SY0-601 Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :May 26, 2026

CompTIA SY0-601 Online Questions & Answers

  • Question 981:

    A security analyst is using a recently released security advisory to review historical logs, looking for the specific activity that was outlined in the advisory. Which of the following is the analyst doing?

    A. A packet capture
    B. A user behavior analysis
    C. Threat hunting
    D. Credentialed vulnerability scanning

  • Question 982:

    The SIEM at an organization has detected suspicious traffic coming from a workstation in its internal network. An analyst in the SOC investigates the workstation and discovers malware that is associated with a botnet is installed on the

    device.

    A review of the logs on the workstation reveals that the privileges of the local account were escalated to a local administrator.

    To which of the following groups should the analyst report this real-world event?

    A. The NOC team
    B. The vulnerability management team
    C. The CIRT
    D. The read team

  • Question 983:

    A user forwarded a suspicious email to the security team, Upon investigation, a malicious URL was discovered. Which of the following should be done FIRST to prevent other users from accessing the malicious URL?

    A. Configure the web content filter for the web address.
    B. Report the website to threat intelligence partners
    C. Set me SIEM to alert for any activity to the web address.
    D. Send out a corporate communication to warn all users Of the malicious email.

  • Question 984:

    An engineer is configuring AAA authentication on a Cisco MDS 9000 Series Switch. The LDAP server is located under the IP 10.10.2.2. The data sent to the LDAP server should be encrypted. Which command should be used to meet these requirements?

    A. Idap-server 10.10.2.2 key SSL_KEY
    B. Idap-server host 10.10.2.2 key SSL_KEY
    C. Idap-server 10.10.2.2 port 443
    D. Idap-server host 10.10.2.2 enable-ssl

  • Question 985:

    A network engineer has been asked to investigate why several wireless barcode scanners and wireless computers in a warehouse have intermittent connectivity to the shipping server. The barcode scanners and computers are all on forklift trucks and move around the warehouse during their regular use. Which of the following should the engineer do to determine the issue? (Choose two.)

    A. Perform a site survey
    B. Deploy an FTK Imager
    C. Create a heat map
    D. Scan for rogue access points
    E. Upgrade the security protocols
    F. Install a captive portal

  • Question 986:

    During an engagement, penetration testers left USB keys that contained specially crafted malware in the company's parking lot. A couple days later, the malware contacted the command-and-control server, giving the penetration testers unauthorized access to the company endpoints. Which of the following will most likely be a recommendation in the engagement report?

    A. Conduct an awareness campaign on the usage of removable media.
    B. Issue a user guidance program focused on vishing campaigns.
    C. Implement more complex password management practices.
    D. Establish a procedure on identifying and reporting suspicious messages.

  • Question 987:

    While reviewing the /etc/shadow file, a security administrator notices files with the same values. Which of the following attacks should the administrator be concerned about?

    A. Plaintext
    B. Birthdat
    C. Brute-force
    D. Rainbow table

  • Question 988:

    An analyst has determined that a server was not patched and an external actor exfiltrated data on port 139. Which of the following sources should the analyst review to BEST ascertain how the incident could have been prevented?

    A. The vulnerability scan output
    B. The security logs
    C. The baseline report
    D. The correlation of events

  • Question 989:

    A company was recently breached. Part of the company's new cybersecurity strategy is to centralize the logs from all security devices. Which of the following components forwards the logs to a central source?

    A. Log enrichment
    B. Log queue
    C. Log parser
    D. Log collector

  • Question 990:

    Which of the following supplies non-repudiation during a forensics investigation?

    A. Dumping volatile memory contents first
    B. Duplicating a drive with dd
    C. Using a SHA-2 signature of a drive image
    D. Logging everyone in contact with evidence
    E. Encrypting sensitive data

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.