SY0-501 Exam Details

  • Exam Code
    :SY0-501
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1423 Q&As
  • Last Updated
    :Sep 04, 2023

CompTIA SY0-501 Online Questions & Answers

  • Question 401:

    When conducting a penetration test, a pivot is used to describe a scenario in which?

    A. the penetration tester uses pass-the-hash to gam access to a server via SMB, and then uses this server to SSH to another server
    B. a penetration tester is able to download the Active Directory database after exploiting an unpatched vulnerability on the domain controller
    C. the vulnerability scanner reveals a flaw in SMB signing, which can be used to send a netcat recon tool to one of the servers on the network.
    D. the penetration tester is able to access the datacenter or network closet by using a lockpick

  • Question 402:

    An organization has implemented a two-step verification process to protect user access to data that is stored in the cloud. Each employee now uses an email address or mobile number to receive a code to access the data. Which of the following authentication methods did the organization implement?

    A. Token key
    B. Static code
    C. Push notification
    D. HOTP

  • Question 403:

    After successfully breaking into several networks and infecting multiple machines with malware, hackers contact the network owners, demanding payment to remove the infection and decrypt files. The hackers threaten to publicly release information about the breach if they are not paid. Which of the following BEST describes these attackers?

    A. Gray hat hackers
    B. Organized crime
    C. Insiders
    D. Hacktivists

  • Question 404:

    A security analyst is running a credential-based vulnerability scanner on a Windows host. The vulnerability scanner is using the protocol NetBIOS over TCP/IP to connect to various systems, However, the scan does not return any results. To address the issue, the analyst should ensure that which of the following default ports is open on systems?

    A. 135
    B. 137
    C. 3389
    D. 5060

  • Question 405:

    A new mobile application is being developed in-house. Security reviews did not pick up any major flaws, however vulnerability scanning results show fundamental issues at the very end of the project cycle. Which of the following security activities should also have been performed to discover vulnerabilities earlier in the lifecycle?

    A. Architecture review
    B. Risk assessment
    C. Protocol analysis
    D. Code review

  • Question 406:

    Which of the following is a deployment concept that can be used to ensure only the required OS access is exposed to software applications?

    A. Staging environment
    B. Sandboxing
    C. Secure baseline
    D. Trusted OS

  • Question 407:

    A company network is currently under attack. Although security controls are in place to stop the attack, the security administrator needs more information about the types of attacks being used. Which of the following network types would BEST help the administrator gather this information?

    A. DMZ
    B. Guest network
    C. Ad hoc
    D. Honeynet

  • Question 408:

    An intruder sniffs network traffic and captures a packet of internal network transactions that add funds to a game card. The intruder pushes the same packet multiple times across the network, which increments the funds on the game card. Which of the following should a security administrator implement to BEST protect against this type of attack?

    A. An IPS
    B. A WAF
    C. SSH
    D. An IPSec VPN

  • Question 409:

    Using an ROT13 cipher to protocol confidential information for unauthorized access is known as:

    A. Steganography
    B. Obfuscation
    C. Non repudiation
    D. diffusion

  • Question 410:

    A security administrator begins assessing a network with software that checks for available exploits against a known database using both credentials and external scripts A report will be compiled and used to confirm patching levels. This is an example of

    A. penetration testing
    B. fuzzing
    C. static code analysis
    D. vulnerability scanning

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-501 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.