SY0-501 Exam Details

  • Exam Code
    :SY0-501
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1423 Q&As
  • Last Updated
    :Sep 04, 2023

CompTIA SY0-501 Online Questions & Answers

  • Question 1131:

    The exploitation of a buffer-overrun vulnerability in an application will MOST likely lead to:

    A. arbitrary code execution.
    B. resource exhaustion.
    C. exposure of authentication credentials.
    D. dereferencing of memory pointers.

  • Question 1132:

    The Chief Executive Officer (CEO) of an organization would like staff members to have the flexibility to work from home anytime during business hours, including during a pandemic or crisis. However, the CEO is concerned that some staff members may take advantage of the flexibility and work from high-risk countries while on holiday or outsource work to a third-party organization in another country. The Chief Information Officer (CIO) believes the company can implement some basic controls to mitigate the majority of the risk. Which of the following would be BEST to mitigate the CEO's concerns? (Choose two.)

    A. Geolocation
    B. Time-of-day restrictions
    C. Certificates
    D. Tokens
    E. Geotagging
    F. Role-based access controls

  • Question 1133:

    A security analyst wants to harden the company's VoIP PBX. The analyst is worried that credentials may be intercepted and compromised when IP phones authenticate with the BPX. Which of the following would best prevent this from occurring?

    A. Implement SRTP between the phones and the PBX.
    B. Place the phones and PBX in their own VLAN.
    C. Restrict the phone connections to the PBX.
    D. Require SIPS on connections to the PBX.

  • Question 1134:

    An organization has hired a penetration tester to test the security of its ten web servers. The penetration tester is able to gain root/administrative access in several servers by exploiting vulnerabilities associated with the implementation of SMTP, POP, DNS, FTP, Telnet, and IMAP. Which of the following recommendations should the penetration tester provide to the organization to better protect their web servers in the future?

    A. Use a honeypot
    B. Disable unnecessary services
    C. Implement transport layer security
    D. Increase application event logging

  • Question 1135:

    An organization has hired a security analyst to perform a penetration test. The analyst captures 1GB worth of inbound network traffic to the server and transfers the pcap back to the machine for analysis. Which of the following tools should the analyst use to future review the pcap?

    A. Nmap
    B. cURL
    C. Netcat
    D. Wireshark

  • Question 1136:

    A technician wants to add wireless guest capabilities to an enterprise wireless network that is currently implementing 802.1X EAP-TLS The guest network must

    Support client Isolation.

    Issue a unique encryption key to each client.

    Allow guests to register using their personal email addresses

    Which of the following should the technician implement? (Select TWO),

    A. RADIUS Federation
    B. Captive portal
    C. EAP-PEAP
    D. WPA2-PSK
    E. A separate guest SSID
    F. P12 certicate format

  • Question 1137:

    A security administrator has configured a RADIUS and a TACACS+ server on the company's network. Network devices will be required to connect to the TACACS+ server for authentication and send accounting information to the RADIUS server. Given the following information: RADIUS IP: 192.168.20.45 TACACS+ IP: 10.23.65.7 Which of the following should be configured on the network clients? (Select two.)

    A. Accounting port: TCP 389
    B. Accounting port: UDP 1812
    C. Accounting port: UDP 1813
    D. Authentication port: TCP 49
    E. Authentication port: TCP 88
    F. Authentication port: UDP 636

  • Question 1138:

    A technician must configure a firewall to block external DNS traffic from entering a network. Which of the following ports should they block on the firewall?

    A. 53
    B. 110
    C. 143
    D. 443

  • Question 1139:

    Users in a corporation currently authenticate with a username and password. A security administrator wishes to implement two-factor authentication to improve security. Which of the following authentication methods should be deployed to achieve this goal?

    A. PIN
    B. Security Question:
    C. Smart card
    D. Passphrase
    E. CAPTCHA

  • Question 1140:

    Which of the following implements a lossy algorithm?

    A. Blowfish
    B. ROT13
    C. Diffie-Hellman
    D. SHA

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-501 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.