CompTIA Security+ Certification Exam (SY0-301) Sample Questions:
1. The systems administrator wishes to implement a hardware-based encryption method that could also be used to sign code. They can achieve this by:
A) Moving data and applications into the cloud.
B) Utilizing the already present TPM.
C) Configuring secure application sandboxes.
D) Enforcing whole disk encryption.
2. Mandatory vacations are a security control which can be used to uncover which of the following?
A) Software vulnerabilities in vendor code
B) The need for additional security staff
C) Poor password security among users
D) Fraud committed by a system administrator
3. Which of the following protocols is vulnerable to man-in-the-middle attacks by NOT using end to end TLS encryption?
A) WEP
B) WPA
C) HTTPS
D) WPA 2
4. Which of the following disaster recovery strategies has the highest cost and shortest recovery time?
A) Warm site
B) Cold site
C) Hot site
D) Co-location site
5. Jane, the security administrator, sets up a new AP but realizes too many outsiders are able to connect to that AP and gain unauthorized access. Which of the following would be the BEST way to mitigate this issue and still provide coverage where needed? (Select TWO).
A) Enable MAC filtering
B) Disable the wired ports
C) Use channels 1, 4 and 7 only
D) Disable SSID broadcast
E) Switch from 802.11a to 802.11b
Solutions:
| Question # 1 Answer: B | Question # 2 Answer: D | Question # 3 Answer: B | Question # 4 Answer: C | Question # 5 Answer: A,D |

We're so confident of our products that we provide no hassle product exchange.


By John


