SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 461:

    A system administrator wants to enable WPA2 CCMP. Which of the following is the only encryption used?

    A. RC4
    B. DES
    C. 3DES
    D. AES

  • Question 462:

    Which of the following BEST describes disk striping with parity?

    A. RAID O
    B. RAID 1
    C. RAID 2
    D. RAID 5

  • Question 463:

    The security administration team at a company has been tasked with implementing a data- at-rest solution for its company storage. Due to the large amount of storage the Chief Information Officer (CISO) decides that a 128-bit cipher is needed but the CISO also does not want to degrade system performance any more than necessary. Which of the following encryptions needs BOTH of these needs?

    A. SHA1
    B. DSA
    C. AES
    D. 3DES

  • Question 464:

    The Chief Information Security Officer (CISO) has mandated that all IT systems with credit card data be segregated from the main corporate network to prevent unauthorized access and that access to the IT systems should be logged. Which of the following would BEST meet the CISO's requirements?

    A. Sniffers
    B. NIDS
    C. Firewalls
    D. Web proxies
    E. Layer 2 switches

  • Question 465:

    An auditor's report discovered several accounts with no activity for over 60 days. The accounts were later identified as contractors' accounts who would be returning in three months and would need to resume the activities. Which of the following would mitigate and secure the auditors finding?

    A. Disable unnecessary contractor accounts and inform the auditor of the update.
    B. Reset contractor accounts and inform the auditor of the update.
    C. Inform the auditor that the accounts belong to the contractors.
    D. Delete contractor accounts and inform the auditor of the update.

  • Question 466:

    A computer is suspected of being compromised by malware. The security analyst examines the computer and finds that a service called Telnet is running and connecting to an external website over port 443. This Telnet service was found by comparing the system's services to the list of standard services on the company's system image. This review process depends on:

    A. MAC filtering.
    B. System hardening.
    C. Rogue machine detection.
    D. Baselining.

  • Question 467:

    A recent review of accounts on various systems has found that after employees passwords are required to change they are recycling the same password as before. Which of the following policies should be enforced to prevent this from happening? (Select TWO)

    A. Reverse encryption
    B. Minimum password age
    C. Password complexity
    D. Account lockouts
    E. Password history
    F. Password expiration

  • Question 468:

    A distributed denial of service attack can BEST be described as:

    A. Invalid characters being entered into a field in a database application.
    B. Users attempting to input random or invalid data into fields within a web browser application.
    C. Multiple computers attacking a single target in an organized attempt to deplete its resources.
    D. Multiple attackers attempting to gain elevated privileges on a target system.

  • Question 469:

    Ann, a security administrator, has concerns regarding her company's wireless network. The network is open and available for visiting prospective clients in the conference room, but she notices that many more devices are connecting to the network than should be.

    Which of the following would BEST alleviate Ann's concerns with minimum disturbance of current functionality for clients?

    A. Enable MAC filtering on the wireless access point.
    B. Configure WPA2 encryption on the wireless access point.
    C. Lower the antenna's broadcasting power.
    D. Disable SSID broadcasting.

  • Question 470:

    Which of the following would the security engineer set as the subnet mask for the servers below to utilize host addresses on separate broadcast domains? Server 1: 192.168.100.6 Server 2: 192.168.100.9 Server 3: 192.169.100.20

    A. /24
    B. /27
    C. /28
    D. /29
    E. /30

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.