SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 631:

    A company's application is hosted at a data center. The data center provides security controls for the infrastructure. The data center provides a report identifying serval vulnerabilities regarding out of date OS patches. The company recommends the data center assumes the risk associated with the OS vulnerabilities. Which of the following concepts is being implemented?

    A. Risk Transference
    B. Risk Acceptance
    C. Risk Avoidance
    D. Risk Deterrence

  • Question 632:

    In intrusion detection system vernacular, which account is responsible for setting the security policy for an organization?

    A. Supervisor
    B. Administrator
    C. Root
    D. Director

  • Question 633:

    Which of the following is BEST utilized to identify common misconfigurations throughout the enterprise?

    A. Vulnerability scanning
    B. Port scanning
    C. Penetration testing
    D. Black box

  • Question 634:

    Company A sends a PGP encrypted file to company B. If company A used company B's public key to encrypt the file, which of the following should be used to decrypt data at company B?

    A. Registration
    B. Public key
    C. CRLs
    D. Private key

  • Question 635:

    Which of the following malware types may require user interaction, does not hide itself, and is commonly identified by marketing pop-ups based on browsing habits?

    A. Botnet
    B. Rootkit
    C. Adware
    D. Virus

  • Question 636:

    Which of the following metrics is important for measuring the extent of data required during backup and recovery?

    A. MOU
    B. ARO
    C. ALE
    D. RPO

  • Question 637:

    Which of the following is replayed during wireless authentication to exploit a weak key infrastructure?

    A. Preshared keys
    B. Ticket exchange
    C. Initialization vectors
    D. Certificate exchange

  • Question 638:

    Company XYZ's laptops was recently stolen from a user which led to the exposure if confidential information. Which of the following should the security team implement on laptops to prevent future compromise?

    A. Cipher locks
    B. Strong passwords
    C. Biometrics
    D. Full Disk Encryption

  • Question 639:

    A network administrator recently updated various network devices to ensure redundancy throughout the network. If an interface on any of the Layer 3 devices were to go down, traffic will still pass through another interface and the production environment would be unaffected. This type of configuration represents which of the following concepts?

    A. High availability
    B. Load balancing
    C. Backout contingency plan
    D. Clustering

  • Question 640:

    A security administrator at a company which implements key escrow and symmetric encryption only, needs to decrypt an employee's file. The employee refuses to provide the decryption key to the file. Which of the following can the administrator do to decrypt the file?

    A. Use the employee's private key
    B. Use the CA private key
    C. Retrieve the encryption key
    D. Use the recovery agent

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.