SY0-301 Exam Details

  • Exam Code
    :SY0-301
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :820 Q&As
  • Last Updated
    :Dec 12, 2021

CompTIA SY0-301 Online Questions & Answers

  • Question 201:

    A quality assurance analyst is reviewing a new software product for security, and has complete access to the code and data structures used by the developers. This is an example of which of the following types of testing?

    A. Black box
    B. Penetration
    C. Gray box
    D. White box

  • Question 202:

    Ann would like to forward some Personal Identifiable Information to her HR department by email, but she is worried about the confidentiality of the information. Which of the following will accomplish this task securely?

    A. Digital Signatures
    B. Hashing
    C. Secret Key
    D. Encryption

  • Question 203:

    Which of the following security strategies allows a company to limit damage to internal systems and provides loss control?

    A. Restoration and recovery strategies
    B. Deterrent strategies
    C. Containment strategies
    D. Detection strategies

  • Question 204:

    A CA is compromised and attacks start distributing maliciously signed software updates. Which of the following can be used to warn users about the malicious activity?

    A. Key escrow
    B. Private key verification
    C. Public key verification
    D. Certificate revocation list

  • Question 205:

    Which of the following can be used to maintain a higher level of security in a SAN by allowing isolation of mis-configurations or faults?

    A. VLAN
    B. Protocol security
    C. Port security
    D. VSAN

  • Question 206:

    Each server on a subnet is configured to only allow SSH access from the administrator's workstation. Which of the following BEST describes this implementation?

    A. Host-based firewalls
    B. Network firewalls
    C. Network proxy
    D. Host intrusion prevention

  • Question 207:

    An administrator connects VoIP phones to the same switch as the network PCs and printers. Which of the following would provide the BEST logical separation of these three device types while still allowing traffic between them via ACL?

    A. Create three VLANs on the switch connected to a router
    B. Define three subnets, configure each device to use their own dedicated IP address range, and then connect the network to a router
    C. Install a firewall and connect it to the switch
    D. Install a firewall and connect it to a dedicated switch for each device type

  • Question 208:

    A new intern was assigned to the system engineering department, which consists of the system architect and system software developer's teams. These two teams have separate privileges. The intern requires privileges to view the system architectural drawings and comment on some software development projects. Which of the following methods should the system administrator implement?

    A. Group base privileges
    B. Generic account prohibition
    C. User access review
    D. Credential management

  • Question 209:

    A company hired Joe, an accountant. The IT administrator will need to create a new account for Joe. The company uses groups for ease of management and administration of user accounts. Joe will need network access to all directories, folders and files within the accounting department. Which of the following configurations will meet the requirements?

    A. Create a user account and assign the user account to the accounting group.
    B. Create an account with role-based access control for accounting.
    C. Create a user account with password reset and notify Joe of the account creation.
    D. Create two accounts: a user account and an account with full network administration rights.

  • Question 210:

    A security administrator develops a web page and limits input into their fields on the web page as well as filters special characters in output. The administrator is trying to prevent which of the following attacks?

    A. Spoofing
    B. XSS
    C. Fuzzing
    D. Pharming

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-301 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.