SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 1561:

    Human Resources (HR) would like executives to undergo only two specific security training programs a year. Which of the following provides the BEST level of security training for the executives? (Select TWO).

    A. Acceptable use of social media
    B. Data handling and disposal
    C. Zero day exploits and viruses
    D. Phishing threats and attacks
    E. Clean desk and BYOD
    F. Information security awareness

  • Question 1562:

    A network technician is trying to determine the source of an ongoing network based attack. Which of the following should the technician use to view IPv4 packet data on a particular internal network segment?

    A. Proxy
    B. Protocol analyzer
    C. Switch
    D. Firewall

  • Question 1563:

    A team of firewall administrators have access to a `master password list' containing service account passwords. Which of the following BEST protects the master password list?

    A. File encryption
    B. Password hashing
    C. USB encryption
    D. Full disk encryption

  • Question 1564:

    During a recent investigation, an auditor discovered that an engineer's compromised workstation was being used to connect to SCADA systems while the engineer was not logged in. The engineer is responsible for administering the SCADA systems and cannot be blocked from connecting to them. The SCADA systems cannot be modified without vendor approval which requires months of testing.

    Which of the following is MOST likely to protect the SCADA systems from misuse?

    A. Update anti-virus definitions on SCADA systems
    B. Audit accounts on the SCADA systems
    C. Install a firewall on the SCADA network
    D. Deploy NIPS at the edge of the SCADA network

  • Question 1565:

    Which of the following is considered the MOST effective practice when securing printers or scanners in an enterprise environment?

    A. Routine vulnerability scanning of peripherals
    B. Install in a hardened network segment
    C. Turn off the power to the peripherals at night
    D. Enable print sharing only from workstations

  • Question 1566:

    A company recently experienced several security breaches that resulted in confidential data being infiltrated form the network. The forensic investigation revealed that the data breaches were caused by an insider accessing files that resided in shared folders who then encrypted the data and sent it to contacts via third party email. Management is concerned that other employees may also be sending confidential files outside of the company to the same organization. Management has requested that the IT department implement a solution that will allow them to:

    Track access and sue of files marked confidential, provide documentation that can be sued for investigations, prevent employees from sending confidential data via secure third party email, identify other employees that may be involved in these activities.

    Which of the following would be the best choice to implement to meet the above requirements?

    A. Web content filtering capable of inspe4cting and logging SSL traffic used by third party webmail providers
    B. Full disk encryption on all computers with centralized event logging and monitoring enabled
    C. Host based firewalls with real time monitoring and logging enabled
    D. Agent-based DLP software with correlations and logging enabled

  • Question 1567:

    RADIUS provides which of the following?

    A. Authentication, Authorization, Availability
    B. Authentication, Authorization, Auditing
    C. Authentication, Accounting, Auditing
    D. Authentication, Authorization, Accounting

  • Question 1568:

    During an application design, the development team specifics a LDAP module for single sign-on communication with the company's access control database. This is an example of which of the following?

    A. Application control
    B. Data in-transit
    C. Identification
    D. Authentication

  • Question 1569:

    One of the most consistently reported software security vulnerabilities that leads to major exploits is:

    A. Lack of malware detection.
    B. Attack surface decrease.
    C. Inadequate network hardening.
    D. Poor input validation.

  • Question 1570:

    Jane, a security analyst, is reviewing logs from hosts across the Internet which her company uses to gather data on new malware. Which of the following is being implemented by Jane's company?

    A. Vulnerability scanner
    B. Honeynet
    C. Protocol analyzer
    D. Port scanner

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.