SY0-601 Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :May 26, 2026

CompTIA SY0-601 Online Questions & Answers

  • Question 771:

    An end user reports a computer has been acting slower than normal for a few weeks. During an investigation, an analyst determines the system is sending the user's email address and a ten-digit number to an IP address once a day. The only recent log entry regarding the user's computer is the following:

    Which of the following is the MOST likely cause of the issue?

    A. The end user purchased and installed a PUP from a web browser
    B. A bot on the computer is brute forcing passwords against a website
    C. A hacker is attempting to exfiltrate sensitive data
    D. Ransomware is communicating with a command-and-control server

  • Question 772:

    Which of the following would be BEST for a technician to review to determine the total risk an organization can bear when assessing a "cloud-first" adoption strategy?

    A. Risk matrix
    B. Risk tolerance
    C. Risk register
    D. Risk appetite

  • Question 773:

    DRAG DROP

    A security engineer is setting up passwordless authentication for the first time.

    INSTRUCTIONS

    Use the minimum set of commands to set this up and verify that it works. Commands cannot be reused.

    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

    Select and Place:

  • Question 774:

    A security researcher has alerted an organization that its sensitive user data was found for sale on a website. Which of the following should the organization use to inform the affected parties?

    A. An incident response plan
    B. A communications plan
    C. A business continuity plan
    D. A disaster recovery plan

  • Question 775:

    Which of the following in a forensic investigation should be priorities based on the order of volatility? (Select TWO).

    A. Page files
    B. Event logs
    C. RAM
    D. Cache
    E. Stored files
    F. HDD

  • Question 776:

    Which of the following in the incident response process is the BEST approach to improve the speed of the identification phase?

    A. Activate verbose logging in all critical assets.
    B. Tune monitoring in order to reduce false positive rates.
    C. Redirect all events to multiple syslog servers.
    D. Increase the number of sensors present on the environment.

  • Question 777:

    Adding a value to the end of a password to create a different password hash is called:

    A. salting.
    B. key stretching.
    C. steganography.
    D. MD5 checksum.

  • Question 778:

    Accompany deployed a WiFi access point in a public area and wants to harden the configuration to make it more secure. After performing an assessment, an analyst identifies that the access point is configured to use WPA3, AES, WPS, and RADIUS. Which of the following should the analyst disable to enhance the access point security?

    A. WPA3
    B. AES
    C. RADIUS
    D. WPS

  • Question 779:

    A large bank with two geographically dispersed data centers is concerned about major power disruptions at both locations. Every day each location experiences very brief outages that last for a few seconds. However, during the summer a high risk of intentional brownouts that last up to an hour exists, particularly at one of the locations near an industrial smelter.

    Which of the following is the BEST solution to reduce the risk of data loss?

    A. Dual supply
    B. Generator
    C. UPS
    D. POU
    E. Daily backups

  • Question 780:

    A security analyst is investigating what appears to be unauthorized access to a corporate web application. The security analyst reviews the web server logs and finds the flowing entries:

    Which of the following password attacks is taking place?

    A. Dictionary
    B. Brute-force
    C. Rainbow table
    D. Spraying

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.