getcertified4sure.com

Top CompTIA SY0-401 preparation labs Choices




The CompTIA SY0-401 exam is probably the CompTIA certification exams. It examines the particular candidates abilities and also skills in order to operate and also troubleshoot a network. Candidates can easily take the particular CompTIA CompTIA exam training course at Pass4sure to get certified. The CompTIA SY0-401 course includes printable Pdf courseware and also downloadable test engine; exclusive learning zone which you can communicate with other candidates; live chat with our own instructors at anytime round the clock; passing guarantee which have info proof; one yr free upgrades policy.

2021 Apr SY0-401 braindumps

Q361. A security administrator must implement a network that is immune to ARP spoofing attacks. Which of the following should be implemented to ensure that a malicious insider will not be able to successfully use ARP spoofing techniques? 

A. UDP 

B. IPv6 

C. IPSec 

D. VPN 

Answer:

Explanation: 


Q362. A small company can only afford to buy an all-in-one wireless router/switch. The company has 3 wireless BYOD users and 2 web servers without wireless access. Which of the following should the company configure to protect the servers from the user devices? (Select TWO). 

A. Deny incoming connections to the outside router interface. 

B. Change the default HTTP port 

C. Implement EAP-TLS to establish mutual authentication 

D. Disable the physical switch ports 

E. Create a server VLAN 

F. Create an ACL to access the server 

Answer: E,F 

Explanation: 

We can protect the servers from the user devices by separating them into separate VLANs (virtual local area networks). 

The network device in the question is a router/switch. We can use the router to allow access from devices in one VLAN to the servers in the other VLAN. We can configure an ACL (Access Control List) on the router to determine who is able to access the server. 

In computer networking, a single layer-2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them via one or more routers; such a domain is referred to as a virtual local area network, virtual LAN or VLAN. This is usually achieved on switch or router devices. Simpler devices only support partitioning on a port level (if at all), so sharing VLANs across devices requires running dedicated cabling for each VLAN. More sophisticated devices can mark packets through tagging, so that a single interconnect (trunk) may be used to transport data for multiple VLANs. Grouping hosts with a common set of requirements regardless of their physical location by VLAN can greatly simplify network design. A VLAN has the same attributes as a physical local area network (LAN), but it allows for end stations to be grouped together more easily even if they are not on the same network switch. The network described in this question is a DMZ, not a VLAN. 


Q363. A network stream needs to be encrypted. Sara, the network administrator, has selected a cipher which will encrypt 8 bits at a time before sending the data across the network. Which of the following has Sara selected? 

A. Block cipher 

B. Stream cipher 

C. CRC 

D. Hashing algorithm 

Answer:

Explanation: 

With a block cipher the algorithm works on chunks of data—encrypting one and then moving to the 

next. 

Example: Blowfish is an encryption system that performs a 64-bit block cipher at very fast speeds. 


Q364. A user was reissued a smart card after the previous smart card had expired. The user is able to log into the domain but is now unable to send digitally signed or encrypted email. Which of the following would the user need to perform? 

A. Remove all previous smart card certificates from the local certificate store. 

B. Publish the new certificates to the global address list. 

C. Make the certificates available to the operating system. 

D. Recover the previous smart card certificates. 

Answer:

Explanation: 

CAs can be either private or public, with VeriSign being one of the best known of the public variety. Many operating system providers allow their systems to be configured as CA systems. 

These CA systems can be used to generate internal certificates that are used within a business or in large external settings. The process provides certificates to the users. Since the user in question has been re-issued a smart card, the user must receive a new certificate by the CA to allow the user to send digitally signed email. This is achieved by publishing the new certificates to the global address list. 


Q365. An administrator needs to secure a wireless network and restrict access based on the hardware address of the device. Which of the following solutions should be implemented? 

A. Use a stateful firewall 

B. Enable MAC filtering 

C. Upgrade to WPA2 encryption 

D. Force the WAP to use channel 1 

Answer:

Explanation: 


Improved SY0-401 test engine:

Q366. Joe is the accounts payable agent for ABC Company. Joe has been performing accounts payable function for the ABC Company without any supervision. Management has noticed several new accounts without billing invoices that were paid. Which of the following is the BEST management option for review of the new accounts? 

A. Mandatory vacation 

B. Job rotation 

C. Separation of duties 

D. Replacement 

Answer:

Explanation: 


Q367. Which of the following is a concern when encrypting wireless data with WEP? 

A. WEP displays the plain text entire key when wireless packet captures are reassembled 

B. WEP implements weak initialization vectors for key transmission 

C. WEP uses a very weak encryption algorithm 

D. WEP allows for only four pre-shared keys to be configured 

Answer:

Explanation: 

The initialization vector (IV) that WEP uses for encryption is 24-bit, which is quite weak and means that IVs are reused with the same key. By examining the repeating result, it was easy for attackers to crack the WEP secret key. This is known as an IV attack. 


Q368. In the initial stages of an incident response, Matt, the security administrator, was provided the hard drives in question from the incident manager. Which of the following incident response procedures would he need to perform in order to begin the analysis? (Select TWO). 

A. Take hashes 

B. Begin the chain of custody paperwork 

C. Take screen shots 

D. Capture the system image 

E. Decompile suspicious files 

Answer: A,D 

Explanation: 

A: Take Hashes. NIST (the National Institute of Standards and Technology) maintains a National Software Reference Library (NSRL). One of the purposes of the NSRL is to collect “known, traceable software applications” through their hash values and store them in a Reference Data Set (RDS). The RDS can then be used by law enforcement, government agencies, and businesses to determine which fi les are important as evidence in criminal investigations. 

D: A system image is a snapshot of what exists. Capturing an image of the operating system in its exploited state can be helpful in revisiting the issue after the fact to learn more about it. 


Q369. RADIUS provides which of the following? 

A. Authentication, Authorization, Availability 

B. Authentication, Authorization, Auditing 

C. Authentication, Accounting, Auditing 

D. Authentication, Authorization, Accounting 

Answer:

Explanation: 

The Remote Authentication Dial In User Service (RADIUS) networking protocol offers centralized Authentication, Authorization, and Accounting (AAA) management for users who make use of a network service. It is for this reason that A, B, and C: are incorrect. 

References: http://en.wikipedia.org/wiki/RADIUS 


Q370. Which of the following statements is MOST likely to be included in the security awareness training about P2P? 

A. P2P is always used to download copyrighted material. 

B. P2P can be used to improve computer system response. 

C. P2P may prevent viruses from entering the network. 

D. P2P may cause excessive network bandwidth. 

Answer:

Explanation: 

P2P networking by definition involves networking which will reduce available bandwidth for the rest of the users on the network.