And so, should you have pondered placing some sort of CompTIA SY0-401 abilities once name, keep in mind that it does have a perceived and intensely true worth. Whether youre excited about finding your own CompTIA SY0-401 recognition ( CompTIA Security+ Certification ) youre for directly on keep track of in the direction of taking your job to a different and higher amount.


♥♥ 2021 NEW RECOMMEND ♥♥

Free VCE & PDF File for CompTIA SY0-401 Real Exam (Full Version!)

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW SY0-401 Exam Dumps (PDF & VCE):
Available on: http://www.surepassexam.com/SY0-401-exam-dumps.html

2021 Mar SY0-401 real exam

Q161. A large bank has moved back office operations offshore to another country with lower wage costs in an attempt to improve profit and productivity. Which of the following would be a customer concern if the offshore staff had direct access to their data? 

A. Service level agreements 

B. Interoperability agreements 

C. Privacy considerations 

D. Data ownership 

Answer: C 

Explanation: 


Q162. Which of the following risk mitigation strategies will allow Ann, a security analyst, to enforce least privilege principles? 

A. User rights reviews 

B. Incident management 

C. Risk based controls 

D. Annual loss expectancy 

Answer: A 

Explanation: 

A least privilege policy should be used when assigning permissions. Give users only the permissions and rights that they need to do their work and no more. 


Q163. The security department has implemented a new laptop encryption product in the environment. The product requires one user name and password at the time of boot up and also another password after the operating system has finished loading. This setup is using which of the following authentication types? 

A. Two-factor authentication 

B. Single sign-on 

C. Multifactor authentication 

D. Single factor authentication 

Answer: D 

Explanation: 

Single-factor authentication is when only one authentication factor is used. In this case, Something you know is being used as an authentication factor. Username, password, and PIN form part of Something you know. 


Q164. Jane, a VPN administrator, was asked to implement an encryption cipher with a MINIMUM effective security of 128-bits. Which of the following should Jane select for the tunnel encryption? 

A. Blowfish 

B. DES 

C. SHA256 

D. HMAC 

Answer: A 

Explanation: 

Blowfish is an encryption system that performs a 64-bit block cipher at very fast speeds. It is a symmetric block cipher that can use variable-length keys (from 32 bits to 448 bits). Among the alternatives listed above, it is the only cipher that can use a 128-bit key and which does provide additional security through a symmetric key. 


Q165. A security administrator must implement a system to allow clients to securely negotiate encryption keys with the company’s server over a public unencrypted communication channel. 

Which of the following implements the required secure key negotiation? (Select TWO). 

A. PBKDF2 

B. Symmetric encryption 

C. Steganography 

D. ECDHE 

E. Diffie-Hellman 

Answer: D,E 

Explanation: 

Elliptic curve Diffie–Hellman (ECDH) is an anonymous key agreement protocol that allows two parties, each having an elliptic curve public-private key pair, to establish a shared secret over an insecure channel. This shared secret may be directly used as a key, or better yet, to derive another key which can then be used to encrypt subsequent communications using a symmetric key cipher. It is a variant of the Diffie–Hellman protocol using elliptic curve cryptography. Note: Adding an ephemeral key to Diffie-Hellman turns it into DHE (which, despite the order of the acronym, stands for Ephemeral Diffie-Hellman). Adding an ephemeral key to Elliptic Curve Diffie-Hellman turns it into ECDHE (again, overlook the order of the acronym letters, it is called Ephemeral Elliptic Curve Diffie-Hellman). It is the ephemeral component of each of these that provides the perfect forward secrecy. 


Up to date SY0-401 real exam:

Q166. A company is trying to implement physical deterrent controls to improve the overall security posture of their data center. Which of the following BEST meets their goal? 

A. Visitor logs 

B. Firewall 

C. Hardware locks 

D. Environmental monitoring 

Answer: C 

Explanation: 

Hardware security involves applying physical security modifications to secure the system(s) and preventing them from leaving the facility. Don’t spend all of your time worrying about intruders coming through the network wire while overlooking the obvious need for physical security. Hardware security involves the use of locks to prevent someone from picking up and carrying out your equipment. 


Q167. ON NO: 50 

The Human Resources department has a parent shared folder setup on the server. There are two groups that have access, one called managers and one called staff. There are many sub folders under the parent shared folder, one is called payroll. The parent folder access control list propagates all subfolders and all subfolders inherit the parent permission. Which of the following is the quickest way to prevent the staff group from gaining access to the payroll folder? 

A. Remove the staff group from the payroll folder 

B. Implicit deny on the payroll folder for the staff group 

C. Implicit deny on the payroll folder for the managers group 

D. Remove inheritance from the payroll folder 

Answer: B 

Explanation: Implicit deny is the default security stance that says if you aren’t specifically granted access or privileges for a resource, you’re denied access by default. 


Q168. Account lockout is a mitigation strategy used by Jane, the administrator, to combat which of the following attacks? (Select TWO). 

A. Spoofing 

B. Man-in-the-middle 

C. Dictionary 

D. Brute force 

E. Privilege escalation 

Answer: C,D 

Explanation: 

Account lockout is a useful method for slowing down online password-guessing attacks. A dictionary attack performs password guessing by making use of a pre-existing list of likely passwords. A brute-force attack is intended to try every possible valid combination of characters to create possible passwords in the attempt to discover the specific passwords used by user accounts. 


Q169. A user ID and password together provide which of the following? 

A. Authorization 

B. Auditing 

C. Authentication 

D. Identification 

Answer: C 

Explanation: 

Authentication generally requires one or more of the following: 

Something you know: a password, code, PIN, combination, or secret phrase. 

Something you have: a smart card, token device, or key. 

Something you are: a fingerprint, a retina scan, or voice recognition; often referred to as 

biometrics, discussed later in this chapter. 

Somewhere you are: a physical or logical location. 

Something you do: typing rhythm, a secret handshake, or a private knock. 


Q170. A hacker has discovered a simple way to disrupt business for the day in a small company which relies on staff working remotely. In a matter of minutes the hacker was able to deny remotely working staff access to company systems with a script. Which of the following security controls is the hacker exploiting? 

A. DoS 

B. Account lockout 

C. Password recovery 

D. Password complexity 

Answer: B 

Explanation: 

B: Account lockout automatically disables an account due to repeated failed log on attempts. The hacker must have executed a script to repeatedly try logging on to the remote accounts, forcing the account lockout policy to activate.