SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 1441:

    In performing an authorized penetration test of an organization's system security, a penetration tester collects information pertaining to the application versions that reside on a server. Which of the following is the best way to collect this type of information?

    A. Protocol analyzer
    B. Banner grabbing
    C. Port scanning
    D. Code review

  • Question 1442:

    Which of the following tests a number of security controls in the least invasive manner?

    A. Vulnerability scan
    B. Threat assessment
    C. Penetration test
    D. Ping sweep

  • Question 1443:

    Which of the following are MOST susceptible to birthday attacks?

    A. Hashed passwords
    B. Digital certificates
    C. Encryption passwords
    D. One time passwords

  • Question 1444:

    Ann, the network administrator, is receiving reports regarding a particular wireless network in the building. The network was implemented for specific machines issued to the developer department, but the developers are stating that they are having connection issues as well as slow bandwidth. Reviewing the wireless router's logs, she sees that devices not belonging to the developers are connecting to the access point. Which of the following would BEST alleviate the developer's reports?

    A. Configure the router so that wireless access is based upon the connecting device's hardware address.
    B. Modify the connection's encryption method so that it is using WEP instead of WPA2.
    C. Implement connections via secure tunnel with additional software on the developer's computers.
    D. Configure the router so that its name is not visible to devices scanning for wireless networks.

  • Question 1445:

    A security manager is preparing the training portion of an incident plan. Which of the following job roles should receive training on forensics, chain of custody, and the order of volatility?

    A. System owners
    B. Data custodians
    C. First responders
    D. Security guards

  • Question 1446:

    Privilege creep among long-term employees can be mitigated by which of the following procedures?

    A. User permission reviews
    B. Mandatory vacations
    C. Separation of duties
    D. Job function rotation

  • Question 1447:

    A system administrator runs a network inventory scan every Friday at 10:00 am to track the progress of a large organization's operating system upgrade of all laptops. The system administrator discovers that some laptops are now only being reported as IP addresses. Which of the following options is MOST likely the cause of this issue?

    A. HIDS
    B. Host-based firewalls rules
    C. All the laptops are currently turned off
    D. DNS outage

  • Question 1448:

    A new mobile banking application is being developed and uses SSL / TLS certificates but penetration tests show that it is still vulnerable to man-in-the-middle attacks, such as DNS hijacking. Which of the following would mitigate this attack?

    A. Certificate revocation
    B. Key escrow
    C. Public key infrastructure
    D. Certificate pinning

  • Question 1449:

    An employee reports work was being completed on a company owned laptop using a public wireless hot-spot. A pop-up screen appeared and the user closed the pop-up. Seconds later the desktop background was changed to the image of a padlock with a message demanding immediate payment to recover the data. Which of the following types of malware MOST likely caused this issue?

    A. Ransomware
    B. Rootkit
    C. Scareware
    D. Spyware

  • Question 1450:

    A company is starting to allow employees to use their own personal without centralized management. Employees must contract IT to have their devices configured to use corporate email; access is also available to the corporate cloud-based services. Which of the following is the BEST policy to implement under these circumstances?

    A. Acceptable use policy
    B. Security policy
    C. Group policy
    D. Business Agreement policy

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.