★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW SY0-401 Exam Dumps (PDF & VCE):
Available on: https://www.certleader.com/SY0-401-dumps.html


Our CompTIA CompTIA exam questions are usually in multiple choice which are the same since the real exam. CompTIA CompTIA practice tests are usually available using instant accessibility after paying the particular fees. Download the particular Pdf formats and also print these. Download the examination engine on your PC and practice the particular CompTIA SY0-401 simulated tests. This can generate an almost real setting for you. Your own confidence will be boosted upward and your skills will b enhanced a lot. We are usually sure that you may master all the essential points of the CompTIA SY0-401 exam and help to make great achievements. Superior top quality and ideal value. 100% passing assure and complete money back.

2021 Sep security+ sy0-401 vce:

Q411. A network administrator noticed various chain messages have been received by the company. 

Which of the following security controls would need to be implemented to mitigate this issue? 

A. Anti-spam 

B. Antivirus 

C. Host-based firewalls 

D. Anti-spyware 

Answer: A 

Explanation: A spam filter is a software or hardware solution used to identify and block, filter, or remove unwanted messages sent via email or instant messaging (IM). 


Q412. Which of the following password attacks is MOST likely to crack the largest number of randomly generated passwords? 

A. Hybrid 

B. Birthday attack 

C. Dictionary 

D. Rainbow tables 

Answer: D 

Explanation: 


Q413. A hospital IT department wanted to secure its doctor’s tablets. The IT department wants operating system level security and the ability to secure the data from alteration. Which of the following methods would MOST likely work? 

A. Cloud storage 

B. Removal Media 

C. TPM 

D. Wiping 

Answer: C 

Explanation: 

Trusted Platform Module (TPM) is a hardware-based encryption solution that is embedded in the system’s motherboard and is enabled or disable in BIOS. It helps with hash key generation and stores cryptographic keys, passwords, or certificates. 


Q414. Which of the following types of cryptography should be used when minimal overhead is necessary for a mobile device? 

A. Block cipher 

B. Elliptical curve cryptography 

C. Diffie-Hellman algorithm 

D. Stream cipher 

Answer: B 

Explanation: 

Regarding the performance of ECC applications on various mobile devices, ECC is the most suitable PKC (Public-key cryptography) scheme for use in a constrained environment. Note: Elliptic curve cryptography (ECC) is an approach to public-key cryptography based on the algebraic structure of elliptic curves over finite fields. One of the main benefits in comparison with non-ECC cryptography (with plain Galois fields as a basis) is the same level of security provided by keys of smaller size. Using smaller key size would be faster. 


Q415. A company is looking to improve their security posture by addressing risks uncovered by a recent penetration test. Which of the following risks is MOST likely to affect the business on a day-to-day basis? 

A. Insufficient encryption methods 

B. Large scale natural disasters 

C. Corporate espionage 

D. Lack of antivirus software 

Answer: D 

Explanation: 

The most common threat to computers is computer viruses. A computer can become infected with a virus through day-to-day activities such as browsing web sites or emails. As browsing and opening emails are the most common activities performed by all users, computer viruses represent the most likely risk to a business. 


SY0-401 exam prep

Up to date comptia security+ pdf sy0-401:

Q416. A security analyst is reviewing firewall logs while investigating a compromised web server. The following ports appear in the log: 

22, 25, 445, 1433, 3128, 3389, 6667 

Which of the following protocols was used to access the server remotely? 

A. LDAP 

B. HTTP 

C. RDP 

D. HTTPS 

Answer: C 

Explanation: 

RDP uses TCP port 3389. 


Q417. Which of the following is a measure of biometrics performance which rates the ability of a system to correctly authenticate an authorized user? 

A. Failure to capture 

B. Type II 

C. Mean time to register 

D. Template capacity 

Answer: B 

Explanation: 

Type II, or false acceptance rate (FAR), is the measure of the likelihood that the biometric security system will incorrectly accept an access attempt by an unauthorized user. 


Q418. A security administrator must implement a firewall rule to allow remote employees to VPN onto the company network. The VPN concentrator implements SSL VPN over the standard HTTPS port. Which of the following is the MOST secure ACL to implement at the company's gateway firewall? 

A. PERMIT TCP FROM ANY 443 TO 199.70.5.25 443 

B. PERMIT TCP FROM ANY ANY TO 199.70.5.23 ANY 

C. PERMIT TCP FROM 199.70.5.23 ANY TO ANY ANY 

D. PERMIT TCP FROM ANY 1024-65535 TO 199.70.5.23 443 

Answer: D 

Explanation: 


Q419. A business has set up a Customer Service kiosk within a shopping mall. The location will be staffed by an employee using a laptop during the mall business hours, but there are still concerns regarding the physical safety of the equipment while it is not in use. Which of the following controls would BEST address this security concern? 

A. Host-based firewall 

B. Cable locks 

C. Locking cabinets 

D. Surveillance video 

Answer: C 

Explanation: 


Q420. An administrator has successfully implemented SSL on srv4.comptia.com using wildcard certificate *.comptia.com, and now wishes to implement SSL on srv5.comptia.com. Which of the following files should be copied from srv4 to accomplish this? 

A. certificate, private key, and intermediate certificate chain 

B. certificate, intermediate certificate chain, and root certificate 

C. certificate, root certificate, and certificate signing request 

D. certificate, public key, and certificate signing request 

Answer: A 

Explanation: 

a wildcard certificate is a public key certificate which can be used with multiple subdomains of a domain. In public-key cryptography, the receiver has a private key known only to them; a public key corresponds to it, which they make known to others. The public key can be sent to all other parties; the private key is never divulged. A symmetric algorithm requires that receivers of the message use the same private key. Thus you should copy the certificate, the private key and the intermediate certificate chain from srv4 to srv5.