Exam Details

  • Exam Code
    :SY0-601
  • Exam Name
    :CompTIA Security+
  • Certification
    :CompTIA Security+
  • Vendor
    :CompTIA
  • Total Questions
    :1334 Q&As
  • Last Updated
    :Dec 12, 2024

CompTIA CompTIA Security+ SY0-601 Questions & Answers

  • Question 1:

    A systems administrator is auditing all company servers to ensure they meet the minimum security baseline. While auditing a Linux server, the systems administrator observes the /etc/shadow file has permissions beyond the baseline recommendation.

    Which of the following commands should the systems administrator use to resolve this issue?

    A. chmod

    B. grep

    C. dd

    D. passwd

  • Question 2:

    A company wants to implement MFA. Which of the following enables the additional factor while using a smart card?

    A. PIN

    B. Hardware token

    C. User ID

    D. SMS

  • Question 3:

    An enterprise has hired an outside security firm to conduct penetration testing on its network and applications. The firm has been given all the developer's documentation about the internal architecture. Which of the following best represents the type of testing that will occur?

    A. Bug bounty

    B. White-box

    C. Black-box

    D. Gray-box

  • Question 4:

    A new vulnerability enables a type of malware that allows the unauthorized movement of data from a system.

    Which of the following would detect this behavior?

    A. Implementing encryption

    B. Monitoring outbound traffic

    C. Using default settings

    D. Closing all open ports

  • Question 5:

    In which of the following scenarios is tokenization the best privacy technique to use?

    A. Providing pseudo-anonymization for social media user accounts

    B. Serving as a second factor for authentication requests

    C. Enabling established customers to safely store credit card information

    D. Masking personal information inside databases by segmenting data

  • Question 6:

    A security administrator received an alert for a user account with the following log activity:

    Which of the following best describes the trigger for the alert the administrator received?

    A. Number of failed log-in attempts

    B. Geolocation

    C. Impossible travel time

    D. Time-based log-in attempt

  • Question 7:

    A security team created a document that details the order in which critical systems should be brought back online after a major outage. Which of the following documents did the team create?

    A. Communication plan

    B. Incident response plan

    C. Data retention policy

    D. Disaster recovery plan

  • Question 8:

    A company wants to reconfigure an existing wireless infrastructure. The company needs to ensure the projected WAP placement will provide proper signal strength to all workstations. Which of the following should the company use to best fulfill the requirements?

    A. Network diagram

    B. WPS

    C. 802.1X

    D. Heat map

  • Question 9:

    A security engineer is working to address the growing risks that shadow IT services are introducing to the organization. The organization has taken a cloud-first approach and does not have an on-premises IT infrastructure. Which of the following would best secure the organization?

    A. Upgrading to a next-generation firewall

    B. Deploying an appropriate in-line CASB solution

    C. Conducting user training on software policies

    D. Configuring double key encryption in SaaS platforms

  • Question 10:

    Which of the following are the most likely vectors for the unauthorized or unintentional inclusion of vulnerable code in a software company's final software releases? (Choose two).

    A. Certificate mismatch

    B. Use of penetration-testing utilities

    C. Weak passwords

    D. Included third-party libraries

    E. Vendors/supply chain

    F. Outdated anti-malware software

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SY0-601 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.