SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 731:

    A Chief Executive Officer (CEO) is steering company towards cloud computing. The CEO is requesting a federated sign-on method to have users sign into the sales application. Which of the following methods will be effective for this purpose?

    A. SAML
    B. RADIUS
    C. Kerberos
    D. LDAP

  • Question 732:

    A security administrator is selecting an MDM solution for an organization, which has strict security requirements for the confidentiality of its data on end user devices. The organization decides to allow BYOD, but requires that users wishing to participate agree to the following specific device configurations; camera disablement, password enforcement, and application whitelisting. The organization must be able to support a device portfolio of differing mobile operating systems. Which of the following represents the MOST relevant technical security criteria for the MDM?

    A. Breadth of support for device manufacturers' security configuration APIS
    B. Ability to extend the enterprise password polices to the chosen MDM
    C. Features to support the backup and recovery of the stored corporate data
    D. Capability to require the users to accept an AUP prior to device onboarding

  • Question 733:

    A computer security officer has investigated a possible data breach and has found it credible. The officer notifies the data center manager and the Chief Information Security Officer (CISO). This is an example of:

    A. escalation and notification.
    B. first responder.
    C. incident identification.
    D. incident mitigation.

  • Question 734:

    An employee attempts to go to a well-known bank site using the company-standard web browser by correctly typing in the address of the site into the web browser. The employee is directed to a website that looks like the bank's site but is not the actual bank site. The employee's user name and password are subsequently stolen. This is an example of which of the following?

    A. Watering hole attack
    B. Cross-site scripting
    C. DNS poisoning
    D. Man-in-the-middle attack

  • Question 735:

    Encryption of data at rest is important for sensitive information because of which of the following?

    A. Facilitates tier 2 support, by preventing users from changing the OS
    B. Renders the recovery of data harder in the event of user password loss
    C. Allows the remote removal of data following eDiscovery requests
    D. Prevents data from being accessed following theft of physical equipment

  • Question 736:

    Joe needs to track employees who log into a confidential database and edit files. In the past, critical files have been edited, and no one admits to making the edits. Which of the following does Joe need to implement in order to enforce accountability?

    A. Non-repudiation
    B. Fault tolerance
    C. Hashing
    D. Redundancy

  • Question 737:

    Which of the following is a hardware-based security technology included in a computer?

    A. Symmetric key
    B. Asymmetric key
    C. Whole disk encryption
    D. Trusted platform module

  • Question 738:

    Based on information leaked to industry websites, business management is concerned that unauthorized employees are accessing critical project information for a major, well-known new product. To identify any such users, the security administrator could:

    A. Set up a honeypot and place false project documentation on an unsecure share.
    B. Block access to the project documentation using a firewall.
    C. Increase antivirus coverage of the project servers.
    D. Apply security updates and harden the OS on all project servers.

  • Question 739:

    Sara, an application developer, implemented error and exception handling alongside input validation. Which of the following does this help prevent?

    A. Buffer overflow
    B. Pop-up blockers
    C. Cross-site scripting
    D. Fuzzing

  • Question 740:

    A system administrator is configuring UNIX accounts to authenticate against an external server. The configuration file asks for the following information DC=ServerName and DC=COM. Which of the following authentication services is being used?

    A. RADIUS
    B. SAML
    C. TACACS+
    D. LDAP

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.