CompTIA CompTIA certification is the aspiration of all of the IT enthusiasts who want to have a very bright future in the area of That. However, passing the actual CompTIA certification exam is not the easy activity only simply by yourself. Should you be one of these kinds of IT aspirants, please end at Exambible.net and find everything you want for the CompTIA SY0-401 exam preparation.

2021 Feb SY0-401 download

Q551. An organization's security policy states that users must authenticate using something you do. Which of the following would meet the objectives of the security policy? 

A. Fingerprint analysis 

B. Signature analysis 

C. Swipe a badge 

D. Password 

Answer:

Explanation: 


Q552. A user has plugged in a wireless router from home with default configurations into a network jack at the office. This is known as: 

A. an evil twin. 

B. an IV attack. 

C. a rogue access point. 

D. an unauthorized entry point. 

Answer:

Explanation: 


Q553. A security engineer is reviewing log data and sees the output below: 

POST: /payload.php HTTP/1.1 HOST: localhost Accept: */* Referrer: http://localhost/ ******* HTTP/1.1 403 Forbidden Connection: close 

Log: Access denied with 403. Pattern matches form bypass Which of the following technologies was MOST likely being used to generate this log? 

A. Host-based Intrusion Detection System 

B. Web application firewall 

C. Network-based Intrusion Detection System 

D. Stateful Inspection Firewall 

E. URL Content Filter 

Answer:

Explanation: 

A web application firewall is a device, server add-on, virtual service, or system filter that defines a strict set of communication rules for a website and all visitors. It’s intended to be an application-specific firewall to prevent cross-site scripting, SQL injection, and other web application attacks. 


Q554. The Chief Information Officer (CIO) wants to implement a redundant server location to which the production server images can be moved within 48 hours and services can be quickly restored, in case of a catastrophic failure of the primary datacenter’s HVAC. Which of the following can be implemented? 

A. Cold site 

B. Load balancing 

C. Warm site 

D. Hot site 

Answer:

Explanation: 

Warm sites provide computer systems and compatible media capabilities. If a warm site is used, administrators and other staff will need to install and configure systems to resume operations. For most organizations, a warm site could be a remote office, a leased facility, or another organization with which yours has a reciprocal agreement. 


Q555. An administrator needs to renew a certificate for a web server. Which of the following should be submitted to a CA? 

A. CSR 

B. Recovery agent 

C. Private key 

D. CRL 

Answer:

Explanation: 

In public key infrastructure (PKI) systems, a certificate signing request (also CSR or certification 

request) is a message sent from an applicant to a certificate authority in order to apply for a digital 

identity certificate. 

When you renew a certificate you send a CSR to the CA to get the certificate resigned. 


Renewal SY0-401 rapidshare:

Q556. XYZ Corporation is about to purchase another company to expand its operations. The CEO is concerned about information leaking out, especially with the cleaning crew that comes in at night. 

The CEO would like to ensure no paper files are leaked. Which of the following is the BEST policy to implement? 

A. Social media policy 

B. Data retention policy 

C. CCTV policy 

D. Clean desk policy 

Answer:

Explanation: 

Clean Desk Policy Information on a desk—in terms of printouts, pads of note paper, sticky notes, and the like—can be easily seen by prying eyes and taken by thieving hands. To protect data and your business, encourage employees to maintain clean desks and to leave out only those papers that are relevant to the project they are working on at that moment. All sensitive information should be put away when the employee is away from their desk. 


Q557. The method to provide end users of IT systems and applications with requirements related to acceptable use, privacy, new threats and trends, and use of social networking is: 

A. Security awareness training. 

B. BYOD security training. 

C. Role-based security training. 

D. Legal compliance training. 

Answer:

Explanation: 

Security awareness and training are critical to the success of a security effort. They include explaining policies, procedures, and current threats to both users and management. 


Q558. A small business needs to incorporate fault tolerance into their infrastructure to increase data availability. Which of the following options would be the BEST solution at a minimal cost? 

A. Clustering 

B. Mirrored server 

C. RAID 

D. Tape backup 

Answer:

Explanation: 

RAID, or redundant array of independent disks (RAID). RAID allows your existing servers to have more than one hard drive so that if the main hard drive fails, the system keeps functioning. RAID can achieve fault tolerance using software which can be done using the existing hardware and software. 


Q559. Which of the following protocols is the security administrator observing in this packet capture? 

12:33:43, SRC 192.168.4.3:3389, DST 10.67.33.20:8080, SYN/ACK 

A. HTTPS 

B. RDP 

C. HTTP 

D. SFTP 

Answer:

Explanation: 

Remote Desktop Protocol (RDP) is a proprietary protocol developed by Microsoft, which provides 

a user with a graphical interface to connect to another computer over a network connection. 

Example of RDP tracing output: 

No. Time Delta Source Destination Protocol Length Info 

5782, 2013-01-06 09:52:15.407, 0.000 , SRC 10.7.3.187 , DST 10.0.107.58, TCP, 62, 3389 > 

59193 [SYN, ACK] 


Q560. Which of the following is the default port for TFTP? 

A. 20 

B. 69 

C. 21 

D. 68 

Answer:

Explanation: 

TFTP makes use of UDP port 69.