SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 1181:

    The Human Resources department has a parent shared folder setup on the server. There are two groups that have access, one called managers and one called staff. There are many sub folders under the parent shared folder, one is called payroll. The parent folder access control list propagates all subfolders and all subfolders inherit the parent permission. Which of the following is the quickest way to prevent the staff group from gaining access to the payroll folder?

    A. Remove the staff group from the payroll folder
    B. Implicit deny on the payroll folder for the staff group
    C. Implicit deny on the payroll folder for the managers group
    D. Remove inheritance from the payroll folder

  • Question 1182:

    Which of the following is BEST carried out immediately after a security breach is discovered?

    A. Risk transference
    B. Access control revalidation
    C. Change management
    D. Incident management

  • Question 1183:

    The firewall administrator is adding a new certificate for the company's remote access solution. The solution requires that the uploaded file contain the entire certificate chain for the certificate to load properly. The administrator loads the company certificate and the root CA certificate into the file. The file upload is rejected. Which of the following is required to complete the certificate chain?

    A. Certificate revocation list
    B. Intermediate authority
    C. Recovery agent
    D. Root of trust

  • Question 1184:

    The user of a news service accidently accesses another user's browsing history. From this the user can tell what competitors are reading, querying, and researching. The news service has failed to properly implement which of the following?

    A. Application white listing
    B. In-transit protection
    C. Access controls
    D. Full disk encryption

  • Question 1185:

    A new employee has joined the accounting department and is unable to access the accounting server. The employee can access other network resources and the Internet. Other accounting employees are able to access the accounting server without any issues. Which of the following is the MOST likely issue?

    A. The server's IDS is blocking the new employee's connection
    B. The workstation is unable to join the domain
    C. The server's drive is not mapped on the new employee's workstation
    D. The new account is not in the proper role-based profile

  • Question 1186:

    A security engineer is reviewing log data and sees the output below:

    POST: /payload.php HTTP/1.1 HOST: localhost Accept: */* Referrer: http://localhost/ ******* HTTP/1.1 403 Forbidden Connection: close Log: Access denied with 403. Pattern matches form bypass Which of the following technologies was MOST likely being used to generate this log?

    A. Host-based Intrusion Detection System
    B. Web application firewall
    C. Network-based Intrusion Detection System
    D. Stateful Inspection Firewall
    E. URL Content Filter

  • Question 1187:

    Joe, a security technician, is configuring two new firewalls through the web on each. Each time Joe connects, there is a warning message in the browser window about the certificate being untrusted. Which of the following will allow Joe to configure a certificate for the firewall so that firewall administrators are able to connect both firewalls without experiencing the warning message?

    A. Apply a permanent override to the certificate warning in the browser
    B. Apply a wildcard certificate obtained from the company's certificate authority
    C. Apply a self-signed certificate generated by each of the firewalls
    D. Apply a single certificate obtained from a public certificate authority

  • Question 1188:

    An administrator needs to secure RADIUS traffic between two servers. Which of the following is the BEST solution?

    A. Require IPSec with AH between the servers
    B. Require the message-authenticator attribute for each message
    C. Use MSCHAPv2 with MPPE instead of PAP
    D. Require a long and complex shared secret for the servers

  • Question 1189:

    A security manager must remain aware of the security posture of each system. Which of the following supports this requirement?

    A. Training staff on security policies
    B. Establishing baseline reporting
    C. Installing anti-malware software
    D. Disabling unnecessary accounts/services

  • Question 1190:

    The network manager has obtained a public IP address for use with a new system to be available via the internet. This system will be placed in the DMZ and will communicate with a database server on the LAN. Which of the following should be used to allow fir proper communication between internet users and the internal systems?

    A. VLAN
    B. DNS
    C. NAT
    D. HTTP
    E. SSL

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.