Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :May 09, 2025

CompTIA CompTIA Certifications SY0-601 Questions & Answers

  • Question 371:

    An engineer recently deployed a group of 100 web servers in a cloud environment. Per the security policy, all web-server ports except 443 should be disabled. Which of the following can be used to accomplish this task?

    A. Application allow list

    B. SWG

    C. Host-based firewall

    D. VPN

  • Question 372:

    A recent audit cited a risk involving numerous low-criticality vulnerabilities created by a web application using a third-party library. The development staff state there are still customers using the application even though it is end of life and it would be a substantial burden to update the application for compatibility with more secure libraries. Which of the following would be the MOST prudent course of action?

    A. Accept the risk if there is a clear road map for timely decommission

    B. Deny the risk due to the end-of-life status of the application.

    C. Use containerization to segment the application from other applications to eliminate the risk

    D. Outsource the application to a third-party developer group

  • Question 373:

    Which of the following control types is focused primarily on reducing risk before an incident occurs?

    A. Preventive

    B. Deterrent

    C. Corrective

    D. Detective

  • Question 374:

    Which of the following is the MOST effective control against zero-day vulnerabilities?

    A. Network segmentation

    B. Patch management

    C. Intrusion prevention system

    D. Multiple vulnerability scanners

  • Question 375:

    An organization wants to participate in threat intelligence information sharing with peer groups. Which of the following would MOST likely meet the organizations requirement?

    A. Perform OSINT investigations

    B. Subscribe to threat intelligence feeds

    C. Submit RFCs

    D. Implement a TAXII server

  • Question 376:

    An organization is planning lo open other data centers to sustain operations in the event of a natural disaster. Which of the following considerations would BEST support the organization's resiliency?

    A. Geographic dispersal

    B. Generator power

    C. Fire suppression

    D. Facility automation

  • Question 377:

    An organization has developed an application that needs a patch to fix a critical vulnerability In which of the following environments should the patch be deployed LAST?

    A. Test

    B. Staging

    C. Development

    D. Production

  • Question 378:

    An attacker was eavesdropping on a user who was shopping online. The attacker was able to spoof the IP address associated with the shopping site. Later, the user received an email regarding the credit card statement with unusual purchases. Which of the following attacks took place?

    A. On-path attack

    B. Protocol poisoning

    C. Domain hijacking

    D. Bluejacking

  • Question 379:

    As part of a security compliance assessment, an auditor performs automated vulnerability scans. In addition, which of the following should the auditor do to complete the assessment?

    A. User behavior analysis

    B. Packet captures

    C. Configuration reviews

    D. Log analysis

  • Question 380:

    A company is auditing the manner in which its European customers' personal information is handled Which of the following should the company consult?

    A. GDPR

    B. ISO

    C. NIST

    D. PCI DSS

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.