Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Security+
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :Apr 24, 2024

CompTIA CompTIA Security+ SY0-601 Questions & Answers

  • Question 1:

    The website http://companywebsite.com requires users to provide personal information, including security question responses, for registration. Which of the following would MOST likely cause a data breach?

    A. Lack of input validation

    B. Open permissions

    C. Unsecure protocol

    D. Missing patches

  • Question 2:

    An analyst is trying to identify insecure services that are running on the internal network. After performing a port scan, the analyst identifies that a server has some insecure services enabled on default ports. Which of the following BEST describes the services that are currently running and the secure alternatives for replacing them? (Choose three.)

    A. SFTP, FTPS

    B. SNMPv2, SNMPv3

    C. HTTP, HTTPS

    D. TEIP, FIP

    E. SNMPv1, SNMPv2

    F. Telnet, SSH

    G. TLS, SSL

    H. POP, IMAP

    I. Login, rlogin

  • Question 3:

    Which of the following often operates in a client-server architecture to act as a service repository, providing enterprise consumers access to structured threat intelligence data?

    A. STIX

    B. CIRT

    C. OSINT

    D. TAXII

  • Question 4:

    The new Chief Executive Officer (CEO) of a large company has announced a partnership with a vendor that will provide multiple collaboration applications t make remote work easier. The company has a geographically dispersed staff located in numerous remote offices in different countries. The company's IT administrators are concerned about network traffic and load if all users simultaneously download the application.

    Which of the following would work BEST to allow each geographic region to download the software without negatively impacting the corporate network?

    A. Update the host IDS rules.

    B. Enable application whitelisting.

    C. Modify the corporate firewall rules.

    D. Deploy all applications simultaneously.

  • Question 5:

    A Chief Executive Officer (CEO) is dissatisfied with the level of service from the company's new service provider. The service provider is preventing the CEO from sending email from a work account to a personal account. Which of the following types of service providers is being used?

    A. Telecommunications service provider

    B. Cloud service provider

    C. Master managed service provider

    D. Managed security service provider

  • Question 6:

    A security analyst needs to perform periodic vulnerability scans on production systems. Which of the following scan types would produce the BEST vulnerability scan report?

    A. Port

    B. Intrusive

    C. Host discovery

    D. Credentialed

  • Question 7:

    To further secure a company's email system, an administrator is adding public keys to DNS records in the company's domain Which of the following is being used?

    A. PFS

    B. SPF

    C. DMARC

    D. DNSSEC

  • Question 8:

    Which of the following distributes data among nodes, making it more difficult to manipulate the data while also minimizing downtime?

    A. MSSP

    B. Public cloud

    C. Hybrid cloud

    D. Fog computing

  • Question 9:

    A company uses specially configured workstations for any work that requires administrator privileges to its Tier 0 and Tier 1 systems. The company follows a strict process to harden systems immediately upon delivery. Even with these strict security measures in place, an incident occurred from one of the workstations. The root cause appears to be that the SoC was tampered with or replaced. Which of the following MOST likely occurred?

    A. Fileless malware

    B. A downgrade attack

    C. A supply-chain attack

    D. A logic bomb

    E. Misconfigured BIOS

  • Question 10:

    A network administrator at a large organization is reviewing methods to improve the security of the wired LAN. Any security improvement must be centrally managed and allow corporate-owned devices to have access to the intranet but limit others to Internet access only. Which of the following should the administrator recommend?

    A. 802.1X utilizing the current PKI infrastructure

    B. SSO to authenticate corporate users

    C. MAC address filtering with ACLS on the router

    D. PAM for user account management

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.