SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 701:

    An administrator is building a development environment and requests that three virtual servers are cloned and placed in a new virtual network isolated from the production network. Which of the following describes the environment the administrator is building?

    A. Cloud
    B. Trusted
    C. Sandbox
    D. Snapshot

  • Question 702:

    Due to issues with building keys being duplicated and distributed, a security administrator wishes to change to a different security control regarding a restricted area. The goal is to provide access based upon facial recognition. Which of the following will address this requirement?

    A. Set up mantraps to avoid tailgating of approved users.
    B. Place a guard at the entrance to approve access.
    C. Install a fingerprint scanner at the entrance.
    D. Implement proximity readers to scan users' badges.

  • Question 703:

    A recent audit of a company's identity management system shows that 30% of active accounts belong to people no longer with the firm. Which of the following should be performed to help avoid this scenario? (Select TWO).

    A. Automatically disable accounts that have not been utilized for at least 10 days.
    B. Utilize automated provisioning and de-provisioning processes where possible.
    C. Request that employees provide a list of systems that they have access to prior to leaving the firm.
    D. Perform regular user account review / revalidation process.
    E. Implement a process where new account creations require management approval.

  • Question 704:

    A web application is configured to target browsers and allow access to bank accounts to siphon money to a foreign account. This is an example of which of the following attacks?

    A. SQL injection
    B. Header manipulation
    C. Cross-site scripting
    D. Flash cookie exploitation

  • Question 705:

    Developers currently have access to update production servers without going through an approval process. Which of the following strategies would BEST mitigate this risk?

    A. Incident management
    B. Clean desk policy
    C. Routine audits
    D. Change management

  • Question 706:

    A security program manager wants to actively test the security posture of a system. The system is not yet in production and has no uptime requirement or active user base. Which of the following methods will produce a report which shows vulnerabilities that were actually exploited?

    A. Peer review
    B. Component testing
    C. Penetration testing
    D. Vulnerability testing

  • Question 707:

    Which of the following is primarily used to provide fault tolerance at the application level? (Select TWO)

    A. Load balancing
    B. RAID array
    C. RAID 6
    D. Server clustering
    E. JBOD array

  • Question 708:

    A network administrator has a separate user account with rights to the domain administrator group. However, they cannot remember the password to this account and are not able to login to the server when needed. Which of the following is MOST accurate in describing the type of issue the administrator is experiencing?

    A. Single sign-on
    B. Authorization
    C. Access control
    D. Authentication

  • Question 709:

    A bank has a fleet of aging payment terminals used by merchants for transactional processing. The terminals currently support single DES but require an upgrade in order to be compliant with security standards. Which of the following is likely to be the simplest upgrade to the aging terminals which will improve in-transit protection of transactional data?

    A. AES
    B. 3DES
    C. RC4
    D. WPA2

  • Question 710:

    Matt, the Chief Information Security Officer (CISO), tells the network administrator that a security company has been hired to perform a penetration test against his network. The security company asks Matt which type of testing would be most beneficial for him. Which of the following BEST describes what the security company might do during a black box test?

    A. The security company is provided with all network ranges, security devices in place, and logical maps of the network.
    B. The security company is provided with no information about the corporate network or physical locations.
    C. The security company is provided with limited information on the network, including all network diagrams.
    D. The security company is provided with limited information on the network, including some subnet ranges and logical network diagrams.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.