SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 781:

    A malicious person gained access to a datacenter by ripping the proximity badge reader off the wall near the datacenter entrance. This caused the electronic locks on the datacenter door to release because the:

    A. badge reader was improperly installed.
    B. system was designed to fail open for life-safety.
    C. system was installed in a fail closed configuration.
    D. system used magnetic locks and the locks became demagnetized.

  • Question 782:

    Requiring technicians to report spyware infections is a step in which of the following?

    A. Routine audits
    B. Change management
    C. Incident management
    D. Clean desk policy

  • Question 783:

    Which of the following is described as an attack against an application using a malicious file?

    A. Client side attack
    B. Spam
    C. Impersonation attack
    D. Phishing attack

  • Question 784:

    A security analyst has been notified that trade secrets are being leaked from one of the executives in the corporation. When reviewing this executive's laptop they notice several pictures of the employee's pets are on the hard drive and on a cloud storage network. When the analyst hashes the images on the hard drive against the hashes on the cloud network they do not match.

    Which of the following describes how the employee is leaking these secrets?

    A. Social engineering
    B. Steganography
    C. Hashing
    D. Digital signatures

  • Question 785:

    Connections using point-to-point protocol authenticate using which of the following? (Select TWO).

    A. RIPEMD
    B. PAP
    C. CHAP
    D. RC4
    E. Kerberos

  • Question 786:

    A security administrator must implement all requirements in the following corporate policy:

    Passwords shall be protected against offline password brute force attacks. Passwords shall be protected against online password brute force attacks. Which of the following technical controls must be implemented to enforce the corporate

    policy? (Select THREE).

    A. Account lockout
    B. Account expiration
    C. Screen locks
    D. Password complexity
    E. Minimum password lifetime
    F. Minimum password length

  • Question 787:

    The Chief Executive Officer (CEO) Joe notices an increase in the wireless signal in this office and thanks the IT director for the increase in network speed, Upon investigation the IT department finds an access point hidden in the dropped ceiling outside of joe's office. Which of the following types of attack is MOST likely occurring?

    A. Packet sniffing
    B. Bluesnarfing
    C. Man-in-the-middle
    D. Evil twin

  • Question 788:

    A system administrator wants to configure a setting that will make offline password cracking more challenging. Currently the password policy allows upper and lower case characters a minimum length of 5 and a lockout after 10 invalid attempts. Which of the following has the GREATEST impact on the time it takes to crack the passwords?

    A. Increase the minimum password length to 8 while keeping the same character set
    B. Implement an additional password history and reuse policy
    C. Allow numbers and special characters in the password while keeping the minimum length at 5
    D. Implement an account lockout policy after three unsuccessful logon attempts

  • Question 789:

    After disabling SSID broadcast, a network administrator still sees the wireless network listed in available networks on a client laptop. Which of the following attacks may be occurring?

    A. Evil Twin
    B. ARP spoofing
    C. Disassociation flooding
    D. Rogue access point
    E. TKIP compromise

  • Question 790:

    Which of the following could cause a browser to display the message below?

    "The security certificate presented by this website was issued for a different website's address."

    A. The website certificate was issued by a different CA than what the browser recognizes in its trusted CAs.
    B. The website is using a wildcard certificate issued for the company's domain.
    C. HTTPS://127.0.01 was used instead of HTTPS://localhost.
    D. The website is using an expired self signed certificate.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.