Thursday, August 5, 2021

Updated Version SY0-601 CompTIA Security+ 2021 Exam Free Training

 

The CompTIA Security+ certification exam will verify the successful candidate has the knowledge and skills required to assess the security posture of an enterprise environment and recommend and implement appropriate security solutions; monitor and secure hybrid environments, including cloud, mobile, and IoT; operate with an awareness of applicable laws and policies, including principles of governance, risk, and compliance; identify, analyze, and respond to security events and incidents

Number of Questions Maximum of 90 questions
Type of Questions Multiple choice and performance-based
Length of Test 90 minutes
Passing Score 750 (on a scale of 100-900)
Recommended Experience CompTIA Network+ and two years of experience in IT administration with a security focus
Languages English, Japanese, Portuguese and Simplified Chinese English, Japanese
Retirement English retires: July 31, 2021
All other languages retire: Q1 2022
Usually three years after launch
Testing Provider Pearson VUE
Testing Centers : Online Testing

Official CompTIA Content (OCC) has been designed from the ground up to help you learn and master the material in your certification exam. Trust self-paced CompTIA study guides that are

Clearly written and structured.
Flexible so you can learn at any pace.
Focused on your exam success.

Save With a Bundle
CompTIA Training bundles are a great way to continue your learning process in every stage of your exam preparation. Complement a study guide with popular training options such as:

Learn online with CertMaster Learn.
Apply your knowledge with CertMaster Labs
Practice and prepare for your exam with CertMaster Practice.

Why is it different?
More choose Security+ - chosen by more corporations and defense organizations than any other certification on the market to validate baseline security skills and for fulfilling the DoD 8570 compliance.
Security+ proves hands-on skills – the only baseline cybersecurity certification emphasizing hands-on practical skills, ensuring the security professional is better prepared to problem solve a wider variety of today’s complex issues.
More job roles turn to Security+ to supplement skills – baseline cybersecurity skills are applicable across more of today’s job roles to secure systems, software and hardware.
Security+ is aligned to the latest trends and techniques – covering the most core technical skills in risk assessment and management, incident response, forensics, enterprise networks, hybrid/cloud operations, and security controls, ensuring high-performance on the job.

Two people looking at many monitors.

About the exam

CompTIA Security+ (SY0-501) English language exam will retire on July 31, 2021.

The new Security+ (SY0-601) is now available.

CompTIA Security+ is the first security certification a candidate should earn. It establishes the core knowledge required of any cybersecurity role and provides a springboard to intermediate-level cybersecurity jobs. Security+ incorporates best practices in hands-on troubleshooting, ensuring candidates have practical security problem-solving skills required to:

Assess the security posture of an enterprise environment and recommend and implement appropriate security solutions
Monitor and secure hybrid environments, including cloud, mobile, and IoT
Operate with an awareness of applicable laws and policies, including principles of governance, risk, and compliance
Identify, analyze, and respond to security events and incidents

Security+ is compliant with ISO 17024 standards and approved by the US DoD to meet directive 8140/8570.01-M requirements. Regulators and government rely on ANSI accreditation, because it provides confidence and trust in the outputs of an accredited program. Over 2.3 million CompTIA ISO/ANSI-accredited exams have been delivered since January 1, 2011.

What Skills Will You Learn?
HARDWARE : Attacks, Threats and Vulnerabilities

Focusing on more threats, attacks, and vulnerabilities on the Internet from newer custom devices that must be mitigated, such as IoT and embedded devices, newer DDoS attacks, and social engineering attacks based on current events.

SECURITY
Architecture and Design

Includes coverage of enterprise environments and reliance on the cloud, which is growing quickly as organizations transition to hybrid networks.

HARDWARE & NETWORK TROUBLESHOOTING

Implementation
Expanded to focus on administering identity, access management, PKI, basic cryptography, wireless, and end-to-end security.

WINDOWS OPERATING SYSTEMS

Operations and Incident Response
Covering organizational security assessment and incident response procedures, such as basic threat detection, risk mitigation techniques, security controls, and basic digital forensics.
SOFTWARE TROUBLESHOOTING
Governance, Risk and Compliance

Expanded to support organizational risk management and compliance to regulations, such as PCI-DSS, SOX, HIPAA, GDPR, FISMA, NIST, and CCPA.

Jobs that use CompTIA Security+
Security Administrator

Systems Administrator
Helpdesk Manager / Analyst

Network / Cloud Engineer
Security Engineer / Analyst

DevOps / Software Developer
IT Auditors

IT Project Manager

QUESTION 1
Which of the following will MOST likely adversely impact the operations of unpatched traditional programmable-logic controllers, running a back-end LAMP server and OT systems with human-management interfaces that are accessible over the Internet via a web interface? (Choose two.)

A. Cross-site scripting
B. Data exfiltration
C. Poor system logging
D. Weak encryption
E. SQL injection
F. Server-side request forgery

Correct Answer: DF

QUESTION 2
A company recently transitioned to a strictly BYOD culture due to the cost of replacing lost or damaged corporate-owned mobile devices. Which of the following technologies would be BEST to balance the BYOD
culture while also protecting the company’s data?

A. Containerization
B. Geofencing
C. Full-disk encryption
D. Remote wipe

Correct Answer: C

QUESTION 3
A network engineer has been asked to investigate why several wireless barcode scanners and wireless computers in a warehouse have intermittent connectivity to the shipping server. The barcode scanners and computers are all on forklift trucks and move around the warehouse during their regular use. Which of the following should the engineer do to determine the issue? (Choose two.)

A. Perform a site survey
B. Deploy an FTK Imager
C. Create a heat map
D. Scan for rogue access points
E. Upgrade the security protocols
F. Install a captive portal

Correct Answer: AC

QUESTION 4
Which of the following is MOST likely to outline the roles and responsibilities of data controllers and data processors?

A. SSAE SOC 2
B. PCI DSS
C. GDPR
D. ISO 31000

Correct Answer: C

Actualkey CompTIA Security+ SY0-601 Exam pdf, Certkingdom CompTIA Security+ SY0-601 PDF

MCTS Training, MCITP Trainnig

Best CompTIA Security+ SY0-601 Certification, CompTIA Security+ SY0-601 Training at certkingdom.com

Saturday, July 31, 2021

2V0-62.21 Professional VMware Workspace ONE 21.X Exam

 

Professional VMware Workspace ONE 21.X

EXAM OVERVIEW
The Professional VMware Workspace ONE 21.X exam validates an individual can install, configure, manage, maintain and perform basic troubleshooting of VMware Workspace ONE and related solutions, as well as properly identify and differentiate any needed supporting products and components.

Exam Info
Duration 130 minutes
Number of Questions 60
Passing Score 300 Learn more
Format Multiple Choice, Multiple Choice Multiple Selection, Drag and Drop, Matching, Hot Area

Additional Resources
VCP Community
VMware Customer Connect Learning
VMware Press
VMware Certification Market Place

Exam Details:
(Last Updated: 5/21/2021) The Professional VMware Workspace ONE 21.X exam (2V0-62.21) which leads to VMware Certified Professional – Digital Workspace 2020 certification is a 60-item exam, with a passing score of 300 using a scaled method. Candidates are given an appointment time of 130 minutes, which includes five-minute seating time and adequate time to complete the exam for non-native English speakers. Actual exam time is 125 minutes. Exam Delivery This is a proctored exam delivered through Pearson VUE. For more information, visit the Pearson VUE website. Certification Information For details and a complete list of requirements and recommendations for attainment, please reference the VMware Education Services – Certification website.Minimally Qualified Candidate The Minimally Qualified Candidate has a working knowledge of the VMware Workspace ONE platform. The MQC installs, configures, manages, maintains, and performs basic troubleshooting of VMware Workspace ONE and related solutions using publicly available documents. The MQC is knowledgeable of software, infrastructure design, and implementation. The MQC is familiar with standard operating systems across devices, productivity applications, and technologies related to Workspace ONE configuration. The MQC has a minimum of 6 months of general IT experience and typically 6 months of VMware experience installing and configuring the Workspace ONE platform. The MQC must have all the knowledge contained in the VCP-Digital Workspace exam blueprint. Exam Sections VMware exam blueprint sections are now standardized to the seven sections below, some of which may NOT be included in the final exam blueprint depending on the exam objectives.

Section 1 – Architecture and Technologies
Section 2 – Products and Solutions
Section 3 – Planning and Designing
Section 4 – Installing, Configuring, and Setup
Section 5 – Performance-tuning, Optimization, and Upgrades
Section 6 – Troubleshooting and Repairing
Section 7 – Administrative and Operational Tasks

If a section does not have testable objectives in this version of the exam, it will be noted below, accordingly. The objective numbering may be referenced in your score report at the end of your testing event for further preparation should a retake of the exam be necessary.

Sections Included in this Exam

Section 1 –Architectures and Technologies

Objective 1.1 - Differentiate and illustrate the differences between physical architecture and logical architecture
Objective 1.2 - Differentiate between cloud computing and on-prem unified endpoint management
Objective 1.3 - Differentiate between endpoint operating systems as well as various manufacturer differences
Objective 1.4 - Describe and define identity and access management concepts
Objective 1.5 - Differentiate between traditional management and modern management
Objective 1.6 - Explain authentication methods (2 factor authentication, Kerberos, Identity Chain, SAML, SAML Transformation, Mobile SSO, etc.)
Objective 1.7 - Describe security concepts in relation to endpoint management (DMZ, Zero Trust, authentication, authorization, etc.) Section 2 – VMware Products and Solutions

Section 2 –VMware Products and Solutions
Objective 2.1 - Describe UEM + Access components and sub-components (AirWatch Cloud Connector, Workspace ONE Access Connector, Workspace ONE Assist, UAG, ENS, AWCM, LTE Connector, VMverify, Intelligent Hub, Drop-ship (Factory) Provisioning, etc.)
Objective 2.1.1 - Describe AirWatch Cloud Connector features and functions
Objective 2.1.2 - Describe Workspace ONE Access Connector features and functions
Objective 2.1.3 - Describe Workspace ONE Assist features and functions
Objective 2.1.4 - Describe UAG features and functions
Objective 2.1.5 - Describe ENS features and functions
Objective 2.1.6 - Describe AWCM features and functions
Objective 2.1.7 - Describe LTE Connector features and functions
Objective 2.1.8 - Describe VMverify features and functions
Objective 2.1.9 - Describe Intelligent Hub features and functions
Objective 2.1.10 - Describe Drop-ship (Factory) Provisioning) features and functions
Objective 2.2 - Differentiate and match use case for VMware products
Objective 2.3 - Explain VMware best practices when using VMware products
Objective 2.4 - Identify and describe Workspace ONE relevant Disaster Recovery, HA, Scalability (UEM, Access, AirWatch Cloud Connector, Workspace ONE Access Connector, UAG, etc.)
Objective 2.5 - Explain Workspace ONE Intelligence, dashboard, custom reports, sensors, etc.
Objective 2.6 - Explain Unified Access Gateway Workspace ONE Edge Services
Objective 2.7 - Explain use cases for Workspace ONE SDK
Objective 2.8 - Explain the use case for Windows 10 Modern Management transformation and migration (Workspace ONE Airlift)
Objective 2.9 - Describe desktop management use cases other than Windows

Section 3 – There are no testable objectives for this section


Section 4 – Installation, Configuration, and Setup
Objective 4.1 - Identify infrastructure requirements (minimums, maximums, and recommended sizing requirements, OS version support, database versions, email infrastructure, directory services, etc.)
Objective 4.2 - Install and configure Workspace ONE components
Objective 4.2.1 - Install and configure UEM components
Objective 4.2.1.1 - Configure Android Enterprise
Objective 4.2.1.2 - Configure Apple device enrollment and purchased content management
Objective 4.2.1.3 - Configure Certificate Authority Integration
Objective 4.2.1.4 - Configure Mobile Email Management (PowerShell integration, SEG, G-Suite, Office 365, Microsoft eXchange)
Objective 4.2.1.5 - Install and configure ACC
Objective 4.2.2 - Install and configure Access components (connectors, UAG)
Objective 4.2.3 - Configure UAG Edge Services (Tunnel, SEG and Content Gateway)
Objective 4.2.4 - Configure Directory Services (users and groups)
Objective 4.2.4.1 - Configure and test Active Directory connection
Objective 4.2.4.2 - Import Active Directory users and groups
Objective 4.3 - Configure branding for administrative consoles
Objective 4.4 - Configure Hub services
Objective 4.4.1 – Configure branding
Objective 4.4.2 – Configure catalog
Objective 4.4.3 – Configure people search
Objective 4.4.4 – Configure notifications
Objective 4.4.5 – Configure custom tab (homepage)
Objective 4.4.6 – Configure support tab
Objective 4.4.7 – Configure templates
Objective 4.4.8 – Configure new hire welcome

Section 5 - There are no testable objectives for this section

Section 6 – Troubleshooting and Repairing
Objective 6.1 - Understand the various logs and their purpose
Objective 6.2 - Detect networking misconfigurations (DNS, NTP, etc.)
Objective 6.3 - Identify endpoint enrollment and management non-connectivity
Objective 6.4 - Identify end-user authentication failures
Objective 6.5 - Use console to resolve device misconfigurations

Section 7 – Administrative and Operational Tasks

Objective 7.1 - Configure and manage device profiles for mobile and desktop endpoint OS
Objective 7.2 - Configure and manage certificate authority and certificate templates
Objective 7.3 - Manage Assignment Groups and Organization Groups
Objective 7.4 - Add and manage Accounts (users, admins, groups)
Objective 7.5 - Add, assign, and manage Resources
Objective 7.6 - Add, assign, and manage Content
Objective 7.7 - Configure and manage Email policies
Objective 7.8 - Configure and manage Compliance policies for mobile and desktop endpoints
Objective 7.9 - Perform device management on device endpoints
Objective 7.10 - Add and Manage SaaS, Web Applications on Workspace ONE Access
Objective 7.11 - Configure and manage connectors
Objective 7.12 - Manage UEM reporting
Objective 7.13 - Manage user and admin access on Workspace ONE Access Console
Objective 7.14 - Add and manage conditional access, access policy in Workspace ONE Access Console
Objective 7.15 - Manage authentication methods in Workspace ONE Access
Objective 7.16 - Configure privacy and security controls
Objective 7.17 - Create custom reports (Workspace ONE Intelligence)
Objective 7.18 - Configure and manage API settings
Objective 7.19 - Configure and manage automation, dashboard, and widget

Recommended Courses VMware Workspace ONE: Deploy and Manage [V21.x] - ILT VMware Workspace ONE: Deploy and Manage [V21.x] - On Demand VMware Workspace ONE: Skills for UEM [V21.x] - ILT VMware Workspace ONE: Skills for UEM [V21.x] – On Demand VMware Workspace ONE: Integrating Access with UEM [V21.x] - ILT VMware Workspace ONE: Integrating Access with UEM [V21.x] - On Demand

In addition to the recommended courses, item writers use the following references for information when writing exam questions. It is recommended that you study the reference content as you prepare to take the exam, in addition to any recommended training.
*Workspace ONE content in this exam based on v21.X. Review all v21.X and [U1] release notes and material for features and function.

QUESTION 1
As a Workspace ONE administrator, you have been tasked with creating a custom visualization for
management that shows device statistics, trust network threats, and application adoption metrics in a single view.
Which feature of Workspace ONE can be used?

A. Workspace ONE Intelligence Dashboards
B. Workspace ONE Access Application View
C. Workspace ONE Intelligence Automations
D. Workspace ONE UEM Device List View

Correct Answer: A

Explanation/Reference:

QUESTION 2
Which Workspace ONE UEM feature can assist in sending event log information to a Security Information and Event Management (SIEM) tool?

A. Syslog Integration
B. Relay Server Integration
C. Certificate Authority Integration
D. File Storage Integration

Correct Answer: A

QUESTION 3
Which two steps would an administrator complete to enable auto-discovery for their Workspace ONE UEM environment? (Choose two.)

A. Enter the email domain when installing the AirWatch Cloud Connector.
B. Verify the domain by accepting the link in the email that registered auto-discovery.
C. Register email domain within Workspace ONE UEM.
D. Enter the email domain when establishing directory services.
E. Email auto-discovery@workspaceone.com with the domain the administrator wants to register.

Correct Answer: BC

QUESTION 4
What two features of Hub Services can be enabled without enabling Workspace ONE Access and having the authentication mode set to Workspace ONE UEM? (Choose two.)

A. enable SSO for applications
B. enable People Search
C. notifications for iOS and Android
D. Hub Virtual Assistant Chatbot
E. Hub Catalog layout

Correct Answer: AB

QUESTION 5
Where is Hub Services component co-located?

A. Workspace ONE Intelligence
B. Workspace ONE Access
C. Workspace ONE Airlift
D. Workspace ONE UEM

Correct Answer: B

QUESTION 6
Which two Workspace ONE UEM core components are required for all on-premises environments? (Choosetwo.)

A. Device Services
B. AirWatch Cloud Connector
C. Unified Access Gateway
D. Secure Email Gateway
E. Console Services

Correct Answer: AB

ACtualkey VMware 2V0-62.21 Exam pdf, Certkingdom VMware 2V0-62.21 PDF

MCTS Training, MCITP Trainnig

Best VMware 2V0-62.21 Certification, VMware 2V0-62.21 Training at Certkingdom.com

Friday, June 25, 2021

500-220 Engineering Cisco Meraki Solutions v1.0 Exam

 

Engineering Cisco Meraki Solutions v1.0 (500-220)
Exam Description: The Engineering Cisco Meraki Solutions v1.0 (ECMS 500-220) is a 90-minute exam associated with the Cisco Meraki Solutions Specialist. This exam tests a candidate's knowledge and skills to engineer Meraki solutions including cloud management, design, implementing, monitoring, and troubleshooting. The courses, Engineering Cisco Meraki Solutions Part 1 and Part 2, help candidates to prepare for this exam.
The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. To better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.

15% 1.0 Cisco Meraki Cloud Management
1.1 Explain Cisco Meraki cloud architecture
1.2 Explain access methods to dashboard and devices
1.3 Explain organizational structure, segmentation and permissions
1.4 Explain licensing, co-termination, and renewals
1.5 Compare deployment workflows

30% 2.0 Design
2.1 Design scalable Meraki Auto VPN architectures
2.2 Explain deployment consideration for the vMX
2.3 Design dynamic path selection policies
2.4 Design stable, secure, and scalable routing deployments
2.5 Design Enterprise network services
2.5a Redundant networks and high availability
2.5b QOS strategy for voice and video
2.5c Applying security at layer 2
2.5d Firewall and IPS rules on MX and MR
2.5e Network access control solutions
2.6 Design Enterprise wireless services
2.6a High density wireless deployments
2.6b MR wireless networks for Enterprise
2.6c MR wireless networks for guest access
2.7 Compare endpoint device and application management methods
2.7a Device enrollment such as supervised and device owner
2.7b Application deployment

25% 3.0 Implementation
3.1 Configuring MX security appliances
3.1a SVI, dynamic routing and static routes
3.1b Auto VPN
3.1c Traffic shaping and SD-WAN
3.1d Threat protection and content filtering rules
3.1e Access policies and 802.1x
3.2 Configuring MS switches
3.2a SVI, dynamic routing and static routes
3.2b QoS using Meraki switching networks
3.2c Access policies and 802.1x
3.2d Replicate a switch configuration
3.3 Configuring MR wireless access points
3.3a SSIDs for Enterprise and BYOD deployments
3.3b Traffic shaping
3.3c RF profiles
3.3d Air Marshal
3.4 Configuring SM endpoint management
3.4a Management profiles
3.4b Security policies
3.4c Sentry for Meraki managed deployments
3.5 Configuring MV security cameras
3.5a Camera video and alerting
3.5b Retention settings
3.6 Configuring MI application assurance
3.6a Standard applications
3.6b Application thresholds

30% 4.0 Monitoring and Troubleshooting

4.1 Interpret information from monitoring and reporting tools
4.1a Alerts with Dashboard, SNMP, Syslog and Netflow in Dashboard
4.1b Logging and reporting in Dashboard
4.2 Describe how to use the dashboard API to monitor and maintain networks
4.3 Explain firmware upgrades
4.4 Troubleshooting Enterprise networks
4.4a Layer 2 technologies using Dashboard
4.4b Layer 3 technologies using Dashboard
4.4c Wireless client connectivity issues using Dashboard
4.4d Device local status pages
4.4e Security threats using Security Center
4.4f Application performance issues using Meraki Insight

QUESTION 1
When an SSID is configured with Sign-On Splash page enabled, which two settings must be configured for unauthenticated clients to have full network access and not be allow listed? (Choose two.)

A. Controller disconnection behavior
B. Captive Portal strength
C. Simultaneous logins
D. Firewall & traffic shaping
E. RADIUS for splash page settings

Correct Answer: AB

QUESTION 2
For which two reasons can an organization become “Out of License”? (Choose two.)

A. licenses that are in the wrong network
B. more hardware devices than device licenses
C. expired device license
D. licenses that do not match the serial numbers in the organization
E. MR licenses that do not match the MR models in the organization

Correct Answer: BC

QUESTION 3
Which Cisco Meraki best practice method preserves complete historical network event logs?

A. Configuring the preserved event number to maximize logging.
B. Configuring the preserved event period to unlimited.
C. Configuring a syslog server for the network.
D. Configuring Dashboard logging to preserve only certain event types.

Correct Answer: A

QUESTION 4
Which design requirement is met by implementing syslog versus SNMP?

A. when automation capabilities are needed
B. when proactive alerts for critical events must be generated
C. when organization-wide information must be collected
D. when information such as flows and client connectivity must be gathered

Correct Answer: D

Actualkey Cisco 500-220 Exam pdf, Certkingdom Cisco 500-220 PDF

MCTS Training, MCITP Trainnig

Best Cisco 500-220 Certification, Cisco 500-220 Training at certkingdom.com

Thursday, June 24, 2021

PT1-002 CompTIA PenTest+ Certification Exam

 

CompTIA PenTest+ is for cybersecurity professionals tasked with penetration testing and vulnerability management.

Why is it different?
CompTIA PenTest+ is the only penetration testing exam taken at a Pearson VUE testing center with both hands-on, performance-based questions and multiple-choice, to ensure each candidate possesses the skills, knowledge, and ability to perform tasks on systems. PenTest+ exam also includes management skills used to plan, scope, and manage weaknesses, not just exploit them.

PenTest+ is unique because our certification requires a candidate to demonstrate the hands-on ability and knowledge to test devices in new environments such as the cloud and mobile, in addition to traditional desktops and servers.

About the exam
The new PenTest+ (PT0-002) exam will launch October, 2021!

Beta exam registration available on April 13, 2021. Interested in taking the beta exam? Registration on the Pearson VUE site.

CompTIA PenTest+ assesses the most up-to-date penetration testing, and vulnerability assessment and management skills necessary to determine the resiliency of the network against attacks.
Successful candidates will have the intermediate skills required to customize assessment frameworks to effectively collaborate on and report findings.
Candidates will also have the best practices to communicate recommended strategies to improve the overall state of IT security.

CompTIA PenTest+ is compliant with ISO 17024 standards and approved by the US DoD to meet directive 8140/8570.01-M requirements. Regulators and government rely on ANSI accreditation, because it provides confidence and trust in the outputs of an accredited program. Over 2.3 million CompTIA ISO/ANSI-accredited exams have been delivered since January 1, 2011.

What Skills Will You Learn?
HARDWARE
PLANNING & SCOPING

Explain the importance of planning and key aspects of compliance-based assessments
WINDOWS OPERATING SYSTEMS
INFORMATION GATHERING &
VULNERABILITY IDENTIFICATION

Gather information to prepare for exploitation then perform a vulnerability scan and analyze results.
SOFTWARE TROUBLESHOOTING
ATTACKS & EXPLOITS

Exploit network, wireless, application, and RF-based vulnerabilities, summarize physical security attacks, and perform post-exploitation techniques
NETWORKING
PENETRATION TESTING TOOLS

Conduct information gathering exercises with various tools and analyze output and basic scripts (limited to: Bash, Python, Ruby, PowerShell)
HARDWARE & NETWORK TROUBLESHOOTING
REPORTING & COMMUNICATION

Utilize report writing and handling best practices explaining recommended mitigation strategies for discovered vulnerabilities
obs that use CompTIA PenTest+
Penetration Tester
Vulnerability Tester
Security Analyst (II)
Vulnerability Assessment Analyst
Network Security Operations
Application Security Vulnerability

Renewal
Keep your certification up to date with CompTIA’s Continuing Education (CE) program. It’s designed to be a continued validation of your expertise and a tool to expand your skillset. It’s also the ace up your sleeve when you’re ready to take the next step in your career.

Get the most out of your certification
Information technology is an incredibly dynamic field, creating new opportunities and challenges every day. Participating in our Continuing Education program will enable you to stay current with new and evolving technologies and remain a sought-after IT and security expert.

The CompTIA Continuing Education program
Your CompTIA PenTest+ certification is good for three years from the date of your exam. The CE program allows you to extend your certification in three-year intervals through activities and training that relate to the content of your certification.

It’s easy to renew
You can participate in a number of activities and training programs, including higher certifications, to renew your CompTIA PenTest+ certification. Collect at least 60 Continuing Education Units (CEUs) in three years and upload them to your certification account, and your CompTIA PenTest+ certification will automatically renew.

QUESTION 1
Which of the following should a penetration tester consider FIRST when engaging in a penetration test in a cloud environment?

A. Whether the cloud service provider allows the penetration tester to test the environment
B. Whether the specific cloud services are being used by the application
C. The geographical location where the cloud services are running
D. Whether the country where the cloud service is based has any impeding laws

Correct Answer: C

QUESTION 2
A penetration tester who is conducting a web-application test discovers a clickjacking vulnerability associated
with a login page to financial data. Which of the following should the tester do with this information to make this a successful exploit?

A. Perform XSS.
B. Conduct a watering-hole attack.
C. Use BeEF.
D. Use browser autopwn.

Correct Answer: A

QUESTION 3
A company that requires minimal disruption to its daily activities needs a penetration tester to perform
information gathering around the company’s web presence. Which of the following would the tester find MOST
helpful in the initial information-gathering steps? (Choose two.)

A. IP addresses and subdomains
B. Zone transfers
C. DNS forward and reverse lookups
D. Internet search engines
E. Externally facing open ports
F. Shodan results

Correct Answer: AB

QUESTION 4
A penetration tester discovers that a web server within the scope of the engagement has already been
compromised with a backdoor. Which of the following should the penetration tester do NEXT?

A. Forensically acquire the backdoor Trojan and perform attribution
B. Utilize the backdoor in support of the engagement
C. Continue the engagement and include the backdoor finding in the final report
D. Inform the customer immediately about the backdoor

Correct Answer: C

QUESTION 5
Which of the following are the MOST important items to include in the final report for a penetration test? (Choose two.)

A. The CVSS score of the finding
B. The network location of the vulnerable device
C. The vulnerability identifier
D. The client acceptance form
E. The name of the person who found the flaw
F. The tool used to find the issue

Correct Answer: CF

QUESTION 6
A penetration tester who is performing a physical assessment of a company’s security practices notices the
company does not have any shredders inside the office building. Which of the following techniques would be
BEST to use to gain confidential information?

A. Badge cloning
B. Dumpster diving
C. Tailgating
D. Shoulder surfing

Correct Answer: B

QUESTION 7
A penetration tester conducted an assessment on a web server. The logs from this session show the
following:
http://www.thecompanydomain.com/servicestatus.php?serviceID=892&serviceID=892 ‘ ;
DROP TABLE SERVICES; --
Which of the following attacks is being attempted?

A. Clickjacking
B. Session hijacking
C. Parameter pollution
D. Cookie hijacking
E. Cross-site scripting

Correct Answer: C

Actualkey CompTIA PT1-002 Exam pdf, Certkingdom CompTIA PT1-002 PDF

MCTS Training, MCITP Trainnig

Best CompTIA PT1-002 Certification, CompTIA PT1-002 Training at certkingdom.com

Wednesday, June 23, 2021

GCP-GC-ADM Genesys Cloud Certified Professional - Contact Center Administration Exam

 

The Genesys Cloud Certified Professional - Contact Center Admin exam introduces the fundamental concepts and major components associated with the Contact Center feature set of the Genesys Cloud platform.

This exam provides an overview of the Genesys Cloud interface and presents scenarios to facilitate your understanding of the administration of a contact center. You will also gain familiarity with daily contact center monitoring and administration tasks.

Note: The Genesys Cloud Certified Professional (GCP-GC) certification is obtained by completing the following three exams (Contact Center Administration, Implementation, and Reporting & Analytics). The prerequisite for GCP-GC is the Genesys Cloud Certified Associate (GCA-GC) certification.

Target Audience
The Genesys Cloud Certified Professional - Contact Center Admin exam is intended for system administrators, contact center managers, project managers, and supervisors to help them monitor and administer the contact center. The exam is also useful for anyone else who needs to learn the basic functionality of Genesys Cloud Contact Center.

Course Objectives
Genesys Cloud Collaborate
Basic overview of the Genesys Cloud Platform and Administration
Overview of Genesys Cloud Collaborate
List the features of Genesys Cloud Contact Center
List the three levels of Contact Center licensing
Configure Automatic Call Distribution to optimize customer service
Describe ACD processing
Explain interaction flow and queue design
Evaluation and routing combination
Configure agent utilization
Configure ACD Skills and Language Skills
Configure wrap-up codes
Configure After Call Work
Activate and deactivate agents on queues
Test ACD call routing
Configure ACD email in Admin settings
Test ACD email routing
Describe ACD Messages
Purpose and capabilities of Genesys Cloud Architect
Features of Genesys Cloud Architect
Describe the options for Inbound
Describe how to create and edit System and User Prompts
Genesys Cloud Data Actions Integration
Describe the function and purpose of the Genesys Cloud data actions Integration
Scripting in a Genesys Cloud contact center
Describe Scripts and basic script functionality
Genesys Cloud Outbound Dialing
Describe the Outbound Dialing modes
Explain the use of Contact Lists
Configure and test an Outbound Power Dialing campaign
Use of Reports and Dynamic Views
List the main types of reports and describe their use
List the main Dynamic Views and describe their use
Configure and run an Interaction Details report
Quality Management in a Genesys Cloud contact center
Quality Policies Overview
Describe how to enable call recording on a Trunk
Create a recording policy
Create and publish an Evaluation form
Quality Evaluator and Quality Administrator dashboards
Workforce Management in a Genesys Cloud contact center
Workforce Management Overview
Working with Schedules
Benefits of scheduling agents
Create a manual schedule

QUESTION 1
A Queue is configured for Standard ACD routing and Disregard skills, next agent for the Evaluation Method.
What agent property is used to determine the next available agent?

A. Skill
B. Time since they last handled an ACD interaction
C. Cost
D. Department

Correct Answer: A

QUESTION 2
Which definition matches the After Call Work option Mandatory, Time-boxed?

A. The agent may or may not complete after call work. The system will set them to Available after an interaction completes.
They are responsible for setting their availability appropriately if performing After Call Work.

B. The agent is automatically placed into an After Call Work status and the system will automatically set them to Available when the After Call Timeout is reached.
The agent may set themselves to Available if they complete their After Call Work early.

C. The agent is automatically placed into an After Call Work status and the system will automatically set them to Available when the After Call Timeout is reached.
The agent may not set themselves to Available if they complete their After Call Work early.

D. The agent is placed in an After Call Work status and must manually set their status back to available when their after call work is complete.

Correct Answer: B

QUESTION 3
Currently, you manage all agents’ schedules by using a spreadsheet. This shows when each agent is working
when they are on breaks, and when they have meetings or other events that take them away from the queue.
You would like to be able to schedule agents in an easier and more automated way. What Genesys Cloud
Contact Center feature can you use to replace and automate the spreadsheet schedule?

A. Workforce Management
B. Workflow Process Automation
C. Genesys Cloud Architect
D. Genesys Cloud Reporting

Correct Answer: A

QUESTION 4
Select all the roles that are automatically assigned by default to the user who sets up the organization.
(Choose two.)

A. Employee
B. Master Admin
C. Genesys Cloud User
D. Admin
E. Telephony Admin

Correct Answer: AD

Actualkey Genesys GCP-GC-ADM Exam pdf, Certkingdom Genesys GCP-GC-ADM PDF

MCTS Training, MCITP Trainnig

Best Genesys GCP-GC-ADM Certification, Genesys GCP-GC-ADM Training at certkingdom.com

Monday, June 7, 2021

250-439 Administration of Symantec IT Management Suite 8.1 (Broadcom) Exam

 

Administration of Symantec Client Management Suite 8.5
The certified candidate will demonstrate an understanding of the planning, designing, deploying and optimization of the Symantec Client Management Suite. This understanding serves as a basis of technical knowledge and competency for the Symantec Client Management Suite 8.5 solution in an enterprise environment.

To achieve this level of certification, candidates must pass the technical exam and accept the Symantec Certification Agreement.

Exam Details:
# of Questions: 65-75
Exam Duration: 90 minutes
Passing Score: 70%
Languages: English

Exam Study Guide
Recommended 3 months regular experience working with Symantec ITMS or CMS, SMS or AMS solutions and products with at least the ability to complete the following:
Create a high-level design of a basic Client Management Suite 8.5 implementation
Install the Client Management Suite 8.5 components, updates and perform post installation tasks
Import and discover endpoint resources
Create/Apply/Manage Filters, Targets & Organizational Views/Groups
Inventory managed computers
Configure the Software Catalog, Portal and Library
Deploy software packages
Download, stage, and deploy software updates
View and use reports to assist with managing computers
Create, configure, and deploy images to managed computers

Client Management Suite 8.1 or 8.5 Administration

Current Class Schedule

IT Management Suite Fundamentals
Available in the Symantec LearnCentral eLibrary

Optional Instructor-led Courses:
IT Management Suite 8.1 Administration
Current Class Schedule

ITMS 8.1 Diagnostics and Troubleshooting
Current Class Schedule

Asset Management Suite 8.1 or 8.5 Administration

Current Class Schedule

Additional online training is available 24/7 in the Symantec eLibrary.

Note: If you do not have prior experience with this product, it is recommended that you complete an in-person, classroom training or Virtual Academy virtual classroom training class in preparation for the SCS exam. If you have experience with this product, you may find an online course equivalent to be sufficient. Be cautioned that attendance in a training course does not guarantee passage of a certification exam.


QUESTION 1
Which two (2) fields are essential to tracking assets when creating a warranty contract in IT Management
Suite 8.1? (Choose two.)

A. Contract's Assigned User
B. Covered Hardware
C. Contract's Location
D. Start and End Date
E. Internal Reference

Correct Answer: CD

QUESTION 2
An administrator has been notified that a new office location will be opening within a few weeks. The office is a
large site that will have 8,000 managed endpoints. The data center is located in Lindon, Utah and the office is
located in Houston, Texas.
What is the minimum number of site servers needed to support the new office location?

A. Four site servers
B. Two site servers
C. One site server
D. Three site servers

Correct Answer: C

QUESTION 3
An administrator needs to ensure the following functionality for managed computers in an IT Management
Suite 8.1 environment:
- Monitoring hardware and software
- Scheduling software installations and file updates
- Collecting basic inventory information
- Managing policies and packages
Which components work together to provide this functionality for managed computers?

A. Notification Server and Symantec Management Agent
B. Symantec Management Console and Internet Gateway
C. Symantec Management Console and Symantec Management Agent
D. Notification Server and Internet Gateway

Correct Answer: C

QUESTION 4
How can an administrator quickly view and export report results while creating a filter based on the location of computers?

A. Executing the Filter Results Report Builder
B. Executing Assets by Location Organizational View Builder
C. Executing and saving the IT Analytics Computers by Location Report Builder
D. Executing the Computers by Location Report Builder

Correct Answer: A

Actualkey Symantec SCS 250-439 Exam pdf, Certkingdom Symantec SCS 250-439 PDF

MCTS Training, MCITP Trainnig

Best Symantec SCS 250-439 Certification, Symantec SCS 250-439 Training at certkingdom.com

SC-900 Microsoft Security Compliance and Identity Fundamentals Exam

 

Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals

This certification is targeted to those looking to familiarize themselves with the fundamentals of security, compliance, and identity (SCI) across cloud-based and related Microsoft services.

This is a broad audience that may include business stakeholders, new or existing IT professionals, or students who have an interest in Microsoft security, compliance, and identity solutions.

Candidates should be familiar with Microsoft Azure and Microsoft 365 and want to understand how Microsoft security, compliance, and identity solutions can span across these solution areas to provide a holistic and end-to-end solution.

Part of the requirements for: Microsoft Certified: Security, Compliance, and Identity Fundamentals

Related exams: none
Schedule exam
Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals
Languages: English, Japanese, Chinese (Simplified), Korean, Dutch, French, Spanish, Portuguese (Brazil), Russian, Arabic (Saudi Arabia)
Retirement date: none

This exam measures your ability to describe the following: concepts of security, compliance, and identity; capabilities of Microsoft identity and access management solutions; capabilities of Microsoft security solutions; and capabilities of Microsoft compliance solutions.

Skills measured
Describe the concepts of security, compliance, and identity (5-10%)
Describe the capabilities of Microsoft identity and access management solutions (25-30%)
Describe the capabilities of Microsoft security solutions (30-35%)
Describe the capabilities of Microsoft compliance solutions (25-30%)

Audience Profile
This certification is targeted to those looking to familiarize themselves with the fundamentals of security, compliance, and identity (SCI) across cloud-based and related Microsoft services.
This is a broad audience that may include business stakeholders, new or existing IT professionals, or students who have an interest in Microsoft security, compliance, and identity solutions.

Candidates should be familiar with Microsoft Azure and Microsoft 365 and want to understand how Microsoft security, compliance, and identity solutions can span across these solution areas to provide a holistic and end-to-end solution.

Skills Measured
NOTE: The bullets that appear below each of the skills measured are intended to illustrate how we are assessing that skill. This list is not definitive or exhaustive.

NOTE: Most questions cover features that are General Availability (GA). The exam may contain questions on Preview features if those features are commonly used.

Describe the Concepts of Security, Compliance, and Identity (5-10%)
Describe security methodologies
 describe the Zero-Trust methodology
 describe the shared responsibility model
 define defense in depth

Describe security concepts
 describe common threats
 describe encryption

Describe Microsoft Security and compliance principles
 describe Microsoft's privacy principles
 describe the offerings of the service trust portal

Describe the capabilities of Microsoft Identity and Access Management
Solutions (25-30%)
Define identity principles/concepts

 define identity as the primary security perimeter
 define authentication
 define authorization
 describe what identity providers are
 describe what Active Directory is
 describe the concept of Federated services
 define common Identity Attacks

Describe the basic identity services and identity types of Azure AD
 describe what Azure Active Directory is
 describe Azure AD identities (users, devices, groups, service principals/applications)
 describe what hybrid identity is
 describe the different external identity types (Guest Users)

Describe the authentication capabilities of Azure AD
 describe the different authentication methods
 describe self-service password reset
 describe password protection and management capabilities
 describe Multi-factor Authentication
 describe Windows Hello for Business

Describe access management capabilities of Azure AD
 describe what conditional access is
 describe uses and benefits of conditional access
 describe the benefits of Azure AD roles

Describe the identity protection & governance capabilities of Azure AD
 describe what identity governance is
 describe what entitlement management and access reviews is
 describe the capabilities of PIM
 describe Azure AD Identity Protection

Describe the capabilities of Microsoft Security Solutions (30-35%)
Describe basic security capabilities in Azure
 describe Azure Network Security groups
 describe Azure DDoS protection
 describe what Azure Firewall is
 describe what Azure Bastion is
 describe what Web Application Firewall is
 describe ways Azure encrypts data

Describe security management capabilities of Azure
 describe the Azure Security center
 describe Azure Secure score
 describe the benefit and use cases of Azure Defender - previously the cloud workload protection platform (CWPP)
 describe Cloud security posture management (CSPM)
 describe security baselines for Azure

Describe security capabilities of Azure Sentinel
 define the concepts of SIEM, SOAR, XDR
 describe the role and value of Azure Sentinel to provide integrated threat protection

Describe threat protection with Microsoft 365 Defender (formerly Microsoft Threat Protection)
 describe Microsoft 365 Defender services
 describe Microsoft Defender for Identity (formerly Azure ATP)
 describe Microsoft Defender for Office 365 (formerly Office 365 ATP)
 describe Microsoft Defender for Endpoint (formerly Microsoft Defender ATP)
 describe Microsoft Cloud App Security

Describe security management capabilities of Microsoft 365
 describe the Microsoft 365 Security Center
 describe how to use Microsoft Secure Score
 describe security reports and dashboards
 describe incidents and incident management capabilities

Describe endpoint security with Microsoft Intune
 describe what Intune is
 describe endpoint security with Intune
 describe the endpoint security with the Microsoft Endpoint Manager admin center

Describe the Capabilities of Microsoft Compliance Solutions (25-30%)
Describe the compliance management capabilities in Microsoft
 describe the compliance center
 describe compliance manager
 describe use and benefits of compliance score

Describe information protection and governance capabilities of Microsoft 365
 describe data classification capabilities
 describe the value of content and activity explorer
 describe sensitivity labels
 describe Retention Polices and Retention Labels
 describe Records Management
 describe Data Loss Prevention

Describe insider risk capabilities in Microsoft 365
 describe Insider risk management solution
 describe communication compliance
 describe information barriers
 describe privileged access management
 describe customer lockbox

Describe the eDiscovery capabilities of Microsoft 365
 describe the purpose of eDiscovery
 describe the capabilities of the content search tool
 describe the core eDiscovery workflow
 describe the advanced eDisovery workflow

Describe the audit capabilities in Microsoft 365
 describe the core audit capabilities of M365
 describe purpose and value of Advanced Auditing

Describe resource governance capabilities in Azure
 describe the use of Azure Resource locks
 describe what Azure Blueprints is
 define Azure Policy and describe its use cases
 describe cloud adoption framework

QUESTION 1
Which score measures an organization's progress in completing actions that help reduce risks associated to data protection and regulatory standards?

A. Microsoft Secure Score
B. Productivity Score
C. Secure score in Azure Security Center
D. Compliance score

Correct Answer: D

QUESTION 2
What do you use to provide real-time integration between Azure Sentinel and another security source?

A. Azure AD Connect
B. a Log Analytics workspace
C. Azure Information Protection
D. a connector

Correct Answer: D

QUESTION 3
Which Microsoft 365 compliance center feature can you use to identify all the documents on a Microsoft SharePoint Online site that contain a specific key word?

A. Audit
B. Compliance Manager
C. Content Search
D. Alerts

Correct Answer: C

QUESTION 4
Which Microsoft 365 compliance feature can you use to encrypt content automatically based on specific conditions?

A. Content Search
B. sensitivity labels
C. retention policies
D. eDiscovery

Correct Answer: B

Actualkey Microsoft SC-900 Exam pdf, Certkingdom Microsoft SC-900 PDF

MCTS Training, MCITP Trainnig

Best Microsoft SC-900 Certification, Microsoft SC-900 Training at certkingdom.com