SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 1541:

    In Kerberos, the Ticket Granting Ticket (TGT) is used for which of the following?

    A. Identification
    B. Authorization
    C. Authentication
    D. Multifactor authentication

  • Question 1542:

    Which of the following controls can be implemented together to prevent data loss in the event of theft of a mobile device storing sensitive information? (Select TWO).

    A. Full device encryption
    B. Screen locks
    C. GPS
    D. Asset tracking
    E. Inventory control

  • Question 1543:

    Multi-tenancy is a concept found in which of the following?

    A. Full disk encryption
    B. Removable media
    C. Cloud computing
    D. Data loss prevention

  • Question 1544:

    The below report indicates that the system is MOST likely infected by which of the following?

    Protocol LOCAL IP FOREIGN IP STATE

    TCP 0.0.0:445 0.0.0.0:0 Listening

    TCP 0.0.0.0:3390 0.0.0.0:0 Listening

    A. Trojan
    B. Worm
    C. Logic bomb
    D. Spyware

  • Question 1545:

    A company has decided to move large data sets to a cloud provider in order to limit the costs of new infrastructure. Some of the data is sensitive and the Chief Information Officer wants to make sure both parties have a clear understanding of the controls needed to protect the data.

    Which of the following types of interoperability agreement is this?

    A. ISA
    B. MOU
    C. SLA
    D. BPA

  • Question 1546:

    A network security analyst has confirmed that the public facing web server has been compromised. Which of the following stages if the Incident Handling Response does this describe?

    A. Analyzing
    B. Recovering
    C. Identification
    D. Mitigation

  • Question 1547:

    When an order was submitted via the corporate website, an administrator noted special characters (e.g., ";--" and "or 1=1 --") were input instead of the expected letters and numbers.

    Which of the following is the MOST likely reason for the unusual results?

    A. The user is attempting to highjack the web server session using an open-source browser.
    B. The user has been compromised by a cross-site scripting attack (XSS) and is part of a botnet performing DDoS attacks.
    C. The user is attempting to fuzz the web server by entering foreign language characters which are incompatible with the website.
    D. The user is sending malicious SQL injection strings in order to extract sensitive company or customer data via the website.

  • Question 1548:

    An organization processes credit card transactions and is concerned that an employee may intentionally email credit card numbers to external email addresses. This company should consider which of the following technologies?

    A. IDS
    B. Firewalls
    C. DLP
    D. IPS

  • Question 1549:

    A security administrator would like to ensure that system administrators are not using the same password for both their privileged and non-privileged accounts. Which of the following security controls BEST accomplishes this goal?

    A. Require different account passwords through a policy
    B. Require shorter password expiration for non-privileged accounts
    C. Require shorter password expiration for privileged accounts
    D. Require a greater password length for privileged accounts

  • Question 1550:

    A Chief Security Officer (CSO) has been unsuccessful in attempts to access the website for a potential partner (www.example.net). Which of the following rules is preventing the CSO from accessing the site?

    Blocked sites: *.nonews.com, *.rumorhasit.net, *.mars?

    A. Rule 1: deny from inside to outside source any destination any service smtp
    B. Rule 2: deny from inside to outside source any destination any service ping
    C. Rule 3: deny from inside to outside source any destination {blocked sites} service http- https
    D. Rule 4: deny from any to any source any destination any service any

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.