SY0-501 Exam Details

  • Exam Code
    :SY0-501
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1423 Q&As
  • Last Updated
    :Sep 04, 2023

CompTIA SY0-501 Online Questions & Answers

  • Question 431:

    A Chief Executive Officer (CEO) is staying at a hotel during a business trip. The hotel's wireless network does not show a lock symbol. Which of the following precautions should the CEO take? (Choose two.)

    A. Change the connection type to WPA2
    B. Change TKIP to CCMP
    C. Use a VPN
    D. Tether to a mobile phone
    E. Create a tunnel connection with EAP-TTLS

  • Question 432:

    In highly secure environments where the risk of malicious actors attempting to steal data is high, which of the following is the BEST reason to deploy Faraday cages?

    A. To provide emanation control to prevent credential harvesting
    B. To minimize signal attenuation over distances to maximize signal strength
    C. To minimize external RF interference with embedded processors
    D. To protect the integrity of audit logs from malicious alteration

  • Question 433:

    A company is deploying smartphones for its mobile salesforce. These devices are for personal and business use but are owned by the company. Sales personnel will save new customer data via a custom application developed for the company. This application will integrate with the contact information stored in the smartphones and will populate new customer records onto it. The customer application's data is encrypted at rest, and the application's connection to the back office system is considered secure. The Chief Information Security Officer (CISO) has concerns that customer contact information may be accidentally leaked due to the limited security capabilities of the devices and the planned controls. Which of the following will be the MOST efficient security control to implement to lower this risk?

    A. Implement a mobile data loss agent on the devices to prevent any user manipulation with the contact information.
    B. Restrict screen capture features on the devices when using the custom application and the contact information.
    C. Restrict contact information storage dataflow so it is only shared with the customer application.
    D. Require complex passwords for authentication when accessing the contact information.

  • Question 434:

    A company has a data classification system with definitions for "Private" and "Public". The company's security policy outlines how data should be protected based on type. The company recently added the data type "Proprietary". Which of the following is the MOST likely reason the company added this data type?

    A. Reduced cost
    B. More searchable data
    C. Better data classification
    D. Expanded authority of the privacy officer

  • Question 435:

    The computer resource center issued smartphones to all first-level and above managers. The managers have the ability to install mobile tools. Which of the following tools should be implemented to control the types of tools the managers install?

    A. Download manager
    B. Content manager
    C. Segmentation manager
    D. Application manager

  • Question 436:

    During a risk assessment, results show that a fire in one of the company's datacenters could cost up to $20 million in equipment damages and lost revenue. As a result, the company insures the datacenter for up to $20 million in damages for the cost of $30,000 a year. Which of the following risk response techniques has the company chosen?

    A. Transference
    B. Avoidance
    C. Mitigation
    D. Acceptance

  • Question 437:

    A technician needs to prevent data loss in a laboratory. The laboratory is not connected to any external networks. Which of the following methods would BEST prevent the exfiltration of data? (Select TWO).

    A. VPN
    B. Drive encryption
    C. Network firewall
    D. File-level encryption
    E. USB blocker
    F. MFA

  • Question 438:

    Which of the following concepts ensure ACL rules on a directory are functioning as expected? (Select TWO).

    A. Accounting
    B. Authentication
    C. Auditing
    D. Authorization
    E. Non-repudiation

  • Question 439:

    An organization is providing employees on the shop floor with computers that will log their time based on when they sign on and off the network. Which of the following account types should the employees receive?

    A. Shared account
    B. Privileged account
    C. User account
    D. Service account

  • Question 440:

    Which of the following physical security controls is MOST effective when trying to prevent tailgating?

    A. CCTV
    B. Mantrap
    C. Biometrics
    D. RFID badge
    E. Motion detection

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-501 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.