Exam Details

  • Exam Code
    :RC0-501
  • Exam Name
    :CompTIA Security+ Recertification Exam
  • Certification
    :CompTIA Security+
  • Vendor
    :CompTIA
  • Total Questions
    :349 Q&As
  • Last Updated
    :Apr 25, 2024

CompTIA CompTIA Security+ RC0-501 Questions & Answers

  • Question 1:

    A company was recently audited by a third party. The audit revealed the company's network devices were transferring files in the clear. Which of the following protocols should the company use to transfer files?

    A. HTTPS

    B. LDAPS

    C. SCP

    D. SNMPv3

  • Question 2:

    During a monthly vulnerability scan, a server was flagged for being vulnerable to an Apache Struts explogt. Upon further investigation, the developer responsible for the server informs the security team that Apache Struts is not installed on the server. Which of the following BEST describes how the security team should reach to this incident?

    A. The finding is a false positive and can be disregarded

    B. The Struts module needs to be hardened on the server

    C. The Apache software on the server needs to be patched and updated

    D. The server has been compromised by malware and needs to be quarantined.

  • Question 3:

    An application developer is designing an application involving secure transports from one service to another that will pass over port 80 for a request. Which of the following secure protocols is the developer MOST likely to use?

    A. FTPS

    B. SFTP

    C. SSL

    D. LDAPS

  • Question 4:

    Which of the following precautions MINIMIZES the risk from network attacks directed at multifunction printers, as well as the impact on functionality at the same time?

    A. Isolating the systems using VLANs

    B. Installing a software-based IPS on all devices

    C. Enabling full disk encryption

    D. Implementing a unique user PIN access functions

  • Question 5:

    After an identified security breach, an analyst is tasked to initiate the IR process. Which of the following is the NEXT step the analyst should take?

    A. Recovery

    B. Identification

    C. Preparation

    D. Documentation

    E. Escalation

  • Question 6:

    Which of the following are methods to implement HA in a web application server environment? (Select two.)

    A. Load balancers

    B. Application layer firewalls

    C. Reverse proxies

    D. VPN concentrators

    E. Routers

  • Question 7:

    As part of the SDLC, a third party is hired to perform a penetration test. The third party will have access to the source code, integration tests, and network diagrams. Which of the following BEST describes the assessment being performed?

    A. Black box

    B. Regression

    C. White box

    D. Fuzzing

  • Question 8:

    A dumpster diver recovers several hard drives from a company and is able to obtain confidential data from one of the hard drives. The company then discovers its information is posted online. Which of the following methods would have MOST likely prevented the data from being exposed?

    A. Removing the hard drive from its enclosure

    B. Using software to repeatedly rewrite over the disk space

    C. Using Blowfish encryption on the hard drives

    D. Using magnetic fields to erase the data

  • Question 9:

    The availability of a system has been labeled as the highest priority. Which of the following should be focused on the MOST to ensure the objective?

    A. Authentication

    B. HVAC

    C. Full-disk encryption

    D. File integrity checking

  • Question 10:

    Joe, a security administrator, needs to extend the organization's remote access functionality to be used by staff while travelling. Joe needs to maintain separate access control functionalities for internal, external, and VOIP services. Which of the following represents the BEST access technology for Joe to use?

    A. RADIUS

    B. TACACS+

    C. Diameter

    D. Kerberos

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your RC0-501 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.