SY0-301 Exam Details

  • Exam Code
    :SY0-301
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :820 Q&As
  • Last Updated
    :Dec 12, 2021

CompTIA SY0-301 Online Questions & Answers

  • Question 741:

    A network administrator is responsible for securing applications against external attacks. Every month, the underlying operating system is updated. There is no process in place for other software updates. Which of the following processes could MOST effectively mitigate these risks?

    A. Application hardening
    B. Application change management
    C. Application patch management
    D. Application firewall review

  • Question 742:

    Which of the following is true about an email that was signed by User A and sent to User B?

    A. User A signed with User B's private key and User B verified with their own public key.
    B. User A signed with their own private key and User B verified with User A's public key.
    C. User A signed with User B's public key and User B verified with their own private key.
    D. User A signed with their own public key and User B verified with User A's private key.

  • Question 743:

    Prior to leaving for an extended vacation, Joe uses his mobile phone to take a picture of his family in the house living room. Joe posts the picture on a popular social media site together with the messagE. "Heading to our two weeks vacation to Italy." Upon returning home, Joe discovers that the house was burglarized. Which of the following is the MOST likely reason the house was burglarized if nobody knew Joe's home address?

    A. Joe has enabled the device access control feature on his mobile phone.
    B. Joe's home address can be easily found using the TRACEROUTE command.
    C. The picture uploaded to the social media site was geo-tagged by the mobile phone.
    D. The message posted on the social media site informs everyone the house will be empty.

  • Question 744:

    A company has purchased an application that integrates into their enterprise user directory for account authentication. Users are still prompted to type in their usernames and passwords. Which of the following types of authentication is being utilized here?

    A. Separation of duties
    B. Least privilege
    C. Same sign-on
    D. Single sign-on

  • Question 745:

    The security administrator is observing unusual network behavior from a workstation. The workstation is communicating with a known malicious destination over an encrypted tunnel. A full antivirus scan, with an updated antivirus definition file, does not show any signs of infection. Which of the following has happened on the workstation?

    A. Zero-day attack
    B. Known malware infection
    C. Session hijacking
    D. Cookie stealing

  • Question 746:

    Which of the following will help prevent smurf attacks?

    A. Allowing necessary UDP packets in and out of the network
    B. Disabling directed broadcast on border routers
    C. Disabling unused services on the gateway firewall
    D. Flash the BIOS with the latest firmware

  • Question 747:

    The Chief Risk Officer is concerned about the new employee BYOD device policy and has requested the security department implement mobile security controls to protect corporate data in the event that a device is lost or stolen. The level of protection must not be compromised even if the communication SIM is removed from the device. Which of the following BEST meets the requirements? (Select TWO).

    A. Asset tracking
    B. Screen-locks
    C. Geo-tagging
    D. Patch management
    E. Device encryption

  • Question 748:

    The network administrator has been tasked to rebuild a compromised web server. The administrator is to remove the malware and install all the necessary updates and patches. This represents which of the following stages of the Incident Handling Response?

    A. Lessons Learned
    B. Plan of action
    C. Eradication
    D. Reconstitution

  • Question 749:

    A security administrator notices large amounts of traffic within the network heading out to an external website. The website seems to be a fake bank site with a phone number that when called, asks for sensitive information. After further investigation, the security administrator notices that a fake link was sent to several users. This is an example of which of the following attacks?

    A. Vishing
    B. Phishing
    C. Whaling
    D. SPAM
    E. SPIM

  • Question 750:

    A security analyst performs the following activities: monitors security logs, installs surveillance cameras and analyzes trend reports. Which of the following job responsibilities is the analyst performing? (Select TWO).

    A. Detect security incidents
    B. Reduce attack surface of systems
    C. Implement monitoring controls
    D. Hardening network devices
    E. Prevent unauthorized access

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-301 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.