SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 721:

    An information bank has been established to store contacts, phone numbers and other records.

    An application running on UNIX would like to connect to this index server using port 88. Which of the following authentication services would this use this port by default?

    A. Kerberos
    B. TACACS+
    C. Radius
    D. LDAP

  • Question 722:

    When implementing a Public Key Infrastructure, which of the following should the sender use to digitally sign a document?

    A. A CSR
    B. A private key
    C. A certificate authority
    D. A public key

  • Question 723:

    A security technician has removed the sample configuration files from a database server. Which of the following application security controls has the technician attempted?

    A. Application hardening
    B. Application baselines
    C. Application patch management
    D. Application input validation

  • Question 724:

    A security administrator discovered that all communication over the company's encrypted wireless network is being captured by savvy employees with a wireless sniffing tool and is then being decrypted in an attempt to steal other employee's credentials. Which of the following technology is MOST likely in use on the company's wireless?

    A. WPA with TKIP
    B. VPN over open wireless
    C. WEP128-PSK
    D. WPA2-Enterprise

  • Question 725:

    An administrator is investigating a system that may potentially be compromised, and sees the following log entries on the router.

    *Jul 15 14:47:29.779:%Router1: list 101 permitted tcp 192.10.3.204(57222) (FastEthernet 0/3) -> 10.10.1.5 (6667), 3 packets.

    *Jul 15 14:47:38.779:%Router1: list 101 permitted tcp 192.10.3.204(57222) (FastEthernet 0/3) -> 10.10.1.5 (6667), 6 packets.

    *Jul 15 14:47:45.779:%Router1: list 101 permitted tcp 192.10.3.204(57222) (FastEthernet 0/3) -> 10.10.1.5 (6667), 8 packets.

    Which of the following BEST describes the compromised system?

    A. It is running a rogue web server
    B. It is being used in a man-in-the-middle attack
    C. It is participating in a botnet
    D. It is an ARP poisoning attack

  • Question 726:

    Which of the following BEST describes an attack where communications between two parties are intercepted and forwarded to each party with neither party being aware of the interception and potential modification to the communications?

    A. Spear phishing
    B. Main-in-the-middle
    C. URL hijacking
    D. Transitive access

  • Question 727:

    A new intern was assigned to the system engineering department, which consists of the system architect and system software developer's teams. These two teams have separate privileges. The intern requires privileges to view the system architectural drawings and comment on some software development projects. Which of the following methods should the system administrator implement?

    A. Group based privileges
    B. Generic account prohibition
    C. User access review
    D. Credential management

  • Question 728:

    A small IT security form has an internal network composed of laptops, servers, and printers. The network has both wired and wireless segments and supports VPN access from remote sites. To protect the network from internal and external threats, including social engineering attacks, the company decides to implement stringent security controls. Which of the following lists is the BEST combination of security controls to implement?

    A. Disable SSID broadcast, require full disk encryption on servers, laptop, and personally owned electronic devices, enable MAC filtering on WAPs, require photographic ID to enter the building.
    B. Enable port security; divide the network into segments for servers, laptops, public and remote users; apply ACLs to all network equipment; enable MAC filtering on WAPs; and require two-factor authentication for network access.
    C. Divide the network into segments for servers, laptops, public and remote users; require the use of one time pads for network key exchange and access; enable MAC filtering ACLs on all servers.
    D. Enable SSID broadcast on a honeynet; install monitoring software on all corporate equipment' install CCTVs to deter social engineering; enable SE Linux in permissive mode.

  • Question 729:

    A company has a corporate infrastructure where end users manage their own certificate keys. Which of the following is considered the MOST secure way to handle master keys associated with these certificates?

    A. Key escrow with key recovery
    B. Trusted first party
    C. Personal Identity Verification
    D. Trusted third party

  • Question 730:

    A security technician is concerned there4 is not enough security staff available the web servers and database server located in the DMZ around the clock. Which of the following technologies, when deployed, would provide the BEST round the clock automated protection?

    A. HIPS and SIEM
    B. NIPS and HIDS
    C. HIDSand SIEM
    D. NIPSandHIPS

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.