SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 951:

    An IT security technician needs to establish host based security for company workstations. Which of the following will BEST meet this requirement?

    A. Implement IIS hardening by restricting service accounts.
    B. Implement database hardening by applying vendor guidelines.
    C. Implement perimeter firewall rules to restrict access.
    D. Implement OS hardening by applying GPOs.

  • Question 952:

    The Chief Security Officer (CISO) at a multinational banking corporation is reviewing a plan to upgrade the entire corporate IT infrastructure. The architecture consists of a centralized cloud environment hosting the majority of data, small server clusters at each corporate location to handle the majority of customer transaction processing, ATMs, and a new mobile banking application accessible from smartphones, tablets, and the Internet via HTTP. The corporation does business having varying data retention and privacy laws. Which of the following technical modifications to the architecture and corresponding security controls should be implemented to provide the MOST complete protection of data?

    A. Revoke exiting root certificates, re-issue new customer certificates, and ensure all transactions are digitally signed to minimize fraud, implement encryption for data in-transit between data centers
    B. Ensure all data is encryption according to the most stringent regulatory guidance applicable, implement encryption for data in-transit between data centers, increase data availability by replicating all data, transaction data, logs between each corporate location
    C. Store customer data based on national borders, ensure end-to end encryption between ATMs, end users, and servers, test redundancy and COOP plans to ensure data is not inadvertently shifted from one legal jurisdiction to another with more stringent regulations
    D. Install redundant servers to handle corporate customer processing, encrypt all customer data to ease the transfer from one country to another, implement end-to-end encryption between mobile applications and the cloud.

  • Question 953:

    When using PGP, which of the following should the end user protect from compromise? (Select TWO).

    A. Private key
    B. CRL details
    C. Public key
    D. Key password
    E. Key escrow
    F. Recovery agent

  • Question 954:

    The IT department noticed that there was a significant decrease in network performance during the afternoon hours. The IT department performed analysis of the network and discovered this was due to users accessing and downloading music and video streaming from social sites. The IT department notified corporate of their findings and a memo was sent to all employees addressing the misuse of company resources and requesting adherence to company policy. Which of the following policies is being enforced?

    A. Acceptable use policy
    B. Telecommuting policy
    C. Data ownership policy
    D. Non disclosure policy

  • Question 955:

    Which of the following provides additional encryption strength by repeating the encryption process with additional keys?

    A. AES
    B. 3DES
    C. TwoFish
    D. Blowfish

  • Question 956:

    Which of the following MUST Matt, a security administrator, implement to verify both the integrity and authenticity of a message while requiring a shared secret?

    A. RIPEMD
    B. MD5
    C. SHA
    D. HMAC

  • Question 957:

    Which of the following is used by the recipient of a digitally signed email to verify the identity of the sender?

    A. Recipient's private key
    B. Sender's public key
    C. Recipient's public key
    D. Sender's private key

  • Question 958:

    Purchasing receives an automated phone call from a bank asking to input and verify credit card information. The phone number displayed on the caller ID matches the bank. Which of the following attack types is this?

    A. Hoax
    B. Phishing
    C. Vishing
    D. Whaling

  • Question 959:

    Ann a technician received a spear-phishing email asking her to update her personal information by clicking the link within the body of the email. Which of the following type of training would prevent Ann and other employees from becoming victims to such attacks?

    A. User Awareness
    B. Acceptable Use Policy
    C. Personal Identifiable Information
    D. Information Sharing

  • Question 960:

    Ann, a security technician, is reviewing the IDS log files. She notices a large number of alerts for multicast packets from the switches on the network. After investigation, she discovers that this is normal activity for her network. Which of the following BEST describes these results?

    A. True negatives
    B. True positives
    C. False positives
    D. False negatives

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.