<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Comptia Security+ Sy0-201 Training Materials  and Study Guide &#187; Briandumps</title>
	<atom:link href="http://www.sy0-201.net/category/briandumps/feed" rel="self" type="application/rss+xml" />
	<link>http://www.sy0-201.net</link>
	<description>PassGuide  SY0-201 CompTIA Security+ (2008 Edition) Braindumps</description>
	<lastBuildDate>Thu, 24 Sep 2009 15:17:22 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>passguide comptia sy0-201 vce dumps</title>
		<link>http://www.sy0-201.net/passguide-comptia-sy0-201-vce-dumps.html</link>
		<comments>http://www.sy0-201.net/passguide-comptia-sy0-201-vce-dumps.html#comments</comments>
		<pubDate>Thu, 24 Sep 2009 14:32:10 +0000</pubDate>
		<dc:creator>Comptia Security</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.sy0-201.net/?p=42</guid>
		<description><![CDATA[http://www.4shared.com/file/135084568/fe71adde/PassGuide_comptia_sy0-201_770q.html
http://rapidshare.com/files/284391168/PassGuide_comptia_sy0-201_770q.rar.html
http://www.2shared.com/file/8015334/3cbf8141/PassGuide_comptia_sy0-201_770q.html
http://uploading.com/files/f5d26886/PassGuide%2Bcomptia%2Bsy0-201%2B770q.rar/
http://www.passguide.com/sy0-201.html
]]></description>
			<content:encoded><![CDATA[<p>http://www.4shared.com/file/135084568/fe71adde/PassGuide_comptia_sy0-201_770q.html</p>
<p>http://rapidshare.com/files/284391168/PassGuide_comptia_sy0-201_770q.rar.html</p>
<p>http://www.2shared.com/file/8015334/3cbf8141/PassGuide_comptia_sy0-201_770q.html</p>
<p>http://uploading.com/files/f5d26886/PassGuide%2Bcomptia%2Bsy0-201%2B770q.rar/</p>
<p>http://www.passguide.com/sy0-201.html</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sy0-201.net/passguide-comptia-sy0-201-vce-dumps.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>passguide comptia sy0-201 braindumps 1</title>
		<link>http://www.sy0-201.net/passguide-comptia-sy0-201-braindumps-1.html</link>
		<comments>http://www.sy0-201.net/passguide-comptia-sy0-201-braindumps-1.html#comments</comments>
		<pubDate>Thu, 24 Sep 2009 14:16:09 +0000</pubDate>
		<dc:creator>Comptia Security</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.sy0-201.net/?p=40</guid>
		<description><![CDATA[Exam Name:  CompTIA Security+ (2008 Edition) Exam
Exam Type:  CompTIA
Exam Code:  SY0-201  Total Questions:  490 Who is responsible for establishing access permissions to network resources in the DAC access
control model? 
A. The system administrator.
B. The owner of the resource.
C. The system administrator and the owner of the resource.
D. The user requiring [...]]]></description>
			<content:encoded><![CDATA[<p>Exam Name:  CompTIA Security+ (2008 Edition) Exam<br />
Exam Type:  CompTIA<br />
Exam Code:  SY0-201  Total Questions:  490 <span id="more-40"></span>Who is responsible for establishing access permissions to network resources in the DAC access<br />
control model? </p>
<p>A. The system administrator.<br />
B. The owner of the resource.<br />
C. The system administrator and the owner of the resource.<br />
D. The user requiring access to the resource. </p>
<p>Answer: B </p>
<p>The Public Key Infrastructure (PKI) is a set of hardware, software, people, policies, and<br />
procedures needed to create, manage, store, distribute, and revoke digital certificates. The public<br />
key infrastructure is based on which encryption schemes? </p>
<p>A. Symmetric<br />
B. Quantum<br />
C. Asymmetric<br />
D. Elliptical curve </p>
<p>Answer: C<br />
Which definition best defines what a challenge-response session is? </p>
<p>A. A challenge-response session is a workstation or system that produces a random challenge<br />
string that the user provides, when prompted, in conjunction with the proper PIN (Personal<br />
Identification Number).<br />
B. A challenge-response session is a workstation or system that produces a random login ID that<br />
the user provides, when prompted, in conjunction with the proper PIN (Personal Identification<br />
Number).<br />
C. A challenge-response session is a special hardware device used to produce random text in a<br />
cryptography system.<br />
D. A challenge-response session is the authentication mechanism in the workstation or system<br />
that does not determine whether the owner should be authenticated. </p>
<p>Answer: A<br />
For which reason are clocks used in Kerberos authentication? </p>
<p>A. Clocks are used to ensure proper connections.<br />
B. Clocks are used to ensure that tickets expire correctly.<br />
C. Clocks are used to generate the seed value for the encryptions keys.<br />
D. Clocks are used to both benchmark and specify the optimal encryption algorithm. </p>
<p>Answer: B </p>
<p>To reduce vulnerabilities on a web server, an administrator should adopt which of the following<br />
preventative measures? </p>
<p>A. Use packet sniffing software on all inbound communications<br />
B. Apply the most recent manufacturer updates and patches to the server.<br />
C. Enable auditing on the web server and periodically review the audit logs<br />
D. Block all Domain Name Service (DNS) requests coming into the server. </p>
<p>Answer: B<br />
A travel reservation organization conducts the majority of its transactions via a public facing<br />
website. Any downtime to this website will lead to serious financial damage for this organization.<br />
One web server is connected to several distributed database servers. Which statement is correct<br />
about this scenario? </p>
<p>A. RAID<br />
B. Warm site<br />
C. Proxy server<br />
D. Single point of failure </p>
<p>Answer: D<br />
Which of the following types of firewalls provides inspection at layer 7 of the OSI model? </p>
<p>A. Application-proxy<br />
B. Network address translation (NAT)<br />
C. Packet filters<br />
D. Stateful inspection </p>
<p>Answer: A<br />
A newly hired security specialist is asked to evaluate a company&#8217;s network security. The security<br />
specialist discovers that users have installed personal software; the network OS has default<br />
settings and no patches have been installed and passwords are not required to be changed<br />
regularly. Which of the following would be the FIRST step to take? </p>
<p>A. Install software patches.<br />
B. Disable non-essential services.<br />
C. Enforce the security policy.<br />
D. Password management </p>
<p>Answer: C </p>
<p>Giving each user or group of users only the access they need to do their job is an example of<br />
which of the following security principals? </p>
<p>A. Least privilege<br />
B. Defense in depth<br />
C. Separation of duties<br />
D. Access control </p>
<p>Answer: A<br />
In computing, the Basic Input/Output System (BIOS , also known as the System BIOS, is a de<br />
facto standard defining a firmware interface for IBM PC Compatible computers. A user is<br />
concerned with the security of their laptops BIOS. The user would not like anyone to be able to<br />
access control functions except themselves. Which of the following could make the BIOS more<br />
secure? </p>
<p>A. Password<br />
B. Flash the BIOS<br />
C. Encrypt the hard drive<br />
D. Create an access-list </p>
<p>Answer: A<br />
In computing, a Uniform Resource Locator (URL) is a type of Uniform Resource Identifier (URI)<br />
that specifies where an identified resource is available and the mechanism for retrieving it. When<br />
a user attempts to go to a website, he notices the URL has changed, which attack will MOST<br />
likely cause the problem? </p>
<p>A. ARP poisoning<br />
B. DLL injection<br />
C. DNS poisoning<br />
D. DDoS attack </p>
<p>Answer: C<br />
What does the DAC access control model use to identify the users who have permissions to a<br />
resource? </p>
<p>A. Predefined access privileges.<br />
B. The role or responsibilities users have in the organization<br />
C. Access Control Lists<br />
D. None of the above. </p>
<p>Answer: C </p>
<p><a href="http://www.passguide.com/n10-004.html">n10-004 exam</a><br />
<a href="http://www.passguide.com/sy0-201.html">PassGuide sy0-201</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sy0-201.net/passguide-comptia-sy0-201-braindumps-1.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>preplogic comptia sy0-201</title>
		<link>http://www.sy0-201.net/preplogic-comptia-sy0-201.html</link>
		<comments>http://www.sy0-201.net/preplogic-comptia-sy0-201.html#comments</comments>
		<pubDate>Sun, 26 Apr 2009 15:32:39 +0000</pubDate>
		<dc:creator>Comptia Security</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.sy0-201.net/?p=36</guid>
		<description><![CDATA[About this Printables title:
This printable includes 328 practice questions with answers and detailed explanations. It covers all CompTIA Security+ (SY0-201) exam objectives. Topics covered include: Systems Security, Network Infrastructure, Access Control, Assessments and Audits, Cryptography, and Organizational Security.
PrepLogic Printables for Security+ (SY0-201) gives you the power to train anywhere with a deep pool of printable [...]]]></description>
			<content:encoded><![CDATA[<p>About this Printables title:<br />
This printable includes 328 practice questions with answers and detailed explanations. It covers all CompTIA Security+ (SY0-201) exam objectives. Topics covered include: Systems Security, Network Infrastructure, Access Control, Assessments and Audits, Cryptography, and Organizational Security.<br />
PrepLogic Printables for Security+ (SY0-201) gives you the power to train anywhere with a deep pool of printable practice questions for every domain of the Security+ (SY0-201) exam, including:<br />
Systems Security &#8211; 35 questions<br />
Network Infrastructure &#8211; 110 questions<br />
Access Control &#8211; 55 questions<br />
Assessments and Audits &#8211; 11 questions<br />
Cryptography &#8211; 101 questions<br />
Organizational Security &#8211; 55 questions<br />
Only PrepLogic gives you the genuine exam-quality questions you need to study anywhere and be ready on exam day. To learn more, view a Free Sample. </p>
<p>Since most of us don&#8217;t have a lot of time to study for exams, we created PrepLogic Printables. Printables gives you a big selection of exam questions in a PDF format that&#8217;s easy to print and easy to use, so you can study anywhere. </p>
<p>When you can&#8217;t be in front of a computer you have to find creative ways to study. Many of our customers suggest printing multiples so you can have a copy in the car, at your desk or in your gym bag. Printables gives you many more chances to study, and that gives you a much better chance to pass the first time.<br />
The CompTIA Security+ exam has long stood as the forefront entry-level exam to the field of security. Through its difficulty, complexity of scope, and broad spectrum covering numerous aspects of the IT field, it has become one of the most sought after and respected certification offered by CompTIA, so much so that other companies, such as Microsoft, have long since used the CompTIA Security+ as an alternative choice for their elective exams for the MCSE. </p>
<p>The CompTIA Security+ exam is approximately 100 questions long and is available through both Pearson Vue and Thomson Prometric training facilities. The test is approximately 90 minutes long and contains the following official objectives: </p>
<p>Systems Security<br />
Network Infrastructure<br />
Access Control<br />
Assessments &#038; Audits<br />
Cryptography<br />
Organizational Security</p>
<p><a href="http://rapidshare.com/files/225989605/preplogic__comptia_SY0-201.rar.html">http://rapidshare.com/files/225989605/preplogic__comptia_SY0-201.rar.html</a></p>
<p>http://rapidshare.de/files/46911119/preplogic__comptia_SY0-201.rar.html</p>
<p>http://uploading.com/files/E1RFQ0TK/preplogic__comptia_SY0-201.rar.html</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sy0-201.net/preplogic-comptia-sy0-201.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Download Links: CompTIA eBooks</title>
		<link>http://www.sy0-201.net/download-links-comptia-ebooks.html</link>
		<comments>http://www.sy0-201.net/download-links-comptia-ebooks.html#comments</comments>
		<pubDate>Sat, 28 Mar 2009 15:40:39 +0000</pubDate>
		<dc:creator>Comptia Security</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.sy0-201.net/?p=30</guid>
		<description><![CDATA[ 

Download ActualTests.CompTIA.SY0-101.Exam.Q.and.A.08.01.06.pdf [1,188 KB]
Download Sybex[1][1].CompTIA.A.plus.Complete.Fast.Pass.Sep.2006.pdf [12,608 KB]
Download Sybex CompTIA Security+ Studyguide 3rd Ed.pdf [10,876 KB]
Download CompTIA Security+ Certification.chm [1231 KB]
Download SY0-101 Comptia Security+.pdf [2,444 KB]
Download CompTIA Security +.rar [7,486 KB]
Download ComptiaA_Plus_220-601.pdf [1,453 KB]
Download CompTIA A+ Complete Study Guide (2007).rar [12,472 KB]
Download CompTIA A+ Guide to Managing and Troubleshooting PCs Lab Manual.rar [17,332 KB]
Download P4S_Comptia_Linux_Plus.zip [487 [...]]]></description>
			<content:encoded><![CDATA[<p> </p>
<ol>
<li><a href="http://www.4shared.com/file/5982872/6bfa6451/ActualTestsCompTIASY0-101ExamQandA080106.html"><strong>Download ActualTests.CompTIA.SY0-101.Exam.Q.and.A.08.01.06.pdf [1,188 KB</strong></a>]</li>
<li><a href="http://www.4shared.com/file/12887592/723c7a59/Sybex11CompTIAAplusCompleteFastPassSep2006.html"><strong>Download Sybex[1][1].CompTIA.A.plus.Complete.Fast.Pass.Sep.2006.pdf [12,608 KB]</strong></a></li>
<li><a href="http://www.4shared.com/file/26981788/1c81d9e1/Sybex_CompTIA_Security_Studyguide_3rd_Ed.html"><strong>Download Sybex CompTIA Security+ Studyguide 3rd Ed.pdf [10,876 KB]</strong></a></li>
<li><a href="http://www.4shared.com/file/21311820/8ac581fd/CompTIA_Security_Certification.html"><strong>Download CompTIA Security+ Certification.chm [1231 KB]</strong></a></li>
<li><a href="http://www.4shared.com/file/26517640/e094893e/SY0-101_Comptia_Security.html"><strong>Download SY0-101 Comptia Security+.pdf [2,444 KB]</strong></a></li>
<li><a href="http://www.4shared.com/file/22587303/e2659909/CompTIA_Security_.html"><strong>Download CompTIA Security +.rar [7,486 KB]</strong></a></li>
<li><a href="http://www.4shared.com/file/33939324/c427e35b/ComptiaA_Plus_220-601.html"><strong>Download ComptiaA_Plus_220-601.pdf [1,453 KB]</strong></a></li>
<li><a href="http://www.4shared.com/file/29229860/940e8b04/CompTIA_A_Complete_Study_Guide__2007_.html"><strong>Download CompTIA A+ Complete Study Guide (2007).rar [12,472 KB]</strong></a></li>
<li><a href="http://www.4shared.com/file/30289550/a4791678/CompTIA_A_Guide_to_Managing_and_Troubleshooting_PCs_Lab_Manual.html"><strong>Download CompTIA A+ Guide to Managing and Troubleshooting PCs Lab Manual.rar [17,332 KB]</strong></a></li>
<li><a href="http://www.4shared.com/file/29048284/7a43d48b/P4S_Comptia_Linux_Plus.html"><strong>Download P4S_Comptia_Linux_Plus.zip [487 KB]</strong></a></li>
<li><a href="http://www.4shared.com/file/35360623/2b2b62b5/Comptia_networkplus_15min_guide.html"><strong>Download Comptia_networkplus_15min_guide.pdf [380 KB]</strong></a></li>
<li><a href="http://www.4shared.com/file/35404608/93e88bf0/CompTIA_A220-603.html"><strong>Download CompTIA A+220-603.pdf [249 KB]</strong></a></li>
<li><a href="http://www.4shared.com/file/35262745/f485111f/SybexCompTIARFIDplus_ExamRF0-101_Dec2006.html"><strong>Download Sybex.CompTIA.RFID.plus_Exam.RF0-101._Dec.2006.chm [2402 KB]</strong></a></li>
<li><a href="http://www.esnips.com/nsdoc/8bcf2bb2-b074-40a9-9661-4a19a98ac018"><strong>Download TestKing CompTia sy0-101 V15.pdf</strong></a></li>
<li><a href="http://www.esnips.com/nsdoc/8833942a-8290-4050-a9e7-534978683b4e"><strong>Download KNOWLEDGENET COMPTIA SECURITY PLUS STUDENT GUIDE V1.pdf</strong></a></li>
</ol>
<p align="justify"><strong>Note</strong>: The above mentioned links are external links only and no file is being uploaded on blogger’s server. If any of these links violates copyright, please inform us, we will remove that link immediately.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sy0-201.net/download-links-comptia-ebooks.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Comptia sy0-201 Practice Test</title>
		<link>http://www.sy0-201.net/comptia-sy0-201-practice-test.html</link>
		<comments>http://www.sy0-201.net/comptia-sy0-201-practice-test.html#comments</comments>
		<pubDate>Sat, 28 Mar 2009 15:17:01 +0000</pubDate>
		<dc:creator>Comptia Security</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.sy0-201.net/?p=17</guid>
		<description><![CDATA[PrepKit SY0-201, CompTIA Security+ (2008 Edition) is an interactive software that helps you learn, tracks your progress, identifies areas for improvements and simulates the actual exam. This PrepKit contains 8 interactive practice tests with over many challenging questions guaranteed to comprehensively cover all the objectives for the SY0-201: exam. With detailed analysis for each question, [...]]]></description>
			<content:encoded><![CDATA[<p>PrepKit SY0-201, CompTIA Security+ (2008 Edition) is an interactive software that helps you learn, tracks your progress, identifies areas for improvements and simulates the actual exam. This PrepKit contains 8 interactive practice tests with over many challenging questions guaranteed to comprehensively cover all the objectives for the SY0-201: exam. With detailed analysis for each question, over 678 study notes, interactive quizzes, tips and technical articles, this PrepKit ensures that you get a solid grasp of core technical concepts to ace your certification exam.<br />
<span id="more-17"></span></p>
<p>We will send you the registration code immediately. Use it to unlock and start learning.</p>
<p><a href="http://www.examguard.net/download/braindumps/freetestking/comptia">Click here to download 15 free practice questions</a>.</p>
<p>Our PrepKit are backed by money back guarantee. So, if you don’t get certified in the first attempt, we will return your money.<br />
What is Security (SY0-201) exam?</p>
<p>CompTIA’s SY0-201 test is designed to measure your ability to implement and troubleshoot Security issues. Upon passing this test you will become Security Certified Professional. This is a vendor neutral entry-level test, which prepares you for advanced security related certifications such as CISSP, ISC2, SSCP, MCSE, MCSE: Security and MCSA: Security.<br />
Is Security (SY0-201) exam right for you?</p>
<p>Are you interested in network security related technologies and want to work as a Network Administrator, Security Specialist or Network Technician? Then this test is right for you. You can also take this test if you are an entry-level network professional and want to be an expert in network security. If you would like to know more about the Security test SY0-201, please visit the CompTIA Website.<br />
Although there are no prerequisites for this test, CompTIA recommends that you should have at least two years of experience in network support or administration.<br />
What to expect in Security (SY0-201) exam?</p>
<p>This test consists of multiple-choice questions. There are no case study type questions and the test is not adaptive. You will be required to attempt approximately 100 questions in 90 minutes. To pass, you need a score of 764 on a 100-900 scale.<br />
How to prepare for SY0-201 exam?</p>
<p>We designed SY0-201 preparation kit to help you get certified effortlessly. Now you don’t need to spend your time and money searching for study materials, books, etc., this CompTIA Security+ (2008 Edition) exam preparation kit contains everything you need to get certified. Just follow the instructions, focus on the study material and getting certified will be easy.<br />
Don’t take our word for it, decide the quality of our PrepKit yourself. Download the trial version of the PrepKit now to get over 15 questions and 44 study notes, absolutely free. Once you are convinced, you can buy this PrepKit to get all questions and study notes. And of course, we trust our PrepKits so much that all our PrepKits are backed with a full money back guarantee in case you do not pass the CompTIA Security+ (2008 Edition) exam.<br />
What is covered in PrepKit SY0-201?</p>
<p>The PrepKit covers 100% objectives for CompTIA’s SY0-201: CompTIA Security+ (2008 Edition) exam, in accordance with actual exam pattern and question types</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sy0-201.net/comptia-sy0-201-practice-test.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sy0-201 sample questions and answers</title>
		<link>http://www.sy0-201.net/sy0-201-sample-questions-and-answers.html</link>
		<comments>http://www.sy0-201.net/sy0-201-sample-questions-and-answers.html#comments</comments>
		<pubDate>Sat, 28 Mar 2009 15:04:12 +0000</pubDate>
		<dc:creator>Comptia Security</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.sy0-201.net/?p=10</guid>
		<description><![CDATA[Quality and Value for the SY0-201 Exam comptia  Practice Exams for CompTIA CompTIA Security+ SY0-201 are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development.
 
1. All of the following provide confidentiality protection as part of the underlying protocol EXCEPT:
A.SSL.
B.SSH.
C.L2TP.
D.IPSec.WBerlin Sans FBArialZX
ANSWER: C
2. Which [...]]]></description>
			<content:encoded><![CDATA[<p>Quality and Value for the SY0-201 Exam comptia  Practice Exams for CompTIA CompTIA Security+ SY0-201 are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development.<br />
 <span id="more-10"></span><br />
1. All of the following provide confidentiality protection as part of the underlying protocol EXCEPT:<br />
A.SSL.<br />
B.SSH.<br />
C.L2TP.<br />
D.IPSec.WBerlin Sans FBArialZX<br />
ANSWER: C<br />
2. Which  of  the  following  allows  an  attacker  to manipulate  files  by  using  the  least  significant  bit(s)  to<br />
secretly embed data?<br />
A.Steganography<br />
B.Worm<br />
C.Trojan horse<br />
D.VirusWBerlin Sans FBArialZX<br />
ANSWER: A<br />
3. Which of the following type of attacks would allow an attacker to capture HTTP requests and send back<br />
a spoofed page?<br />
A.Teardrop<br />
B.TCP/IP hijacking<br />
C.Phishing<br />
D.Replay WBerlin Sans FBArialZX<br />
ANSWER: B<br />
4. How should a company test the integrity of its backup data?<br />
A.By conducting another backup<br />
B.By using software to recover deleted files<br />
C.By restoring part of the backup<br />
D.By reviewing the written proceduresWBerlin Sans FBArialZX<br />
ANSWER: C<br />
5. Which of following can BEST be used to determine the topology of a network and discover unknown<br />
devices?<br />
A.Vulnerability scanner<br />
B.NIPS<br />
C.Protocol analyzer<br />
D.Network mapperWBerlin Sans FBArialZX<br />
ANSWER: D<br />
6. When should a technician perform penetration testing?<br />
A.When the technician suspects that weak passwords exist on the network<br />
B.When the technician is trying to guess passwords on a network<br />
C.When the technician has permission from the owner of the network<br />
D.When the technician is war driving and trying to gain accessWBerlin Sans FBArialZX  </p>
<p>| English | Chinese | Japan | Korean |                &#8211; 3 &#8211;                Test Information Co., Ltd. All rights reserved.<br />
ANSWER: C<br />
7. An administrator has implemented a new SMTP service on a server. A public IP address translates to<br />
the internal SMTP server. The administrator notices many sessions to the server, and gets notification that<br />
the  servers public  IP address  is now  reported  in a  spam  real-time block  list. Which of  the  following  is<br />
wrong with the server?<br />
A.SMTP open relaying is enabled.<br />
B.It does not have a spam filter.<br />
C.The amount of sessions needs to be limited.<br />
D.The public IP address is incorrect.WBerlin Sans FBArialZX<br />
ANSWER: A<br />
8. Which of the following is MOST efficient for encrypting large amounts of data?<br />
A.Hashing algorithms<br />
B.Symmetric key algorithms<br />
C.Asymmetric key algorithms<br />
D.ECC algorithmsWBerlin Sans FBArialZX<br />
ANSWER: B<br />
9. Which of the following is a reason why a company should disable the SSID broadcast of the wireless<br />
access points?<br />
A.Rogue access points<br />
B.War driving<br />
C.Weak encryption<br />
D.Session hijackingWBerlin Sans FBArialZX<br />
ANSWER: B<br />
10. Which of the following BEST describes ARP?<br />
A.Discovering the IP address of a device from the MAC address<br />
B.Discovering the IP address of a device from the DNS name<br />
C.Discovering the MAC address of a device from the IP address<br />
D.Discovering the DNS name of a device from the IP addressWBerlin Sans FBArialZX<br />
ANSWER: C<br />
11. Which of the following would be BEST to use to apply corporate security settings to a device?<br />
A.A security patch<br />
B.A security hotfix<br />
C.An OS service pack<br />
D.A security templateWBerlin Sans FBArialZX<br />
ANSWER: D<br />
12. A small call  center business decided  to  install an email  system  to  facilitate communications  in  the<br />
office. As part of the upgrade the vendor offered to supply anti-malware software for a cost of $5,000 per</p>
<p>| English | Chinese | Japan | Korean |                &#8211; 4 &#8211;                Test Information Co., Ltd. All rights reserved.<br />
year. The IT manager read there was a 90% chance each year that workstations would be compromised if<br />
not adequately protected. If workstations are compromised it will take three hours to restore services for<br />
the  30  staff.  Staff members  in  the  call  center  are  paid  $90  per  hour.  If  the  anti-malware  software  is<br />
purchased, which of the following is the expected net savings?<br />
A.$900<br />
B.$2,290<br />
C.$2,700<br />
D.$5,000b<br />
ANSWER: B<br />
13. Which of the following is the main objective of steganography?<br />
A.Message digest<br />
B.Encrypt information<br />
C.Hide information<br />
D.Data integrityWBerlin Sans FBArialZX<br />
ANSWER: C<br />
14. Which of  the  following would allow  for secure key exchange over an unsecured network without a<br />
pre-shared key?<br />
A.3DES<br />
B.AES<br />
C.DH-ECC<br />
D.MD5WBerlin Sans FBArialZX<br />
ANSWER: C<br />
15. Which of the following improves security in a wireless system?<br />
A.IP spoofing<br />
B.MAC filtering<br />
C.SSID spoofing<br />
D.Closed networkWBerlin Sans FBArialZX<br />
ANSWER: B<br />
16. A user wants to implement secure LDAP on the network. Which of the following port numbers secure<br />
LDAP use by default?<br />
A.53<br />
B.389<br />
C.443<br />
D.636WBerlin Sans FBArialZX<br />
ANSWER: D<br />
17. On which of the following is a security technician MOST likely to find usernames?<br />
A.DNS logs<br />
B.Application logs  </p>
<p>| English | Chinese | Japan | Korean |                &#8211; 5 &#8211;                Test Information Co., Ltd. All rights reserved.<br />
C.Firewall logs<br />
D.DHCP logsWBerlin Sans FBArialZX<br />
ANSWER: B<br />
18. How many keys are utilized with asymmetric cryptography?<br />
A.One<br />
B.Two<br />
C.Five<br />
D.SevenWBerlin Sans FBArialZX<br />
ANSWER: B<br />
19. During a risk assessment it is discovered that only one system administrator is assigned several tasks<br />
critical to continuity of operations. It is recommended to cross train other system administrators to perform<br />
these tasks and mitigate which of the following risks?<br />
A.DDoS<br />
B.Privilege escalation<br />
C.Disclosure of PII<br />
D.Single point of failureWBerlin Sans FBArialZX<br />
ANSWER: D<br />
20. Which of the following network filtering devices will rely on signature updates to be effective?<br />
A.Proxy server<br />
B.Firewall<br />
C.NIDS<br />
D.HoneynetWBerlin Sans FBArialZX<br />
ANSWER: C<br />
21. Which of the following is a single server that is setup in the DMZ or outer perimeter in order to distract<br />
attackers?<br />
A.Honeynet<br />
B.DMZ<br />
C.Honeypot<br />
D.VLANWBerlin Sans FBArialZX<br />
ANSWER: C<br />
22. Which of the following encryption algorithms is decrypted in the LEAST amount of time?<br />
A.RSA<br />
B.AES<br />
C.3DES<br />
D.L2TPWBerlin Sans FBArialZX<br />
ANSWER: B<br />
23. An administrator is trying to secure a network from threats originating outside the network. Which of</p>
<p>| English | Chinese | Japan | Korean |                &#8211; 6 &#8211;                Test Information Co., Ltd. All rights reserved.<br />
the following<br />
devices provides protection for the DMZ from attacks launched from the Internet?<br />
A.Antivirus<br />
B.Content filter<br />
C.Firewall<br />
D.Proxy serverWBerlin Sans FBArialZX<br />
ANSWER: C<br />
24. Which of the following is a way to manage operating system updates?<br />
A.Service pack management<br />
B.Patch application<br />
C.Hotfix management<br />
D.Change managementWBerlin Sans FBArialZX<br />
ANSWER: D<br />
25. Which of the following is a list of discrete entries that are known to be benign?<br />
A.Whitelist<br />
B.Signature<br />
C.Blacklist<br />
D.ACLWBerlin Sans FBArialZX<br />
ANSWER: A<br />
26. Which of the following increases the collision resistance of a hash?<br />
A.Salt<br />
B.Increase the input length<br />
C.Rainbow Table<br />
D.Larger key spaceWBerlin Sans FBArialZX<br />
ANSWER: A<br />
27. A programmer has decided to alter the server variable in the coding of an authentication function for a<br />
proprietary sales application. Before implementing  the new routine on the production application server,<br />
which of the following processes should be followed?<br />
A.Change management<br />
B.Secure disposal<br />
C.Password complexity<br />
D.Chain of custodyWBerlin Sans FBArialZX<br />
ANSWER: A<br />
28. When deploying 50 new workstations on the network, which of following should be completed FIRST?<br />
A.Install a word processor.<br />
B.Run the latest spyware.<br />
C.Apply the baseline configuration.<br />
D.Run OS updates.WBerlin Sans FBArialZX  </p>
<p>| English | Chinese | Japan | Korean |                &#8211; 7 &#8211;                Test Information Co., Ltd. All rights reserved.<br />
ANSWER: C<br />
29. Which of  the  following should be  implemented  to have all workstations and servers  isolated  in  their<br />
own broadcast domains?<br />
A.VLANs<br />
B.NAT<br />
C.Access lists<br />
D.IntranetWBerlin Sans FBArialZX<br />
ANSWER: A<br />
30. End users are complaining about receiving a lot of email from online vendors and pharmacies. Which<br />
of the following is this an example of?<br />
A.Trojan<br />
B.Spam<br />
C.Phishing<br />
D.DNS poisoningWBerlin Sans FBArialZX<br />
ANSWER: B </p>
]]></content:encoded>
			<wfw:commentRss>http://www.sy0-201.net/sy0-201-sample-questions-and-answers.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>comptia sy0-201 test question</title>
		<link>http://www.sy0-201.net/comptia-sy0-201-test-question.html</link>
		<comments>http://www.sy0-201.net/comptia-sy0-201-test-question.html#comments</comments>
		<pubDate>Sat, 28 Mar 2009 14:57:43 +0000</pubDate>
		<dc:creator>Comptia Security</dc:creator>
				<category><![CDATA[Briandumps]]></category>

		<guid isPermaLink="false">http://www.sy0-201.net/?p=5</guid>
		<description><![CDATA[1.  Which type of audit can be used to determine whether accounts have been established properly
and verify that privilege creep isn’t occurring?
A.  Privilege audit
B.  Usage audit
C.  Escalation audit
D.  Report audit
2.  What kind of physical access device restricts access to a small number of individuals at
one time?
A.  Checkpoint
B.  [...]]]></description>
			<content:encoded><![CDATA[<p>1.  Which type of audit can be used to determine whether accounts have been established properly<br />
and verify that privilege creep isn’t occurring?<span id="more-5"></span><br />
A.  Privilege audit<br />
B.  Usage audit<br />
C.  Escalation audit<br />
D.  Report audit<br />
2.  What kind of physical access device restricts access to a small number of individuals at<br />
one time?<br />
A.  Checkpoint<br />
B.  Perimeter security<br />
C.  Security zones<br />
D.  Mantrap<br />
3.  Which of the following is a set of voluntary standards governing encryption?<br />
A.  PKI<br />
B.  PKCS<br />
C.  ISA<br />
D.  SSL<br />
4.  Which protocol is used to create a secure environment in a wireless network?<br />
A.  WAP<br />
B.  WEP<br />
C.  WTLS<br />
D.  WML<br />
5.  An Internet server interfaces with TCP/IP at which layer of the DOD model?<br />
A.  Transport layer<br />
B.  Network layer<br />
C.  Process layer<br />
D.  Internet layer<br />
6.  You want to establish a network connection between two LANs using the Internet. Which<br />
technology would best accomplish that for you?<br />
A.  IPSec<br />
B.  L2TP<br />
C.  PPP<br />
D.  SLIP</p>
<p>7.  Which design concept limits access to systems from outside users while protecting users and<br />
systems inside the LAN?<br />
A.  DMZ<br />
B.  VLAN<br />
C.  I&#038;A<br />
D.  Router<br />
8.  In the key recovery process, which key must be recoverable?<br />
A.  Rollover key<br />
B.  Secret key<br />
C.  Previous key<br />
D.  Escrow key<br />
9.  Which kind of attack is designed to overload a particular protocol or service?<br />
A.  Spoofing<br />
B.  Back door<br />
C.  Man in the middle<br />
D.  Flood<br />
10.  Which component of an IDS collects data?<br />
A.  Data source<br />
B.  Sensor<br />
C.  Event<br />
D.  Analyzer<br />
11.  What is the process of making an operating system secure from attack called?<br />
A.  Hardening<br />
B.  Tuning<br />
C.  Sealing<br />
D.  Locking down<br />
12.  The integrity objective addresses which characteristic of information security?<br />
A.  Verification that information is accurate<br />
B.  Verification that ethics are properly maintained<br />
C.  Establishment of clear access control of data<br />
D.  Verification that data is kept private and secure<br />
13.  Which mechanism is used by PKI to allow immediate verification of a certificate’s validity?<br />
A.  CRL<br />
B.  MD5<br />
C.  SSHA<br />
D.  OCSP<br />
14.  Which of the following is the equivalent of a VLAN from a physical security perspective?<br />
A.  Perimeter security<br />
B.  Partitioning<br />
C.  Security zones<br />
D.  Physical barrier<br />
15.  A user has just reported that he downloaded a file from a prospective client using IM. The<br />
user indicates that the file was called account.doc. The system has been behaving unusu-<br />
ally since he downloaded the file. What is the most likely event that occurred?<br />
A.  Your user inadvertently downloaded a virus using IM.<br />
B.  Your user may have a defective hard drive.<br />
C.  Your user is hallucinating and should increase his medication.<br />
D.  The system is suffering from power surges.<br />
16.  Which mechanism or process is used to enable or disable access to a network resource<br />
based on an IP address?<br />
A.  NDS<br />
B.  ACL<br />
C.  Hardening<br />
D.  Port blocking<br />
17.  Which of the following would provide additional security to an Internet web server?<br />
A.  Changing the port address to 80.<br />
B.  Changing the port address to 1019.<br />
C.  Adding a firewall to block port 80.<br />
D.  Web servers can’t be secured.<br />
18.  What type of program exists primarily to propagate and spread itself to other systems?<br />
A.  Virus<br />
B.  Trojan horse<br />
C.  Logic bomb<br />
D.  Worm<br />
19.  An individual presents herself at your office claiming to be a service technician. She wants to<br />
discuss your current server configuration. This may be an example of what type of attack?<br />
A.  Social engineering<br />
B.  Access control<br />
C.  Perimeter screening<br />
D.  Behavioral engineering<br />
20.  Which of the following is a major security problem with FTP servers?<br />
A.  Password files are stored in an unsecure area on disk.<br />
B.  Memory traces can corrupt file access.<br />
C.  User IDs and passwords are unencrypted.<br />
D.  FTP sites are unregistered.<br />
21.  Which system would you install to provide active protection and notification of security<br />
problems in a network connected to the Internet?<br />
A.  IDS<br />
B.  Network monitoring<br />
C.  Router<br />
D.  VPN<br />
22.  The process of verifying the steps taken to maintain the integrity of evidence is called what?<br />
A.  Security investigation<br />
B.  Chain of custody<br />
C.  Three A’s of investigation<br />
D.  Security policy<br />
23.  What encryption process uses one message to hide another?<br />
A.  Steganography<br />
B.  Hashing<br />
C.  MDA<br />
D.  Cryptointelligence<br />
24.  Which policy dictates how computers are used in an organization?<br />
A.  Security policy<br />
B.  User policy<br />
C.  Use policy<br />
D.  Enforcement policy<br />
25.  Which algorithm is used to create a temporary secure session for the exchange of key<br />
information?<br />
A.  KDC<br />
B.  KEA<br />
C.  SSL<br />
D.  RSA<br />
26.  You’ve been hired as a security consultant for a company that’s beginning to implement<br />
handheld devices, such as PDAs. You’re told that the company must use an asymmetric<br />
system. Which security standard would you recommend it implement?<br />
A.  ECC<br />
B.  PKI<br />
C.  SHA<br />
D.  MD<br />
27.  Which of the following backup methods will generally provide the fastest backup times?<br />
A.  Full backup<br />
B.  Incremental backup<br />
C.  Differential backup<br />
D.  Archival backup<br />
28.  You want to grant access to network resources based on authenticating an individual’s<br />
retina during a scan. Which security method uses a physical characteristic as a method of<br />
determining identity?<br />
A.  Smart card<br />
B.  I&#038;A<br />
C.  Biometrics<br />
D.  CHAP<br />
29.  Which access control method is primarily concerned with the role that individuals have in<br />
the organization?<br />
A.  MAC<br />
B.  DAC<br />
C.  RBAC<br />
D.  STAC<br />
30.  The process of investigating a computer system for clues into an event is called what?<br />
A.  Computer forensics<br />
B.  Virus scanning<br />
C.  Security policy<br />
D.  Evidence gathering<br />
Answers to Assessment Test<br />
1.  A.  A privilege audit is used to determine that all groups, users, and other accounts have<br />
the appropriate privileges assigned according to the policies of an organization. For more<br />
information, see Chapter 8.<br />
2.  D.  A mantrap limits access to a small number of individuals. It could be, for example, a<br />
small room. Mantraps typically use electronic locks and other methods to control access.<br />
For more information, see Chapter 6.<br />
3.  B.  Public-Key Cryptography Standards is a set of voluntary standards for public-key cryp-<br />
tography. This set of standards is coordinated by RSA. For more information, see Chapter 7.<br />
4.  B.  Wired Equivalent Privacy (WEP) is designed to provide security equivalent to that of a<br />
wired network. WEP has vulnerabilities and isn’t considered highly secure. For additional<br />
information, see Chapter 7.<br />
5.  C.  The Process layer interfaces with applications and encapsulates trafic through the<br />
Host-to-Host or Transport layer, the Internet layer, and the Network Access layer. For<br />
more information, see Chapter 2.<br />
6.  B.  L2TP (Layer 2 Tunneling Protocol) is a tunneling protocol that can be used between<br />
LANs. L2TP isn’t secure, and you should use IPSec with it to provide data security. For<br />
more information, see Chapter 3.<br />
7.  A.  A DMZ (demilitarized zone) is an area in a network that allows restrictive access to<br />
untrusted users and isolates the internal network from access by external users and systems.<br />
It does so by using routers and irewalls to limit access to sensitive network resources. For<br />
more information, see Chapter 1.<br />
8.  C.  A key recovery process must be able to recover a previous key. If the previous key can’t<br />
be recovered, then all the information for which the key was used will be irrecoverably lost.<br />
For more information, see Chapter 7.<br />
9.  D.  A lood attack is designed to overload a protocol or service by repeatedly initiating a<br />
request for service. This type of attack usually results in a DoS (denial of service) situation<br />
occurring because the protocol freezes or excessive bandwidth is used in the network as a<br />
result of the requests. For more information, see Chapter 2.<br />
10.  B.  A sensor collects data from the data source and passes it on to the analyzer. If the analyzer<br />
determines that unusual activity has occurred, an alert may be generated. For additional infor-<br />
mation, see Chapter 4.<br />
11.  A.  Hardening is the term used to describe the process of securing a system. This is accom-<br />
plished in many ways, including disabling unneeded protocols. For additional information on<br />
hardening, see Chapter 5.<br />
12.  A.  To meet the goal of integrity, you must verify that information being used is accurate<br />
and hasn’t been tampered with. Integrity is coupled with accountability to ensure that data<br />
is accurate and that a inal authority exists to verify this, if needed. For more information,<br />
see Chapter 1.<br />
13.  D.  Online Certiicate Status Protocol (OCSP) is the mechanism used to immediately verify<br />
whether a certiicate is valid. The Certiicate Revocation List (CRL) is published on a regular<br />
basis, but it isn’t current once it’s published. For additional information, see Chapter 7.<br />
14.  B.  Partitioning is the process of breaking a network into smaller components that can each<br />
be individually protected. The concept is the same as building walls in an ofice building. For<br />
additional information, see Chapter 6.<br />
15.  A.  IM and other systems allow unsuspecting users to download iles that may contain<br />
viruses. Due to a weakness in the ile extension naming conventions, a ile that appears to<br />
have one extension may actually have another extension. For example, the ile account.<br />
doc.vbs would appear in many applications as account.doc, but it’s actually a Visual<br />
Basic script and could contain malicious code. For additional information, see Chapter 4.<br />
16.  B.  Access control lists (ACLs) are used to allow or deny an IP address access to a network.<br />
ACL mechanisms are implemented in many routers, irewalls, and other network devices.<br />
For additional information, see Chapter 5.<br />
17.  B.  The default port for a web server is port 80. By changing the port to 1019, you force<br />
users to specify this port when they are using a browser. This action provides a little addi-<br />
tional security for your website. Adding a irewall to block port 80 would secure your web-<br />
site so much that no one would be able to access it. For more information, see Chapter 3.<br />
18.  D.  A worm is designed to multiply and propagate. Worms may carry viruses that cause sys-<br />
tem destruction, but that isn’t their primary mission. For more information, see Chapter 2.<br />
19.  A.  Social engineering is using human intelligence methods to gain access or information<br />
about your organization. For additional information, see Chapter 6.<br />
20.  C.  In most environments, FTP sends account and password information unencrypted.<br />
This makes these accounts vulnerable to network snifing. For additional information, see<br />
Chapter 5.<br />
21.  A.  An intrusion detection system (IDS) provides active monitoring and rule-based responses<br />
to unusual activities on a network. A irewall provides passive security by preventing access<br />
from unauthorized trafic. If the irewall were compromised, the IDS would notify you based<br />
on rules it’s designed to implement. For more information, see Chapter 3.<br />
22.  B.  The chain of custody ensures that each step taken with evidence is documented and<br />
accounted for from the point of collection. Chain of custody is the Who, What, When,<br />
Where, and Why of evidence storage. For additional information, see Chapter 8.<br />
23.  A.  Steganography is the process of hiding one message in another. Steganography may<br />
also be referred to as electronic watermarking. For additional information, see Chapter 7.<br />
24.  C.  The use policy is also referred to as the usage policy. It should state acceptable uses<br />
of computer and organizational resources by employees. This policy should outline con-<br />
sequences of noncompliance. For additional information, see Chapter 8.<br />
25.  B.  The Key Exchange Algorithm (KEA) is used to create a temporary session to exchange<br />
key information. This session creates a secret key. When the key has been exchanged, the<br />
regular session begins. For more information, see Chapter 7.<br />
26.  A.  Elliptic Curve Cryptography (ECC) would probably be your best choice for a PDA.<br />
ECC is designed to work with smaller processors. The other systems may be options, but<br />
they require more computing power than ECC. For additional information, see Chapter 7.<br />
27.  B.  An incremental backup will generally be the fastest of the backup methods because<br />
it backs up only the iles that have changed since the last incremental or full backup. See<br />
Chapter 8 for more information.<br />
28.  C.  Biometrics is the authentication process that uses physical characteristics, such as a palm<br />
print or retinal pattern, to establish identiication. For more information, see Chapter 1.<br />
29.  C.  Role-Based Access Control (RBAC) is primarily concerned with providing access to<br />
systems that a user needs based on the user’s role in the organization. For more informa-<br />
tion, see Chapter 8.<br />
30.  A.  Computer forensics is the process of investigating a computer system to determine the<br />
cause of an incident. Part of this process would be gathering evidence. For additional infor-<br />
mation, see Chapter 8.</p>
<p><a href="http://www.sy0-201.net/comptia-security-deluxe-study-guide-sy0-201-hardcover.html">sy0-201 books</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sy0-201.net/comptia-sy0-201-test-question.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
