Which of the following is a physical security control that ensures onty the authorized user is present when gaining access to a secured area?
A. A biometric scannerWhich of the following threat vectors would appear to be the most legitimate when used by a malicious actor to impersonate a company?
A. Phone callThe local administrator account for a company's VPN appliance was unexpectedly used to log in to the remote management interface. Which of the following would have prevented this from happening?
A. Using least privilegeAn employee finds a USB flash drive labeled "Salary Info" in an office parking lot. The employee picks up the USB flash drive, goes into the office, and plugs it into a laptop. Later, a technician inspects the laptop and realizes it has been compromised by malware. Which of the following types of social engineering attacks has occurred?
A. SmishingAn audit report showed that a former employee saved the following files to an external USB drive before the employee's termination date:
? annual_tax_form.pdf ? encrypted_passwords.db ? team_picture.jpg ? contact_list.db ? human_resources.txt
Which of the following could the former employee do to potentially compromise corporate credentials?
A. Perform an offline brute-force attackWhich of the following is the phase in the incident response process when a security analyst reviews roles and responsibilities?
A. PreparationA junior security analyst is reviewing web server logs and identifies the following pattern in the log file:
http://comptia.org/../../../etc/passwd
Which ol the following types of attacks is being attempted and how can it be mitigated?
A. XSS. mplement a SIEMDevelopment team members set up multiple application environments so they can develop, test, and deploy code in a secure and reliable manner. One of the environments is configured with real data that has been obfuscated so the team can adequately assess how the code will work in production. Which of the following environments is set up?
A. Quality assuranceA security analyst is reviewing a secure website that is generating TLS certificate errors. The analyst determines that the browser is unable to receive a response from the OCSP for the certificate. Which of the following actions would most likely resolve the issue?
A. Run a traceroute on the OCSP domain to find where the domain is failing.Which of the following best describes why a company would erase a newly purchased device and install its own image with an operating system and applications?
A. Installing a new operating system thoroughly tests the equipmentNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.