SY0-301 Exam Details

  • Exam Code
    :SY0-301
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :820 Q&As
  • Last Updated
    :Dec 12, 2021

CompTIA SY0-301 Online Questions & Answers

  • Question 401:

    Purchasing receives a phone call from a vendor asking for a payment over the phone. The phone number displayed on the caller ID matches the vendor's number. When the purchasing agent asks to call the vendor back, they are given a

    different phone number with a different area code.

    Which of the following attack types is this?

    A. Hoax
    B. Impersonation
    C. Spear phishing
    D. Whaling

  • Question 402:

    Which of the following security concepts would Sara, the security administrator, use to mitigate the risk of data loss?

    A. Record time offset
    B. Clean desk policy
    C. Cloud computing
    D. Routine log review

  • Question 403:

    Mandatory vacations are a security control which can be used to uncover which of the following?

    A. Fraud committed by a system administrator
    B. Poor password security among users
    C. The need for additional security staff
    D. Software vulnerabilities in vendor code

  • Question 404:

    Which of the following application attacks is used to gain access to SEH?

    A. Cookie stealing
    B. Buffer overflow
    C. Directory traversal
    D. XML injection

  • Question 405:

    Matt, a developer, recently attended a workshop on a new application. The developer installs the new application on a production system to test the functionality. Which of the following is MOST likely affected?

    A. Application design
    B. Application security
    C. Initial baseline configuration
    D. Management of interfaces

  • Question 406:

    Ann, a security analyst, has been notified that trade secrets are being leaked from one of the executives in the corporation. When reviewing this executive's laptop she notices several pictures of the employee's pets are on the hard drive and on a cloud storage network. When Ann hashes the images on the hard drive against the hashes on the cloud network they do not match. Which of the following describes how the employee is leaking these secrets?

    A. Social engineering
    B. Steganography
    C. Hashing
    D. Digital signatures

  • Question 407:

    Pete, a security analyst, has been tasked with explaining the different types of malware to his colleagues. The two malware types that the group seems to be most interested in are botnets and viruses. Which of the following explains the difference between these two types of malware?

    A. Viruses are a subset of botnets which are used as part of SYN attacks.
    B. Botnets are a subset of malware which are used as part of DDoS attacks.
    C. Viruses are a class of malware which create hidden openings within an OS.
    D. Botnets are used within DR to ensure network uptime and viruses are not.

  • Question 408:

    Digital Signatures provide which of the following?

    A. Confidentiality
    B. Authorization
    C. Integrity
    D. Authentication
    E. Availability

  • Question 409:

    A network administrator is looking for a way to automatically update company browsers so they import a list of root certificates from an online source. This online source will then be responsible for tracking which certificates are to be trusted or not trusted. Which of the following BEST describes the service that should be implemented to meet these requirements?

    A. Trust model
    B. Key escrow
    C. OCSP
    D. PKI

  • Question 410:

    Pete, the security administrator, has been notified by the IDS that the company website is under attack. Analysis of the web logs show the following string, indicating a user is trying to post a comment on the public bulletin board. INSERT INTO message ` This is an example of which of the following?

    A. XSS attack
    B. XML injection attack
    C. Buffer overflow attack
    D. SQL injection attack

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-301 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.