SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 351:

    A recent audit has revealed that all employees in the bookkeeping department have access to confidential payroll information, while only two members of the bookkeeping department have job duties that require access to the confidential information. Which of the following can be implemented to reduce the risk of this information becoming compromised in this scenario? (Select TWO)

    A. Rule-based access control
    B. Role-based access control
    C. Data loss prevention
    D. Separation of duties E. Group-based permissions

  • Question 352:

    A trojan was recently discovered on a server. There are now concerns that there has been a security breach that allows unauthorized people to access data. The administrator should be looking for the presence of a/an:

    A. Logic bomb.
    B. Backdoor.
    C. Adware application.
    D. Rootkit.

  • Question 353:

    One of the system administrators at a company is assigned to maintain a secure computer lab. The administrator has rights to configure machines, install software, and perform user account maintenance. However, the administrator cannot add new computers to the domain, because that requires authorization from the Information Assurance Officer. This is an example of which of the following?

    A. Mandatory access
    B. Rule-based access control
    C. Least privilege
    D. Job rotation

  • Question 354:

    The security administrator receives an email on a non-company account from a coworker stating that some reports are not exporting correctly. Attached to the email was an example report file with several customers' names and credit card numbers with the PIN. Which of the following is the BEST technical controls that will help mitigate this risk of disclosing sensitive data?

    A. Configure the mail server to require TLS connections for every email to ensure all transport data is encrypted
    B. Create a user training program to identify the correct use of email and perform regular audits to ensure compliance
    C. Implement a DLP solution on the email gateway to scan email and remove sensitive data or files
    D. Classify all data according to its sensitivity and inform the users of data that is prohibited to share

  • Question 355:

    In an effort to reduce data storage requirements, a company devices to hash every file and eliminate duplicates. The data processing routines are time sensitive so the hashing algorithm is fast and supported on a wide range of systems. Which of the following algorithms is BEST suited for this purpose?

    A. MD5
    B. SHA
    C. RIPEMD
    D. AES

  • Question 356:

    A quality assurance analyst is reviewing a new software product for security, and has complete access to the code and data structures used by the developers. This is an example of which of the following types of testing?

    A. Black box
    B. Penetration
    C. Gray box
    D. White box

  • Question 357:

    Which of the following functions provides an output which cannot be reversed and converts data into a string of characters?

    A. Hashing
    B. Stream ciphers
    C. Steganography
    D. Block ciphers

  • Question 358:

    Which of the following controls would allow a company to reduce the exposure of sensitive systems from unmanaged devices on internal networks?

    A. 802.1x
    B. Data encryption
    C. Password strength
    D. BGP

  • Question 359:

    A video surveillance audit recently uncovered that an employee plugged in a personal laptop and used the corporate network to browse inappropriate and potentially malicious websites after office hours. Which of the following could BEST prevent a situation like this form occurring again?

    A. Intrusion detection
    B. Content filtering
    C. Port security
    D. Vulnerability scanning

  • Question 360:

    A supervisor in your organization was demoted on Friday afternoon. The supervisor had the ability to modify the contents of a confidential database, as well as other managerial permissions. On Monday morning, the database administrator reported that log files indicated that several records were missing from the database. Which of the following risk mitigation startegies should have been implemented when the supervisor was demoted?

    A. Incident management
    B. Routine auditing
    C. IT governance
    D. Monthly user rights reviews

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.