it is very easy for novice users to set up evil twin exploits. Incorrect Answers: A: Infrastructure as a Service is a term used to describe cloud based services hosted by cloud service providers. For example, a cloud provider might provide a web service. The cloud provider hosts the service on virtualized computers behind the scenes. As a customer, you just pay for web service without requiring knowledge of the hardware that the service is hosted on. This is not what is described in this question. Therefore, this answer is incorrect. B: A load balancer distributes traffic between servers. For example, you could have two or more web servers hosting your corporate website. The DNS record for the website will point to the virtual IP of the load balancer. The load balancer will then share web requests between the web servers. This is not what is described in this question. Therefore, this answer is incorrect. D: A virtualized network is a network created on physical servers running Hypervisor software such as Microsoft HyperV or VMware VSphere. Virtualized networks are also used by cloud service providers. A cloud service is a service running on virtual servers. This is not what is described in this question. Therefore, this answer is incorrect. References: http://www.techopedia.com/definition/5057/evil-twin
Question 944:
A security administrator has implemented a policy to prevent data loss. Which of the following is the BEST method of enforcement?
A. Internet networks can be accessed via personally-owned computers. B. Data can only be stored on local workstations. C. Wi-Fi networks should use WEP encryption by default. D. Only USB devices supporting encryption are to be used.
D. Only USB devices supporting encryption are to be used. The concern for preventing data loss is the concern for maintaining data confidentiality. This can be accomplished through encryption, access controls, and steganography. USB encryption is usually provided by the vendor of the USB device. It is not included on all USB devices. Incorrect Answers: A: Allowing personally-owned computers to access the intranet or internet would not prevent data loss. Allowing them to access the intranet would increase the risk of data loss while allowing them to access the internet would be of no consequence. B: Storing data on local workstations does not reduce the risk of data loss as the data can still be accessed if it is not encrypted. C: Wired Equivalent Privacy (WEP) is the original wireless encryption standard that has inherent weakness and has been replaced by WiFi Protected Access (WPA). The current version of WPA is WPA2. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 148,
Question 945:
Pete, a security administrator, is informed that people from the HR department should not have access to the accounting department's server, and the accounting department should not have access to the HR department's server. The network is separated by switches. Which of the following is designed to keep the HR department users from accessing the accounting department's server and vice-versa?
A. ACLs B. VLANs C. DMZs D. NATS
B. VLANs A virtual local area network (VLAN) is a hardware-imposed network segmentation created by switches. VLANs are used for traffic management. Communications between ports within the same VLAN occur without hindrance, but communications between VLANs require a routing function. Incorrect Answers: A: Access control lists (ACLs) are used to define who is allowed to or denied permission to perform a specified activity or action. C: A demilitarized zone (DMZ) is an area of a network that is designed specifically for public users to access. The DMZ is a buffer network between the public untrusted Internet and the private trusted LAN. Often a DMZ is deployed through the use of a multihomed firewall. D: NAT converts the IP addresses of internal systems found in the header of network packets into public IP addresses. References: Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp 39, 277.
Question 946:
Which of the following technical controls is BEST used to define which applications a user can install and run on a company issued mobile device?
A. Authentication B. Blacklisting C. Whitelisting D. Acceptable use policy
C. Whitelisting White lists are closely related to ACLs and essentially, a white list is a list of items that are allowed. Incorrect Answers: A: Authentication is always required when applications are installed and uninstalled and to log in to an application. B: Black lists are exactly the opposite of white lists in that it is essentially a list of items that are not allowed. D: Acceptable use policy describe how the employees in an organization can use company systems and resources, both software and hardware. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, pp 24, 221 http://searchsecurity.techtarget.com/definition/application-whitelisting
Question 947:
Which of the following describes the purpose of an MOU?
A. Define interoperability requirements B. Define data backup process C. Define onboard/offboard procedure D. Define responsibilities of each party
D. Define responsibilities of each party MOU or Memorandum of Understanding is a document outlining which party is responsible for what portion of the work. Incorrect Answers: A: The memorandum of understanding is a part of the interoperability agreement between the parties involved. B: Data backup processes are part of data recovery and incidence response and are not the purpose of a memorandum of understanding. C: Onboard and offboard procedures are not part of the MOU, it just refers to the transitioning phase that both parties have to engage in. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, p 398
Question 948:
Which of the following is a security advantage of using NoSQL vs. SQL databases in a three-tier environment?
A. NoSQL databases are not vulnerable to XSRF attacks from the application server. B. NoSQL databases are not vulnerable to SQL injection attacks. C. NoSQL databases encrypt sensitive information by default. D. NoSQL databases perform faster than SQL databases on the same hardware.
B. NoSQL databases are not vulnerable to SQL injection attacks.
Question 949:
Datacenter access is controlled with proximity badges that record all entries and exits from the datacenter. The access records are used to identify which staff members accessed the data center in the event of equipment theft. Which of the following MUST be prevented in order for this policy to be effective?
A. Password reuse B. Phishing C. Social engineering D. Tailgating
D. Tailgating Tailgating is the term used for someone being so close to you when you enter a building that they are able to come in right behind you without needing to use a key, a card, or any other security device. This should be prevented in this case. Incorrect Answers: A: Password reuse will not impact on the effectiveness of proximity badges. B: Phishing is a form of social engineering in which you simply ask someone for a piece of information that you want by making it look like a legitimate request. This is not addressed in this question. C: Social engineering is the process by which intruders gain access to any facility by exploiting the generally trusting nature of people. It is a very broad term and includes attacks such as shoulder surfing, passwords entered on Apple products, dumpster diving, tailgating, impersonation, hoaxes, etc. these are not impacting on the effectiveness of proximity badges. References: Dulaney, Emmett and Chuck Eastton, CompTIA Security+ Study Guide, Sixth Edition, Sybex, Indianapolis, 2014, p 405
Question 950:
An organization must implement controls to protect the confidentiality of its most sensitive data. The company is currently using a central storage system and group based access control for its sensitive information. Which of the following
controls can further secure the data in the central storage system?
A. Data encryption B. Patching the system C. Digital signatures D. File hashing
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only CompTIA exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your JK0-022 exam preparations
and CompTIA certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.