SY0-401試験番号:SY0-401
試験科目:「CompTIA Security+ Certification」

NO.1 Recent data loss on financial servers due to security breaches forced the system administrator
to harden their systems. Which of the following algorithms with transport encryption would be
implemented to provide the MOST secure web connections to manage and access these servers?
Answer: C
Transport Layer Security (TLS) and its predecessor, Secure Sockets Layer (SSL), are cryptographic
protocols designed to provide communications security over a computer network. Transport Layer
Security (TLS) is a security protocol that expands upon SSL. Many industry analysts predict that TLS
will replace SSL in the future. TLS 1.0 was first defined in RFC 2246 in January 1999 as an upgrade of
SSL Version 3.0. As of February 2015, the latest versions of all major web browsers support TLS 1.0,
1.1, and 1.2, have them enabled by default.

NO.2 A recent audit has discovered that at the time of password expiration clients are able to
recycle the previous credentials for authentication. Which of the following controls should be used
together to prevent this from occurring? (Select TWO).
A. Password history
B. Password age
C. Password hashing
D. Password complexity
E. Password length
Answer: A,B

D: Password history determines the number of previous passwords that cannot be used when a user
changes his password. For example, a password history value of 5 would disallow a user from
changing his password to any of his previous 5 passwords.
A: When a user is forced to change his password due to a maximum password age period expiring, he
could change his password to a previously used password. Or if a password history value of 5 is
configured, the user could change his password six times to cycle back round to his original password.
This is where the minimum password age comes in. This is the period that a password must be used
for. For example, a minimum password age of 30 would determine that when a user changes his
password, he must continue to use the same password for at least 30 days.

NO.3 A user in the company is in charge of various financial roles but needs to prepare for an
upcoming audit. They use the same account to access each financial system. Which of the following
security controls will MOST likely be implemented within the company?
A. Separation of duties
B. Account password enforcement
C. Account lockout policy
D. Password complexity enabled
Answer: A

Separation of duties means that users are granted only the permissions they need to do their work
and no more. More so it means that there is differentiation between users, employees and duties per
se which form part of best practices.

NO.4 Which of the following are unique to white box testing methodologies? (Select two)
A. Bluesnarfing
B. Application program interface API testing
C. Input fuzzing
D. External network penetration testing
E. Function, statement and code coverage
Answer: B,E

