SY0-601 Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :May 26, 2026

CompTIA SY0-601 Online Questions & Answers

  • Question 1211:

    Which of the following often operates in a client-server architecture to act as a service repository, providing enterprise consumers access to structured threat intelligence data?

    A. STIX
    B. CIRT
    C. OSINT
    D. TAXII

  • Question 1212:

    A recent phishing campaign resulted in several compromised user accounts. The security incident response team has been tasked with reducing the manual labor of filtering through all the phishing emails as they arrive and blocking the sender's email address, along with other time-consuming mitigation actions. Which of the following can be configured to streamline those tasks?

    A. SOAR playbook
    B. MOM policy
    C. Firewall rules
    D. URL filter
    E. SIEM data collection

  • Question 1213:

    A network engineer receives a call regarding multiple LAN-connected devices that are on the same switch. The devices have suddenly been experiencing speed and latency issues while connecting to network resources. The engineer enters the command show mac address-table and reviews the following output

    Which of the following best describes the attack that is currently in progress?

    A. MAC flooding
    B. Evil twin
    C. ARP poisoning
    D. DHCP spoofing

  • Question 1214:

    Which of the following would MOST likely support the integrity of a voting machine?

    A. Asymmetric encryption
    B. Blockchain
    C. Transport Layer Security
    D. Perfect forward secrecy

  • Question 1215:

    After a recent security breach a security analyst reports that several admimstratrve usemames and passwords are being sent via cieartext across the network to access network devices over prot 23 Which of the following should be implemented so all credentials sent over the network are encrypted when remotely accessing and configunng network devices?

    A. SSH
    B. SNMPv3
    C. SFTP
    D. Telnet
    E. FTP

  • Question 1216:

    A company reduced the area utilized in its datacenter by creating virtual networking through automation and by creating provisioning routes and rules through scripting. Which of the following does this example describe?

    A. laC
    B. MSSP
    C. Containers
    D. SaaS

  • Question 1217:

    A hospital's administration is concerned about a potential loss of patient data that is stored on tablets. A security administrator needs to implement controls to alert the SOC any time the devices are near exits. Which of the following would BEST achieve this objective?

    A. Geotargeting
    B. Geolocation
    C. Geotagging
    D. Geofencing

  • Question 1218:

    Which of the following is the BEST example of a cost-effective physical control to enforce a USB removable media restriction policy?

    A. Putting security/antitamper tape over USB ports, logging the port numbers, and regularly inspecting the ports
    B. Implementing a GPO that will restrict access to authorized USB removable media and regularly verifying that it is enforced
    C. Placing systems into locked key-controlled containers with no access to the USB ports
    D. Installing an endpoint agent to detect connectivity of USB and removable media

  • Question 1219:

    Which of the following is a benefit of including a risk management framework into an organization's security approach?

    A. It defines expected service levels from participating supply chain partners to ensure system outages are remediated in a timely manner
    B. It identifies specific vendor products that have been tested and approved for use in a secure environment.
    C. It provides legal assurances and remedies in the event a data breach occurs
    D. It incorporates control, development, policy, and management activities into IT operations.

  • Question 1220:

    Which of the following technical controls is BEST suited for the detection and prevention of buffer overflows on hosts?

    A. DLP
    B. HIDS
    C. EDR
    D. NIPS

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.