CompTIA Security+ Certification Exam (SY0-301) (SY0-301) Free Practice Test
Question 1
Customers' credit card information was stolen from a popular video streaming company. A security consultant determined that the information was stolen, while in transit, from the gaming consoles of a particular vendor. Which of the following methods should the company consider to secure this data in the future?
Correct Answer: B
Question 2
When verifying file integrity on a remote system that is bandwidth limited, which of the following tool combinations provides the STRONGEST confidence?
Correct Answer: C
Question 3
Mike, a security professional, is tasked with actively verifying the strength of the security controls on a company's live modem pool. Which of the following activities is MOST appropriate?
Correct Answer: B
Question 4
Sara, a company's security officer, often receives reports of unauthorized personnel having access codes to the cipher locks of secure areas in the building. Sara should immediately implement which of the following?
Correct Answer: B
Question 5
An attacker attempted to compromise a web form by inserting the following input into the username fielD.
admin)(|(password=*)) Which of the following types of attacks was attempted?
admin)(|(password=*)) Which of the following types of attacks was attempted?
Correct Answer: C
Question 6
Which of the following BEST describes a protective countermeasure for SQL injection?
Correct Answer: A
Question 7
Which of the following should an administrator implement to research current attack methodologies?
Correct Answer: A
Question 8
A security administrator plans on replacing a critical business application in five years. Recently, there was a security flaw discovered in the application that will cause the IT department to manually re-enable user accounts each month at a cost of $2,000. Patching the application today would cost $140,000 and take two months to implement. Which of the following should the security administrator do in regards to the application?
Correct Answer: A
Question 9
During which of the following phases of the Incident Response process should a security administrator define and implement general defense against malware?
Correct Answer: C
Question 10
Pete, the system administrator, has blocked users from accessing social media web sites. In addition to protecting company information from being accidentally leaked, which additional security benefit does this provide?
Correct Answer: A
Question 11
Which of the following should Pete, a security manager, implement to reduce the risk of employees working in collusion to embezzle funds from their company?
Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 12
Sara, a security administrator, is noticing a slow down in the wireless network response. Sara launches a wireless sniffer and sees a large number of ARP packets being sent to the AP. Which of the following type of attacks is underway?
Correct Answer: B