Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :May 17, 2025

CompTIA CompTIA Certifications SY0-601 Questions & Answers

  • Question 921:

    Which of the following is the BEST reason to maintain a functional and effective asset management policy that aids in ensuring the security of an organization?

    A. To provide data to quantity risk based on the organization's systems.

    B. To keep all software and hardware fully patched for known vulnerabilities

    C. To only allow approved, organization-owned devices onto the business network

    D. To standardize by selecting one laptop model for all users in the organization

  • Question 922:

    An organization regularly scans its infrastructure for missing security patches but is concerned about hackers gaining access to the scanner's account. Which of the following would be BEST to minimize this risk?

    A. Require a complex, eight-character password that is updated every 90 days.

    B. Perform only non-intrusive scans of workstations.

    C. Use non-credentialed scans against high-risk servers.

    D. Log and alert on unusual scanner account logon times.

  • Question 923:

    Several large orders of merchandise were recently purchased on an e-commerce company's website. The totals for each of the transactions were negative values, resulting in credits on the customers' accounts. Which of the following should be implemented to prevent similar situations in the future?

    A. Ensure input validation is in place to prevent the use of invalid characters and values.

    B. Calculate all possible values to be added together and ensure the use of the proper integer in the code.

    C. Configure the web application firewall to look for and block session replay attacks.

    D. Make sure transactions that are submitted within very short time periods are prevented from being processed.

  • Question 924:

    After installing a Windows server, a cybersecurity administrator needs to harden it, following security best practices. Which of the following will achieve the administrator's goal? (Select TWO).

    A. Disabling guest accounts

    B. Disabling service accounts

    C. Enabling network sharing

    D. Disabling NetBIOS over TCP/IP

    E. Storing LAN manager hash values

    F. Enabling NTLM

  • Question 925:

    The concept of connecting a user account across the systems of multiple enterprises is BEST known as:

    A. federation.

    B. a remote access policy.

    C. multifactor authentication.

    D. single sign-on.

  • Question 926:

    An analyst is trying to identify insecure services that are running on the internal network. After performing a port scan, the analyst identifies that a server has some insecure services enabled on default ports. Which of the following BEST describes the services that are currently running and the secure alternatives for replacing them? (Choose three.)

    A. SFTP. FIPS

    B. SNMPv2, SNMPv3

    C. HTTP, HTTPS

    D. TFTP, FTP

    E. SNMPyt, SNMPy2

    F. Tenet, SSH

    G. TLS, SSL

    H. POP, IMAP

    I. Login, nogin

  • Question 927:

    A security analyst is concerned about traffic initiated to the dark web form the corporate LAN. Which of the following networks should the analyst monitor?

    A. SFTP

    B. AS

    C. Tor

    D. LoC

  • Question 928:

    Accompany deployed a WiFi access point in a public area and wants to harden the configuration to make it more secure. After performing an assessment, an analyst identifies that the access point is configured to use WPA3, AES, WPS, and RADIUS. Which of the following should the analyst disable to enhance the access point security?

    A. WPA3

    B. AES

    C. RADIUS

    D. WPS

  • Question 929:

    The human resources department of a large online retailer has received multiple customer complaints about the rudeness of the automated chatbots it uses to interface and assist online shoppers. The system, which continuously learns and adapts, was working fine when it was installed a few months ago. Which of the following BEST describes the method being used to exploit the system?

    A. Baseline modification

    B. A fileless virus

    C. Tainted training data

    D. Cryptographic manipulation

  • Question 930:

    A local coffee shop runs a small WiFi hotspot for its customers that utilizes WPA2-PSK. The coffee shop would like to stay current with security trends and wants to implement WPA3 to make its WiFi even more secure. Which of the following technologies should the coffee shop use in place of PSK?

    A. WEP

    B. MSCHAP

    C. WPS

    D. SAE

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.