SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 1401:

    After connecting to the corporate network a user types the URL if a popular social media website in the browser but reports being redirected to a login page with the corporate logo. Which of the following is this an example of?

    A. LEAP
    B. MAC filtering
    C. WPA2-Enterprise
    D. Captive portal

  • Question 1402:

    Ann, a security administrator at a call center, has been experiencing problems with users intentionally installing unapproved and occasionally malicious software on their computers. Due to the nature of their jobs, Ann cannot change their permissions. Which of the following would BEST alleviate her concerns?

    A. Deploy a HIDS suite on the users' computers to prevent application installation.
    B. Maintain the baseline posture at the highest OS patch level.
    C. Enable the pop-up blockers on the users' browsers to prevent malware.
    D. Create an approved application list and block anything not on it.

  • Question 1403:

    A security analyst implemented group-based privileges within the company active directory. Which of the following account management techniques should be undertaken regularly to ensure least privilege principles?

    A. Leverage role-based access controls.
    B. Perform user group clean-up.
    C. Verify smart card access controls.
    D. Verify SHA-256 for password hashes.

  • Question 1404:

    Joe uses his badge to enter the server room, Ann follows Joe entering without using her badge. It is later discovered that Ann used a USB drive to remove confidential data from a server. Which of the following principles is potentially being violated? (Select TWO)

    A. Clean desk policy
    B. Least privilege
    C. Tailgating
    D. Zero-day exploits
    E. Data handling

  • Question 1405:

    A security technician received notification of a remotely exploitable vulnerability affecting all multifunction printers firmware installed throughout the organization. The vulnerability allows a malicious user to review all the documents processed by the affected printers. Which of the following compensating controls can the security technician to mitigate the security risk of a sensitive document leak?

    A. Create a separate printer network
    B. Perform penetration testing to rule out false positives
    C. Install patches on the print server
    D. Run a full vulnerability scan of all the printers

  • Question 1406:

    Digital signatures are used for ensuring which of the following items? (Select TWO).

    A. Confidentiality
    B. Integrity
    C. Non-Repudiation
    D. Availability
    E. Algorithm strength

  • Question 1407:

    The BEST methods for a web developer to prevent the website application code from being vulnerable to cross-site request forgery (XSRF) are to: (Select TWO).

    A. Permit redirection to Internet-facing web URLs.
    B. Ensure all HTML tags are enclosed in angle brackets, e.g., "".
    C. Validate and filter input on the server side and client side.
    D. Use a web proxy to pass website requests between the user and the application.
    E. Restrict and sanitize use of special characters in input and URLs.

  • Question 1408:

    An organization is working with a cloud services provider to transition critical business applications to a hybrid cloud environment. The organization retains sensitive customer data and wants to ensure the provider has sufficient administrative and logical controls in place to protect its data. In which of the following documents would this concern MOST likely be addressed?

    A. Service level agreement
    B. Interconnection security agreement
    C. Non-disclosure agreement
    D. Business process analysis

  • Question 1409:

    A security analyst, while doing a security scan using packet c capture security tools, noticed large volumes of data images of company products being exfiltrated to foreign IP addresses. Which of the following is the FIRST step in responding to scan results?

    A. Incident identification
    B. Implement mitigation
    C. Chain of custody
    D. Capture system image

  • Question 1410:

    A software company has completed a security assessment. The assessment states that the company should implement fencing and lighting around the property. Additionally, the assessment states that production releases of their software should be digitally signed. Given the recommendations, the company was deficient in which of the following core security areas? (Select TWO).

    A. Fault tolerance
    B. Encryption
    C. Availability
    D. Integrity
    E. Safety
    F. Confidentiality

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.