SY0-601 Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :May 26, 2026

CompTIA SY0-601 Online Questions & Answers

  • Question 821:

    A multinational organization that offers web-based services has datacenters that are located only in the United States; however, a large number of its customers are in Australia, Europe, and China. Payments for services are managed by a third party in the United Kingdom that specializes in payment gateways. The management team is concerned the organization is not compliant with privacy laws that cover some of its customers. Which of the following frameworks should the management team follow?

    A. Payment Card Industry Data Security Standard
    B. Cloud Security Alliance Best Practices
    C. ISO/IEC 27032 Cybersecurity Guidelines
    D. General Data Protection Regulation

  • Question 822:

    The new Chief Executive Officer (CEO) of a large company has announced a partnership with a vendor that will provide multiple collaboration applications t make remote work easier. The company has a geographically dispersed staff located in numerous remote offices in different countries. The company's IT administrators are concerned about network traffic and load if all users simultaneously download the application.

    Which of the following would work BEST to allow each geographic region to download the software without negatively impacting the corporate network?

    A. Update the host IDS rules.
    B. Enable application whitelisting.
    C. Modify the corporate firewall rules.
    D. Deploy all applications simultaneously.

  • Question 823:

    A company's end users are reporting that they are unable to reach external websites. After reviewing the performance data for the DNS severs, the analyst discovers that the CPU, disk, and memory usage are minimal, but the network interface is flooded with inbound traffic. Network logs show only a small number of DNS queries sent to this server. Which of the following best describes what the security analyst is seeing?

    A. Concurrent session usage
    B. Secure DNS cryptographic downgrade
    C. On-path resource consumption
    D. Reflected denial of service

  • Question 824:

    An organization maintains several environments in which patches are developed and tested before deployed to an operation status. Which of the following is the environment in which patches will be deployed just prior to being put into an operational status?

    A. Development
    B. Test
    C. Production
    D. Staging

  • Question 825:

    A security analyst is assessing several company firewalls. Which of the following tools would the analyst most likely use to generate custom packets to use during the assessment?

    A. hping
    B. Wireshark
    C. PowerShell
    D. netstat

  • Question 826:

    During a security incident investigation, an analyst consults the company's SIEM and sees an event concerning high traffic to a known, malicious command-and-control server. The analyst would like to determine the number of company workstations that may be impacted by this issue. Which of the following can provide the information?

    A. WAF logs
    B. DNS logs
    C. System logs
    D. Application logs

  • Question 827:

    DRAG DROP

    An attack has occurred against a company.

    INSTRUCTIONS

    You have been tasked to do the following:

    Identify the type of attack that is occurring on the network by clicking on the attacker's tablet and reviewing the output. (Answer Area 1)

    Identify which compensating controls should be implemented on the assets, in order to reduce the effectiveness of future attacks by dragging them to the correct server. (Answer area 2) All objects will be used, but not all placeholders may be filled. Objects may only be used once. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

    Select and Place:

  • Question 828:

    Which of the following control types is focused primarily on reducing risk before an incident occurs?

    A. Preventive
    B. Deterrent
    C. Corrective
    D. Detective

  • Question 829:

    An engineer needs to deploy a security measure to identify and prevent data tampering within the enterprise. Which of the following will accomplish this goal?

    A. Antivirus
    B. IPS.
    C. FTP
    D. FIM

  • Question 830:

    A database administrator wants to grant access to an application that will be reading and writing data to a database. The database is shared by other applications also used by the finance department Which of the following account types Is MOST appropriate for this purpose?

    A. Service
    B. Shared
    C. eneric
    D. Admin

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.