Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :Jul 04, 2025

CompTIA CompTIA Certifications SY0-601 Questions & Answers

  • Question 691:

    he SIEM at an organization has detected suspicious traffic coming from a workstation in its internal network. An analyst in the SOC investigates the workstation and discovers malware that is associated with a botnet is installed on the device. A review of the logs on the workstation reveals that the privileges of the local account were escalated to a local administrator. To which of the following groups should the analyst report this real-world event?

    A. The NOC team

    B. The vulnerability management team

    C. The CIRT

    D. The red team

  • Question 692:

    Which of the following policies would help an organization identify and mitigate potential single points of failure in the company's IT/security operations?

    A. Least privilege

    B. Awareness training

    C. Separation of duties

    D. Mandatory vacation

  • Question 693:

    A security administrator suspects an employee has been emailing proprietary information to a competitor.

    Company policy requires the administrator to capture an exact copy of the employee's hard disk. Which of the following should the administrator use?

    A. dd

    B. chmod

    C. dnsenum

    D. logger

  • Question 694:

    A network manager is concerned that business may be negatively impacted if the firewall in its datacenter goes offline. The manager would like to implement a high availability pair to:

    A. ned that business may be negatecrease the mean time between failures.

    B. remove the single point of failure.

    C. cut down the mean time to repair,

    D. reduce the recovery time objective.

  • Question 695:

    A recent audit uncovered a key finding regarding the use of a specific encryption standard in a web application that is used to communicate with business customers. Due to the technical limitations of its customers the company is unable to upgrade the encryption standard. Which of the following types of controls should be used to reduce the risk created by this scenario?

    A. Physical

    B. Detective

    C. Preventive

    D. Compensating

  • Question 696:

    A nuclear plant was the victim of a recent attack, and all the networks were air gapped. A subsequent investigation revealed a worm as the source of the issue. Which of the following BEST explains what happened?

    A. A malicious USB was introduced by an unsuspecting employee.

    B. The ICS firmware was outdated

    C. A local machine has a RAT installed.

    D. The HVAC was connected to the maintenance vendor.

  • Question 697:

    While reviewing the wireless router, a systems administrator of a small business determines someone is spoofing the MAC address of an authorized device. Given the table below:

    Which of the following should be the administrator's NEXT step to detect if there is a rague system without impacting availability?

    A. Conduct a ping sweep.

    B. Physically check each system.

    C. Deny Internet access to the "UNKNOWN" hostname.

    D. Apply MAC filtering.

  • Question 698:

    Which of the following ISO standards is certified for privacy?

    A. ISO 9001

    B. ISO 27002

    C. ISO 27701

    D. ISO 31000

  • Question 699:

    A user enters a password to log in to a workstation and is then prompted to enter an authentication code. Which of the following MFA factors or attributes are being utilized in the authentication process? (Select TWO).

    A. Something you know

    B. Something you have

    C. Somewhere you are

    D. Someone you are

    E. Something you are

    F. Something you can do

  • Question 700:

    Which of the following types of controls is a turnstile?

    A. Physical

    B. Detective

    C. Corrective

    D. Technical

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.