SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 491:

    A network administrator is looking for a way to automatically update company browsers so they import a list of root certificates from an online source. This online source will then be responsible for tracking which certificates are to be trusted or not trusted. Which of the following BEST describes the service that should be implemented to meet these requirements?

    A. Trust model
    B. Key escrow
    C. OCSP
    D. PKI

  • Question 492:

    Which of the following is a common coding error in which boundary checking is not performed?

    A. Input validation
    B. Fuzzing
    C. Secure coding
    D. Cross-site scripting

  • Question 493:

    Joe processes several requisitions during the day and during the night shift they are approved by Ann. This is an example of which of the following?

    A. Separation of duties
    B. Discretionary access
    C. Mandatory access
    D. Time of day restrictions

  • Question 494:

    A security administrator notices large amounts of traffic within the network heading out to an external website. The website seems to be a fake bank site with a phone number that when called, asks for sensitive information. After further investigation, the security administrator notices that a fake link was sent to several users. This is an example of which of the following attacks?

    A. Vishing
    B. Phishing
    C. Whaling
    D. SPAM
    E. SPIM

  • Question 495:

    A security administrator is reviewing the company's continuity plan. The plan specifies an RTO of six hours and RPO of two days. Which of the following is the plan describing?

    A. Systems should be restored within six hours and no later than two days after the incident.
    B. Systems should be restored within two days and should remain operational for at least six hours.
    C. Systems should be restored within six hours with a minimum of two days worth of data.
    D. Systems should be restored within two days with a minimum of six hours worth of data.

  • Question 496:

    An organization currently uses FTP for the transfer of large files, due to recent security enhancements, is now required to use a secure method of file transfer and is testing both SFTP and FTPS as alternatives. Which of the following ports should be opened on the firewall in order to test the two alternatives? (Select Two)

    A. TCP 22
    B. TCP 25
    C. TCP 69
    D. UDP 161
    E. TCP 990
    F. TCP 3380

  • Question 497:

    Which of the following is the proper way to quantify the total monetary damage resulting from an exploited vulnerability?

    A. Calculate the ALE
    B. Calculate the ARO
    C. Calculate the MTBF
    D. Calculate the TCO

  • Question 498:

    Joe a sales employee is connecting to a wireless network and has entered the network information correctly. His computer remains connected to the network but he cannot access any resources on the network. Which of the following is the MOST likely cause of this issue?

    A. The encryption is too strong
    B. The network SSID is disabled
    C. MAC filtering is enabled
    D. The wireless antenna power is set too low

  • Question 499:

    The chief Risk officer is concerned about the new employee BYOD device policy and has requested the security department implement mobile security controls to protect corporate data in the event that a device is lost or stolen. The level of protection must not be compromised even if the communication SIM is removed from the device. Which of the following BEST meets the requirements? (Select TWO)

    A. Asset tracking
    B. Screen-locks
    C. GEO-Tracking
    D. Device encryption

  • Question 500:

    Data execution prevention is a feature in most operating systems intended to protect against which type of attack?

    A. Cross-site scripting
    B. Buffer overflow
    C. Header manipulation
    D. SQL injection

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.