CompTIA accreditation will be the earths many well-respected international accreditation. Therefore SY0-401 is very required for those who find themselves nervous to enter the actual That company. But it is extremely tough if youre busy functioning or studying to pass the actual CompTIA Security+ Certification check. Testking CompTIA SY0-401 examine guides can help you preserving a large amount of time,power and resource within the SY0-401 check. You can manage this kind of SY0-401 check efficiently by our own SY0-401 pdf and check motor. Were able to keep the product in a timely manner and let visitors to learn CompTIA information very easily. You can also down load the actual CompTIA SY0-401 pdf demo edition totally free.

2021 Dec SY0-401 exam question

Q681. Which of the following should be implemented to stop an attacker from mapping out addresses and/or devices on a network? 

A. Single sign on 

B. IPv6 

C. Secure zone transfers 

D. VoIP 

Answer:

Explanation: 

C: A primary DNS server has the "master copy" of a zone, and secondary DNS servers keep copies of the zone for redundancy. When changes are made to zone data on the primary DNS server, these changes must be distributed to the secondary DNS servers for the zone. This is done through zone transfers. If you allow zone transfers to any server, all the resource records in the zone are viewable by any host that can contact your DNS server. Thus you will need to secure the zone transfers to stop an attacker from mapping out your addresses and devices on your network. 


Q682. TION NO: 174 

Jane, an administrator, needs to make sure the wireless network is not accessible from the parking area of their office. Which of the following would BEST help Jane when deploying a new access point? 

A. Placement of antenna 

B. Disabling the SSID 

C. Implementing WPA2 

D. Enabling the MAC filtering 

Answer:

Explanation: 

You should try to avoid placing access points near metal (which includes appliances) or near the ground. Placing them in the center of the area to be served and high enough to get around most obstacles is recommended. On the chance that the signal is actually traveling too far, some access points include power level controls, which allow you to reduce the amount of output provided. 


Q683. The security administrator is currently unaware of an incident that occurred a week ago. Which of the following will ensure the administrator is notified in a timely manner in the future? 

A. User permissions reviews 

B. Incident response team 

C. Change management 

D. Routine auditing 

Answer:

Explanation: 

Routine audits are carried out after you have implemented security controls based on risk. These audits include aspects such as user rights and permissions and specific events. 


Q684. Which of the following controls mitigates the risk of Matt, an attacker, gaining access to a company network by using a former employee’s credential? 

A. Account expiration 

B. Password complexity 

C. Account lockout 

D. Dual factor authentication 

Answer:

Explanation: 

Account expiration is a secure feature to employ on user accounts for temporary workers, interns, or consultants. It automatically disables a user account or causes the account to expire at a specific time and on a specific day. 


Up to date SY0-401 exam topics:

Q685. Pete, the system administrator, is reviewing his disaster recovery plans. He wishes to limit the downtime in the event of a disaster, but does not have the budget approval to implement or maintain an offsite location that ensures 99.99% availability. Which of the following would be Pete’s BEST option? 

A. Use hardware already at an offsite location and configure it to be quickly utilized. 

B. Move the servers and data to another part of the company’s main campus from the server room. 

C. Retain data back-ups on the main campus and establish redundant servers in a virtual environment. 

D. Move the data back-ups to the offsite location, but retain the hardware on the main campus for redundancy. 

Answer:

Explanation: 

A warm site provides some of the capabilities of a hot site, but it requires the customer to do more work to become operational. Warm sites provide computer systems and compatible media capabilities. If a warm site is used, administrators and other staff will need to install and configure systems to resume operations. For most organizations, a warm site could be a remote office, a leased facility, or another organization with which yours has a reciprocal agreement. Warm sites may be for your exclusive use, but they don’t have to be. A warm site requires more advanced planning, testing, and access to media for system recovery. Warm sites represent a compromise between a hot site, which is very expensive, and a cold site, which isn’t preconfigured. 


Q686. Users report that after downloading several applications, their systems’ performance has noticeably decreased. Which of the following would be used to validate programs prior to installing them? 

A. Whole disk encryption 

B. SSH 

C. Telnet 

D. MD5 

Answer:

Explanation: 

MD5 can be used to locate the data which has changed. 

The Message Digest Algorithm (MD) creates a hash value and uses a one-way hash. The hash 

value is used to help maintain integrity. There are several versions of MD; the most common are 

MD5, MD4, and MD2. 


Q687. Which of the following types of technologies is used by security and research personnel for identification and analysis of new security threats in a networked environment by using false data/hosts for information collection? 

A. Honeynet 

B. Vulnerability scanner 

C. Port scanner 

D. Protocol analyzer 

Answer:

Explanation: 


Q688. A network inventory discovery application requires non-privileged access to all hosts on a network for inventory of installed applications. A service account is created by the network inventory discovery application for accessing all hosts. Which of the following is the MOST efficient method for granting the account non-privileged access to the hosts? 

A. Implement Group Policy to add the account to the users group on the hosts 

B. Add the account to the Domain Administrator group 

C. Add the account to the Users group on the hosts 

D. Implement Group Policy to add the account to the Power Users group on the hosts. 

Answer:

Explanation: 

Group Policy is an infrastructure that allows you to implement specific configurations for users and computers. Group Policy settings are contained in Group Policy objects (GPOs), which are linked to the following Active Directory directory service containers: sites, domains, or organizational units (OUs). This means that if the GPO is linked to the domain, all Users groups in the domain will include the service account. 


Q689. The system administrator is tasked with changing the administrator password across all 2000 computers in the organization. Which of the following should the system administrator implement to accomplish this task? 

A. A security group 

B. A group policy 

C. Key escrow 

D. Certificate revocation 

Answer:

Explanation: 

Group policy is used to manage Windows systems in a Windows network domain environment by means of a Group Policy Object (GPO). GPO’s include a number of settings related to credentials, such as password complexity requirements, password history, password length, account lockout settings.