SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 711:

    A web administrator has just implemented a new web server to be placed in production. As part of the company's security plan, any new system must go through a security test before it is placed in production. The security team runs a port scan resulting in the following data: 21 tcp open FTP 23 tcp open Telnet 22 tcp open SSH 25 UDP open smtp 110 tcp open pop3 443 tcp open https Which of the following is the BEST recommendation for the web administrator?

    A. Implement an IPS
    B. Disable unnecessary services
    C. Disable unused accounts
    D. Implement an IDS
    E. Wrap TELNET in SSL

  • Question 712:

    Which of the following describes a type of malware which is difficult to reverse engineer in a virtual lab?

    A. Armored virus
    B. Polymorphic malware
    C. Logic bomb
    D. Rootkit

  • Question 713:

    While opening an email attachment, Pete, a customer, receives an error that the application has encountered an unexpected issue and must be shut down. This could be an example of which of the following attacks?

    A. Cross-site scripting
    B. Buffer overflow
    C. Header manipulation
    D. Directory traversal

  • Question 714:

    The internal audit group discovered that unauthorized users are making unapproved changes to various system configuration settings. This issue occurs when previously authorized users transfer from one department to another and maintain the same credentials. Which of the following controls can be implemented to prevent such unauthorized changes in the future?

    A. Periodic access review
    B. Group based privileges
    C. Least privilege
    D. Account lockout

  • Question 715:

    Which of the following describes the implementation of PAT?

    A. Translating the source and destination IPS, but not the source and destination ports
    B. A one to one persistent mapping between on private IP and one Public IP
    C. Changing the priority of a TCP stream based on the source address
    D. Associating multiple public IP addresses with one private address

  • Question 716:

    Which of the following ports is used to securely transfer files between remote UNIX systems?

    A. 21
    B. 22
    C. 69
    D. 445

  • Question 717:

    A company has 5 users. Users 1, 2 and 3 need access to payroll and users 3, 4 and 5 need access to sales. Which of the following should be implemented to give the appropriate access while enforcing least privilege?

    A. Assign individual permissions to users 1 and 2 for payroll. Assign individual permissions to users 4 and 5 for sales. Make user 3 an administrator.
    B. Make all users administrators and then restrict users 1 and 2 from sales. Then restrict users 4 and 5 from payroll.
    C. Create two additional generic accounts, one for payroll and one for sales that users utilize.
    D. Create a sales group with users 3, 4 and 5. Create a payroll group with users 1, 2 and 3.

  • Question 718:

    Which of the following would prevent a user from installing a program on a company-owned mobile device?

    A. White-listing
    B. Access control lists
    C. Geotagging
    D. Remote wipe

  • Question 719:

    A chief Financial Officer (CFO) has asked the Chief Information Officer (CISO) to provide responses to a recent audit report detailing deficiencies in the organization security controls. The CFO would like to know ways in which the organization can improve its authorization controls. Given the request by the CFO, which of the following controls should the CISO focus on in the report? (Select Three)

    A. Password complexity policies
    B. Hardware tokens
    C. Biometric systems
    D. Role-based permissions
    E. One time passwords
    F. Separation of duties
    G. Multifactor authentication
    H. Single sign-on
    I. Lease privilege

  • Question 720:

    A security administrator must implement a firewall rule to allow remote employees to VPN onto the company network. The VPN concentrator implements SSL VPN over the standard HTTPS port. Which of the following is the MOST secure ACL to implement at the company's gateway firewall?

    A. PERMIT TCP FROM ANY 443 TO 199.70.5.25 443
    B. PERMIT TCP FROM ANY ANY TO 199.70.5.23 ANY
    C. PERMIT TCP FROM 199.70.5.23 ANY TO ANY ANY
    D. PERMIT TCP FROM ANY 1024-65535 TO 199.70.5.23 443

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.