SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 541:

    Which of the following forms of software testing can best be performed with no knowledge of how a system is internally structured or functions? (Select Two.)

    A. Boundary testing
    B. White box
    C. Fuzzing
    D. Black box
    E. Grey Box

  • Question 542:

    Which of the following password attacks is MOST likely to crack the largest number of randomly generated passwords?

    A. Hybrid
    B. Birthday attack
    C. Dictionary
    D. Rainbow tables

  • Question 543:

    A web startup wants to implement single sign-on where its customers can log on to the site by suing their personal and existing corporate email credentials regardless of which company they work for. Is this directly supported by SAML?

    A. Mo not without extensive partnering and API integration with all required email providers
    B. Yes SAML is a web based single sign-on implementation exactly fir this purpose
    C. No a better approach would be to use required email providers LDAP or RADIUS repositories
    D. Yes SAML can use oauth2 to provide this functionality out of the box

  • Question 544:

    Which of the following automated or semi-automated software testing techniques relies on inputting large amounts of random data to detect coding errors or application loopholes?

    A. Fuzzing
    B. Black box
    C. Fault injection
    D. SQL injection

  • Question 545:

    Which of the following is an advantage of implementing individual file encryption on a hard drive which already deploys full disk encryption?

    A. Reduces processing overhead required to access the encrypted files
    B. Double encryption causes the individually encrypted files to partially lose their properties
    C. Individually encrypted files will remain encrypted when copied to external media
    D. File level access control only apply to individually encrypted files in a fully encrypted drive

  • Question 546:

    A security administrator is troubleshooting an authentication issues using a network sniffer. The security administrator reviews a packet capture of the authentication process and notices that authentication is performed using extensible markup over SOAP. Which of the following authentication services is the security administrator troubleshooting?

    A. SAML
    B. XTACACS
    C. Secure LDAP
    D. RADIUS

  • Question 547:

    A recently installed application update caused a vital application to crash during the middle of the workday. The application remained down until a previous version could be reinstalled on the server, and this resulted in a significant loss of data and revenue.

    Which of the following could BEST prevent this issue from occurring again?

    A. Application configuration baselines
    B. Application hardening
    C. Application access controls
    D. Application patch management

  • Question 548:

    Which of the following BEST describes the type of attack that is occurring?

    A. Smurf Attack
    B. Man in the middle
    C. Backdoor
    D. Replay
    E. Spear Phishing
    F. Xmas Attack
    G. Blue Jacking
    H. Ping of Death

  • Question 549:

    In regards to secure coding practices, why is input validation important?

    A. It mitigates buffer overflow attacks.
    B. It makes the code more readable.
    C. It provides an application configuration baseline.
    D. It meets gray box testing standards.

  • Question 550:

    An organization uses a Kerberos-based LDAP service for network authentication. The service is also utilized for internal web applications. Finally access to terminal applications is achieved using the same authentication method by joining the legacy system to the Kerberos realm. This company is using Kerberos to achieve which of the following?

    A. Trusted Operating System
    B. Rule-based access control
    C. Single sign on
    D. Mandatory access control

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.