SY0-401 Exam Details

  • Exam Code
    :SY0-401
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1789 Q&As
  • Last Updated
    :Dec 14, 2021

CompTIA SY0-401 Online Questions & Answers

  • Question 961:

    A security administrator wishes to prevent certain company devices from using specific access points, while still allowing them on others. All of the access points use the same SSID and wireless password. Which of the following would be MOST appropriate in this scenario?

    A. Require clients to use 802.1x with EAPOL in order to restrict access
    B. Implement a MAC filter on the desired access points
    C. Upgrade the access points to WPA2 encryption
    D. Use low range antennas on the access points that ne4ed to be restricted

  • Question 962:

    A network administrator wants to ensure that users do not connect any unauthorized devices to the company network. Each desk needs to connect a VoIP phone and computer. Which of the following is the BEST way to accomplish this?

    A. Enforce authentication for network devices
    B. Configure the phones on one VLAN, and computers on another
    C. Enable and configure port channels
    D. Make users sign an Acceptable use Agreement

  • Question 963:

    While testing a new host based firewall configuration a security administrator inadvertently blocks access to localhost which causes problems with applications running on the host. Which of the following addresses refer to localhost?

    A. ::0
    B. 127.0.0.0
    C. 120.0.0.1
    D. 127.0.0/8
    E. 127::0.1

  • Question 964:

    A security analyst has been asked to perform a review of an organization's software development lifecycle. The analyst reports that the lifecycle does not contain a phase in which team members evaluate and provide critical feedback of another developer's code. Which of the following assessment techniques is BEST described in the analyst's report?

    A. Architecture evaluation
    B. Baseline reporting
    C. Whitebox testing
    D. Peer review

  • Question 965:

    A system administrator is responding to a legal order to turn over all logs from all company servers. The system administrator records the system time of all servers to ensure that:

    A. HDD hashes are accurate.
    B. the NTP server works properly.
    C. chain of custody is preserved.
    D. time offset can be calculated.

  • Question 966:

    While performing surveillance activities, an attacker determines that an organization is using 802.1X to secure LAN access. Which of the following attack mechanisms can the attacker utilize to bypass the identified network security?

    A. MAC spoofing
    B. Pharming
    C. Xmas attack
    D. ARP poisoning

  • Question 967:

    The access control list (ACL) for a file on a server is as follows:

    User: rwx

    User: Ann: r-

    User: Joe: r-

    Group: rwx

    Group: sales: r-x

    Other: r-x

    Joe and Ann are members of the Human Resources group. Will Ann and Joe be able to run the file?

    A. No since Ann and Joe are members of the Sales group owner of the file
    B. Yes since the regular permissions override the ACL for the file
    C. No since the ACL overrides the regular permissions for the file
    D. Yes since the regular permissions and the ACL combine to create the effective permissions on the file

  • Question 968:

    A penetration tester is measuring a company's posture on social engineering. The penetration tester sends a phishing email claiming to be from IT asking employees to click a link to update their VPN software immediately. Which of the following reasons would explain why this attack could be successful?

    A. Principle of Scarcity
    B. Principle of Intimidation
    C. Principle of Urgency
    D. Principle of liking

  • Question 969:

    Which of the following can be used to maintain a higher level of security in a SAN by allowing isolation of mis-configurations or faults?

    A. VLAN
    B. Protocol security
    C. Port security
    D. VSAN

  • Question 970:

    A technician has been assigned a service request to investigate a potential vulnerability in the organization's extranet platform. Once the technician performs initial investigative measures, it is determined that the potential vulnerability was a false-alarm. Which of the following actions should the technician take in regards to the findings?

    A. Write up the findings and disable the vulnerability rule in future vulnerability scans
    B. Refer the issue to the server administrator for resolution
    C. Mark the finding as a false-negative and close the service request
    D. Document the results and report the findings according to the incident response plan

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-401 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.