SY0-601 Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :May 26, 2026

CompTIA SY0-601 Online Questions & Answers

  • Question 621:

    Which of the following function as preventive, detective, and deterrent controls to reduce the risk of physical theft? (Select TWO).

    A. Mantraps
    B. Security guards
    C. Video surveillance
    D. Fences
    E. Bollards
    F. Antivirus

  • Question 622:

    A security engineer at an offline government facility is concerned about the validity of an SSL certificate. The engineer wants to perform the fastest check with the least delay to determine if the certificate has been revoked.

    Which of the following would BEST these requirement?

    A. RA
    B. OCSP
    C. CRL
    D. CSR

  • Question 623:

    A security analyst is receiving numerous alerts reporting that the response time of an internet-facing application has been degraded However, the internal network performance was not degraded. Which of the following MOST likely explains this behavior?

    A. DNS poisoning
    B. MAC flooding
    C. DDoS attack
    D. ARP poisoning

  • Question 624:

    Security analysts notice a server login from a user who has been on vacation for two weeks

    The analysts confirm that the user did not log in to the system while on vacation After reviewing packet capture logs, the analysts notice the following:

    Which of the following occurred?

    A. A buffer overflow was exploited to gain unauthorized access
    B. The user's account was compromised, and an attacker changed the login credentials
    C. An attacker used a pass-the-hash attack to gain access
    D. An insider threat with username smithJA logged in to the account

  • Question 625:

    A security analyst needs to generate a server certificate to be used for 802.1X and secure RDP connections. The analyst is unsure what is required to perform the task and solicits help from a senior colleague. Which of the following is the FIRST step the senior colleague will most likely tell the analyst to perform to accomplish this task?

    A. Create an OCSP
    B. Generate a CSR
    C. Create a CRL
    D. Generate a .pfx file

  • Question 626:

    A security analyst needs to centrally manage credentials and permissions to the company's network devices. The following security requirements must be met:

    All actions performed by the network staff must be logged.

    Per-command permissions must be possible.

    The authentication server and the devices must communicate through TCP.

    Which of the following authentication protocols should the analyst choose?

    A. Kerberos
    B. CHAP
    C. TACACS+
    D. RADIUS

  • Question 627:

    A security incident has been resolved

    Which of the following BEST describes the importance of the final phase of the incident response plan?

    A. It examines and documents how well the team responded discovers what caused the incident, and determines how the incident can be avoided in the future
    B. It returns the affected systems back into production once systems have been fully patched, data restored and vulnerabilities addressed
    C. It identifies the incident and the scope of the breach how it affects the production environment, and the ingress point
    D. It contains the affected systems and disconnects them from the network, preventing further spread of the attack or breach

  • Question 628:

    A user recent an SMS on a mobile phone that asked for bank delays. Which of the following social-engineering techniques was used in this case?

    A. SPIM
    B. Vishing
    C. Spear phishing
    D. Smishing

  • Question 629:

    A penetration test revealed that several Linux servers were misconfigured at the file level and access was granted incorrectly. A security analyst is referencing the instructions in the incident response runbook for remediation information. Which of the following is the best command to use to resolve the issue?

    A. chmod
    B. cat
    C. grep
    D. dig

  • Question 630:

    The new Chief Information Security Officer at a company has asked the security team to implement stronger user account policies. The new policies require:

    1.

    Users to choose a password unique to their last ten passwords

    2.

    Users to not log in from certain high-risk countries

    Which of the following should the security team implement? (Select TWO).

    A. Password complexity
    B. Password history
    C. Geolocation
    D. Geofencing
    E. Geotagging
    F. Password reuse

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.