The Replace Guide To SY0-401 rapidshare Mar 2021

Our CompTIA CompTIA exam questions as well as answers are presented in a pair of versions. One will be Pdf formats which are printable and the various other is Examination Engine software which can be downloadable. Both are free for you personally after purchasing. Stay in your house and download the CompTIA test motor and learn them along with your own tempo. All the required practice materials inside the CompTIA exam braindumps are treasured for you to be able to prepare for that CompTIA SY0-401 exam. Our team associated with certified experts research and create the CompTIA certification exam dumps according to the syllabus of the CompTIA genuine test. The actual SY0-401 practice questions are updated continuously and supplied on the Exambible website timely. You should visit our home web site regularly in order to revise your current CompTIA CompTIA exam practice tests in time.


♥♥ 2021 NEW RECOMMEND ♥♥

Free VCE & PDF File for CompTIA SY0-401 Real Exam (Full Version!)

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW SY0-401 Exam Dumps (PDF & VCE):
Available on: http://www.surepassexam.com/SY0-401-exam-dumps.html

2021 Mar SY0-401 book

Q401. Which of the following is the primary security concern when deploying a mobile device on a network? 

A. Strong authentication 

B. Interoperability 

C. Data security 

D. Cloud storage technique 

Answer:

Explanation: 

Mobile devices, such as laptops, tablet computers, and smartphones, provide security challenges above those of desktop workstations, servers, and such in that they leave the office and this increases the odds of their theft which makes data security a real concern. At a bare minimum, the following security measures should be in place on mobile devices: Screen lock, Strong password, Device encryption, Remote Wipe or Sanitation, voice encryption, GPS tracking, Application control, storage segmentation, asses tracking and device access control. 


Q402. The systems administrator notices that many employees are using passwords that can be easily guessed or are susceptible to brute force attacks. Which of the following would BEST mitigate this risk? 

A. Enforce password rules requiring complexity. 

B. Shorten the maximum life of account passwords. 

C. Increase the minimum password length. 

D. Enforce account lockout policies. 

Answer:

Explanation: 

Password complexity often requires the use of a minimum of three out of four standard character types for a password. The more characters in a password that includes some character complexity, the more resistant it is to brute force attacks. 


Q403. Which of the following is an example of a false negative? 

A. The IDS does not identify a buffer overflow. 

B. Anti-virus identifies a benign application as malware. 

C. Anti-virus protection interferes with the normal operation of an application. 

D. A user account is locked out after the user mistypes the password too many times. 

Answer:

Explanation: 

With a false negative, you are not alerted to a situation when you should be alerted. 


Q404. Configuring key/value pairs on a RADIUS server is associated with deploying which of the following? 

A. WPA2-Enterprise wireless network 

B. DNS secondary zones 

C. Digital certificates 

D. Intrusion detection system 

Answer:

Explanation: 

WPA2-Enterprise is designed for enterprise networks and requires a RADIUS authentication server. 


Q405. When using PGP, which of the following should the end user protect from compromise? (Select TWO). 

A. Private key 

B. CRL details 

C. Public key 

D. Key password 

E. Key escrow 

F. Recovery agent 

Answer: A,D 

Explanation: 

A: In PGP only the private key belonging to the receiver can decrypt the session key. 

PGP combines symmetric-key encryption and public-key encryption. The message is encrypted 

using a symmetric encryption algorithm, which requires a symmetric key. Each symmetric key is 

used only once and is also called a session key. 

D: PGP uses a passphrase to encrypt your private key on your machine. Your private key is 

encrypted on your disk using a hash of your passphrase as the secret key. You use the 

passphrase to decrypt and use your private key. 


Renewal SY0-401 free practice test:

Q406. Jane, a security analyst, is reviewing logs from hosts across the Internet which her company uses to gather data on new malware. Which of the following is being implemented by Jane’s company? 

A. Vulnerability scanner 

B. Honeynet 

C. Protocol analyzer 

D. Port scanner 

Answer:

Explanation: 

The Internet hosts used to gather data on new malware are known as honeypots. A collection of honeypots is known as a honeynet. A honeynet is a network set up with intentional vulnerabilities; its purpose is to invite attack, so that an attacker's activities and methods can be studied and that information used to increase network security. A honeynet contains one or more honey pots, which are computer systems on the Internet expressly set up to attract and "trap" people who attempt to penetrate other people's computer systems. Although the primary purpose of a honeynet is to gather information about attackers' methods and motives, the decoy network can benefit its operator in other ways, for example by diverting attackers from a real network and its resources. The Honeynet Project, a non-profit research organization dedicated to computer security and information sharing, actively promotes the deployment of honeynets. In addition to the honey pots, a honeynet usually has real applications and services so that it seems like a normal network and a worthwhile target. However, because the honeynet doesn't actually serve any authorized users, any attempt to contact the network from without is likely an illicit attempt to breach its security, and any outbound activity is likely evidence that a system has been compromised. For this reason, the suspect information is much more apparent than it would be in an actual network, where it would have to be found amidst all the legitimate network data. Applications within a honeynet are often given names such as "Finances" or "Human Services" to make them sound appealing to the attacker. 

A virtual honeynet is one that, while appearing to be an entire network, resides on a single server. 


Q407. An information bank has been established to store contacts, phone numbers and other records. 

An application running on UNIX would like to connect to this index server using port 88. Which of the following authentication services would this use this port by default? 

A. Kerberos 

B. TACACS+ 

C. Radius 

D. LDAP 

Answer:

Explanation: Kerberos makes use of port 88. 


Q408. In order to maintain oversight of a third party service provider, the company is going to implement a Governance, Risk, and Compliance (GRC) system. This system is promising to provide overall security posture coverage. Which of the following is the MOST important activity that should be considered? 

A. Continuous security monitoring 

B. Baseline configuration and host hardening 

C. Service Level Agreement (SLA) monitoring 

D. Security alerting and trending 

Answer:

Explanation: 

The company is investing in a Governance, Risk, and Compliance (GRC) system to provide overall security posture coverage. This is great for testing the security posture. However, to be effective and ensure the company always has a good security posture, you need to monitor the security continuously. 

Once a baseline security configuration is documented, it is critical to monitor it to see that this baseline is maintained or exceeded. A popular phrase among personal trainers is “that which gets measured gets improved.” Well, in network security, “that which gets monitored gets secure.” Continuous monitoring means exactly that: ongoing monitoring. This may involve regular measurements of network traffic levels, routine evaluations for regulatory compliance, and checks of network security device configurations. 


Q409. The data security manager is notified that a client will be sending encrypted information on optical discs for import into the company database. Once imported, the information is backed up and the discs are no longer needed. Following the import, which of the following is the BEST action for the manager to take? 

A. Wipe the discs and place into inventory for future use 

B. Send the discs back to the client 

C. Contract with a third party to shred the discs 

D. Instruct employees to store the discs in a secure area 

Answer:

Explanation: 


Q410. Which of the following network design elements allows for many internal devices to share one public IP address? 

A. DNAT 

B. PAT 

C. DNS 

D. DMZ 

Answer:

Explanation: 

Port Address Translation (PAT), is an extension to network address translation (NAT) that permits multiple devices on a local area network (LAN) to be mapped to a single public IP address. The goal of PAT is to conserve IP addresses. 

Most home networks use PAT. In such a scenario, the Internet Service Provider (ISP) assigns a single IP address to the home network's router. When Computer X logs on the Internet, the router assigns the client a port number, which is appended to the internal IP address. This, in effect, gives Computer X a unique address. If Computer Z logs on the Internet at the same time, the router assigns it the same local IP address with a different port number. Although both computers are sharing the same public IP address and accessing the Internet at the same time, the router knows exactly which computer to send specific packets to because each computer has a unique internal address.