0% found this document useful (0 votes)
43 views118 pages

Pages From CompTIA - SY0-401

The document discusses study guides for IT certification exams that contain actual exam questions and detailed explanations verified by experts. The guides can be downloaded for free to test their quality. The website certificationking.com offers the guides for purchase and provides pricing and payment options.

Uploaded by

p4mg
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
43 views118 pages

Pages From CompTIA - SY0-401

The document discusses study guides for IT certification exams that contain actual exam questions and detailed explanations verified by experts. The guides can be downloaded for free to test their quality. The website certificationking.com offers the guides for purchase and provides pricing and payment options.

Uploaded by

p4mg
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 118

Looking for Real Exam Questions for IT Certification Exams!

We guarantee you can pass any IT certification exam at your first attempt with just 10-12
hours study of our guides.

Our study guides contain actual exam questions; accurate answers with detailed explanation
verified by experts and all graphics and drag-n-drop exhibits shown just as on the real test.

To test the quality of our guides, you can download the one-fourth portion of any guide from
http://www.certificationking.com absolutely free. You can also download the guides for retired
exams that you might have taken in the past.

For pricing and placing order, please visit http://certificationking.com/order.html


We accept all major credit cards through www.paypal.com

For other payment options and any further query, feel free to mail us at
[email protected]
CompTIA SY0-401 : Practice Test
Topic break down

Topic No. of Questions


Topic 1: Volume A 100
Topic 2: Volume B 100
Topic 3: Volume C 99
Topic 4: Volume D 100
Topic 5: Volume E 100
Topic 6: Volume F 100
Topic 7: Volume G 100
Topic 8: Volume H 99
Topic 9: Volume I 100
Topic 10: Volume J 138

www.CertificationKing.com 2
CompTIA SY0-401 : Practice Test
Topic 1, Volume A

Question No : 1 - (Topic 1)

A company determines a need for additional protection from rogue devices plugging into
physical ports around the building.

Which of the following provides the highest degree of protection from unauthorized wired
network access?

A. Intrusion Prevention Systems


B. MAC filtering
C. Flood guards
D. 802.1x

Answer: D

Question No : 2 - (Topic 1)

A network administrator has been tasked with securing the WLAN. Which of the following
cryptographic products would be used to provide the MOST secure environment for the
WLAN?

A. WPA2 CCMP
B. WPA
C. WPA with MAC filtering
D. WPA2 TKIP

Answer: A

Question No : 3 - (Topic 1)

Which of the following components of an all-in-one security appliance would MOST likely
be configured in order to restrict access to peer-to-peer file sharing websites?

A. Spam filter
B. URL filter
C. Content inspection

www.CertificationKing.com 3
CompTIA SY0-401 : Practice Test
D. Malware inspection

Answer: B

Question No : 4 - (Topic 1)

After a company has standardized to a single operating system, not all servers are immune
to a well-known OS vulnerability. Which of the following solutions would mitigate this issue?

A. Host based firewall


B. Initial baseline configurations
C. Discretionary access control
D. Patch management system

Answer: D

Question No : 5 - (Topic 1)

The Quality Assurance team is testing a new third party developed application. The Quality
team does not have any experience with the application. Which of the following is the team
performing?

A. Grey box testing


B. Black box testing
C. Penetration testing
D. White box testing

Answer: B

Question No : 6 - (Topic 1)

In Kerberos, the Ticket Granting Ticket (TGT) is used for which of the following?

A. Identification
B. Authorization
C. Authentication
D. Multifactor authentication

www.CertificationKing.com 4
CompTIA SY0-401 : Practice Test
Answer: C

Question No : 7 - (Topic 1)

A compromised workstation utilized in a Distributed Denial of Service (DDOS) attack has


been removed from the network and an image of the hard drive has been created.
However, the system administrator stated that the system was left unattended for several
hours before the image was created. In the event of a court case, which of the following is
likely to be an issue with this incident?

A. Eye Witness
B. Data Analysis of the hard drive
C. Chain of custody
D. Expert Witness

Answer: C

Question No : 8 - (Topic 1)

Which of the following ciphers would be BEST used to encrypt streaming video?

A. RSA
B. RC4
C. SHA1
D. 3DES

Answer: B

Question No : 9 - (Topic 1)

A network engineer is designing a secure tunneled VPN. Which of the following protocols
would be the MOST secure?

A. IPsec
B. SFTP
C. BGP
D. PPTP

www.CertificationKing.com 5
CompTIA SY0-401 : Practice Test
Answer: A

Question No : 10 - (Topic 1)

The information security technician wants to ensure security controls are deployed and
functioning as intended to be able to maintain an appropriate security posture. Which of the
following security techniques is MOST appropriate to do this?

A. Log audits
B. System hardening
C. Use IPS/IDS
D. Continuous security monitoring

Answer: D

Question No : 11 - (Topic 1)

A company is trying to implement physical deterrent controls to improve the overall security
posture of their data center. Which of the following BEST meets their goal?

A. Visitor logs
B. Firewall
C. Hardware locks
D. Environmental monitoring

Answer: C

Question No : 12 - (Topic 1)

Deploying a wildcard certificate is one strategy to:

A. Secure the certificate’s private key.


B. Increase the certificate’s encryption key length.
C. Extend the renewal date of the certificate.
D. Reduce the certificate management burden.

Answer: D

www.CertificationKing.com 6
CompTIA SY0-401 : Practice Test

Question No : 13 - (Topic 1)

A small company can only afford to buy an all-in-one wireless router/switch. The company
has 3 wireless BYOD users and 2 web servers without wireless access. Which of the
following should the company configure to protect the servers from the user devices?
(Select TWO).

A. Deny incoming connections to the outside router interface.


B. Change the default HTTP port
C. Implement EAP-TLS to establish mutual authentication
D. Disable the physical switch ports
E. Create a server VLAN
F. Create an ACL to access the server

Answer: E,F

Question No : 14 - (Topic 1)

A system security analyst using an enterprise monitoring tool notices an unknown internal
host exfiltrating files to several foreign IP addresses. Which of the following would be an
appropriate mitigation technique?

A. Disabling unnecessary accounts


B. Rogue machine detection
C. Encrypting sensitive files
D. Implementing antivirus

Answer: B

Question No : 15 - (Topic 1)

Which of the following should an administrator implement to research current attack


methodologies?

A. Design reviews
B. Honeypot

www.CertificationKing.com 7
CompTIA SY0-401 : Practice Test
C. Vulnerability scanner
D. Code reviews

Answer: B

Question No : 16 - (Topic 1)

A company’s employees were victims of a spear phishing campaign impersonating the


CEO. The company would now like to implement a solution to improve the overall security
posture by assuring their employees that email originated from the CEO. Which of the
following controls could they implement to BEST meet this goal?

A. Spam filter
B. Digital signatures
C. Antivirus software
D. Digital certificates

Answer: B

Question No : 17 - (Topic 1)

A datacenter requires that staff be able to identify whether or not items have been removed
from the facility. Which of the following controls will allow the organization to provide
automated notification of item removal?

A. CCTV
B. Environmental monitoring
C. RFID
D. EMI shielding

Answer: C

Question No : 18 - (Topic 1)

Which of the following is being tested when a company’s payroll server is powered off for
eight hours?

www.CertificationKing.com 8
CompTIA SY0-401 : Practice Test
A. Succession plan
B. Business impact document
C. Continuity of operations plan
D. Risk assessment plan

Answer: C

Question No : 19 - (Topic 1)

During the analysis of a PCAP file, a security analyst noticed several communications with
a remote server on port 53. Which of the following protocol types is observed in this traffic?

A. FTP
B. DNS
C. Email
D. NetBIOS

Answer: B

Question No : 20 - (Topic 1)

The concept of rendering data passing between two points over an IP based network
impervious to all but the most sophisticated advanced persistent threats is BEST
categorized as which of the following?

A. Stream ciphers
B. Transport encryption
C. Key escrow
D. Block ciphers

Answer: B

Question No : 21 - (Topic 1)

A security analyst, Ann, is reviewing an IRC channel and notices that a malicious exploit
has been created for a frequently used application. She notifies the software vendor and
asks them for remediation steps, but is alarmed to find that no patches are available to
mitigate this vulnerability.

www.CertificationKing.com 9
CompTIA SY0-401 : Practice Test
Which of the following BEST describes this exploit?

A. Malicious insider threat


B. Zero-day
C. Client-side attack
D. Malicious add-on

Answer: B

Question No : 22 - (Topic 1)

The helpdesk reports increased calls from clients reporting spikes in malware infections on
their systems. Which of the following phases of incident response is MOST appropriate as
a FIRST response?

A. Recovery
B. Follow-up
C. Validation
D. Identification
E. Eradication
F. Containment

Answer: D

Question No : 23 - (Topic 1)

Which of the following is a security concern regarding users bringing personally-owned


devices that they connect to the corporate network?

A. Cross-platform compatibility issues between personal devices and server-based


applications
B. Lack of controls in place to ensure that the devices have the latest system patches and
signature files
C. Non-corporate devices are more difficult to locate when a user is terminated
D. Non-purchased or leased equipment may cause failure during the audits of company-
owned assets

Answer: B

www.CertificationKing.com 10
CompTIA SY0-401 : Practice Test

Question No : 24 - (Topic 1)

During the information gathering stage of a deploying role-based access control model,
which of the following information is MOST likely required?

A. Conditional rules under which certain systems may be accessed


B. Matrix of job titles with required access privileges
C. Clearance levels of all company personnel
D. Normal hours of business operation

Answer: B

Question No : 25 - (Topic 1)

Which of the following can result in significant administrative overhead from incorrect
reporting?

A. Job rotation
B. Acceptable usage policies
C. False positives
D. Mandatory vacations

Answer: C

Question No : 26 - (Topic 1)

Which of the following controls would allow a company to reduce the exposure of sensitive
systems from unmanaged devices on internal networks?

A. 802.1x
B. Data encryption
C. Password strength
D. BGP

Answer: A

Question No : 27 - (Topic 1)

www.CertificationKing.com 11
CompTIA SY0-401 : Practice Test
Identifying residual risk is MOST important to which of the following concepts?

A. Risk deterrence
B. Risk acceptance
C. Risk mitigation
D. Risk avoidance

Answer: B

Question No : 28 - (Topic 1)

A company is preparing to decommission an offline, non-networked root certificate server.


Before sending the server’s drives to be destroyed by a contracted company, the Chief
Security Officer (CSO) wants to be certain that the data will not be accessed. Which of the
following, if implemented, would BEST reassure the CSO? (Select TWO).

A. Disk hashing procedures


B. Full disk encryption
C. Data retention policies
D. Disk wiping procedures
E. Removable media encryption

Answer: B,D

Question No : 29 - (Topic 1)

On Monday, all company employees report being unable to connect to the corporate
wireless network, which uses 802.1x with PEAP. A technician verifies that no configuration
changes were made to the wireless network and its supporting infrastructure, and that
there are no outages.

Which of the following is the MOST likely cause for this issue?

A. Too many incorrect authentication attempts have caused users to be temporarily


disabled.
B. The DNS server is overwhelmed with connections and is unable to respond to queries.
C. The company IDS detected a wireless attack and disabled the wireless network.
D. The Remote Authentication Dial-In User Service server certificate has expired.

www.CertificationKing.com 12
CompTIA SY0-401 : Practice Test
Answer: D

Question No : 30 - (Topic 1)

Which of the following protocols operates at the HIGHEST level of the OSI model?

A. ICMP
B. IPSec
C. SCP
D. TCP

Answer: C

Question No : 31 - (Topic 1)

A security researcher wants to reverse engineer an executable file to determine if it is


malicious. The file was found on an underused server and appears to contain a zero-day
exploit. Which of the following can the researcher do to determine if the file is malicious in
nature?

A. TCP/IP socket design review


B. Executable code review
C. OS Baseline comparison
D. Software architecture review

Answer: C

Question No : 32 - (Topic 1)

Which of the following ports is used for SSH, by default?

A. 23
B. 32
C. 12
D. 22

Answer: D

www.CertificationKing.com 13
CompTIA SY0-401 : Practice Test

Question No : 33 - (Topic 1)

A security team has established a security awareness program. Which of the following
would BEST prove the success of the program?

A. Policies
B. Procedures
C. Metrics
D. Standards

Answer: C

Question No : 34 - (Topic 1)

A security administrator discovers an image file that has several plain text documents
hidden in the file. Which of the following security goals is met by camouflaging data inside
of other files?

A. Integrity
B. Confidentiality
C. Steganography
D. Availability

Answer: C

Question No : 35 - (Topic 1)

A company has proprietary mission critical devices connected to their network which are
configured remotely by both employees and approved customers. The administrator wants
to monitor device security without changing their baseline configuration. Which of the
following should be implemented to secure the devices without risking availability?

A. Host-based firewall
B. IDS
C. IPS
D. Honeypot

www.CertificationKing.com 14
CompTIA SY0-401 : Practice Test
Answer: B

Question No : 36 - (Topic 1)

Joe, a user, wants to send an encrypted email to Ann. Which of the following will Ann need
to use to verify the validity’s of Joe’s certificate? (Select TWO).

A. The CA’s public key


B. Joe’s private key
C. Ann’s public key
D. The CA’s private key
E. Joe’s public key
F. Ann’s private key

Answer: A,E

Question No : 37 - (Topic 1)

Which of the following network design elements allows for many internal devices to share
one public IP address?

A. DNAT
B. PAT
C. DNS
D. DMZ

Answer: B

Question No : 38 - (Topic 1)

Users can authenticate to a company's web applications using their credentials from a
popular social media site. Which of the following poses the greatest risk with this
integration?

A. Malicious users can exploit local corporate credentials with their social media credentials
B. Changes to passwords on the social media site can be delayed from replicating to the
company

www.CertificationKing.com 15
CompTIA SY0-401 : Practice Test
C. Data loss from the corporate servers can create legal liabilities with the social media site
D. Password breaches to the social media site affect the company application as well

Answer: D

Question No : 39 - (Topic 1)

A security manager must remain aware of the security posture of each system. Which of
the following supports this requirement?

A. Training staff on security policies


B. Establishing baseline reporting
C. Installing anti-malware software
D. Disabling unnecessary accounts/services

Answer: B

Question No : 40 - (Topic 1)

A security administrator has concerns about new types of media which allow for the mass
distribution of personal comments to a select group of people. To mitigate the risks
involved with this media, employees should receive training on which of the following?

A. Peer to Peer
B. Mobile devices
C. Social networking
D. Personally owned devices

Answer: C

Question No : 41 - (Topic 1)

A user attempting to log on to a workstation for the first time is prompted for the following
information before being granted access: username, password, and a four-digit security pin
that was mailed to him during account registration. This is an example of which of the
following?

www.CertificationKing.com 16
CompTIA SY0-401 : Practice Test
A. Dual-factor authentication
B. Multifactor authentication
C. Single factor authentication
D. Biometric authentication

Answer: C

Question No : 42 - (Topic 1)

A bank has a fleet of aging payment terminals used by merchants for transactional
processing. The terminals currently support single DES but require an upgrade in order to
be compliant with security standards. Which of the following is likely to be the simplest
upgrade to the aging terminals which will improve in-transit protection of transactional
data?

A. AES
B. 3DES
C. RC4
D. WPA2

Answer: B

Question No : 43 - (Topic 1)

The security administrator needs to manage traffic on a layer 3 device to support FTP from
a new remote site. Which of the following would need to be implemented?

A. Implicit deny
B. VLAN management
C. Port security
D. Access control lists

Answer: D

Question No : 44 - (Topic 1)

Which of the following would a security administrator implement in order to identify a


problem between two systems that are not communicating properly?

www.CertificationKing.com 17
CompTIA SY0-401 : Practice Test
A. Protocol analyzer
B. Baseline report
C. Risk assessment
D. Vulnerability scan

Answer: A

Question No : 45 - (Topic 1)

A recent audit has discovered that at the time of password expiration clients are able to
recycle the previous credentials for authentication. Which of the following controls should
be used together to prevent this from occurring? (Select TWO).

A. Password age
B. Password hashing
C. Password complexity
D. Password history
E. Password length

Answer: A,D

Question No : 46 - (Topic 1)

When considering a vendor-specific vulnerability in critical industrial control systems which


of the following techniques supports availability?

A. Deploying identical application firewalls at the border


B. Incorporating diversity into redundant design
C. Enforcing application white lists on the support workstations
D. Ensuring the systems’ anti-virus definitions are up-to-date

Answer: B

Question No : 47 - (Topic 1)

A network administrator is configuring access control for the sales department which has
high employee turnover. Which of the following is BEST suited when assigning user rights
to individuals in the sales department?

www.CertificationKing.com 18
CompTIA SY0-401 : Practice Test
A. Time of day restrictions
B. Group based privileges
C. User assigned privileges
D. Domain admin restrictions

Answer: B

Question No : 48 - (Topic 1)

Which of the following risk concepts requires an organization to determine the number of
failures per year?

A. SLE
B. ALE
C. MTBF
D. Quantitative analysis

Answer: B

Question No : 49 - (Topic 1)

Which of the following is the primary security concern when deploying a mobile device on a
network?

A. Strong authentication
B. Interoperability
C. Data security
D. Cloud storage technique

Answer: C

Question No : 50 - (Topic 1)

A software developer is responsible for writing the code on an accounting application.


Another software developer is responsible for developing code on a system in human
resources. Once a year they have to switch roles for several weeks.

www.CertificationKing.com 19
CompTIA SY0-401 : Practice Test
Which of the following practices is being implemented?

A. Mandatory vacations
B. Job rotation
C. Least privilege
D. Separation of duties

Answer: B

Question No : 51 - (Topic 1)

A security administrator has concerns regarding employees saving data on company


provided mobile devices. Which of the following would BEST address the administrator’s
concerns?

A. Install a mobile application that tracks read and write functions on the device.
B. Create a company policy prohibiting the use of mobile devices for personal use.
C. Enable GPS functionality to track the location of the mobile devices.
D. Configure the devices so that removable media use is disabled.

Answer: D

Question No : 52 - (Topic 1)

A security administrator is segregating all web-facing server traffic from the internal network
and restricting it to a single interface on a firewall. Which of the following BEST describes
this new network?

A. VLAN
B. Subnet
C. VPN
D. DMZ

Answer: D

Question No : 53 - (Topic 1)

www.CertificationKing.com 20
CompTIA SY0-401 : Practice Test
Ann would like to forward some Personal Identifiable Information to her HR department by
email, but she is worried about the confidentiality of the information. Which of the following
will accomplish this task securely?

A. Digital Signatures
B. Hashing
C. Secret Key
D. Encryption

Answer: D

Question No : 54 - (Topic 1)

Maintenance workers find an active network switch hidden above a dropped-ceiling tile in
the CEO’s office with various connected cables from the office. Which of the following
describes the type of attack that was occurring?

A. Spear phishing
B. Packet sniffing
C. Impersonation
D. MAC flooding

Answer: B

Question No : 55 - (Topic 1)

Joe, the system administrator, has been asked to calculate the Annual Loss Expectancy
(ALE) for a $5,000 server, which often crashes. In the past year, the server has crashed 10
times, requiring a system reboot to recover with only 10% loss of data or function. Which of
the following is the ALE of this server?

A. $500
B. $5,000
C. $25,000
D. $50,000

Answer: B

www.CertificationKing.com 21
CompTIA SY0-401 : Practice Test

Question No : 56 - (Topic 1)

The Chief Technical Officer (CTO) has been informed of a potential fraud committed by a
database administrator performing several other job functions within the company. Which
of the following is the BEST method to prevent such activities in the future?

A. Job rotation
B. Separation of duties
C. Mandatory Vacations
D. Least Privilege

Answer: B

Question No : 57 - (Topic 1)

A security administrator wants to perform routine tests on the network during working hours
when certain applications are being accessed by the most people. Which of the following
would allow the security administrator to test the lack of security controls for those
applications with the least impact to the system?

A. Penetration test
B. Vulnerability scan
C. Load testing
D. Port scanner

Answer: B

Question No : 58 - (Topic 1)

The BEST methods for a web developer to prevent the website application code from being
vulnerable to cross-site request forgery (XSRF) are to: (Select TWO).

A. permit redirection to Internet-facing web URLs.


B. ensure all HTML tags are enclosed in angle brackets, e.g., ”<” and “>”.
C. validate and filter input on the server side and client side.
D. use a web proxy to pass website requests between the user and the application.
E. restrict and sanitize use of special characters in input and URLs.

Answer: C,E

www.CertificationKing.com 22
CompTIA SY0-401 : Practice Test

Question No : 59 - (Topic 1)

A network administrator is responsible for securing applications against external attacks.


Every month, the underlying operating system is updated. There is no process in place for
other software updates.

Which of the following processes could MOST effectively mitigate these risks?

A. Application hardening
B. Application change management
C. Application patch management
D. Application firewall review

Answer: C

Question No : 60 - (Topic 1)

Due to issues with building keys being duplicated and distributed, a security administrator
wishes to change to a different security control regarding a restricted area. The goal is to
provide access based upon facial recognition. Which of the following will address this
requirement?

A. Set up mantraps to avoid tailgating of approved users.


B. Place a guard at the entrance to approve access.
C. Install a fingerprint scanner at the entrance.
D. Implement proximity readers to scan users’ badges.

Answer: B

Question No : 61 - (Topic 1)

Which of the following is used to verify data integrity?

A. SHA
B. 3DES

www.CertificationKing.com 23
CompTIA SY0-401 : Practice Test
C. AES
D. RSA

Answer: A

Question No : 62 - (Topic 1)

An administrator has a network subnet dedicated to a group of users. Due to concerns


regarding data and network security, the administrator desires to provide network access
for this group only. Which of the following would BEST address this desire?

A. Install a proxy server between the users’ computers and the switch to filter inbound
network traffic.
B. Block commonly used ports and forward them to higher and unused port numbers.
C. Configure the switch to allow only traffic from computers based upon their physical
address.
D. Install host-based intrusion detection software to monitor incoming DHCP Discover
requests.

Answer: C

Question No : 63 - (Topic 1)

During which of the following phases of the Incident Response process should a security
administrator define and implement general defense against malware?

A. Lessons Learned
B. Preparation
C. Eradication
D. Identification

Answer: B

Question No : 64 - (Topic 1)

Three of the primary security control types that can be implemented are.

www.CertificationKing.com 24
CompTIA SY0-401 : Practice Test
A. Supervisory, subordinate, and peer.
B. Personal, procedural, and legal.
C. Operational, technical, and management.
D. Mandatory, discretionary, and permanent.

Answer: C

Question No : 65 - (Topic 1)

A server with the IP address of 10.10.2.4 has been having intermittent connection issues.
The logs show repeated connection attempts from the following IPs:

10.10.3.16

10.10.3.23

212.178.24.26

217.24.94.83

These attempts are overloading the server to the point that it cannot respond to traffic.
Which of the following attacks is occurring?

A. XSS
B. DDoS
C. DoS
D. Xmas

Answer: B

Question No : 66 - (Topic 1)

A company needs to receive data that contains personally identifiable information. The
company requires both the transmission and data at rest to be encrypted. Which of the
following achieves this goal? (Select TWO).

A. SSH
B. TFTP
C. NTLM
D. TKIP

www.CertificationKing.com 25
CompTIA SY0-401 : Practice Test
E. SMTP
F. PGP/GPG

Answer: A,F

Question No : 67 - (Topic 1)

An achievement in providing worldwide Internet security was the signing of certificates


associated with which of the following protocols?

A. TCP/IP
B. SSL
C. SCP
D. SSH

Answer: B

Question No : 68 - (Topic 1)

Which of the following can be implemented in hardware or software to protect a web server
from cross-site scripting attacks?

A. Intrusion Detection System


B. Flood Guard Protection
C. Web Application Firewall
D. URL Content Filter

Answer: C

Question No : 69 - (Topic 1)

After analyzing and correlating activity from multiple sensors, the security administrator has
determined that a group of very well organized individuals from an enemy country is
responsible for various attempts to breach the company network, through the use of very
sophisticated and targeted attacks. Which of the following is this an example of?

A. Privilege escalation

www.CertificationKing.com 26
CompTIA SY0-401 : Practice Test
B. Advanced persistent threat
C. Malicious insider threat
D. Spear phishing

Answer: B

Question No : 70 - (Topic 1)

A recent spike in virus detections has been attributed to end-users visiting


www.compnay.com. The business has an established relationship with an organization
using the URL of www.company.com but not with the site that has been causing the
infections. Which of the following would BEST describe this type of attack?

A. Typo squatting
B. Session hijacking
C. Cross-site scripting
D. Spear phishing

Answer: A

Question No : 71 - (Topic 1)

Which of the following is BEST used to capture and analyze network traffic between hosts
on the same network segment?

A. Protocol analyzer
B. Router
C. Firewall
D. HIPS

Answer: A

Question No : 72 - (Topic 1)

Which of the following is BEST at blocking attacks and providing security at layer 7 of the
OSI model?

www.CertificationKing.com 27
CompTIA SY0-401 : Practice Test
A. WAF
B. NIDS
C. Routers
D. Switches

Answer: A

Question No : 73 - (Topic 1)

A malicious person gained access to a datacenter by ripping the proximity badge reader off
the wall near the datacenter entrance. This caused the electronic locks on the datacenter
door to release because the:

A. badge reader was improperly installed.


B. system was designed to fail open for life-safety.
C. system was installed in a fail closed configuration.
D. system used magnetic locks and the locks became demagnetized.

Answer: B

Question No : 74 - (Topic 1)

Joe, a user, wants to send an encrypted email to Ann. Which of the following will Ann need
to use to verify that the email came from Joe and decrypt it? (Select TWO).

A. The CA’s public key


B. Ann’s public key
C. Joe’s private key
D. Ann’s private key
E. The CA’s private key
F. Joe’s public key

Answer: D,F

Question No : 75 - (Topic 1)

Which of the following is true about input validation in a client-server architecture, when
data integrity is critical to the organization?

www.CertificationKing.com 28
CompTIA SY0-401 : Practice Test
A. It should be enforced on the client side only.
B. It must be protected by SSL encryption.
C. It must rely on the user’s knowledge of the application.
D. It should be performed on the server side.

Answer: D

Question No : 76 - (Topic 1)

A technician wants to implement a dual factor authentication system that will enable the
organization to authorize access to sensitive systems on a need-to-know basis. Which of
the following should be implemented during the authorization stage?

A. Biometrics
B. Mandatory access control
C. Single sign-on
D. Role-based access control

Answer: A

Question No : 77 - (Topic 1)

Jane, a security administrator, needs to implement a secure wireless authentication


method that uses a remote RADIUS server for authentication.

Which of the following is an authentication method Jane should use?

A. WPA2-PSK
B. WEP-PSK
C. CCMP
D. LEAP

Answer: D

Question No : 78 - (Topic 1)

Which of the following functions provides an output which cannot be reversed and converts

www.CertificationKing.com 29
CompTIA SY0-401 : Practice Test
data into a string of characters?

A. Hashing
B. Stream ciphers
C. Steganography
D. Block ciphers

Answer: A

Question No : 79 - (Topic 1)

Which of the following encrypts data a single bit at a time?

A. Stream cipher
B. Steganography
C. 3DES
D. Hashing

Answer: A

Question No : 80 - (Topic 1)

Due to hardware limitation, a technician must implement a wireless encryption algorithm


that uses the RC4 protocol. Which of the following is a wireless encryption solution that the
technician should implement while ensuring the STRONGEST level of security?

A. WPA2-AES
B. 802.11ac
C. WPA-TKIP
D. WEP

Answer: C

Question No : 81 - (Topic 1)

A bank has recently deployed mobile tablets to all loan officers for use at customer sites.
Which of the following would BEST prevent the disclosure of customer data in the event

www.CertificationKing.com 30
CompTIA SY0-401 : Practice Test
that a tablet is lost or stolen?

A. Application control
B. Remote wiping
C. GPS
D. Screen-locks

Answer: B

Question No : 82 - (Topic 1)

Which of the following technical controls is BEST used to define which applications a user
can install and run on a company issued mobile device?

A. Authentication
B. Blacklisting
C. Whitelisting
D. Acceptable use policy

Answer: C

Question No : 83 - (Topic 1)

Which of the following can a security administrator implement on mobile devices that will
help prevent unwanted people from viewing the data if the device is left unattended?

A. Screen lock
B. Voice encryption
C. GPS tracking
D. Device encryption

Answer: A

Question No : 84 - (Topic 1)

Computer evidence at a crime scene is documented with a tag stating who had possession
of the evidence at a given time.

www.CertificationKing.com 31
CompTIA SY0-401 : Practice Test
Which of the following does this illustrate?

A. System image capture


B. Record time offset
C. Order of volatility
D. Chain of custody

Answer: D

Question No : 85 - (Topic 1)

A Chief Information Security Officer (CISO) wants to implement two-factor authentication


within the company. Which of the following would fulfill the CISO’s requirements?

A. Username and password


B. Retina scan and fingerprint scan
C. USB token and PIN
D. Proximity badge and token

Answer: C

Question No : 86 - (Topic 1)

Which of the following implementation steps would be appropriate for a public wireless hot-
spot?

A. Reduce power level


B. Disable SSID broadcast
C. Open system authentication
D. MAC filter

Answer: C

Question No : 87 - (Topic 1)

Which of the following would BEST deter an attacker trying to brute force 4-digit PIN
numbers to access an account at a bank teller machine?

www.CertificationKing.com 32
CompTIA SY0-401 : Practice Test
A. Account expiration settings
B. Complexity of PIN
C. Account lockout settings
D. PIN history requirements

Answer: C

Question No : 88 - (Topic 1)

After a number of highly publicized and embarrassing customer data leaks as a result of
social engineering attacks by phone, the Chief Information Officer (CIO) has decided user
training will reduce the risk of another data leak. Which of the following would be MOST
effective in reducing data leaks in this situation?

A. Information Security Awareness


B. Social Media and BYOD
C. Data Handling and Disposal
D. Acceptable Use of IT Systems

Answer: A

Question No : 89 - (Topic 1)

A company is trying to limit the risk associated with the use of unapproved USB devices to
copy documents. Which of the following would be the BEST technology control to use in
this scenario?

A. Content filtering
B. IDS
C. Audit logs
D. DLP

Answer: D

Question No : 90 - (Topic 1)

Which of the following has a storage root key?

www.CertificationKing.com 33
CompTIA SY0-401 : Practice Test
A. HSM
B. EFS
C. TPM
D. TKIP

Answer: C

Question No : 91 - (Topic 1)

Which of the following preventative controls would be appropriate for responding to a


directive to reduce the attack surface of a specific host?

A. Installing anti-malware
B. Implementing an IDS
C. Taking a baseline configuration
D. Disabling unnecessary services

Answer: D

Question No : 92 - (Topic 1)

Which of the following means of wireless authentication is easily vulnerable to spoofing?

A. MAC Filtering
B. WPA - LEAP
C. WPA - PEAP
D. Enabled SSID

Answer: A

Question No : 93 - (Topic 1)

A merchant acquirer has the need to store credit card numbers in a transactional database
in a high performance environment. Which of the following BEST protects the credit card
data?

A. Database field encryption

www.CertificationKing.com 34
CompTIA SY0-401 : Practice Test
B. File-level encryption
C. Data loss prevention system
D. Full disk encryption

Answer: A

Question No : 94 - (Topic 1)

A system administrator is configuring UNIX accounts to authenticate against an external


server. The configuration file asks for the following information DC=ServerName and
DC=COM. Which of the following authentication services is being used?

A. RADIUS
B. SAML
C. TACACS+
D. LDAP

Answer: D

Question No : 95 - (Topic 1)

By default, which of the following uses TCP port 22? (Select THREE).

A. FTPS
B. STELNET
C. TLS
D. SCP
E. SSL
F. HTTPS
G. SSH
H. SFTP

Answer: D,G,H

Question No : 96 - (Topic 1)

Which of the following was based on a previous X.500 specification and allows either
unencrypted authentication or encrypted authentication through the use of TLS?

www.CertificationKing.com 35
CompTIA SY0-401 : Practice Test
A. Kerberos
B. TACACS+
C. RADIUS
D. LDAP

Answer: D

Question No : 97 - (Topic 1)

Access mechanisms to data on encrypted USB hard drives must be implemented correctly
otherwise:

A. user accounts may be inadvertently locked out.


B. data on the USB drive could be corrupted.
C. data on the hard drive will be vulnerable to log analysis.
D. the security controls on the USB drive can be bypassed.

Answer: D

Question No : 98 - (Topic 1)

A security technician is attempting to improve the overall security posture of an internal


mail server. Which of the following actions would BEST accomplish this goal?

A. Monitoring event logs daily


B. Disabling unnecessary services
C. Deploying a content filter on the network
D. Deploy an IDS on the network

Answer: B

Question No : 99 - (Topic 1)

An administrator discovers that many users have used their same passwords for years
even though the network requires that the passwords be changed every six weeks. Which
of the following, when used together, would BEST prevent users from reusing their existing
password? (Select TWO).

www.CertificationKing.com 36
CompTIA SY0-401 : Practice Test
A. Length of password
B. Password history
C. Minimum password age
D. Password expiration
E. Password complexity
F. Non-dictionary words

Answer: B,C

Question No : 100 - (Topic 1)

Which of the following is a step in deploying a WPA2-Enterprise wireless network?

A. Install a token on the authentication server


B. Install a DHCP server on the authentication server
C. Install an encryption key on the authentication server
D. Install a digital certificate on the authentication server

Answer: D

Topic 2, Volume B

Question No : 101 - (Topic 2)

An administrator wants to establish a WiFi network using a high gain directional antenna
with a narrow radiation pattern to connect two buildings separated by a very long distance.
Which of the following antennas would be BEST for this situation?

A. Dipole
B. Yagi
C. Sector
D. Omni

Answer: B

Question No : 102 - (Topic 2)

www.CertificationKing.com 37
CompTIA SY0-401 : Practice Test
Ann, a security administrator, has concerns regarding her company’s wireless network. The
network is open and available for visiting prospective clients in the conference room, but
she notices that many more devices are connecting to the network than should be.

Which of the following would BEST alleviate Ann’s concerns with minimum disturbance of
current functionality for clients?

A. Enable MAC filtering on the wireless access point.


B. Configure WPA2 encryption on the wireless access point.
C. Lower the antenna’s broadcasting power.
D. Disable SSID broadcasting.

Answer: C

Question No : 103 - (Topic 2)

Ann, a security administrator, wishes to replace their RADIUS authentication with a more
secure protocol, which can utilize EAP. Which of the following would BEST fit her
objective?

A. CHAP
B. SAML
C. Kerberos
D. Diameter

Answer: D

Question No : 104 - (Topic 2)

Joe, an employee, was escorted from the company premises due to suspicion of revealing
trade secrets to a competitor. Joe had already been working for two hours before leaving
the premises.

A security technician was asked to prepare a report of files that had changed since last
night’s integrity scan.

Which of the following could the technician use to prepare the report? (Select TWO).

www.CertificationKing.com 38
CompTIA SY0-401 : Practice Test
A. PGP
B. MD5
C. ECC
D. AES
E. Blowfish
F. HMAC

Answer: B,F

Question No : 105 - (Topic 2)

Joe, a user, reports to the system administrator that he is receiving an error stating his
certificate has been revoked. Which of the following is the name of the database repository
for these certificates?

A. CSR
B. OSCP
C. CA
D. CRL

Answer: D

Question No : 106 - (Topic 2)

A software company has completed a security assessment. The assessment states that
the company should implement fencing and lighting around the property. Additionally, the
assessment states that production releases of their software should be digitally signed.
Given the recommendations, the company was deficient in which of the following core
security areas? (Select TWO).

A. Fault tolerance
B. Encryption
C. Availability
D. Integrity
E. Safety
F. Confidentiality

Answer: D,E

www.CertificationKing.com 39
CompTIA SY0-401 : Practice Test

Question No : 107 - (Topic 2)

Ann, a sales manager, successfully connected her company-issued smartphone to the


wireless network in her office without supplying a username/password combination. Upon
disconnecting from the wireless network, she attempted to connect her personal tablet
computer to the same wireless network and could not connect.

Which of the following is MOST likely the reason?

A. The company wireless is using a MAC filter.


B. The company wireless has SSID broadcast disabled.
C. The company wireless is using WEP.
D. The company wireless is using WPA2.

Answer: A

Question No : 108 - (Topic 2)

Which of the following types of authentication packages user credentials in a ticket?

A. Kerberos
B. LDAP
C. TACACS+
D. RADIUS

Answer: A

Question No : 109 - (Topic 2)

A security administrator wishes to increase the security of the wireless network. Which of
the following BEST addresses this concern?

A. Change the encryption from TKIP-based to CCMP-based.


B. Set all nearby access points to operate on the same channel.
C. Configure the access point to use WEP instead of WPA2.
D. Enable all access points to broadcast their SSIDs.

www.CertificationKing.com 40
CompTIA SY0-401 : Practice Test
Answer: A

Question No : 110 - (Topic 2)

A new intern was assigned to the system engineering department, which consists of the
system architect and system software developer’s teams. These two teams have separate
privileges. The intern requires privileges to view the system architectural drawings and
comment on some software development projects. Which of the following methods should
the system administrator implement?

A. Group based privileges


B. Generic account prohibition
C. User access review
D. Credential management

Answer: A

Question No : 111 - (Topic 2)

An administrator needs to submit a new CSR to a CA. Which of the following is a valid
FIRST step?

A. Generate a new private key based on AES.


B. Generate a new public key based on RSA.
C. Generate a new public key based on AES.
D. Generate a new private key based on RSA.

Answer: D

Question No : 112 - (Topic 2)

Which of the following is the GREATEST security risk of two or more companies working
together under a Memorandum of Understanding?

A. Budgetary considerations may not have been written into the MOU, leaving an entity to
absorb more cost than intended at signing.
B. MOUs have strict policies in place for services performed between the entities and the

www.CertificationKing.com 41
CompTIA SY0-401 : Practice Test
penalties for compromising a partner are high.
C. MOUs are generally loose agreements and therefore may not have strict guidelines in
place to protect sensitive data between the two entities.
D. MOUs between two companies working together cannot be held to the same legal
standards as SLAs.

Answer: C

Question No : 113 - (Topic 2)

A security administrator must implement a network authentication solution which will


ensure encryption of user credentials when users enter their username and password to
authenticate to the network.

Which of the following should the administrator implement?

A. WPA2 over EAP-TTLS


B. WPA-PSK
C. WPA2 with WPS
D. WEP over EAP-PEAP

Answer: D

Question No : 114 - (Topic 2)

After entering the following information into a SOHO wireless router, a mobile device’s user
reports being unable to connect to the network:

PERMIT 0A: D1: FA. B1: 03: 37

DENY 01: 33: 7F: AB: 10: AB

Which of the following is preventing the device from connecting?

A. WPA2-PSK requires a supplicant on the mobile device.


B. Hardware address filtering is blocking the device.
C. TCP/IP Port filtering has been implemented on the SOHO router.
D. IP address filtering has disabled the device from connecting.

www.CertificationKing.com 42
CompTIA SY0-401 : Practice Test
Answer: B

Question No : 115 - (Topic 2)

A recently installed application update caused a vital application to crash during the middle
of the workday. The application remained down until a previous version could be reinstalled
on the server, and this resulted in a significant loss of data and revenue.

Which of the following could BEST prevent this issue from occurring again?

A. Application configuration baselines


B. Application hardening
C. Application access controls
D. Application patch management

Answer: D

Question No : 116 - (Topic 2)

Acme Corp has selectively outsourced proprietary business processes to ABC Services.
Due to some technical issues, ABC services wants to send some of Acme Corp’s debug
data to a third party vendor for problem resolution. Which of the following MUST be
considered prior to sending data to a third party?

A. The data should be encrypted prior to transport


B. This would not constitute unauthorized data sharing
C. This may violate data ownership and non-disclosure agreements
D. Acme Corp should send the data to ABC Services’ vendor instead

Answer: C

Question No : 117 - (Topic 2)

A network administrator is asked to send a large file containing PII to a business associate.

Which of the following protocols is the BEST choice to use?

www.CertificationKing.com 43
CompTIA SY0-401 : Practice Test
A. SSH
B. SFTP
C. SMTP
D. FTP

Answer: B

Question No : 118 - (Topic 2)

Users are encouraged to click on a link in an email to obtain exclusive access to the
newest version of a popular Smartphone. This is an example of.

A. Scarcity
B. Familiarity
C. Intimidation
D. Trust

Answer: A

Question No : 119 - (Topic 2)

An administrator needs to renew a certificate for a web server. Which of the following
should be submitted to a CA?

A. CSR
B. Recovery agent
C. Private key
D. CRL

Answer: A

Question No : 120 - (Topic 2)

A company is about to release a very large patch to its customers. An administrator is


required to test patch installations several times prior to distributing them to customer PCs.

Which of the following should the administrator use to test the patching process quickly and

www.CertificationKing.com 44
CompTIA SY0-401 : Practice Test
often?

A. Create an incremental backup of an unpatched PC


B. Create an image of a patched PC and replicate it to servers
C. Create a full disk image to restore after each installation
D. Create a virtualized sandbox and utilize snapshots

Answer: D

Question No : 121 - (Topic 2)

A security analyst is reviewing firewall logs while investigating a compromised web server.
The following ports appear in the log:

22, 25, 445, 1433, 3128, 3389, 6667

Which of the following protocols was used to access the server remotely?

A. LDAP
B. HTTP
C. RDP
D. HTTPS

Answer: C

Question No : 122 - (Topic 2)

A security engineer is asked by the company’s development team to recommend the most
secure method for password storage.

Which of the following provide the BEST protection against brute forcing stored
passwords? (Select TWO).

A. PBKDF2
B. MD5
C. SHA2
D. Bcrypt
E. AES

www.CertificationKing.com 45
CompTIA SY0-401 : Practice Test
F. CHAP

Answer: A,D

Question No : 123 - (Topic 2)

Which of the following describes a type of malware which is difficult to reverse engineer in
a virtual lab?

A. Armored virus
B. Polymorphic malware
C. Logic bomb
D. Rootkit

Answer: A

Question No : 124 - (Topic 2)

The security administrator is currently unaware of an incident that occurred a week ago.
Which of the following will ensure the administrator is notified in a timely manner in the
future?

A. User permissions reviews


B. Incident response team
C. Change management
D. Routine auditing

Answer: D

Question No : 125 - (Topic 2)

An organization has introduced token-based authentication to system administrators due to


risk of password compromise. The tokens have a set of numbers that automatically change
every 30 seconds. Which of the following type of authentication mechanism is this?

A. TOTP
B. Smart card

www.CertificationKing.com 46
CompTIA SY0-401 : Practice Test
C. CHAP
D. HOTP

Answer: A

Question No : 126 - (Topic 2)

An administrator wants to ensure that the reclaimed space of a hard drive has been
sanitized while the computer is in use. Which of the following can be implemented?

A. Cluster tip wiping


B. Individual file encryption
C. Full disk encryption
D. Storage retention

Answer: A

Question No : 127 - (Topic 2)

Which of the following controls can be implemented together to prevent data loss in the
event of theft of a mobile device storing sensitive information? (Select TWO).

A. Full device encryption


B. Screen locks
C. GPS
D. Asset tracking
E. Inventory control

Answer: A,B

Question No : 128 - (Topic 2)

A company has decided to move large data sets to a cloud provider in order to limit the
costs of new infrastructure. Some of the data is sensitive and the Chief Information Officer
wants to make sure both parties have a clear understanding of the controls needed to
protect the data.

www.CertificationKing.com 47
CompTIA SY0-401 : Practice Test
Which of the following types of interoperability agreement is this?

A. ISA
B. MOU
C. SLA
D. BPA

Answer: A

Question No : 129 - (Topic 2)

A company is looking to improve their security posture by addressing risks uncovered by a


recent penetration test. Which of the following risks is MOST likely to affect the business on
a day-to-day basis?

A. Insufficient encryption methods


B. Large scale natural disasters
C. Corporate espionage
D. Lack of antivirus software

Answer: D

Question No : 130 - (Topic 2)

A vulnerability scan is reporting that patches are missing on a server. After a review, it is
determined that the application requiring the patch does not exist on the operating system.

Which of the following describes this cause?

A. Application hardening
B. False positive
C. Baseline code review
D. False negative

Answer: B

Question No : 131 - (Topic 2)

www.CertificationKing.com 48
CompTIA SY0-401 : Practice Test
Customers’ credit card information was stolen from a popular video streaming company. A
security consultant determined that the information was stolen, while in transit, from the
gaming consoles of a particular vendor. Which of the following methods should the
company consider to secure this data in the future?

A. Application firewalls
B. Manual updates
C. Firmware version control
D. Encrypted TCP wrappers

Answer: D

Question No : 132 - (Topic 2)

Several employees submit the same phishing email to the administrator. The administrator
finds that the links in the email are not being blocked by the company’s security device.
Which of the following might the administrator do in the short term to prevent the emails
from being received?

A. Configure an ACL
B. Implement a URL filter
C. Add the domain to a block list
D. Enable TLS on the mail server

Answer: C

Question No : 133 - (Topic 2)

A security technician has been asked to recommend an authentication mechanism that will
allow users to authenticate using a password that will only be valid for a predefined time
interval. Which of the following should the security technician recommend?

A. CHAP
B. TOTP
C. HOTP
D. PAP

Answer: B

www.CertificationKing.com 49
CompTIA SY0-401 : Practice Test

Question No : 134 - (Topic 2)

A malicious individual is attempting to write too much data to an application’s memory.


Which of the following describes this type of attack?

A. Zero-day
B. SQL injection
C. Buffer overflow
D. XSRF

Answer: C

Question No : 135 - (Topic 2)

A network administrator wants to block both DNS requests and zone transfers coming from
outside IP addresses. The company uses a firewall which implements an implicit allow and
is currently configured with the following ACL applied to its external interfacE.

PERMIT TCP ANY ANY 80

PERMIT TCP ANY ANY 443

Which of the following rules would accomplish this task? (Select TWO).

A. Change the firewall default settings so that it implements an implicit deny


B. Apply the current ACL to all interfaces of the firewall
C. Remove the current ACL
D. Add the following ACL at the top of the current ACL
DENY TCP ANY ANY 53
E. Add the following ACL at the bottom of the current ACL
DENY ICMP ANY ANY 53
F. Add the following ACL at the bottom of the current ACL
DENY IP ANY ANY 53

Answer: A,F

Question No : 136 - (Topic 2)

A new application needs to be deployed on a virtual server. The virtual server hosts a SQL

www.CertificationKing.com 50
CompTIA SY0-401 : Practice Test
server that is used by several employees.

Which of the following is the BEST approach for implementation of the new application on
the virtual server?

A. Take a snapshot of the virtual server after installing the new application and store the
snapshot in a secure location.
B. Generate a baseline report detailing all installed applications on the virtualized server
after installing the new application.
C. Take a snapshot of the virtual server before installing the new application and store the
snapshot in a secure location.
D. Create an exact copy of the virtual server and store the copy on an external hard drive
after installing the new application.

Answer: C

Question No : 137 - (Topic 2)

A distributed denial of service attack can BEST be described as:

A. Invalid characters being entered into a field in a database application.


B. Users attempting to input random or invalid data into fields within a web browser
application.
C. Multiple computers attacking a single target in an organized attempt to deplete its
resources.
D. Multiple attackers attempting to gain elevated privileges on a target system.

Answer: C

Question No : 138 - (Topic 2)

The system administrator is tasked with changing the administrator password across all
2000 computers in the organization. Which of the following should the system administrator
implement to accomplish this task?

A. A security group
B. A group policy
C. Key escrow
D. Certificate revocation

www.CertificationKing.com 51
CompTIA SY0-401 : Practice Test
Answer: B

Question No : 139 - (Topic 2)

Ann has read and write access to an employee database, while Joe has only read access.
Ann is leaving for a conference.

Which of the following types of authorization could be utilized to trigger write access for Joe
when Ann is absent?

A. Mandatory access control


B. Role-based access control
C. Discretionary access control
D. Rule-based access control

Answer: D

Question No : 140 - (Topic 2)

Which of the following attacks would cause all mobile devices to lose their association with
corporate access points while the attack is underway?

A. Wireless jamming
B. Evil twin
C. Rogue AP
D. Packet sniffing

Answer: A

Question No : 141 - (Topic 2)

The security team would like to gather intelligence about the types of attacks being
launched against the organization. Which of the following would provide them with the
MOST information?

A. Implement a honeynet

www.CertificationKing.com 52
CompTIA SY0-401 : Practice Test
B. Perform a penetration test
C. Examine firewall logs
D. Deploy an IDS

Answer: A

Question No : 142 - (Topic 2)

The company’s sales team plans to work late to provide the Chief Executive Officer (CEO)
with a special report of sales before the quarter ends. After working for several hours, the
team finds they cannot save or print the reports.

Which of the following controls is preventing them from completing their work?

A. Discretionary access control


B. Role-based access control
C. Time of Day access control
D. Mandatory access control

Answer: C

Question No : 143 - (Topic 2)

A security engineer, Joe, has been asked to create a secure connection between his mail
server and the mail server of a business partner. Which of the following protocol would be
MOST appropriate?

A. HTTPS
B. SSH
C. FTP
D. TLS

Answer: D

Question No : 144 - (Topic 2)

Joe analyzed the following log and determined the security team should implement which

www.CertificationKing.com 53
CompTIA SY0-401 : Practice Test
of the following as a mitigation method against further attempts?

Host 192.168.1.123

[00: 00: 01]Successful Login: 015 192.168.1.123 : local

[00: 00: 03]Unsuccessful Login: 022 214.34.56.006 : RDP 192.168.1.124

[00: 00: 04]UnSuccessful Login: 010 214.34.56.006 : RDP 192.168.1.124

[00: 00: 07]UnSuccessful Login: 007 214.34.56.006 : RDP 192.168.1.124

[00: 00: 08]UnSuccessful Login: 003 214.34.56.006 : RDP 192.168.1.124

A. Reporting
B. IDS
C. Monitor system logs
D. Hardening

Answer: D

Question No : 145 - (Topic 2)

Several employees have been printing files that include personally identifiable information
of customers. Auditors have raised concerns about the destruction of these hard copies
after they are created, and management has decided the best way to address this concern
is by preventing these files from being printed.

Which of the following would be the BEST control to implement?

A. File encryption
B. Printer hardening
C. Clean desk policies
D. Data loss prevention

Answer: D

Question No : 146 - (Topic 2)

Which of the following ports and protocol types must be opened on a host with a host-

www.CertificationKing.com 54
CompTIA SY0-401 : Practice Test
based firewall to allow incoming SFTP connections?

A. 21/UDP
B. 21/TCP
C. 22/UDP
D. 22/TCP

Answer: D

Question No : 147 - (Topic 2)

A server dedicated to the storage and processing of sensitive information was


compromised with a rootkit and sensitive data was exfiltrated. Which of the following
incident response procedures is best suited to restore the server?

A. Wipe the storage, reinstall the OS from original media and restore the data from the last
known good backup.
B. Keep the data partition, restore the OS from the most current backup and run a full
system antivirus scan.
C. Format the storage and reinstall both the OS and the data from the most current backup.

D. Erase the storage, reinstall the OS from most current backup and only restore the data
that was not compromised.

Answer: A

Question No : 148 - (Topic 2)

After copying a sensitive document from his desktop to a flash drive, Joe, a user, realizes
that the document is no longer encrypted. Which of the following can a security technician
implement to ensure that documents stored on Joe’s desktop remain encrypted when
moved to external media or other network based storage?

A. Whole disk encryption


B. Removable disk encryption
C. Database record level encryption
D. File level encryption

Answer: D

www.CertificationKing.com 55
CompTIA SY0-401 : Practice Test

Question No : 149 - (Topic 2)

After a security incident involving a physical asset, which of the following should be done at
the beginning?

A. Record every person who was in possession of assets, continuing post-incident.


B. Create working images of data in the following order: hard drive then RAM.
C. Back up storage devices so work can be performed on the devices immediately.
D. Write a report detailing the incident and mitigation suggestions.

Answer: A

Question No : 150 - (Topic 2)

When creating a public / private key pair, for which of the following ciphers would a user
need to specify the key strength?

A. SHA
B. AES
C. DES
D. RSA

Answer: D

Question No : 151 - (Topic 2)

Which of the following solutions provides the most flexibility when testing new security
controls prior to implementation?

A. Trusted OS
B. Host software baselining
C. OS hardening
D. Virtualization

Answer: D

www.CertificationKing.com 56
CompTIA SY0-401 : Practice Test

Question No : 152 - (Topic 2)

An attacker used an undocumented and unknown application exploit to gain access to a file
server. Which of the following BEST describes this type of attack?

A. Integer overflow
B. Cross-site scripting
C. Zero-day
D. Session hijacking
E. XML injection

Answer: C

Question No : 153 - (Topic 2)

A software developer wants to prevent stored passwords from being easily decrypted.
When the password is stored by the application, additional text is added to each password
before the password is hashed. This technique is known as:

A. Symmetric cryptography.
B. Private key cryptography.
C. Salting.
D. Rainbow tables.

Answer: C

Question No : 154 - (Topic 2)

The system administrator has deployed updated security controls for the network to limit
risk of attack. The security manager is concerned that controls continue to function as
intended to maintain appropriate security posture.

Which of the following risk mitigation strategies is MOST important to the security
manager?

A. User permissions
B. Policy enforcement
C. Routine audits
D. Change management

www.CertificationKing.com 57
CompTIA SY0-401 : Practice Test
Answer: C

Question No : 155 - (Topic 2)

Company A submitted a bid on a contract to do work for Company B via email. Company B
was insistent that the bid did not come from Company A. Which of the following would have
assured that the bid was submitted by Company A?

A. Steganography
B. Hashing
C. Encryption
D. Digital Signatures

Answer: D

Question No : 156 - (Topic 2)

A user, Ann, is reporting to the company IT support group that her workstation screen is
blank other than a window with a message requesting payment or else her hard drive will
be formatted. Which of the following types of malware is on Ann’s workstation?

A. Trojan
B. Spyware
C. Adware
D. Ransomware

Answer: D

Question No : 157 - (Topic 2)

Which of the following is a BEST practice when dealing with user accounts that will only
need to be active for a limited time period?

A. When creating the account, set the account to not remember password history.
B. When creating the account, set an expiration date on the account.
C. When creating the account, set a password expiration date on the account.
D. When creating the account, set the account to have time of day restrictions.

www.CertificationKing.com 58
CompTIA SY0-401 : Practice Test
Answer: B

Question No : 158 - (Topic 2)

During a recent investigation, an auditor discovered that an engineer’s compromised


workstation was being used to connect to SCADA systems while the engineer was not
logged in. The engineer is responsible for administering the SCADA systems and cannot
be blocked from connecting to them. The SCADA systems cannot be modified without
vendor approval which requires months of testing.

Which of the following is MOST likely to protect the SCADA systems from misuse?

A. Update anti-virus definitions on SCADA systems


B. Audit accounts on the SCADA systems
C. Install a firewall on the SCADA network
D. Deploy NIPS at the edge of the SCADA network

Answer: D

Question No : 159 - (Topic 2)

Results from a vulnerability analysis indicate that all enabled virtual terminals on a router
can be accessed using the same password. The company’s network device security policy
mandates that at least one virtual terminal have a different password than the other virtual
terminals. Which of the following sets of commands would meet this requirement?

A. line vty 0 6 P@s5W0Rd password line vty 7 Qwer++!Y password


B. line console 0 password password line vty 0 4 password P@s5W0Rd
C. line vty 0 3 password Qwer++!Y line vty 4 password P@s5W0Rd
D. line vty 0 3 password Qwer++!Y line console 0 password P@s5W0Rd

Answer: C

Question No : 160 - (Topic 2)

Ann, an employee, is cleaning out her desk and disposes of paperwork containing
confidential customer information in a recycle bin without shredding it first. This is MOST

www.CertificationKing.com 59
CompTIA SY0-401 : Practice Test
likely to increase the risk of loss from which of the following attacks?

A. Shoulder surfing
B. Dumpster diving
C. Tailgating
D. Spoofing

Answer: B

Question No : 161 - (Topic 2)

Which of the following is required to allow multiple servers to exist on one physical server?

A. Software as a Service (SaaS)


B. Platform as a Service (PaaS)
C. Virtualization
D. Infrastructure as a Service (IaaS)

Answer: C

Question No : 162 - (Topic 2)

A security administrator must implement a wireless encryption system to secure mobile


devices’ communication. Some users have mobile devices which only support 56-bit
encryption. Which of the following wireless encryption methods should be implemented?

A. RC4
B. AES
C. MD5
D. TKIP

Answer: A

Question No : 163 - (Topic 2)

A computer supply company is located in a building with three wireless networks. The
system security team implemented a quarterly security scan and saw the following.

www.CertificationKing.com 60
CompTIA SY0-401 : Practice Test
SSID State Channel Level

Computer AreUs1 connected 1 70dbm

Computer AreUs2 connected 5 80dbm

Computer AreUs3 connected 3 75dbm

Computer AreUs4 connected 6 95dbm

Which of the following is this an example of?

A. Rogue access point


B. Near field communication
C. Jamming
D. Packet sniffing

Answer: A

Question No : 164 - (Topic 2)

Which of the following is an XML based open standard used in the exchange of
authentication and authorization information between different parties?

A. LDAP
B. SAML
C. TACACS+
D. Kerberos

Answer: B

Question No : 165 - (Topic 2)

A network technician is on the phone with the system administration team. Power to the
server room was lost and servers need to be restarted. The DNS services must be the first
to be restarted. Several machines are powered off. Assuming each server only provides
one service, which of the following should be powered on FIRST to establish DNS
services?

A. Bind server

www.CertificationKing.com 61
CompTIA SY0-401 : Practice Test
B. Apache server
C. Exchange server
D. RADIUS server

Answer: A

Question No : 166 - (Topic 2)

A company has several conference rooms with wired network jacks that are used by both
employees and guests. Employees need access to internal resources and guests only
need access to the Internet. Which of the following combinations is BEST to meet the
requirements?

A. NAT and DMZ


B. VPN and IPSec
C. Switches and a firewall
D. 802.1x and VLANs

Answer: D

Question No : 167 - (Topic 2)

An organization does not want the wireless network name to be easily discovered. Which
of the following software features should be configured on the access points?

A. SSID broadcast
B. MAC filter
C. WPA2
D. Antenna placement

Answer: A

Question No : 168 - (Topic 2)

A systems administrator has implemented PKI on a classified government network. In the


event that a disconnect occurs from the primary CA, which of the following should be
accessible locally from every site to ensure users with bad certificates cannot gain access
to the network?

www.CertificationKing.com 62
CompTIA SY0-401 : Practice Test
A. A CRL
B. Make the RA available
C. A verification authority
D. A redundant CA

Answer: A

Question No : 169 - (Topic 2)

A vulnerability assessment indicates that a router can be accessed from default port 80 and
default port 22. Which of the following should be executed on the router to prevent access
via these ports? (Select TWO).

A. FTP service should be disabled


B. HTTPS service should be disabled
C. SSH service should be disabled
D. HTTP service should disabled
E. Telnet service should be disabled

Answer: C,D

Question No : 170 - (Topic 2)

LDAP and Kerberos are commonly used for which of the following?

A. To perform queries on a directory service


B. To store usernames and passwords for Federated Identity
C. To sign SSL wildcard certificates for subdomains
D. To utilize single sign-on capabilities

Answer: D

Question No : 171 - (Topic 2)

An organization does not have adequate resources to administer its large infrastructure. A
security administrator wishes to combine the security controls of some of the network
devices in the organization. Which of the following methods would BEST accomplish this
goal?

www.CertificationKing.com 63
CompTIA SY0-401 : Practice Test
A. Unified Threat Management
B. Virtual Private Network
C. Single sign on
D. Role-based management

Answer: A

Question No : 172 - (Topic 2)

Which of the following protocols is used to validate whether trust is in place and accurate
by returning responses of either "good", "unknown", or "revoked"?

A. CRL
B. PKI
C. OCSP
D. RA

Answer: C

Question No : 173 - (Topic 2)

A security audit identifies a number of large email messages being sent by a specific user
from their company email account to another address external to the company. These
messages were sent prior to a company data breach, which prompted the security audit.
The user was one of a few people who had access to the leaked data. Review of the
suspect’s emails show they consist mostly of pictures of the user at various locations
during a recent vacation. No suspicious activities from other users who have access to the
data were discovered.

Which of the following is occurring?

A. The user is encrypting the data in the outgoing messages.


B. The user is using steganography.
C. The user is spamming to obfuscate the activity.
D. The user is using hashing to embed data in the emails.

Answer: B

www.CertificationKing.com 64
CompTIA SY0-401 : Practice Test

Question No : 174 - (Topic 2)

The incident response team has received the following email messagE.

From: [email protected]

To: [email protected]

Subject: Copyright infringement

A copyright infringement alert was triggered by IP address 13.10.66.5 at 09: 50: 01 GMT.

After reviewing the following web logs for IP 13.10.66.5, the team is unable to correlate and
identify the incident.

09: 45: 33 13.10.66.5 http: //remote.site.com/login.asp?user=john

09: 50: 22 13.10.66.5 http: //remote.site.com/logout.asp?user=anne

10: 50: 01 13.10.66.5 http: //remote.site.com/access.asp?file=movie.mov

11: 02: 45 13.10.65.5 http: //remote.site.com/download.asp?movie.mov=ok

Which of the following is the MOST likely reason why the incident response team is unable
to identify and correlate the incident?

A. The logs are corrupt and no longer forensically sound.


B. Traffic logs for the incident are unavailable.
C. Chain of custody was not properly maintained.
D. Incident time offsets were not accounted for.

Answer: D

Question No : 175 - (Topic 2)

One of the system administrators at a company is assigned to maintain a secure computer


lab. The administrator has rights to configure machines, install software, and perform user
account maintenance. However, the administrator cannot add new computers to the
domain, because that requires authorization from the Information Assurance Officer. This is
an example of which of the following?

www.CertificationKing.com 65
CompTIA SY0-401 : Practice Test
A. Mandatory access
B. Rule-based access control
C. Least privilege
D. Job rotation

Answer: C

Question No : 176 - (Topic 2)

Which of the following types of attacks involves interception of authentication traffic in an


attempt to gain unauthorized access to a wireless network?

A. Near field communication


B. IV attack
C. Evil twin
D. Replay attack

Answer: B

Question No : 177 - (Topic 2)

Ann wants to send a file to Joe using PKI. Which of the following should Ann use in order to
sign the file?

A. Joe’s public key


B. Joe’s private key
C. Ann’s public key
D. Ann’s private key

Answer: D

Question No : 178 - (Topic 2)

An auditing team has found that passwords do not meet best business practices. Which of
the following will MOST increase the security of the passwords? (Select TWO).

A. Password Complexity

www.CertificationKing.com 66
CompTIA SY0-401 : Practice Test
B. Password Expiration
C. Password Age
D. Password Length
E. Password History

Answer: A,D

Question No : 179 - (Topic 2)

A network engineer is setting up a network for a company. There is a BYOD policy for the
employees so that they can connect their laptops and mobile devices.

Which of the following technologies should be employed to separate the administrative


network from the network in which all of the employees’ devices are connected?

A. VPN
B. VLAN
C. WPA2
D. MAC filtering

Answer: B

Question No : 180 - (Topic 2)

Using a heuristic system to detect an anomaly in a computer’s baseline, a system


administrator was able to detect an attack even though the company signature based IDS
and antivirus did not detect it. Further analysis revealed that the attacker had downloaded
an executable file onto the company PC from the USB port, and executed it to trigger a
privilege escalation flaw.

Which of the following attacks has MOST likely occurred?

A. Cookie stealing
B. Zero-day
C. Directory traversal
D. XML injection

Answer: B

www.CertificationKing.com 67
CompTIA SY0-401 : Practice Test

Question No : 181 - (Topic 2)

In which of the following steps of incident response does a team analyze the incident and
determine steps to prevent a future occurrence?

A. Mitigation
B. Identification
C. Preparation
D. Lessons learned

Answer: D

Question No : 182 - (Topic 2)

A way to assure data at-rest is secure even in the event of loss or theft is to use:

A. Full device encryption.


B. Special permissions on the file system.
C. Trusted Platform Module integration.
D. Access Control Lists.

Answer: A

Question No : 183 - (Topic 2)

When performing the daily review of the system vulnerability scans of the network Joe, the
administrator, noticed several security related vulnerabilities with an assigned vulnerability
identification number. Joe researches the assigned vulnerability identification number from
the vendor website. Joe proceeds with applying the recommended solution for identified
vulnerability.

Which of the following is the type of vulnerability described?

A. Network based
B. IDS
C. Signature based
D. Host based

Answer: C

www.CertificationKing.com 68
CompTIA SY0-401 : Practice Test

Question No : 184 - (Topic 2)

A recent vulnerability scan found that Telnet is enabled on all network devices. Which of
the following protocols should be used instead of Telnet?

A. SCP
B. SSH
C. SFTP
D. SSL

Answer: B

Question No : 185 - (Topic 2)

After recovering from a data breach in which customer data was lost, the legal team meets
with the Chief Security Officer (CSO) to discuss ways to better protect the privacy of
customer data.

Which of the following controls support this goal?

A. Contingency planning
B. Encryption and stronger access control
C. Hashing and non-repudiation
D. Redundancy and fault tolerance

Answer: B

Question No : 186 - (Topic 2)

An auditor's report discovered several accounts with no activity for over 60 days. The
accounts were later identified as contractors’ accounts who would be returning in three
months and would need to resume the activities. Which of the following would mitigate and
secure the auditors finding?

A. Disable unnecessary contractor accounts and inform the auditor of the update.

www.CertificationKing.com 69
CompTIA SY0-401 : Practice Test
B. Reset contractor accounts and inform the auditor of the update.
C. Inform the auditor that the accounts belong to the contractors.
D. Delete contractor accounts and inform the auditor of the update.

Answer: A

Question No : 187 - (Topic 2)

An administrator finds that non-production servers are being frequently compromised,


production servers are rebooting at unplanned times and kernel versions are several
releases behind the version with all current security fixes.

Which of the following should the administrator implement?

A. Snapshots
B. Sandboxing
C. Patch management
D. Intrusion detection system

Answer: C

Question No : 188 - (Topic 2)

A user was reissued a smart card after the previous smart card had expired. The user is
able to log into the domain but is now unable to send digitally signed or encrypted email.
Which of the following would the user need to perform?

A. Remove all previous smart card certificates from the local certificate store.
B. Publish the new certificates to the global address list.
C. Make the certificates available to the operating system.
D. Recover the previous smart card certificates.

Answer: B

Question No : 189 - (Topic 2)

An access point has been configured for AES encryption but a client is unable to connect to

www.CertificationKing.com 70
CompTIA SY0-401 : Practice Test
it. Which of the following should be configured on the client to fix this issue?

A. WEP
B. CCMP
C. TKIP
D. RC4

Answer: B

Question No : 190 - (Topic 2)

A security administrator must implement a system to allow clients to securely negotiate


encryption keys with the company’s server over a public unencrypted communication
channel.

Which of the following implements the required secure key negotiation? (Select TWO).

A. PBKDF2
B. Symmetric encryption
C. Steganography
D. ECDHE
E. Diffie-Hellman

Answer: D,E

Question No : 191 - (Topic 2)

A new network administrator is setting up a new file server for the company. Which of the
following would be the BEST way to manage folder security?

A. Assign users manually and perform regular user access reviews


B. Allow read only access to all folders and require users to request permission
C. Assign data owners to each folder and allow them to add individual users to each folder
D. Create security groups for each folder and assign appropriate users to each group

Answer: D

www.CertificationKing.com 71
CompTIA SY0-401 : Practice Test

Question No : 192 - (Topic 2)

A security administrator is reviewing the company’s continuity plan. The plan specifies an
RTO of six hours and RPO of two days. Which of the following is the plan describing?

A. Systems should be restored within six hours and no later than two days after the
incident.
B. Systems should be restored within two days and should remain operational for at least
six hours.
C. Systems should be restored within six hours with a minimum of two days worth of data.
D. Systems should be restored within two days with a minimum of six hours worth of data.

Answer: C

Question No : 193 - (Topic 2)

A small business needs to incorporate fault tolerance into their infrastructure to increase
data availability. Which of the following options would be the BEST solution at a minimal
cost?

A. Clustering
B. Mirrored server
C. RAID
D. Tape backup

Answer: C

Question No : 194 - (Topic 2)

Which of the following would allow the organization to divide a Class C IP address range
into several ranges?

A. DMZ
B. Virtual LANs
C. NAT
D. Subnetting

Answer: D

www.CertificationKing.com 72
CompTIA SY0-401 : Practice Test

Question No : 195 - (Topic 2)

A security technician at a small business is worried about the Layer 2 switches in the
network suffering from a DoS style attack caused by staff incorrectly cabling network
connections between switches.

Which of the following will BEST mitigate the risk if implemented on the switches?

A. Spanning tree
B. Flood guards
C. Access control lists
D. Syn flood

Answer: A

Question No : 196 - (Topic 2)

The call center supervisor has reported that many employees have been playing
preinstalled games on company computers and this is reducing productivity.

Which of the following would be MOST effective for preventing this behavior?

A. Acceptable use policies


B. Host-based firewalls
C. Content inspection
D. Application whitelisting

Answer: D

Question No : 197 - (Topic 2)

A computer is suspected of being compromised by malware. The security analyst


examines the computer and finds that a service called Telnet is running and connecting to
an external website over port 443. This Telnet service was found by comparing the
system's services to the list of standard services on the company's system image. This
review process depends on:

A. MAC filtering.

www.CertificationKing.com 73
CompTIA SY0-401 : Practice Test
B. System hardening.
C. Rogue machine detection.
D. Baselining.

Answer: D

Question No : 198 - (Topic 2)

Ann, the security administrator, wishes to implement multifactor security. Which of the
following should be implemented in order to compliment password usage and smart cards?

A. Hard tokens
B. Fingerprint readers
C. Swipe badge readers
D. Passphrases

Answer: B

Question No : 199 - (Topic 2)

Human Resources suspects an employee is accessing the employee salary database. The
administrator is asked to find out who it is. In order to complete this task, which of the
following is a security control that should be in place?

A. Shared accounts should be prohibited.


B. Account lockout should be enabled
C. Privileges should be assigned to groups rather than individuals
D. Time of day restrictions should be in use

Answer: A

Question No : 200 - (Topic 2)

While configuring a new access layer switch, the administrator, Joe, was advised that he
needed to make sure that only devices authorized to access the network would be
permitted to login and utilize resources. Which of the following should the administrator
implement to ensure this happens?

www.CertificationKing.com 74
CompTIA SY0-401 : Practice Test
A. Log Analysis
B. VLAN Management
C. Network separation
D. 802.1x

Answer: D

Topic 3, Volume C

Question No : 201 - (Topic 3)

A company that purchased an HVAC system for the datacenter is MOST concerned with
which of the following?

A. Availability
B. Integrity
C. Confidentiality
D. Fire suppression

Answer: A

Question No : 202 - (Topic 3)

Which of the following should Jane, a security administrator, perform before a hard drive is
analyzed with forensics tools?

A. Identify user habits


B. Disconnect system from network
C. Capture system image
D. Interview witnesses

Answer: C

Question No : 203 - (Topic 3)

Using proximity card readers instead of the traditional key punch doors would help to
mitigate:

www.CertificationKing.com 75
CompTIA SY0-401 : Practice Test
A. Impersonation
B. Tailgating
C. Dumpster diving
D. Shoulder surfing

Answer: D

Question No : 204 HOTSPOT - (Topic 3)

Select the appropriate attack from each drop down list to label the corresponding illustrated
attack

Instructions: Attacks may only be used once, and will disappear from drop down list if
selected.

When you have completed the simulation, please select the Done button to submit.

www.CertificationKing.com 76
CompTIA SY0-401 : Practice Test

Answer:

Question No : 205 - (Topic 3)


www.CertificationKing.com 77
CompTIA SY0-401 : Practice Test
Configuring the mode, encryption methods, and security associations are part of which of
the following?

A. IPSec
B. Full disk encryption
C. 802.1x
D. PKI

Answer: A

Question No : 206 - (Topic 3)

Which of the following is an example of a false positive?

A. Anti-virus identifies a benign application as malware.


B. A biometric iris scanner rejects an authorized user wearing a new contact lens.
C. A user account is locked out after the user mistypes the password too many times.
D. The IDS does not identify a buffer overflow.

Answer: A

Question No : 207 DRAG DROP - (Topic 3)

Drag and drop the correct protocol to its default port.

www.CertificationKing.com 78
CompTIA SY0-401 : Practice Test

Answer:

www.CertificationKing.com 79
CompTIA SY0-401 : Practice Test

Question No : 208 - (Topic 3)

Which of the following could cause a browser to display the message below?

"The security certificate presented by this website was issued for a different website's
address."

A. The website certificate was issued by a different CA than what the browser recognizes
in its trusted CAs.
B. The website is using a wildcard certificate issued for the company's domain.
C. HTTPS://127.0.01 was used instead of HTTPS://localhost.
D. The website is using an expired self signed certificate.

www.CertificationKing.com 80
CompTIA SY0-401 : Practice Test
Answer: C

Question No : 209 - (Topic 3)

Which of the following should Matt, a security administrator, include when encrypting

smartphones? (Select TWO).

A. Steganography images
B. Internal memory
C. Master boot records
D. Removable memory cards
E. Public keys

Answer: B,D

Question No : 210 - (Topic 3)

A CRL is comprised of.

A. Malicious IP addresses.
B. Trusted CA's.
C. Untrusted private keys.
D. Public keys.

Answer: D

Question No : 211 - (Topic 3)

Data execution prevention is a feature in most operating systems intended to protect


against which type of attack?

A. Cross-site scripting
B. Buffer overflow
C. Header manipulation
D. SQL injection

www.CertificationKing.com 81
CompTIA SY0-401 : Practice Test
Answer: B

Question No : 212 - (Topic 3)

Mike, a network administrator, has been asked to passively monitor network traffic to the
company's sales websites. Which of the following would be BEST suited for this task?

A. HIDS
B. Firewall
C. NIPS
D. Spam filter

Answer: C

Question No : 213 - (Topic 3)

Jane, an administrator, needs to make sure the wireless network is not accessible from the
parking area of their office. Which of the following would BEST help Jane when deploying a
new access point?

A. Placement of antenna
B. Disabling the SSID
C. Implementing WPA2
D. Enabling the MAC filtering

Answer: A

Question No : 214 - (Topic 3)

Which of the following should Pete, a security manager, implement to reduce the risk of
employees working in collusion to embezzle funds from their company?

A. Privacy Policy
B. Least Privilege
C. Acceptable Use
D. Mandatory Vacations

www.CertificationKing.com 82
CompTIA SY0-401 : Practice Test
Answer: D

Question No : 215 - (Topic 3)

Which of the following devices will help prevent a laptop from being removed from a certain
location?

A. Device encryption
B. Cable locks
C. GPS tracking
D. Remote data wipes

Answer: B

Question No : 216 - (Topic 3)

Which of the following is an authentication service that uses UDP as a transport medium?

A. TACACS+
B. LDAP
C. Kerberos
D. RADIUS

Answer: D

Question No : 217 - (Topic 3)

A security administrator needs to update the OS on all the switches in the company. Which
of the following MUST be done before any actual switch configuration is performed?

A. The request needs to be sent to the incident management team.


B. The request needs to be approved through the incident management process.
C. The request needs to be approved through the change management process.
D. The request needs to be sent to the change management team.

Answer: C

www.CertificationKing.com 83
CompTIA SY0-401 : Practice Test

Question No : 218 - (Topic 3)

Matt, an administrator, notices a flood fragmented packet and retransmits from an email
server.

After disabling the TCP offload setting on the NIC, Matt sees normal traffic with packets
flowing in sequence again. Which of the following utilities was he MOST likely using to view
this issue?

A. Spam filter
B. Protocol analyzer
C. Web application firewall
D. Load balancer

Answer: B

Question No : 219 - (Topic 3)

Which of the following mitigation strategies is established to reduce risk when performing
updates to business critical systems?

A. Incident management
B. Server clustering
C. Change management
D. Forensic analysis

Answer: C

Question No : 220 - (Topic 3)

Which of the following protocols is used to authenticate the client and server's digital
certificate?

A. PEAP
B. DNS
C. TLS
D. ICMP

Answer: C

www.CertificationKing.com 84
CompTIA SY0-401 : Practice Test

Question No : 221 - (Topic 3)

Pete, an employee, is terminated from the company and the legal department needs
documents from his encrypted hard drive. Which of the following should be used to
accomplish this task?

(Select TWO).

A. Private hash
B. Recovery agent
C. Public key
D. Key escrow
E. CRL

Answer: B,D

Question No : 222 - (Topic 3)

Which of the following may significantly reduce data loss if multiple drives fail at the same
time?

A. Virtualization
B. RAID
C. Load balancing
D. Server clustering

Answer: B

Question No : 223 - (Topic 3)

Which of the following algorithms has well documented collisions? (Select TWO).

A. AES
B. MD5
C. SHA
D. SHA-256

www.CertificationKing.com 85
CompTIA SY0-401 : Practice Test
E. RSA

Answer: B,C

Question No : 224 - (Topic 3)

Which of the following is a management control?

A. Logon banners
B. Written security policy
C. SYN attack prevention
D. Access Control List (ACL)

Answer: B

Question No : 225 - (Topic 3)

To help prevent unauthorized access to PCs, a security administrator implements screen


savers that lock the PC after five minutes of inactivity. Which of the following controls is
being described in this situation?

A. Management
B. Administrative
C. Technical
D. Operational

Answer: C

Question No : 226 HOTSPOT - (Topic 3)

For each of the given items, select the appropriate authentication category from the
dropdown choices.

Instructions: When you have completed the simu-lation, please select the Done button to
submit.

www.CertificationKing.com 86
CompTIA SY0-401 : Practice Test

www.CertificationKing.com 87
CompTIA SY0-401 : Practice Test

Answer:

www.CertificationKing.com 88
CompTIA SY0-401 : Practice Test

Question No : 227 DRAG DROP - (Topic 3)

Determine the types of attacks below by selecting an option from the dropdown list.

Determine the types of Attacks from right to specific action.

www.CertificationKing.com 89
CompTIA SY0-401 : Practice Test

Answer:

Question No : 228 - (Topic 3)

Which of the following components MUST be trusted by all parties in PKI?

www.CertificationKing.com 90
CompTIA SY0-401 : Practice Test
A. Key escrow
B. CA
C. Private key
D. Recovery key

Answer: B

Question No : 229 - (Topic 3)

Which of the following describes how Sara, an attacker, can send unwanted
advertisements to a mobile device?

A. Man-in-the-middle
B. Bluejacking
C. Bluesnarfing
D. Packet sniffing

Answer: B

Question No : 230 - (Topic 3)

Which of the following pseudocodes can be used to handle program exceptions?

A. If program detects another instance of itself, then kill program instance.


B. If user enters invalid input, then restart program.
C. If program module crashes, then restart program module.
D. If user's input exceeds buffer length, then truncate the input.

Answer: C

Question No : 231 - (Topic 3)

Which of the following protocols uses an asymmetric key to open a session and then
establishes a symmetric key for the remainder of the session?

A. SFTP
B. HTTPS

www.CertificationKing.com 91
CompTIA SY0-401 : Practice Test
C. TFTP
D. TLS

Answer: B

Question No : 232 DRAG DROP - (Topic 3)

Drag the items on the left to show the different types of security for the shown devices. Not
all fields need to be filled. Not all items need to be used.

Answer:

www.CertificationKing.com 92
CompTIA SY0-401 : Practice Test

Question No : 233 - (Topic 3)

Pete, a network administrator, is capturing packets on the network and notices that a large
amount of the traffic on the LAN is SIP and RTP protocols. Which of the following should
he do to segment that traffic from the other traffic?

A. Connect the WAP to a different switch.


B. Create a voice VLAN.
C. Create a DMZ.
D. Set the switch ports to 802.1q mode.

Answer: B

Question No : 234 - (Topic 3)

A user in the company is in charge of various financial roles but needs to prepare for an
upcoming audit. They use the same account to access each financial system. Which of the
following security controls will MOST likely be implemented within the company?

www.CertificationKing.com 93
CompTIA SY0-401 : Practice Test
A. Account lockout policy
B. Account password enforcement
C. Password complexity enabled
D. Separation of duties

Answer: D

Question No : 235 - (Topic 3)

Developers currently have access to update production servers without going through an
approval process. Which of the following strategies would BEST mitigate this risk?

A. Incident management
B. Clean desk policy
C. Routine audits
D. Change management

Answer: D

Question No : 236 - (Topic 3)

Suspicious traffic without a specific signature was detected. Under further investigation, it
was determined that these were false indicators. Which of the following security devices
needs to be configured to disable future false alarms?

A. Signature based IPS


B. Signature based IDS
C. Application based IPS
D. Anomaly based IDS

Answer: D

Question No : 237 DRAG DROP - (Topic 3)

You have been tasked with designing a security plan for your company. Drag and drop the
appropriate security controls on the floor plan-Instructions: All objects must be used and all
place holders must be filled Order does not matter When you have completed the

www.CertificationKing.com 94
CompTIA SY0-401 : Practice Test
simulation, please select the Done button to submit.

Answer:

www.CertificationKing.com 95
CompTIA SY0-401 : Practice Test

Question No : 238 - (Topic 3)

Sara, a user, downloads a keygen to install pirated software. After running the keygen,
system performance is extremely slow and numerous antivirus alerts are displayed. Which
of the following BEST describes this type of malware?

A. Logic bomb
B. Worm
C. Trojan
D. Adware

Answer: C

Question No : 239 - (Topic 3)

Which of the following technologies uses multiple devices to share work?

A. Switching
B. Load balancing
C. RAID
D. VPN concentrator

Answer: B

Question No : 240 - (Topic 3)

If Organization A trusts Organization B and Organization B trusts Organization C, then

Organization A trusts Organization C. Which of the following PKI concepts is this


describing?

A. Transitive trust
B. Public key trust
C. Certificate authority trust
D. Domain level trust

Answer: A

www.CertificationKing.com 96
CompTIA SY0-401 : Practice Test

Question No : 241 - (Topic 3)

Sara, a company's security officer, often receives reports of unauthorized personnel having
access codes to the cipher locks of secure areas in the building. Sara should immediately
implement which of the following?

A. Acceptable Use Policy


B. Physical security controls
C. Technical controls
D. Security awareness training

Answer: D

Question No : 242 - (Topic 3)

A security administrator has configured FTP in passive mode. Which of the following ports
should the security administrator allow on the firewall by default?

A. 20
B. 21
C. 22
D. 23

Answer: B

Question No : 243 - (Topic 3)

Which of the following is used to certify intermediate authorities in a large PKI deployment?

A. Root CA
B. Recovery agent
C. Root user
D. Key escrow

Answer: A

Question No : 244 - (Topic 3)

www.CertificationKing.com 97
CompTIA SY0-401 : Practice Test
Privilege creep among long-term employees can be mitigated by which of the following
procedures?

A. User permission reviews


B. Mandatory vacations
C. Separation of duties
D. Job function rotation

Answer: A

Question No : 245 - (Topic 3)

A security administrator has just finished creating a hot site for the company. This
implementation relates to which of the following concepts?

A. Confidentiality
B. Availability
C. Succession planning
D. Integrity

Answer: B

Question No : 246 - (Topic 3)

After Matt, a user, enters his username and password at the login screen of a web enabled
portal, the following appears on his screen:

`Please only use letters and numbers on these fields'

Which of the following is this an example of?

A. Proper error handling


B. Proper input validation
C. Improper input validation
D. Improper error handling

Answer: B

www.CertificationKing.com 98
CompTIA SY0-401 : Practice Test

Question No : 247 - (Topic 3)

Which of the following can use RC4 for encryption? (Select TWO).

A. CHAP
B. SSL
C. WEP
D. AES
E. 3DES

Answer: B,C

Question No : 248 - (Topic 3)

Which of the following BEST describes a protective countermeasure for SQL injection?

A. Eliminating cross-site scripting vulnerabilities


B. Installing an IDS to monitor network traffic
C. Validating user input in web applications
D. Placing a firewall between the Internet and database servers

Answer: C

Question No : 249 DRAG DROP - (Topic 3)

A Security administrator wants to implement strong security on the company smart phones
and terminal servers located in the data center. Drag and Drop the applicable controls to
each asset type.

Instructions: Controls can be used multiple times and not all placeholders needs to be
filled. When you have completed the simulation, Please select Done to submit.

www.CertificationKing.com 99
CompTIA SY0-401 : Practice Test

Answer:

Question No : 250 - (Topic 3)

Users at a company report that a popular news website keeps taking them to a web page
with derogatory content. This is an example of which of the following?

A. Evil twin
B. DNS poisoning
C. Vishing

www.CertificationKing.com 100
CompTIA SY0-401 : Practice Test
D. Session hijacking

Answer: B

Question No : 251 - (Topic 3)

Which of the following is the below pseudo-code an example of?

IF VARIABLE (CONTAINS NUMBERS = TRUE) THEN EXIT

A. Buffer overflow prevention


B. Input validation
C. CSRF prevention
D. Cross-site scripting prevention

Answer: B

Question No : 252 - (Topic 3)

Which of the following can Pete, a security administrator, use to distribute the processing
effort when generating hashes for a password cracking program?

A. RAID
B. Clustering
C. Redundancy
D. Virtualization

Answer: B

Question No : 253 - (Topic 3)

An email client says a digital signature is invalid and the sender cannot be verified. The
recipient is concerned with which of the following concepts?

A. Integrity
B. Availability
C. Confidentiality

www.CertificationKing.com 101
CompTIA SY0-401 : Practice Test
D. Remediation

Answer: A

Question No : 254 HOTSPOT - (Topic 3)

The security administrator has installed a new firewall which implements an implicit DENY
policy by default Click on the firewall and configure it to allow ONLY the following
communication.

1. The Accounting workstation can ONLY access the web server on the public network
over the default HTTPS port. The accounting workstation should not access other
networks.

2. The HR workstation should be restricted to communicate with the Financial server


ONLY, over the default SCP port

3. The Admin workstation should ONLY be able to access the servers on the secure
network over the default TFTP port.

Instructions: The firewall will process the rules in a top-down manner in order as a first
match The port number must be typed in and only one port number can be entered per rule
Type ANY for all ports. The original firewall configuration can be reset at any time by
pressing the reset button. Once you have met the simulation requirements, click save and
then Done to submit.

www.CertificationKing.com 102
CompTIA SY0-401 : Practice Test

www.CertificationKing.com 103
CompTIA SY0-401 : Practice Test

Answer:

www.CertificationKing.com 104
CompTIA SY0-401 : Practice Test

Question No : 255 HOTSPOT - (Topic 3)

For each of the given items, select the appropriate authentication category from the drop
down choices.

Select the appropriate authentication type for the following items:

www.CertificationKing.com 105
CompTIA SY0-401 : Practice Test

www.CertificationKing.com 106
CompTIA SY0-401 : Practice Test

www.CertificationKing.com 107
CompTIA SY0-401 : Practice Test
Answer:

www.CertificationKing.com 108
CompTIA SY0-401 : Practice Test

Question No : 256 - (Topic 3)

Which of the following MOST interferes with network-based detection techniques?

A. Mime-encoding
B. SSL
C. FTP
D. Anonymous email accounts

Answer: B

Question No : 257 - (Topic 3)

Which of the following transportation encryption protocols should be used to ensure


maximum security between a web browser and a web server?

A. SSLv2
B. SSHv1
C. RSA
D. TLS

Answer: D

Question No : 258 - (Topic 3)

Use of group accounts should be minimized to ensure which of the following?

A. Password security
B. Regular auditing
C. Baseline management
D. Individual accountability

Answer: D

Question No : 259 - (Topic 3)

Which of the following can be used on a smartphone to BEST protect against sensitive

www.CertificationKing.com 109
CompTIA SY0-401 : Practice Test
data loss if the device is stolen? (Select TWO).

A. Tethering
B. Screen lock PIN
C. Remote wipe
D. Email password
E. GPS tracking
F. Device encryption

Answer: C,F

Question No : 260 - (Topic 3)

A company storing data on a secure server wants to ensure it is legally able to dismiss and
prosecute staff who intentionally access the server via Telnet and illegally tamper with
customer data. Which of the following administrative controls should be implemented to
BEST achieve this?

A. Command shell restrictions


B. Restricted interface
C. Warning banners
D. Session output pipe to /dev/null

Answer: C

Question No : 261 - (Topic 3)

Jane, an individual, has recently been calling various financial offices pretending to be
another person to gain financial information. Which of the following attacks is being
described?

A. Phishing
B. Tailgating
C. Pharming
D. Vishing

Answer: D

www.CertificationKing.com 110
CompTIA SY0-401 : Practice Test

Question No : 262 - (Topic 3)

Which of the following authentication services requires the use of a ticket-granting ticket
(TGT) server in order to complete the authentication process?

A. TACACS+
B. Secure LDAP
C. RADIUS
D. Kerberos

Answer: D

Question No : 263 - (Topic 3)

Mike, a security professional, is tasked with actively verifying the strength of the security
controls on a company's live modem pool. Which of the following activities is MOST
appropriate?

A. War dialing
B. War chalking
C. War driving
D. Bluesnarfing

Answer: A

Question No : 264 - (Topic 3)

Which of the following allows Pete, a security technician, to provide the MOST secure
wireless implementation?

A. Implement WPA
B. Disable SSID
C. Adjust antenna placement
D. Implement WEP

Answer: A

Question No : 265 - (Topic 3)


www.CertificationKing.com 111
CompTIA SY0-401 : Practice Test
Several bins are located throughout a building for secure disposal of sensitive information.

Which of the following does this prevent?

A. Dumpster diving
B. War driving
C. Tailgating
D. War chalking

Answer: A

Question No : 266 - (Topic 3)

Jane, a security administrator, has observed repeated attempts to break into a server.
Which of the following is designed to stop an intrusion on a specific server?

A. HIPS
B. NIDS
C. HIDS
D. NIPS

Answer: A

Question No : 267 - (Topic 3)

In which of the following scenarios is PKI LEAST hardened?

A. The CRL is posted to a publicly accessible location.


B. The recorded time offsets are developed with symmetric keys.
C. A malicious CA certificate is loaded on all the clients.
D. All public keys are accessed by an unauthorized user.

Answer: C

Question No : 268 - (Topic 3)

Which of the following security concepts would Sara, the security administrator, use to

www.CertificationKing.com 112
CompTIA SY0-401 : Practice Test
mitigate the risk of data loss?

A. Record time offset


B. Clean desk policy
C. Cloud computing
D. Routine log review

Answer: B

Question No : 269 - (Topic 3)

In the initial stages of an incident response, Matt, the security administrator, was provided
the hard drives in QUESTION NO: from the incident manager. Which of the following
incident response procedures would he need to perform in order to begin the analysis?
(Select TWO).

A. Take hashes
B. Begin the chain of custody paperwork
C. Take screen shots
D. Capture the system image
E. Decompile suspicious files

Answer: A,D

Question No : 270 - (Topic 3)

Which of the following IP addresses would be hosts on the same subnet given the subnet
mask 255.255.255.224? (Select TWO).

A. 10.4.4.125
B. 10.4.4.158
C. 10.4.4.165
D. 10.4.4.189
E. 10.4.4.199

Answer: C,D

Question No : 271 - (Topic 3)

www.CertificationKing.com 113
CompTIA SY0-401 : Practice Test
Which of the following is a difference between TFTP and FTP?

A. TFTP is slower than FTP.


B. TFTP is more secure than FTP.
C. TFTP utilizes TCP and FTP uses UDP.
D. TFTP utilizes UDP and FTP uses TCP.

Answer: D

Question No : 272 - (Topic 3)

Which of the following will allow Pete, a security analyst, to trigger a security alert because
of a tracking cookie?

A. Network based firewall


B. Anti-spam software
C. Host based firewall
D. Anti-spyware software

Answer: D

Question No : 273 - (Topic 3)

A security administrator implements access controls based on the security classification of


the data and need-to-know information. Which of the following BEST describes this level of
access control?

A. Implicit deny
B. Role-based Access Control
C. Mandatory Access Controls
D. Least privilege

Answer: C

Question No : 274 - (Topic 3)

A system administrator is using a packet sniffer to troubleshoot remote authentication. The

www.CertificationKing.com 114
CompTIA SY0-401 : Practice Test
administrator detects a device trying to communicate to TCP port 49. Which of the following
authentication methods is MOST likely being attempted?

A. RADIUS
B. TACACS+
C. Kerberos
D. LDAP

Answer: B

Question No : 275 - (Topic 3)

Which of the following is BEST used as a secure replacement for TELNET?

A. HTTPS
B. HMAC
C. GPG
D. SSH

Answer: D

Question No : 276 CORRECT TEXT - (Topic 3)

www.CertificationKing.com 115
CompTIA SY0-401 : Practice Test

Answer: Use the following answer for this simulation task.

Question No : 277 - (Topic 3)

Which of the following security strategies allows a company to limit damage to internal
systems and provides loss control?

A. Restoration and recovery strategies


B. Deterrent strategies
C. Containment strategies
D. Detection strategies

Answer: C

www.CertificationKing.com 116
CompTIA SY0-401 : Practice Test

Question No : 278 - (Topic 3)

Which of the following is an effective way to ensure the BEST temperature for all
equipment within a datacenter?

A. Fire suppression
B. Raised floor implementation
C. EMI shielding
D. Hot or cool aisle containment

Answer: D

Question No : 279 - (Topic 3)

Which of the following is an example of multifactor authentication?

A. Credit card and PIN


B. Username and password
C. Password and PIN
D. Fingerprint and retina scan

Answer: A

Question No : 280 - (Topic 3)

Jane, a security analyst, is reviewing logs from hosts across the Internet which her
company uses to gather data on new malware. Which of the following is being
implemented by Jane's company?

A. Vulnerability scanner
B. Honeynet
C. Protocol analyzer
D. Port scanner

Answer: B

www.CertificationKing.com 117
CompTIA SY0-401 : Practice Test

Question No : 281 - (Topic 3)

A certificate authority takes which of the following actions in PKI?

A. Signs and verifies all infrastructure messages


B. Issues and signs all private keys
C. Publishes key escrow lists to CRLs
D. Issues and signs all root certificates

Answer: D

Question No : 282 - (Topic 3)

Which of the following is characterized by an attacker attempting to map out an


organization's staff hierarchy in order to send targeted emails?

A. Whaling
B. Impersonation
C. Privilege escalation
D. Spear phishing

Answer: A

Question No : 283 - (Topic 3)

Which of the following can be used to mitigate risk if a mobile device is lost?

A. Cable lock
B. Transport encryption
C. Voice encryption
D. Strong passwords

Answer: D

Question No : 284 - (Topic 3)

Which of the following should be considered to mitigate data theft when using CAT5

www.CertificationKing.com 118

You might also like