New CompTIA Security+ SY0-401 Practice Test with VCE and PDF from PassLeader (Question 1721 – Question 1730)

PassLeader released the NEWEST CompTIA SY0-401 exam dumps recently! Both SY0-401 VCE dumps and SY0-401 PDF dumps are available on PassLeader, either SY0-401 VCE dumps or SY0-401 PDF dumps have the NEWEST SY0-401 exam questions in it, they will help you passing CompTIA SY0-401 exam easily! You can download the valid SY0-401 dumps VCE and PDF from PassLeader here: https://www.passleader.com/sy0-401.html (1868 Q&As Dumps)

Also, previewing the NEWEST PassLeader SY0-401 dumps online for free on Google Drive: https://drive.google.com/open?id=0B-ob6L_QjGLpcG9CWHp3bXlNTTg

QUESTION 1721
A product manager is concerned about continuing operations at a facility located in a region undergoing significant political unrest. After consulting with senior management, a decision is made to suspend operations at the facility until the situation stabilizes. Which of the following risk management strategies BEST describes management’s response?

A.    Deterrence
B.    Mitigation
C.    Avoidance
D.    Acceptance

Answer: C

QUESTION 1722
Joe notices there are several user accounts on the local network generating spam with embedded malicious code. Which of the following technical control should Joe put in place to BEST reduce these incidents?

A.    Account lockout
B.    Group Based Privileges
C.    Least privilege
D.    Password complexity

Answer: A

QUESTION 1723
Two users need to securely share encrypted files via email. Company policy prohibits users from sharing credentials or exchanging encryption keys. Which of the following can be implemented to enable users to share encrypted data while abiding by company policies?

A.    Key escrow
B.    Digital signatures
C.    PKI
D.    Hashing

Answer: B

QUESTION 1724
An information system owner has supplied a new requirement to the development team that calls for increased non-repudiation within the application. After undergoing several audits, the owner determined that current levels of non-repudiation were insufficient. Which of the following capabilities would be MOST appropriate to consider implementing is response to the new requirement?

A.    Transitive trust
B.    Symmetric encryption
C.    Two-factor authentication
D.    Digital signatures
E.    One-time passwords

Answer: D

QUESTION 1725
Joe, a website administrator believes he owns the intellectual property for a company invention and has been replacing image files on the company’s public facing website in the DMZ. Joe is using steganography to hide stolen data. Which of the following controls can be implemented to mitigate this type of inside threat?

A.    Digital signatures
B.    File integrity monitoring
C.    Access controls
D.    Change management
E.    Stateful inspection firewall

Answer: B

QUESTION 1726
The process of applying a salt and cryptographic hash to a password then repeating the process many times is known as which of the following?

A.    Collision resistance
B.    Rainbow table
C.    Key stretching
D.    Brute force attack

Answer: C

QUESTION 1727
Which of the following is commonly used for federated identity management across multiple organizations?

A.    SAML
B.    Active Directory
C.    Kerberos
D.    LDAP

Answer: A

QUESTION 1728
While performing surveillance activities, an attacker determines that an organization is using 802.1x to secure LAN access. Which of the following attack mechanisms can the attacker utilize to bypass the identified network security?

A.    MAC spoofing
B.    Pharming
C.    Xmas attack
D.    ARP poisoning

Answer: A

QUESTION 1729
A security administrator has been asked to implement a VPN that will support remote access over IPSEC. Which of the following is an encryption algorithm that would meet this requirement?

A.    MD5
B.    AES
C.    UDP
D.    PKI

Answer: B

QUESTION 1730
A security administrator is evaluating three different services: radius, diameter, and Kerberos. Which of the following is a feature that is UNIQUE to Kerberos?

A.    It provides authentication services
B.    It uses tickets to identify authenticated users
C.    It provides single sign-on capability
D.    It uses XML for cross-platform interoperability

Answer: B


Welcome to choose PassLeader SY0-401 dumps for 100% passing CompTIA SY0-401 exam: https://www.passleader.com/sy0-401.html (1868 Q&As VCE Dumps and PDF Dumps)

Also, previewing the NEWEST PassLeader SY0-401 dumps online for free on Google Drive: https://drive.google.com/open?id=0B-ob6L_QjGLpcG9CWHp3bXlNTTg