SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 1591:

    A systems administrator is configuring a new file server and has been instructed to configure writeable to by the department manager, and read only for the individual employee. Which of the following is the name for the access control methodology used?

    A. Duty separation
    B. Mandatory
    C. Least privilege
    D. Role-based

  • Question 1592:

    A security administrator is reviewing the below output from a password auditing tool: P@ss.

    @pW1.

    S3cU4

    Which of the following additional policies should be implemented based on the tool's output?

    A. Password age
    B. Password history
    C. Password length
    D. Password complexity

  • Question 1593:

    Input validation is an important security defense because it:

    A. rejects bad or malformed data.
    B. enables verbose error reporting.
    C. protects mis-configured web servers.
    D. prevents denial of service attacks.

  • Question 1594:

    An organization has three divisions: Accounting, Sales, and Human Resources. Users in the Accounting division require access to a server in the Sales division, but no users in the Human Resources division should have access to resources in any other division, nor should any users in the Sales division have access to resources in the Accounting division. Which of the following network segmentation schemas would BEST meet this objective?

    A. Create two VLANS, one for Accounting and Sales, and one for Human Resources.
    B. Create one VLAN for the entire organization.
    C. Create two VLANs, one for Sales and Human Resources, and one for Accounting.
    D. Create three separate VLANS, one for each division.

  • Question 1595:

    Which of the following BEST describes using a smart card and typing in a PIN to gain access to a system?

    A. Biometrics
    B. PKI
    C. Single factor authentication
    D. Multifactor authentication

  • Question 1596:

    An outside security consultant produces a report of several vulnerabilities for a particular server. Upon further investigation, it is determine that the vulnerability reported does not apply to the platform the server is running on. Which of the following should the consultant do in order to produce more accurate results?

    A. A black box test should be used to increase the validity of the scan
    B. Perform a penetration test in addition to a vulnerability scan
    C. Use banner grabbing to identify the target platform
    D. Use baseline reporting to determine the actual configuration

  • Question 1597:

    Company employees are required to have workstation client certificates to access a bank website. These certificates were backed up as a precautionary step before the new computer upgrade. After the upgrade and restoration, users state they can access the bank's website, but not login. Which is the following is MOST likely the issue?

    A. The IP addresses of the clients have change
    B. The client certificate passwords have expired on the server
    C. The certificates have not been installed on the workstations
    D. The certificates have been installed on the CA

  • Question 1598:

    Mike, a security professional, is tasked with actively verifying the strength of the security controls on a company's live modem pool. Which of the following activities is MOST appropriate?

    A. War dialing
    B. War chalking
    C. War driving
    D. Bluesnarfing

  • Question 1599:

    A company uses port security based on an approved MAC list to secure its wired network and WPA2 to secure its wireless network. Which of the following prevents an attacker from learning authorized MAC addresses?

    A. Port security prevents access to any traffic that might provide an attacker with authorized MAC addresses
    B. Port security uses certificates to authenticate devices and is not part of a wireless protocol
    C. Port security relies in a MAC address length that is too short to be cryptographically secure over wireless networks
    D. Port security encrypts data on the network preventing an attacker form reading authorized MAC addresses

  • Question 1600:

    Which of the following can be utilized in order to provide temporary IT support during a disaster, where the organization sets aside funds for contingencies, but does not necessarily have a dedicated site to restore those services?

    A. Hot site
    B. Warm site
    C. Cold site
    D. Mobile site

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.