Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CompTIA Security+ CertMaster Test with Verified Answers

Rating
-
Sold
-
Pages
8
Grade
A+
Uploaded on
25-11-2024
Written in
2024/2025

Employees have the ability to download certain applications onto their workstations to complete work functions. The CIO installed a reliable method to ensure that no modifications to the application have occurred. What method of validation did the CIO implement? - Code signing A network administrator is importing a list of certificates from an online source, so that employees can use a chain of trust and communicate securely with public websites. Which type of certificate is the network administrator currently importing? - Root Which certificate format allows the transfer of private keys and is password protected? - PFX A company has a two-level certificate authority (CA) hierarchy. One of the CA servers is offline, while the others are online. Which statements are true of online and offline CAs? - -An online root is required to add an intermediate CA. -An online CA is needed in order to publish a CRL. An independent penetration testing company is invited to test a company's legacy banking application developed for Android phones. It uses Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates. Penetrations tests reveal the connections with clients were vulnerable to a Man-in-the-Middle (MITM) attack. How does the company prevent this from happening in the public Internet? - Use certificate pinning In a Public Key Infrastructure (PKI), which option best describes how users and multiple Certificate Authorities (CA) interact with each other in a large environment? - Trust model A company with multiple types of archived encrypted data is looking to archive the keys needed to decrypt the data. However, the company wants to separate the two in order to heavily guard these keys. Analyze the scenario to determine the most likely key placement. - Key escrow An authoritative server for a zone creates a Resource Records Set (rrset) signed with a zone signing key. From the following Domain Name System (DNS) traits and functions, what does this scenario demonstrate? - DNS Security Extensions The administrator in an exchange server needs to send digitally signed and encrypted messages. What should the administrator use? - S/MIME An organization uses a Session Initiation Protocol (SIP) endpoint for establishing communications with remote branch offices. Which of the following protocols will provide encryption for streaming data during the call? - SRTP

Show more Read less
Institution
CompTIA Security+ CertMaster
Course
CompTIA Security+ CertMaster

Content preview

CompTIA Security+ CertMaster Test with
Verified Answers

Employees have the ability to download certain applications onto their
workstations to complete work functions. The CIO installed a reliable method to
ensure that no modifications to the application have occurred. What method of
validation did the CIO implement? - ✅✅ Code signing

A network administrator is importing a list of certificates from an online source, so
that employees can use a chain of trust and communicate securely with public
websites. Which type of certificate is the network administrator currently
importing? - ✅✅ Root

Which certificate format allows the transfer of private keys and is password
protected? - ✅✅ PFX

A company has a two-level certificate authority (CA) hierarchy. One of the CA
servers is offline, while the others are online. Which statements are true of online
and offline CAs? - ✅✅ -An online root is required to add an intermediate CA.
-An online CA is needed in order to publish a CRL.

An independent penetration testing company is invited to test a company's legacy
banking application developed for Android phones. It uses Secure Sockets
Layer/Transport Layer Security (SSL/TLS) certificates. Penetrations tests reveal
the connections with clients were vulnerable to a Man-in-the-Middle (MITM)
attack. How does the company prevent this from happening in the public Internet?
- ✅✅ Use certificate pinning

In a Public Key Infrastructure (PKI), which option best describes how users and
multiple Certificate Authorities (CA) interact with each other in a large
environment? - ✅✅ Trust model

A company with multiple types of archived encrypted data is looking to archive the
keys needed to decrypt the data. However, the company wants to separate the two
in order to heavily guard these keys. Analyze the scenario to determine the most
likely key placement. - ✅✅ Key escrow

, An authoritative server for a zone creates a Resource Records Set (rrset) signed
with a zone signing key. From the following Domain Name System (DNS) traits
and functions, what does this scenario demonstrate? - ✅✅ DNS Security
Extensions

The administrator in an exchange server needs to send digitally signed and
encrypted messages. What should the administrator use? - ✅✅ S/MIME

An organization uses a Session Initiation Protocol (SIP) endpoint for establishing
communications with remote branch offices. Which of the following protocols will
provide encryption for streaming data during the call? - ✅✅ SRTP

A web server will utilize a directory protocol to enable users to authenticate with
domain credentials. A certificate will be issued to the server to set up a secure
tunnel. Which protocol is ideal for this situation? - ✅✅ LDAPS

A Transport Layer Security (TLS) Virtual Private Network (VPN) requires a
remote access server listening on port 443 to encrypt traffic with a client machine.
An ipsec (Internet Protocol Security) VPN can deliver traffic in two modes. One
mode encrypts only the payload of the IP packet. The other mode encrypts the
whole IP packet (header and payload). These two modes describe which of the
following? - ✅✅ Tunnel
Transport

Consider the principles of web server hardening and determine which actions a
system administrator should take when deploying a new web server in a
demilitarized zone (DMZ). - ✅✅ Establish a guest zone
Upload files using SSH
Use configuration templates

Which of the following protocols would secure file transfer services for an internal
network? - ✅✅ FTPES

Implementing Lightweight Directory Access Protocol Secure (LDAPS) on a web
server secures direct queries to which of the following? - ✅✅ Directory services

Select the vulnerabilities that can influence routing. - ✅✅ Source routing
Route injection
Software exploits

Written for

Institution
CompTIA Security+ CertMaster
Course
CompTIA Security+ CertMaster

Document information

Uploaded on
November 25, 2024
Number of pages
8
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$11.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
kharowl Stanford University
Follow You need to be logged in order to follow users or courses
Sold
14
Member since
2 year
Number of followers
7
Documents
1509
Last sold
4 months ago
The Scholar's Depot: Where Knowledge Meets Opportunity

Imagine a digital marketplace buzzing with academic vitality—Kharowl. This knowledgeable entrepreneur curates a treasure trove of meticulously crafted exam materials, sharing a passion for aiding fellow scholars in their academic journeys. Their dedication to excellence shines through every document, fostering a community where knowledge is not just sold but shared.

3.0

2 reviews

5
1
4
0
3
0
2
0
1
1

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions