Exam Details

  • Exam Code
    :SY0-501
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1423 Q&As
  • Last Updated
    :Sep 04, 2023

CompTIA CompTIA Certifications SY0-501 Questions & Answers

  • Question 371:

    A security administrator needs to address the following audit recommendations for a public-facing SFTP server:

    Users should be restricted to upload and download files to their own home directories only. Users should not be allowed to use interactive shell login. Which of the following configuration parameters should be implemented? (Select TWO).

    A. PermitTunnel

    B. ChrootDirectory

    C. PermitTTY

    D. AllowTcpForwarding

    E. IgnoreRhosts

  • Question 372:

    Which of the following are used to increase the computing time it takes to brute force a password using an offline attack? (Select TWO)

    A. XOR

    B. PBKDF2

    C. bcrypt

    D. HMAC

    E. RIPEMD

  • Question 373:

    To determine the ALE of a particular risk, which of the following must be calculated? (Select two.)

    A. ARO

    B. ROI

    C. RPO

    D. SLE

    E. RTO

  • Question 374:

    Ann, a security administrator, wants to ensure credentials are encrypted in transit when implementing a RADIUS server for SSO. Which of the following are needed given these requirements? (Select TWO)

    A. Public key

    B. Shared key

    C. Elliptic curve

    D. MD5

    E. Private key

    F. DES

  • Question 375:

    The POODLE attack is an MITM exploit that affects:

    A. TLS1.0 with CBC mode cipher

    B. SSLv2.0 with CBC mode cipher

    C. SSLv3.0 with CBC mode cipher

    D. SSLv3.0 with ECB mode cipher

  • Question 376:

    A third-party penetration testing company was able to successfully use an ARP cache poison technique to gain root access on a server. The tester successfully moved to another server that was not in the original network. Which of the following is the MOST likely method used to gain access to the other host?

    A. Backdoor

    B. Pivoting

    C. Persistance

    D. Logic bomp

  • Question 377:

    The IT department is deploying new computers. To ease the transition, users will be allowed to access their old and new systems. The help desk is receive reports that users are experiencing the following error when attempting to log in to

    their previous system:

    Logon Failure: Access Denied

    Which of the following can cause this issue?

    A. Permission issues

    B. Access violations

    C. Certificate issues

    D. Misconfigured devices

  • Question 378:

    Which of the following could help detect trespassers in a secure facility? (Select TWO)

    A. Faraday cages

    B. Motion-detection sensors

    C. Tall, chain-link fencing

    D. Security guards

    E. Smart cards

  • Question 379:

    A security analyst is updating a BIA document. The security analyst notices the support vendor's time to replace a server hard drive went from eight hours to two hours. Given these new metrics, which of the following can be concluded? (Select TWO)

    A. The MTTR is faster.

    B. The MTTR is slower.

    C. The RTO has increased.

    D. The RTO has decreased.

    E. The MTTF has increased.

    F. The MTTF has decreased.

  • Question 380:

    A web developer improves client access to the company's REST API. Authentication needs to be tokenized but not expose the client's password. Which of the following methods would BEST meet the developer's requirements?

    A. SAML

    B. LDAP

    C. OAuth

    D. Shibboleth

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-501 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.