SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 581:

    A security administrator must implement a system to ensure that invalid certificates are not used by a custom developed application. The system must be able to check the validity of certificates even when internet access is unavailable. Which of the following MUST be implemented to support this requirement?

    A. CSR
    B. OCSP
    C. CRL
    D. SSH

  • Question 582:

    A company is concerned that a compromised certificate may result in a man-in-the-middle attack against backend financial servers. In order to minimize the amount of time a compromised certificate would be accepted by other servers, the company decides to add another validation step to SSL/TLS connections. Which of the following technologies provides the FASTEST revocation capability?

    A. Online Certificate Status Protocol (OCSP)
    B. Public Key Cryptography (PKI)
    C. Certificate Revocation Lists (CRL)
    D. Intermediate Certificate Authority (CA)

  • Question 583:

    Joe a computer forensic technician responds to an active compromise of a database server. Joe first collects information in memory, then collects network traffic and finally conducts an image of the hard drive. Which of the following procedures did Joe follow?

    A. Order of volatility
    B. Chain of custody
    C. Recovery procedure
    D. Incident isolation

  • Question 584:

    A compromised workstation utilized in a Distributed Denial of Service (DDOS) attack has been removed from the network and an image of the hard drive has been created. However, the system administrator stated that the system was left unattended for several hours before the image was created. In the event of a court case, which of the following is likely to be an issue with this incident?

    A. Eye Witness
    B. Data Analysis of the hard drive
    C. Chain of custody
    D. Expert Witness

  • Question 585:

    A company would like to prevent the use of a known set of applications from being used on company computers. Which of the following should the security administrator implement?

    A. Whitelisting
    B. Anti-malware
    C. Application hardening
    D. Blacklisting
    E. Disable removable media

  • Question 586:

    A process in which the functionality of an application is tested without any knowledge of the internal mechanisms of the application is known as:

    A. Black box testing
    B. White box testing
    C. Black hat testing
    D. Gray box testing

  • Question 587:

    An investigator recently discovered that an attacker placed a remotely accessible CCTV camera in a public area overlooking several Automatic Teller Machines (ATMs). It is also believed that user accounts belonging to ATM operators may have been compromised. Which of the following attacks has MOST likely taken place?

    A. Shoulder surfing
    B. Dumpster diving
    C. Whaling attack
    D. Vishing attack

  • Question 588:

    A new virtual server was created for the marketing department. The server was installed on an existing host machine. Users in the marketing department report that they are unable to connect to the server. Technicians verify that the server has an IP address in the same VLAN as the marketing department users. Which of the following is the MOST likely reason the users are unable to connect to the server?

    A. The new virtual server's MAC address was not added to the ACL on the switch
    B. The new virtual server's MAC address triggered a port security violation on the switch
    C. The new virtual server's MAC address triggered an implicit deny in the switch
    D. The new virtual server's MAC address was not added to the firewall rules on the switch

  • Question 589:

    An SSL/TLS private key is installed on a corporate web proxy in order to inspect HTTPS requests. Which of the following describes how this private key should be stored so that it is protected from theft?

    A. Implement full disk encryption
    B. Store on encrypted removable media
    C. Utilize a hardware security module
    D. Store on web proxy file system

  • Question 590:

    Which of the following security devices can be replicated on a Linux based computer using IP tables to inspect and properly handle network based traffic?

    A. Sniffer
    B. Router
    C. Firewall
    D. Switch

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.