SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 451:

    Use of a smart card to authenticate remote servers remains MOST susceptible to which of the following attacks?

    A. Malicious code on the local system
    B. Shoulder surfing
    C. Brute force certificate cracking
    D. Distributed dictionary attacks

  • Question 452:

    A business has set up a Customer Service kiosk within a shopping mall. The location will be staffed by an employee using a laptop during the mall business hours, but there are still concerns regarding the physical safety of the equipment while it is not in use. Which of the following controls would BEST address this security concern?

    A. Host-based firewall
    B. Cable locks
    C. Locking cabinets
    D. Surveillance video

  • Question 453:

    Which of the following BEST describes the weakness in WEP encryption?

    A. The initialization vector of WEP uses a crack-able RC4 encryption algorithm. Once enough packets are captured an XOR operation can be performed and the asymmetric keys can be derived.
    B. The WEP key is stored in plain text and split in portions across 224 packets of random data. Once enough packets are sniffed the IV portion of the packets can be removed leaving the plain text key.
    C. The WEP key has a weak MD4 hashing algorithm used. A simple rainbow table can be used to generate key possibilities due to MD4 collisions.
    D. The WEP key is stored with a very small pool of random numbers to make the cipher text. As the random numbers are often reused it becomes easy to derive the remaining WEP key.

  • Question 454:

    A security administrator needs to update the OS on all the switches in the company. Which of the following MUST be done before any actual switch configuration is performed?

    A. The request needs to be sent to the incident management team.
    B. The request needs to be approved through the incident management process.
    C. The request needs to be approved through the change management process.
    D. The request needs to be sent to the change management team.

  • Question 455:

    Given the following set of firewall rules:

    From the inside to outside allow source any destination any port any

    From inside to dmz allow source any destination any port tcp-80

    From inside to dmz allow source any destination any port tcp-443

    Which of the following would prevent FTP traffic from reaching a server in the DMZ from the inside network?

    A. Implicit deny
    B. Policy routing
    C. Port forwarding
    D. Forwarding proxy

  • Question 456:

    A security administrator is installing a single camera outside in order to detect unauthorized vehicles in the parking lot. Which of the following is the MOST important consideration when deploying a CCTV camera to meet the requirement?

    A. Training
    B. Expense
    C. Resolution
    D. Field of view

  • Question 457:

    Which of the following protocols is MOST likely to be leveraged by users who need additional information about another user?

    A. LDAP
    B. RADIUS
    C. Kerberos
    D. TACACS+

  • Question 458:

    Joe, a technician, is tasked with finding a way to test operating system patches for a wide variety of servers before deployment to the production environment while utilizing a limited amount of hardware resources. Which of the following would provide the BEST environment for performing this testing?

    A. OS hardening
    B. Application control
    C. Virtualization
    D. Sandboxing

  • Question 459:

    Ann, a security administrator, has been instructed to perform fuzz-based testing on the company's applications. Which of the following best describes what she will do?

    A. Enter random or invalid data into the application in an attempt to cause it to fault
    B. Work with the developers to eliminate horizontal privilege escalation opportunities
    C. Test the applications for the existence of built-in- back doors left by the developers
    D. Hash the application to verify it won't cause a false positive on the HIPS.

  • Question 460:

    A company is about to release a very large patch to its customers. An administrator is required to test patch installations several times prior to distributing them to customer PCs. Which of the following should the administrator use to test the patching process quickly and often?

    A. Create an incremental backup of an unpatched PC
    B. Create an image of a patched PC and replicate it to servers
    C. Create a full disk image to restore after each installation
    D. Create a virtualized sandbox and utilize snapshots

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.