401 SEC+ Exam Guaranteed Pass: Expert-Verified
Questions & Comprehensive Solutions with Tested
and Proven Exam Strategies
Which of the following controls should critical application servers implement to protect
themselves from other potentially compromised application services?
A. NIPS
B. Content filter
C. NIDS
D. Host-based firewalls - -correct ans- -Answer: D
Explanation:
A host-based firewall is designed to protect the host from network based attack by using
filters to limit the network traffic that is allowed to enter or leave the host. The action of a
filter is to allow, deny, or log the network packet. Allow enables the packet to continue
toward its destination. Deny blocks the packet from going any further and effectively
discarding it. Log records information about the packet into a log file. Filters can be based
on protocol and ports. By blocking protocols and ports that are not required, other
potentially compromised application services would be prevented from being exploited
across the network.
Which of the following would be MOST appropriate if an organization's requirements
mandate complete control over the data and applications stored in the cloud?
A. Hybrid cloud
B. Community cloud
C. Private cloud
D. Public cloud - -correct ans- -Answer: C
Explanation:
,A private cloud is a cloud service for internal use only and is located within a corporate
network rather than on the Internet. It is usually owned, managed, and operated by the
company, which gives the company full control over the data and applications stored in the
cloud
It has been discovered that students are using kiosk tablets intended for registration and
scheduling to play games and utilize instant messaging. Which of the following could BEST
eliminate this issue?
A. Device encryption
B. Application control
C. Content filtering
D. Screen-locks - -correct ans- -Answer: B
Explanation:
Application control is the process of controlling what applications are installed on a device.
This may reduce exposure to malicious software by limiting the user's ability to install
applications that come from unknown sources or have no work-related features.
Verifying the integrity of data submitted to a computer program at or during run-time, with
the intent of preventing the malicious exploitation of unintentional effects in the structure
of the code, is BEST described as which of the following?
A. Output sanitization
B. Input validation
C. Application hardening
D. Fuzzing - -correct ans- -Answer: B
Explanation:
Input validation is a defensive technique intended to mitigate against possible user input
attacks, such as buffer overflows and fuzzing. Input validation checks every user input
, submitted to the application before processing that input. The check could be a length, a
character type, a language type, or a domain
Which of the following is a security advantage of using NoSQL vs. SQL databases in a three-
tier environment?
A. NoSQL databases are not vulnerable to XSRF attacks from the application server.
B. NoSQL databases are not vulnerable to SQL injection attacks.
C. NoSQL databases encrypt sensitive information by default.
D. NoSQL databases perform faster than SQL databases on the same hardware. - -correct
ans- -Answer: B
Explanation:
NoSQL is a nonrelational database and does not use SQL. It is therefore not vulnerable to
SQL injection attacks but is vulnerable to similar injection-type attacks.
Topic 5, Access Control and Identity Management
Jane, a security administrator, needs to implement a secure wireless authentication
method that uses a remote RADIUS server for authentication.
Which of the following is an authentication method Jane should use?
A. WPA2-PSK
B. WEP-PSK
C. CCMP
D. LEAP - -correct ans- -Answer: D
Explanation:
A RADIUS server is a server with a database of user accounts and passwords used as a
central authentication database for users requiring network access.
Questions & Comprehensive Solutions with Tested
and Proven Exam Strategies
Which of the following controls should critical application servers implement to protect
themselves from other potentially compromised application services?
A. NIPS
B. Content filter
C. NIDS
D. Host-based firewalls - -correct ans- -Answer: D
Explanation:
A host-based firewall is designed to protect the host from network based attack by using
filters to limit the network traffic that is allowed to enter or leave the host. The action of a
filter is to allow, deny, or log the network packet. Allow enables the packet to continue
toward its destination. Deny blocks the packet from going any further and effectively
discarding it. Log records information about the packet into a log file. Filters can be based
on protocol and ports. By blocking protocols and ports that are not required, other
potentially compromised application services would be prevented from being exploited
across the network.
Which of the following would be MOST appropriate if an organization's requirements
mandate complete control over the data and applications stored in the cloud?
A. Hybrid cloud
B. Community cloud
C. Private cloud
D. Public cloud - -correct ans- -Answer: C
Explanation:
,A private cloud is a cloud service for internal use only and is located within a corporate
network rather than on the Internet. It is usually owned, managed, and operated by the
company, which gives the company full control over the data and applications stored in the
cloud
It has been discovered that students are using kiosk tablets intended for registration and
scheduling to play games and utilize instant messaging. Which of the following could BEST
eliminate this issue?
A. Device encryption
B. Application control
C. Content filtering
D. Screen-locks - -correct ans- -Answer: B
Explanation:
Application control is the process of controlling what applications are installed on a device.
This may reduce exposure to malicious software by limiting the user's ability to install
applications that come from unknown sources or have no work-related features.
Verifying the integrity of data submitted to a computer program at or during run-time, with
the intent of preventing the malicious exploitation of unintentional effects in the structure
of the code, is BEST described as which of the following?
A. Output sanitization
B. Input validation
C. Application hardening
D. Fuzzing - -correct ans- -Answer: B
Explanation:
Input validation is a defensive technique intended to mitigate against possible user input
attacks, such as buffer overflows and fuzzing. Input validation checks every user input
, submitted to the application before processing that input. The check could be a length, a
character type, a language type, or a domain
Which of the following is a security advantage of using NoSQL vs. SQL databases in a three-
tier environment?
A. NoSQL databases are not vulnerable to XSRF attacks from the application server.
B. NoSQL databases are not vulnerable to SQL injection attacks.
C. NoSQL databases encrypt sensitive information by default.
D. NoSQL databases perform faster than SQL databases on the same hardware. - -correct
ans- -Answer: B
Explanation:
NoSQL is a nonrelational database and does not use SQL. It is therefore not vulnerable to
SQL injection attacks but is vulnerable to similar injection-type attacks.
Topic 5, Access Control and Identity Management
Jane, a security administrator, needs to implement a secure wireless authentication
method that uses a remote RADIUS server for authentication.
Which of the following is an authentication method Jane should use?
A. WPA2-PSK
B. WEP-PSK
C. CCMP
D. LEAP - -correct ans- -Answer: D
Explanation:
A RADIUS server is a server with a database of user accounts and passwords used as a
central authentication database for users requiring network access.