SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 1411:

    A security administrator wants to block unauthorized access to a web server using a locally installed software program. Which of the following should the administrator deploy?

    A. NIDS
    B. HIPS
    C. NIPS
    D. HIDS

  • Question 1412:

    Ann, a technician, is attempting to establish a remote terminal session to an end user's computer using Kerberos authentication, but she cannot connect to the destination machine. Which of the following default ports should Ann ensure is open?

    A. 22
    B. 139
    C. 443
    D. 3389

  • Question 1413:

    A software security concern when dealing with hardware and devices that have embedded software or operating systems is:

    A. Patching may not always be possible
    B. Configuration support may not be available
    C. These is no way to verify if a patch is authorized or not
    D. The vendor may not have a method for installation of patches

  • Question 1414:

    An organization recently switched from a cloud-based email solution to an in-house email server. The firewall needs to be modified to allow for sending and receiving email. Which of the following ports should be open on the firewall to allow for email traffic? (Select THREE).

    A. TCP 22
    B. TCP 23
    C. TCP 25
    D. TCP 53
    E. TCP 110
    F. TCP 143
    G. TCP 445

  • Question 1415:

    A company administrator has a firewall with an outside interface connected to the Internet and an inside interface connected to the corporate network. Which of the following should the administrator configure to redirect traffic destined for the default HTTP port on the outside interface to an internal server listening on port 8080?

    A. Create a dynamic PAT from port 80 on the outside interface to the internal interface on port 8080
    B. Create a dynamic NAT from port 8080 on the outside interface to the server IP address on port 80
    C. Create a static PAT from port 80 on the outside interface to the internal interface on port
    D. Create a static PAT from port 8080 on the outside interface to the server IP address on port 80

  • Question 1416:

    Which of the following protocols uses TCP instead of UDP and is incompatible with all previous versions?

    A. TACACS
    B. XTACACS
    C. RADIUS
    D. TACACS+

  • Question 1417:

    An attacker is attempting to insert malicious code into an installer file that is available on the internet. The attacker is able to gain control of the web server that houses both the installer and the web page which features information about the downloadable file. To implement the attack and delay detection, the attacker should modify both the installer file and the:

    A. SSL certificate on the web server
    B. The HMAC of the downloadable file available on the website
    C. Digital signature on the downloadable file
    D. MD5 hash of the file listed on the website

  • Question 1418:

    A technician reports a suspicious individual is seen walking around the corporate campus. The individual is holding a smartphone and pointing a small antenna, in order to collect SSIDs. Which of the following attacks is occurring?

    A. Rogue AP
    B. Evil Twin
    C. Man-in-the-middle
    D. War driving

  • Question 1419:

    Which of the following access methods uses radio frequency waves for authentication?

    A. Video surveillance
    B. Mantraps
    C. Proximity readers D. Biometrics

  • Question 1420:

    Pete's corporation has outsourced help desk services to a large provider. Management has published a procedure that requires all users, when receiving support, to call a special number.

    Users then need to enter the code provided to them by the help desk technician prior to allowing the technician to work on their PC. Which of the following does this procedure prevent?

    A. Collusion
    B. Impersonation
    C. Pharming
    D. Transitive Access

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.