Master the sy0 401 study guide pdf CompTIA Security+ Certification content and be ready for exam day success quickly with this Examcollection sy0 401 vce question. We guarantee it!We make it a reality and give you real comptia security+ sy0 401 pdf questions in our CompTIA sy0 401 braindump braindumps.Latest 100% VALID CompTIA sy0 401 vce Exam Questions Dumps at below page. You can use our CompTIA security+ sy0 401 braindumps and pass your exam.


♥♥ 2021 NEW RECOMMEND ♥♥

Free VCE & PDF File for CompTIA SY0-401 Real Exam (Full Version!)

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW SY0-401 Exam Dumps (PDF & VCE):
Available on: http://www.surepassexam.com/SY0-401-exam-dumps.html

Q411. Which of the following defines a business goal for system restoration and acceptable data loss? 

A. MTTR 

B. MTBF 

C. RPO 

D. Warm site 

Answer:

Explanation: 

The recovery point objective (RPO) defines the point at which the system needs to be restored. This could be where the system was two days before it crashed (whip out the old backup tapes) or five minutes before it crashed (requiring complete redundancy). This is an essential business goal insofar as system restoration and acceptable data loss is concerned. 


Q412. Which of the following should be done before resetting a user’s password due to expiration? 

A. Verify the user’s domain membership. 

B. Verify the user’s identity. 

C. Advise the user of new policies. 

D. Verify the proper group membership. 

Answer:

Explanation: 

When resetting a password, users have to establish their identity by answering a series of personal questions, using a hardware authentication token, or responding to a password notification e-mail. Users can then either specify a new, unlocked password, or ask that a randomly generated one be provided. This can be done from their workstation login prompt, or through a telephone call. 


Q413. Ann, a security analyst, has discovered that her company has very high staff turnover and often user accounts are not disabled after an employee leaves the company. Which of the following could Ann implement to help identify accounts that are still active for terminated employees? 

A. Routine audits 

B. Account expirations 

C. Risk assessments 

D. Change management 

Answer:

Explanation: 


Q414. Ann, a security administrator at a call center, has been experiencing problems with users intentionally installing unapproved and occasionally malicious software on their computers. Due to the nature of their jobs, Ann cannot change their permissions. Which of the following would BEST alleviate her concerns? 

A. Deploy a HIDS suite on the users' computers to prevent application installation. 

B. Maintain the baseline posture at the highest OS patch level. 

C. Enable the pop-up blockers on the users' browsers to prevent malware. 

D. Create an approved application list and block anything not on it. 

Answer:

Explanation: 


Q415. When performing the daily review of the system vulnerability scans of the network Joe, the administrator, noticed several security related vulnerabilities with an assigned vulnerability identification number. Joe researches the assigned vulnerability identification number from the vendor website. Joe proceeds with applying the recommended solution for identified vulnerability. Which of the following is the type of vulnerability described? 

A. Network based 

B. IDS 

C. Signature based 

D. Host based 

Answer:

Explanation: 


Q416. A security administrator needs a locally stored record to remove the certificates of a terminated employee. Which of the following describes a service that could meet these requirements? 

A. OCSP 

B. PKI 

C. CA 

D. CRL 

Answer:

Explanation: 

A CRL is a locally stored record containing revoked certificates and revoked keys. 


Q417. Pete, an IT Administrator, needs to secure his server room. Which of the following mitigation methods would provide the MOST physical protection? 

A. Sign in and sign out logs 

B. Mantrap 

C. Video surveillance 

D. HVAC 

Answer:

Explanation: 

Mantraps are designed to contain an unauthorized, potentially hostile person/individual physically until authorities arrive. Mantraps are typically manufactured with bulletproof glass, high-strength doors, and locks and to allow the minimal amount of individuals depending on its size. Some mantraps even include scales that will weigh the person. The doors are designed in such a way as to open only when the mantrap is occupied or empty and not in-between. This means that the backdoor must first close before the front door will open. Mantraps are in most cases also combined with guards. This is the most physical protection any one measure will provide. 


Q418. Which of the following are examples of detective controls? 

A. Biometrics, motion sensors and mantraps. 

B. Audit, firewall, anti-virus and biometrics. 

C. Motion sensors, intruder alarm and audit. 

D. Intruder alarm, mantraps and firewall. 

Answer:

Explanation: 


Q419. Which of the following provides dedicated hardware-based cryptographic functions to an operating system and its applications running on laptops and desktops? 

A. TPM 

B. HSM 

C. CPU 

D. FPU 

Answer:

Explanation: 

Trusted Platform Module (TPM) is a hardware-based encryption solution that is embedded in the system’s motherboard and is enabled or disable in BIOS. It helps with hash key generation and stores cryptographic keys, passwords, or certificates. 


Q420. A password history value of three means which of the following? 

A. Three different passwords are used before one can be reused. 

B. A password cannot be reused once changed for three years. 

C. After three hours a password must be re-entered to continue. 

D. The server stores passwords in the database for three days. 

Answer:

Explanation: 

Password History defines the number of unique new passwords a user must use before an old password can be reused.