SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 1141:

    A new mobile application is being developed in-house. Security reviews did not pick up any major flaws, however vulnerability scanning results show fundamental issues at the very end of the project cycle. Which of the following security activities should also have been performed to discover vulnerabilities earlier in the lifecycle?

    A. Architecture review
    B. Risk assessment
    C. Protocol analysis
    D. Code review

  • Question 1142:

    Which of the following describes the process of removing unnecessary accounts and services from an application to reduce risk exposure?

    A. Error and exception handling
    B. Application hardening
    C. Application patch management
    D. Cross-site script prevention

  • Question 1143:

    Pete, the security engineer, would like to prevent wireless attacks on his network. Pete has implemented a security control to limit the connecting MAC addresses to a single port. Which of the following wireless attacks would this address?

    A. Interference
    B. Man-in-the-middle
    C. ARP poisoning
    D. Rogue access point

  • Question 1144:

    A mobile device user is concerned about geographic positioning information being included in messages sent between users on a popular social network platform. The user turns off the functionality in the application, but wants to ensure the application cannot re-enable the setting without the knowledge of the user. Which of the following mobile device capabilities should the user disable to achieve the stated goal?

    A. Device access control
    B. Location based services
    C. Application control
    D. GEO-Tagging

  • Question 1145:

    The security administrator installed a newly generated SSL certificate onto the company web server. Due to a misconfiguration of the website, a downloadable file containing one of the pieces of the key was available to the public. It was verified that the disclosure did not require a reissue of the certificate. Which of the following was MOST likely compromised?

    A. The file containing the recovery agent's keys.
    B. The file containing the public key.
    C. The file containing the private key.
    D. The file containing the server's encrypted passwords.

  • Question 1146:

    A router was shut down as a result of a DoS attack. Upon review of the router logs, it was determined that the attacker was able to connect to the router using a console cable to complete the attack. Which of the following should have been implemented on the router to prevent this attack? (Select two)

    A. IP ACLs should have been enabled on the console port on the router
    B. Console access to the router should have been disabled
    C. Passwords should have been enabled on the virtual terminal interfaces on the router
    D. Virtual terminal access to the router should have been disabled
    E. Physical access to the router should have been restricted

  • Question 1147:

    A network technician is on the phone with the system administration team. Power to the server room was lost and servers need to be restarted. The DNS services must be the first to be restarted. Several machines are powered off. Assuming each server only provides one service, which of the following should be powered on FIRST to establish DNS services?

    A. Bind server
    B. Apache server
    C. Exchange server
    D. RADIUS server

  • Question 1148:

    Which of the following security awareness training is BEST suited for data owners who are concerned with protecting the confidentiality of their data?

    A. Social networking use training
    B. Personally owned device policy training
    C. Tailgating awareness policy training
    D. Information classification training

  • Question 1149:

    Which of the following is BEST utilized to actively test security controls on a particular system?

    A. Port scanning
    B. Penetration test
    C. Vulnerability scanning
    D. Grey/Gray box

  • Question 1150:

    Which of the following is MOST critical in protecting control systems that cannot be regularly patched?

    A. Asset inventory
    B. Full disk encryption
    C. Vulnerability scanning
    D. Network segmentation

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.