SY0-601 Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :May 26, 2026

CompTIA SY0-601 Online Questions & Answers

  • Question 591:

    Task: Configure the firewall (fill out the table) to allow these four rules:

    Only allow the Accounting computer to have HTTPS access to the Administrative server.

    Only allow the HR computer to be able to communicate with the Server 2 System over SCP.

    Allow the IT computer to have access to both the Administrative Server 1 and Administrative Server 2

    Correct Answer. Check the explanation below

  • Question 592:

    Recent changes to a company's BYOD policy require all personal mobile devices to use a two-factor authentication method that is not something you know or have. Which of the following will meet this requirement?

    A. Facial recognition
    B. Six-digit PIN
    C. PKI certificate
    D. Smart card

  • Question 593:

    An incident response technician collected a mobile device during an investigation. Which of the following should the technician do to maintain chain of custody?

    A. Document the collection and require a sign-off when possession changes.
    B. Lock the device in a safe or other secure location to prevent theft or alteration.
    C. Place the device in a Faraday cage to prevent corruption of the data.
    D. Record the collection in a blockchain-protected public ledger

  • Question 594:

    The CSIRT is reviewing the lessons learned from a recent incident. A worm was able to spread unhindered throughout the network and infect a large number of computers and servers.

    Which of the following recommendations would be BEST to mitigate the impacts of a similar incident in the future?

    A. Install a NIDS device at the boundary.
    B. Segment the network with firewalls.
    C. Update all antivirus signatures daily.
    D. Implement application blacklisting

  • Question 595:

    Which of the following is MOST likely to outline the roles and responsibilities of data controllers and data processors?

    A. SSAE SOC 2
    B. PCI DSS
    C. GDPR
    D. ISO 31000

  • Question 596:

    A security analyst notices several attacks are being blocked by the NIPS but does not see anything on the boundary firewall logs. The attack seems to have been thwarted Which of the following resiliency techniques was applied to the network to prevent this attack?

    A. NIC Teaming
    B. Port mirroring
    C. Defense in depth
    D. High availability
    E. Geographic dispersal

  • Question 597:

    Which of the following should be put in place when negotiating with a new vendor about the timeliness of the response to a significant outage or incident?

    A. MOU
    B. MTTR
    C. SLA
    D. NDA

  • Question 598:

    A network administrator would like to configure a site-to-site VPN utilizing iPSec. The administrator wants the tunnel to be established with data integrity encryption, authentication and anti- replay functions Which of the following should the administrator use when configuring the VPN?

    A. AH
    B. EDR
    C. ESP
    D. DNSSEC

  • Question 599:

    A security engineer is deploying a new wireless for a company. The company shares office space with multiple tenants. Which of the following should the engineer configured on the wireless network to ensure that confidential data is not exposed to unauthorized users?

    A. EAP
    B. TLS
    C. HTTPS
    D. AES

  • Question 600:

    DRAG DROP

    A data owner has been tasked with assigning proper data classifications and destruction methods for various types of data contained within the environment.

    Select and Place:

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.