SY0-601 Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :May 26, 2026

CompTIA SY0-601 Online Questions & Answers

  • Question 161:

    A security analyst has been tasked with creating a new WiFi network for the company. The requirements received by the analyst are as follows:

    1.

    Must be able to differentiate between users connected to WiFi

    2.

    The encryption keys need to change routinely without interrupting the users or forcing reauthentication

    3.

    Must be able to integrate with RADIUS

    4.

    Must not have any open SSIDs

    Which of the following options BEST accommodates these requirements?

    A. WPA2-Enterprise
    B. WPA3-PSK
    C. 802.11n
    D. WPS

  • Question 162:

    A growing company would like to enhance the ability of its security operations center to detect threats but reduce the amount of manual work required for the security analysts. Which of the following would best enable the reduction in manual work?

    A. SOAR
    B. SIEM
    C. MDM
    D. DLP

  • Question 163:

    Which of the following security design features can an development team to analyze the deletion eoting Of data sets the copy?

    A. Stored procedures
    B. Code reuse
    C. Version control
    D. Continunus

  • Question 164:

    An analyst is trying to identify insecure services that are running on the internal network. After performing a port scan, the analyst identifies that a server has some insecure services enabled on default ports. Which of the following BEST describes the services that are currently running and the secure alternatives for replacing them? (Choose three.)

    A. SFTP. FIPS
    B. SNMPv2, SNMPv3
    C. HTTP, HTTPS
    D. TFTP, FTP
    E. SNMPyt, SNMPy2
    F. Tenet, SSH
    G. TLS, SSL
    H. POP, IMAP
    I. Login, nogin

  • Question 165:

    The Chief Technology Officer of a local college would like visitors to utilize the school's WiFi but must be able to associate potential malicious activity to a specific person. Which of the following would BEST allow this objective to be met?

    A. Requiring all new, on-site visitors to configure their devices to use WPS
    B. Implementing a new SSID for every event hosted by the college that has visitors
    C. Creating a unique PSK for every visitor when they arrive at the reception area
    D. Deploying a captive portal to capture visitors' MAC addresses and names

  • Question 166:

    During a security incident, the security operations team identified sustained network traffic from a malicious IP address: 10.1.4.9. A security analyst is creating an inbound firewall rule to block the IP address from accessing the organization's network. Which of the following fulfills this request?

    A. access-list inbound deny ip source 0.0.0.0/0 destination 10.1.4.9/32
    B. access-list inbound deny ip source 10.1.4.9/32 destination 0.0.0.0/0
    C. access-list inbound permit ip source 10.1.4.9/32 destination 0.0.0.0/0
    D. access-list inbound permit ip source 0.0.0.0/0 destination 10.1.4.9/32

  • Question 167:

    During a recent incident an external attacker was able to exploit an SMB vulnerability over the internet. Which of the following action items should a security analyst perform FIRST to prevent this from occurring again?

    A. Check for any recent SMB CVEs
    B. Install AV on the affected server
    C. Block unneeded TCP 445 connections
    D. Deploy a NIDS in the affected subnet

  • Question 168:

    A university with remote campuses, which all use different service providers, loses Internet connectivity across all locations. After a few minutes, Internet and VoIP services are restored, only to go offline again at random intervals, typically within four minutes of services being restored. Outages continue throughout the day, impacting all inbound and outbound connections and services. Services that are limited to the local LAN or WiFi network are not impacted, but all WAN and VoIP services are affected.

    Later that day, the edge-router manufacturer releases a CVE outlining the ability of an attacker to exploit the SIP protocol handling on devices, leading to resource exhaustion and system reloads.

    Which of the following BEST describe this type of attack? (Choose two.)

    A. DoS
    B. SSL stripping
    C. Memory leak
    D. Race condition
    E. Shimming
    F. Refactoring

  • Question 169:

    A security team discovered a large number of company-issued devices with non-work- related software installed. Which of the following policies would most likely contain language that would prohibit this activity?

    A. NDA
    B. BPA
    C. AUP D. SLA

  • Question 170:

    A major political party experienced a server breach. The hacker then publicly posted stolen internal communications concerning campaign strategies to give the opposition party an advantage. Which of the following BEST describes these threat actors?

    A. Semi-authorized hackers
    B. State actors
    C. Script kiddies
    D. Advanced persistent threats

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.