SY0-601 Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :May 26, 2026

CompTIA SY0-601 Online Questions & Answers

  • Question 1151:

    A security operations center wants to implement a solution that can execute files to test for malicious activity. The solution should provide a report of the files' activity against known threats. Which of the following should the security operations center implement?

    A. Harvester
    B. Nessus
    C. Cuckoo
    D. Sniper

  • Question 1152:

    An enterprise has hired an outside security firm to facilitate penetration testing on its network and applications. The firm has agreed to pay for each vulnerability that is discovered. Which of the following BEST represents the type of testing that is being used?

    A. White-box
    B. Red-team
    C. Bug bounty
    D. Gray-box
    E. Black-box

  • Question 1153:

    Which of the following incident response steps occurs before containment?

    A. Eradication
    B. Recovery
    C. Lessons learned
    D. Identification

  • Question 1154:

    To secure an application after a large data breach, an e-commerce site will be resetting all users' credentials. Which of the following will BEST ensure the site's users are not compromised after the reset?

    A. A password reuse policy
    B. Account lockout after three failed attempts
    C. Encrypted credentials in transit
    D. A geofencing policy based on login history

  • Question 1155:

    A security analyst is investigating a report from a penetration test. During the penetration test, consultants were able to download sensitive data from a back-end server. The back-end server was exposing an API that should have only been available from the company's mobile application. After reviewing the back-end server logs, the security analyst finds the following entries:

    Which of the following is the most likely cause of the security control bypass?

    A. IP address allow list
    B. User-agent spoofing
    C. WAF bypass
    D. Referrer manipulation

  • Question 1156:

    Which of the following secure application development concepts aims to block verbose error messages from being shown in a user's interface?

    A. OWASP
    B. Obfuscation/camouflage
    C. Test environment
    D. Prevent of information exposure

  • Question 1157:

    Which of the following is required in order for an IDS and a WAF to be effective on HTTPS traffic?

    A. Hashing
    B. DNS sinkhole
    C. TLS inspection
    D. Data masking

  • Question 1158:

    A network administrator is concerned about users being exposed to malicious content when accessing company cloud applications. The administrator wants to be able to block access to sites based on the AUP. The users must also be protected because many of them work from home or at remote locations, providing on- site customer support. Which of the following should the administrator employ to meet these criteria?

    A. Implement NAC.
    B. Implement an SWG.
    C. Implement a URL filter.
    D. Implement an MDM.

  • Question 1159:

    A company's help desk received several AV alerts indicating Mimikatz attempted to run on the remote systems. Several users also reported that the new company flash drives they picked up in the break room only have 512KB of storage. Which of the following is MOST likely the cause?

    A. The GPO prevents the use of flash drives, which triggers a false positive AV indication and restricts the drives to only 512KB of storage.
    B. The new flash drives need a driver that is being blocked by the AV software because the flash drives are not on the application's allow list, temporarily restricting the drives to 512KB of storage.
    C. The new flash drives are incorrectly partitioned, and the systems are automatically trying to use an unapproved application to repartition the drives.
    D. The GPO blocking the flash drives is being bypassed by a malicious flash drive that is attempting to harvest plaintext credentials from memory.

  • Question 1160:

    Which of the following is an example of transference of risk?

    A. Purchasing insurance
    B. Patching vulnerable servers
    C. Retiring outdated applications
    D. Application owner risk sign-off

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.