SY0-501 Exam Details

  • Exam Code
    :SY0-501
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1423 Q&As
  • Last Updated
    :Sep 04, 2023

CompTIA SY0-501 Online Questions & Answers

  • Question 1011:

    Which of the following best describes the initial processing phase used in mobile device forensics?

    A. The phone should be powered down and the battery removed to preserve the state of data on any internal or removable storage utilized by the mobile device
    B. The removable data storage cards should be processed first to prevent data alteration when examining the mobile device
    C. The mobile device should be examined first, then removable storage and lastly the phone without removable storage should be examined again
    D. The phone and storage cards should be examined as a complete unit after examining the removable storage cards separately.

  • Question 1012:

    Which of the following is the MOST significant difference between intrusive and non-intrusive vulnerability scanning?

    A. One uses credentials, but the other does not
    B. One has a higher potential for disrupting system operations.
    C. One allows systems to activate firewall countermeasures.
    D. One returns service banners, including running versions

  • Question 1013:

    An organization plans to transition the intrusion detection and prevention techniques on a critical subnet to an anomaly-based system. Which of the following does the organization need to determine for this to be successful?

    A. The baseline
    B. The endpoint configurations
    C. The adversary behavior profiles
    D. The IPS signatures

  • Question 1014:

    A security administrator begins assessing a network with software that checks for available exploits against a known database, using both credentials and external scripts. A report will be compiled and used to confirm patching levels. This is an example of:

    A. penetration testing
    B. fuzzing
    C. static code analysis
    D. vulnerability scanning

  • Question 1015:

    The CSIRT is reviewing the lessons learned from a recent incident. A worm was able to spread unhindered throughout the network and infect a large number of computers and server. Which of the following recommendations would be BEST to mitigate the impacts of a similar incident in the future?

    A. Install a NIDS device at the boundary.
    B. Segment the network with firewalls.
    C. Update all antivirus signatures daily.
    D. Implement application blacklisting.

  • Question 1016:

    Given the following output:

    [Missing the output]

    Which of the following BEST describes the scanned environment?

    A. A host was identified as a web server that is hosting multiple domains.
    B. A host was scanned, and web-based vulnerabilities were found.
    C. A connection was established to a domain, and several redirect connections were identified.
    D. A web shell was planted in company corn's content management system.

  • Question 1017:

    Two users must encrypt and transmit large amounts of data between them. Which of the following should they use to encrypt and transmit the data?

    A. Symmetric algorithm
    B. Hash function
    C. Digital signature
    D. Obfuscation

  • Question 1018:

    An organization has created a review process to determine how to best handle data with different sensitivity levels. The process includes the following requirements:

    Soft copy PII must be encrypted.

    Hard copy PII must be placed in a locked container.

    Soft copy PHI must be encrypted and audited monthly.

    Hard copy PHI must be placed in a locked container and inventoried monthly.

    Locked containers must be approved and designated for document storage. Any violations must be reported to the Chief Security Officer (CSO).

    While searching for coffee in the kitchen, an employee unlocks a cabinet and discovers a list of customer names and phone numbers. Which of the following actions should the employee take?

    A. Put the document back in the cabinet, lock the cabinet, and report the incident to the CSO
    B. Take custody of the document, secure it at a desk, and report the incident to the CSO
    C. Take custody of the document and immediately report the incident to the CSO
    D. Put the document back in the cabinet, inventory the contents, lock the cabinet, and report the incident to the CSO

  • Question 1019:

    Select the appropriate attack from each drop down list to label the corresponding illustrated attack Instructions: Attacks may only be used once, and will disappear from drop down list if selected. When you have completed the simulation, please select the Done button to submit.

    Hot Area:

  • Question 1020:

    A member of the IR team has identified an infected computer.

    Which of the following IR phases should the team member conduct NEXT?

    A. Eradication
    B. Recovery
    C. Lessons learned
    D. Containment

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-501 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.