[Jan 19, 2022] SY0-601 Exam Dumps, SY0-601 Practice Test Questions
Free SY0-601 Study Guides Exam Questions & Answer
Exam Prerequisites
While the Security+ renders multiple benefits and helps a security specialist to have an amazing career start, it doesn't impose strict prerequisites. Officially, there are zero prerequisites. However, industry experts and candidates, who have already experienced the CompTIA SY0-601 exam, advise to take up the Network N10-007 exam first. This test imparts some basic yet vital cybersecurity-related knowledge that will make the journey of SY0-601 an easy task.
CompTIA SY0-601 Exam Syllabus Topics:
| Topic | Details |
|---|---|
Threats, Attacks, and Vulnerabilities - 24% | |
| Compare and contrast different types of social engineering techniques. | 1. Phishing 2. Smishing 3. Vishing 4. Spam 5. Spam over instant messaging (SPIM) 6. Spear phishing 7. Dumpster diving 8. Shoulder surfing 9. Pharming 10. Tailgating 11. Eliciting information 12. Whaling 13. Prepending 14. Identity fraud 15. Invoice scams 16. Credential harvesting 17. Reconnaissance 18. Hoax 19. Impersonation 20. Watering hole attack 21. Typosquatting 22. Pretexting 23. Influence campaigns
24. Principles (reasons for effectiveness)
|
| Given a scenario, analyze potential indicatorsto determine the type of attack. | 1. Malware
3. Physical attacks
4. Adversarial artificial intelligence (AI)
6. Cloud-based vs. on-premises attacks 7. Cryptographic attacks
|
| Given a scenario, analyze potential indicatorsassociated with application attacks. | 1. Privilege escalation 2. Cross-site scripting 3. Injections
4. Pointer/object dereference
8. Error handling
11. Integer overflow
13. Application programming interface (API) attacks
18. Pass the hash |
| Given a scenario, analyze potential indicators associated with network attacks. | 1. Wireless
2. On-path attack (previously known as man-in-the-middle attack/man-in-the-browser attack)
4. Domain name system (DNS)
5. Distributed denial-of-service (DDoS)
6. Malicious code or script execution
|
| Explain different threat actors, vectors, and intelligence sources. | 1. Actors and threats
2. Attributes of actors
3. Vectors
4. Threat intelligence sources
5. Research sources
|
| Explain the security concerns associated with various types of vulnerabilities. | 1. Cloud-based vs. on-premises vulnerabilities 2. Zero-day 3. Weak configurations
6. Legacy platforms
|
| Summarize the techniques used in security assessments. | 1. Threat hunting
2. Vulnerability scans
3. Syslog/Security information and event management (SIEM)
|
| Explain the techniques used in penetration testing. | 1. Penetration testing
3. Exercise types
|
Architecture and Design - 21% | |
| Explain the importance of security concepts in an enterprise environment. | 1. Configuration management
2. Data sovereignty
4. Geographical considerations
10. Deception and disruption
|
| Summarize virtualization and cloud computing concepts. | 1. Cloud models
2. Cloud service providers
11. Serverless architecture
|
| Summarize secure application development, deployment, and automation concepts. | 1. Environment
2. Provisioning and deprovisioning
5. Open Web Application Security Project (OWASP)
7. Automation/scripting
8. Elasticity |
| Summarize authentication and authorization design concepts. | 1. Authentication methods
5. Cloud vs. on-premises requirements |
| Given a scenario, implement cybersecurity resilience. | 1. Redundancy
2. Replication
3. On-premises vs. cloud
5. Non-persistence
6. High availability
7. Restoration order
|
| Explain the security implications of embedded and specialized systems. | 1. Embedded systems
2. Supervisory control and data acquisition (SCADA)/industrial control system (ICS)
3. Internet of Things (IoT)
4. Specialized
5. Voice over IP (VoIP)
13. Constraints
|
| Explain the importance of physical security controls. | 1. Bollards/barricades 2. Access control vestibules 3. Badges 4. Alarms 5. Signage 6. Cameras
7. Closed-circuit television (CCTV)
10. Locks
10. USB data blocker
15. Drones
22. Secure data destruction
|
| Summarize the basics of cryptographic concepts. | 1. Digital signatures 2. Key length 3. Key stretching 4. Salting 5. Hashing 6. Key exchange 7. Elliptic-curve cryptography 8. Perfect forward secrecy 9. Quantum
10. Post-quantum
13. Blockchain
14. Cipher suites
15. Symmetric vs. asymmetric
18. Homomorphic encryption
20. Limitations
|
Implementation - 25% | |
| Given a scenario, implement secure protocols. | 1. Protocols
2. Use cases
|
| Given a scenario, implement host or application security solutions. | 1. Endpoint protection
2. Boot integrity
3. Database
4. Application security
5. Hardening
6. Self-encrypting drive (SED)/full-disk encryption (FDE)
7. Hardware root of trust |
| Given a scenario, implement secure network designs. | 1. Load balancing
5. Network access control (NAC)
7. Port security
10. Route security 11. Quality of service (QoS) 12. Implications of IPv6 13. Port spanning/port mirroring
15. File integrity monitors |
| Given a scenario, install and configure wireless security settings. | 1. Cryptographic protocols
2. Authentication protocols
3. Methods
4. Installation considerations
|
| Given a scenario, implement secure mobile solutions | 1. Connection methods and receivers
2. Mobile device management (MDM)
4. Enforcement and monitoring of:
|
| Given a scenario, apply cybersecurity solutions to the cloud. | 1. Cloud security controls
2. Solutions
3. Cloud native controls vs. third-party solutions |
| Given a scenario, implement identity and account management controls. | 1. Identity
2. Account types
3. Account policies
|
| Given a scenario, implement authentication and authorization solutions. | 1. Authentication management
2. Authentication/authorization
3. Access control schemes
|
| Given a scenario, implement public key infrastructure. | 1. Public key infrastructure (PKI)
2. Types of certificates
3. Certificate formats
|
Operations and Incident Response - 16% | |
| Given a scenario, use the appropriate tool to assess organizational security. | 1. Network reconnaissance and discovery
2. File manipulation
3. Shell and script environments
4. Packet capture and replay
5. Forensics
6. Exploitation frameworks |
| Summarize the importance of policies, processes, and procedures for incident response. | 1. Incident response plans 2. Incident response process
6. Communication plan 7. Disaster recovery plan 8. Business continuity plan 9. Continuity of operations planning (COOP) 10. Incident response team 11. Retention policies |
| Given an incident, utilize appropriate data sources to support an investigation. | 1. Vulnerability scan output 2. SIEM dashboards
3. Log files
4. syslog/rsyslog/syslog-ng
9. Netflow/sFlow
10. Protocol analyzer output |
| Given an incident, apply mitigation techniques or controls to secure an environment. | 1. Reconfigure endpoint security solutions
2. Configuration changes
3. Isolation
|
| Explain the key aspects of digital forensics. | 1. Documentation/evidence
2. Acquisition
3. On-premises vs. cloud
4. Integrity
5. Preservation |
Governance, Risk, and Compliance - 14% | |
| Compare and contrast various types of controls. | 1. Category
2. Control type
|
| Explain the importance of applicable regulations, standards, or frameworks that impact organizational security posture. | 1. Regulations, standards, and legislation
2. Key frameworks
|
| Explain the importance of policies to organizational security. | 1. Personnel
2. Diversity of training techniques
4. Data
5. Credential policies
6. Organizational policies
|
| Summarize risk management processes and concepts. | 1. Risk types
3. Risk analysis
|
| Explain privacy and sensitive data concepts in relation to security. | 1. Organizational consequences of privacy and data breaches
2. Notifications of breaches
3. Data types
4. Privacy enhancing technologies
5. Roles and responsibilities
7. Impact assessment 8. Terms of agreement 9. Privacy notice |
NEW QUESTION 121
Select the appropriate attack and remediation from each drop-down list to label the corresponding attack with its remediation.
INSTRUCTIONS
Not all attacks and remediation actions will be used.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Answer:
Explanation:

NEW QUESTION 122
A security analyst is investigating multiple hosts that are communicating to external IP addresses during the hours of 2:00 a.m - 4:00 am. The malware has evaded detection by traditional antivirus software. Which of the following types of malware is MOST likely infecting the hosts?
- A. A worm
- B. Ransomware
- C. A RAT
- D. Polymophic
Answer: D
NEW QUESTION 123
A cybersecurity analyst reviews the log files from a web server and sees a series of files that indicates a directory-traversal attack has occurred. Which of the following is the analyst MOST likely seeing?
A)
B)
C)
D)
- A. Option B
- B. Option A
- C. Option C
- D. Option D
Answer: A
NEW QUESTION 124
A security analyst b concerned about traffic initiated to the dark web from the corporate LAN. Which of the following networks should he analyst monitor?
- A. Tor
- B. SFTP
- C. IoC
- D. AS
Answer: A
NEW QUESTION 125
Which of the following ISO standards is certified for privacy?
- A. ISO 27002
- B. ISO 31000
- C. ISO 27701
- D. ISO 9001
Answer: C
NEW QUESTION 126
An attacker has successfully exfiltrated several non-salted password hashes from an online system. Given the logs below:
Which of the following BEST describes the type of password attack the attacker is performing?
- A. Dictionary
- B. Pass-the-hash
- C. Brute-force
- D. Password spraying
Answer: A
NEW QUESTION 127
A company is adopting a BYOD policy and is looking for a comprehensive solution to protect company information on user devices. Which of the following solutions would BEST support the policy?
- A. Full-device encryption
- B. Mobile device management
- C. Remote wipe
- D. Biometrics
Answer: B
NEW QUESTION 128
A company is launching a new internet platform for its clients. The company does not want to implement its own authorization solution but instead wants to rely on the authorization provided by another platform. Which of the following is the BEST approach to implement the desired solution?
- A. OAuth
- B. RADIUS
- C. TACACS+
- D. SAML
Answer: B
NEW QUESTION 129
A document that appears to be malicious has been discovered in an email that was sent to a company's Chief Financial Officer (CFO). Which of the following would be BEST to allow a security analyst to gather information and confirm it is a malicious document without executing any code it may contain?
- A. Search for matching file hashes on malware websites
- B. View the document's metadata for origin clues
- C. Detonate the document in an analysis sandbox
- D. Open the document on an air-gapped network
Answer: C
NEW QUESTION 130
A forensics investigator is examining a number of unauthorized payments the were reported on the company's website. Some unusual log entries show users received an email for an unwanted mailing list and clicked on a link to attempt to unsubscribe. One of the users reported the email to the phishing team, and the forwarded email revealed the link to be:
Which of the following will the forensics investigator MOST likely determine has occurred?
- A. SQL injection
- B. CSRF
- C. XSS
- D. XSRF
Answer: B
NEW QUESTION 131
A cybersecurity analyst needs to implement secure authentication to third-party websites without users' passwords. Which of the following would be the BEST way to achieve this objective?
- A. SAML
- B. PAP
- C. OAuth
- D. SSO
Answer: C
NEW QUESTION 132
A security analyst is using a recently released security advisory to review historical logs, looking for the specific activity that was outlined in the advisory. Which of the following is the analyst doing?
- A. Threat hunting
- B. A packet capture
- C. A user behavior analysis
- D. Credentialed vulnerability scanning
Answer: A
Explanation:
Explanation
https://www.comptia.org/blog/your-next-move-threat-hunter#:~:text=Threat%20hunters%20are%20IT%20profe
NEW QUESTION 133
A security analyst is Investigating a malware incident at a company. The malware Is accessing a command-and-control website at www.comptia.com. All outbound Internet traffic is logged to a syslog server and stored in /logfiles/messages.
Which of the following commands would be BEST for the analyst to use on the syslog server to search for recent traffic to the command-and-control website?
- A. Option A
- B. Option B
- C. Option C
- D. Option D
Answer: C
NEW QUESTION 134
A global pandemic is forcing a private organization to close some business units and reduce staffing at others.
Which of the following would be BEST to help the organization's executives determine the next course of action?
- A. An incident response plan
- B. A communications plan
- C. A disaster recovery plan
- D. A business continuity plan
Answer: D
Explanation:
Explanation
Business continuity may be defined as "the capability of an organization to continue the delivery of products or services at pre-defined acceptable levels following a disruptive incident",[1] and business continuity planning [2][3] (or business continuity and resiliency planning) is the process of creating systems of prevention and recovery to deal with potential threats to a company.[4] In addition to prevention, the goal is to enable ongoing operations before and during execution of disaster recovery.[5] Business continuity is the intended outcome of proper execution of both business continuity planning and disaster recovery.
NEW QUESTION 135
A researcher has been analyzing large data sets for the last ten months. The researcher works with colleagues from other institutions and typically connects via SSH to retrieve additional data. Historically, this setup has worked without issue, but the researcher recently started getting the following message:
Which of the following network attacks is the researcher MOST likely experiencing?
- A. Man-in-the-middle
- B. Evil twin
- C. MAC cloning
- D. ARP poisoning
Answer: A
NEW QUESTION 136
A security assessment found that several embedded systems are running unsecure protocols. These Systems were purchased two years ago and the company that developed them is no longer in business Which of the following constraints BEST describes the reason the findings cannot be remediated?
- A. inability to authenticate
- B. Unavailable patch
- C. Implied trust
- D. Lack of computing power
Answer: B
NEW QUESTION 137
The manager who is responsible for a data set has asked a security engineer to apply encryption to the data on a hard disk. The security engineer is an example of a:
- A. data controller.
- B. data owner
- C. data custodian.
- D. data processor
Answer: D
NEW QUESTION 138
......
SY0-601 Exam Dumps, SY0-601 Practice Test Questions: https://www.premiumvcedump.com/CompTIA/valid-SY0-601-premium-vce-exam-dumps.html
Attested SY0-601 Dumps PDF Resource [2022]: https://drive.google.com/open?id=1sxqkPGANswurnGfVrzhXZUTcL1c0tT5r