CompTIA SY0-601 Exam Preparation Guide and PDF Download [Q182-Q205]

Share

CompTIA SY0-601 Exam Preparation Guide and PDF Download

Verified & Correct SY0-601 Practice Test Reliable Source Apr 25, 2024 Updated

NEW QUESTION # 182
A security engineer is setting up passwordless authentication for the first time.
INSTRUCTIONS
Use the minimum set of commands to set this up and verify that it works. Commands cannot be reused.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Answer:

Explanation:


NEW QUESTION # 183
A security analyst needs to perform periodic vulnerably scans on production systems. Which of the following scan types would produce the BEST vulnerability scan report?

  • A. Intrusive
  • B. Host discovery
  • C. Credentialed
  • D. Port

Answer: C


NEW QUESTION # 184
A recent security audit reveaied that @ popular website with IP address 172.16 1 also has an FTP service thal employees were using to store sensitive corporate data. The organization's outbound firewall processes rules top-down. Which of the following would permit HTTP and HTTPS, while denying all other services for this host?

  • A.
  • B.
  • C.
  • D.

Answer: C


NEW QUESTION # 185
Several universities are participating m a collaborative research project and need to share compute and storage resources Which of the following cloud deployment strategies would BEST meet this need?

  • A. Hybrid
  • B. Public
  • C. Community
  • D. Private

Answer: C

Explanation:
Community cloud storage is a variation of the private cloud storage model, which offers cloud solutions for specific businesses or communities. In this model, cloud storage providers offer their cloud architecture, software and other development tools to meet the requirements of the community. A community cloud in computing is a collaborative effort in which infrastructure is shared between several organizations from a specific community with common concerns (security, compliance, jurisdiction, etc.), whether managed internally or by a third-party and hosted internally or externally.


NEW QUESTION # 186
A network administrator has been alerted that web pages are experiencing long load times. After determining it is not a routing or DNS issue, the administrator logs in to the router, runs a command, and receives the following output:

Which of the following is the router experiencing?

  • A. Memory leak
  • B. DDoS attack
  • C. Buffer overflow
  • D. Resource exhaustion

Answer: D


NEW QUESTION # 187
A company recently added a DR site and is redesigning the network. Users at the DR site are having issues browsing websites.

INSTRUCTIONS
Click on each firewall to do the following:
1. Deny cleartext web traffic
2. Ensure secure management protocols are used.
3. Resolve issues at the DR site.
The ruleset order cannot be modified due to outside constraints.
Hat any time you would like to bring back the initial state of the simulation, please dick the Reset All button.


Answer:

Explanation:
Check the answer in explanation.
Explanation
In Firewall 1, HTTP inbound Action should be DENY. As shown below

In Firewall 2, Management Service should be DNS, As shown below.

In Firewall 3, HTTP Inbound Action should be DENY, as shown below


NEW QUESTION # 188
After installing a patch On a security appliance. an organization realized a massive data exfiltration occurred.
Which Of the following describes the incident?

  • A. Password attack
  • B. Cryptographic attack
  • C. Supply chain attack
  • D. Ransomware attack

Answer: C

Explanation:
Explanation
A supply chain attack is a type of attack that involves compromising a trusted third-party provider or vendor and using their products or services to deliver malware or gain access to the target organization. The attacker can exploit the trust and dependency that the organization has on the provider or vendor and bypass their security controls. In this case, the attacker may have tampered with the patch for the security appliance and used it to exfiltrate data from the organization.


NEW QUESTION # 189
After segmenting the network, the network manager wants to control the traffic between the segments. Which of the following should the manager use to control the network traffic?

  • A. A VPN a
  • B. An ACL
  • C. A DMZ
  • D. A VLAN

Answer: B

Explanation:
After segmenting the network, a network manager can use an access control list (ACL) to control the traffic between the segments. An ACL is a set of rules that permit or deny traffic based on its characteristics, such as the source and destination IP addresses, protocol type, and port number. References: CompTIA Security+ Certification Guide, Exam SY0-501


NEW QUESTION # 190
A company needs to enhance Its ability to maintain a scalable cloud Infrastructure. The Infrastructure needs to handle the unpredictable loads on the company's web application. Which of the following cloud concepts would BEST these requirements?

  • A. SaaS
  • B. Microservices
  • C. Containers
  • D. VDI

Answer: C

Explanation:
Containers are a type of virtualization technology that allow applications to run in a secure, isolated environment on a single host. They can be quickly scaled up or down as needed, making them an ideal solution for unpredictable loads. Additionally, containers are designed to be lightweight and portable, so they can easily be moved from one host to another. Reference: CompTIA Security+ Sy0-601 official Text book, page 863.


NEW QUESTION # 191
A systems administrator is looking for a low-cost application-hosting solution that is cloud-based. Which of the following meets these requirements?

  • A. SD-WAN
  • B. SDN
  • C. Type 1 hypervisor
  • D. Serverless framework

Answer: D


NEW QUESTION # 192
A security engineer is setting up passwordless authentication for the first time.
INSTRUCTIONS
Use the minimum set of commands to set this up and verify that it works. Commands cannot be reused.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Answer:

Explanation:


NEW QUESTION # 193
An attack has occurred against a company.
INSTRUCTIONS
You have been tasked to do the following:
Identify the type of attack that is occurring on the network by clicking on the attacker's tablet and reviewing the output. (Answer Area 1).
Identify which compensating controls should be implemented on the assets, in order to reduce the effectiveness of future attacks by dragging them to the correct server.
(Answer area 2) All objects will be used, but not all placeholders may be filled. Objects may only be used once.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.


Select and Place:

Answer:

Explanation:

Explanation
Diagram Description automatically generated


NEW QUESTION # 194
A company just implemented a new telework policy that allows employees to use personal devices for official email and file sharing while working from home. Some of the requirements are:
- Employees must provide an alternate work location (i.e., a home address)
- Employees must install software on the device that will prevent the loss of proprietary data but will not restrict any other software from being installed.
Which of the following BEST describes the MDM options the company is using?

  • A. Geofencing, content management, remote wipe, containerization, and storage segmentation
  • B. Remote wipe, geolocation, screen locks, storage segmentation, and full-device encryption
  • C. Application management, remote wipe, geofencing, context-aware authentication, and containerization
  • D. Content management, remote wipe, geolocation, context-aware authentication, and containerization

Answer: C


NEW QUESTION # 195
An analyst visits an Internet forum looking for information about a tool. The analyst finds a thread that appears to contain relevant information. One of the posts says the following:

Which of the following BEST describes the attack that was attempted against the forum readers?

  • A. API attack
  • B. XSS attack
  • C. SQLi attack
  • D. DLL attack

Answer: B

Explanation:
Explanation/Reference:


NEW QUESTION # 196
The security operations center is researching an event concerning a suspicious IP address. A security analyst looks at the following event logs and discovers that a significant portion of the user accounts have experienced failed log-in attempts when authenticating event logs and discovers that a significant portion of the user accounts have experienced failed log-in attempts when authenticating from the same IP address:

Which of the following most likely describes the attack that took place?

  • A. Spraying
  • B. Dictionary
  • C. Brute-force
  • D. Rainbow table

Answer: A


NEW QUESTION # 197
A security analyst received the following requirements for the deployment of a security camera solution:
* The cameras must be viewable by the on-site security guards.
+ The cameras must be able to communicate with the video storage server.
* The cameras must have the time synchronized automatically.
* The cameras must not be reachable directly via the internet.
* The servers for the cameras and video storage must be available for remote maintenance via the company VPN.
Which of the following should the security analyst recommend to securely meet the remote connectivity requirements?

  • A. Deploying a jump server that is accessible via the internal network that can communicate with the servers
  • B. Creating firewall rules that prevent outgoing traffic from the subnet the servers and cameras reside on
  • C. Disabling all unused ports on the switch that the cameras are plugged into and enabling MAC filtering
  • D. Implementing a WAF to allow traffic from the local NTP server to the camera server

Answer: A

Explanation:
A jump server is a system that is used to manage and access systems in a separate security zone. It acts as a bridge between two different security zones and provides a controlled and secure way of accessing systems between them12. A jump server can also be used for auditing traffic and user activity for real-time surveillance
3. By deploying a jump server that is accessible via the internal network, the security analyst can securely meet the remote connectivity requirements for the servers and cameras without exposing them directly to the internet or allowing outgoing traffic from their subnet. The other options are not suitable because:
* A. Creating firewall rules that prevent outgoing traffic from the subnet the servers and cameras reside on would not allow remote maintenance via the company VPN.
* C. Disabling all unused ports on the switch that the cameras are plugged into and enabling MAC filtering would not prevent direct internet access to the cameras or servers.
* D. Implementing a WAF to allow traffic from the local NTP server to the camera server would not address the remote connectivity requirements or protect the servers from internet access.
References:
1: https://www.thesecuritybuddy.com/network-security/what-is-a-jump-server/ 3:
https://www.ssh.com/academy/iam/jump-server 2: https://en.wikipedia.org/wiki/Jump_server


NEW QUESTION # 198
A company installed several crosscut shredders as part of increased information security practices targeting data leakage risks. Which of the following will this practice reduce?

  • A. Credential harvesting
  • B. Dumpster diving
  • C. Information elicitation
  • D. Shoulder surfing

Answer: B

Explanation:
Explanation
Crosscut shredders are used to destroy paper documents and reduce the risk of data leakage through dumpster diving. Dumpster diving is a method of retrieving sensitive information from paper waste by searching through discarded documents.
References:
* CompTIA Security+ Study Guide, Exam SY0-601, 4th Edition, Chapter 2


NEW QUESTION # 199
A user enters a password to log in to a workstation and is then prompted to enter an authentication code.
Which of the following MFA factors or attributes are being utilized in the authentication process? (Select TWO).

  • A. Somewhere you are
  • B. Someone you are
  • C. Something you have
  • D. Something you know
  • E. Something you are
  • F. Something you can do

Answer: C,E


NEW QUESTION # 200
A security analyst needs to recommend a solution that will allow current Active Directory accounts and groups to be used for access controls on both network and remote-access devices. Which of the following should the analyst recommend? (Select two).

  • A. Kerberos
  • B. CHAP
  • C. RADIUS
  • D. OAuth
  • E. OpenlD
  • F. TACACS+

Answer: A,C

Explanation:
RADIUS and Kerberos are two protocols that can be used to integrate Active Directory accounts and groups with network and remote-access devices. RADIUS is a protocol that provides centralized authentication, authorization, and accounting for network access. It can use Active Directory as a backend database to store user credentials and group memberships. Kerberos is a protocol that provides secure authentication and encryption for network services. It is the default authentication protocol for Active Directory and can be used by remote-access devices that support it.


NEW QUESTION # 201
Which of the following is best used to detect fraud by assigning employees to different roles?

  • A. Separation of duties
  • B. Least privilege
  • C. Mandatory vacation
  • D. Job rotation

Answer: A


NEW QUESTION # 202
A new security engineer has started hardening systems. One o( the hardening techniques the engineer is using involves disabling remote logins to the NAS. Users are now reporting the inability lo use SCP to transfer files to the NAS, even though the data is still viewable from the users' PCs. Which of the following is the MOST likely cause of this issue?

  • A. SSH was turned off instead of modifying the configuration file.
  • B. TFTP was disabled on the local hosts.
  • C. Remote login was disabled in the networkd.conf instead of using the sshd. conf.
  • D. Network services are no longer running on the NAS

Answer: A

Explanation:
SSH is used to securely transfer files to the remote server and is required for SCP to work. Disabling SSH will prevent users from being able to use SCP to transfer files to the server. To enable SSH, the security engineer should modify the SSH configuration file (sshd.conf) and make sure that SSH is enabled. For more information on hardening systems and the security techniques that can be used, refer to the CompTIA Security+ SY0-601 Official Text Book and Resources.


NEW QUESTION # 203
An organization is concerned that is hosted web servers are not running the most updated version of the software. Which of the following would work BEST to help identify potential vulnerabilities?

  • A. Hping3 -s comptia, org -p 80
  • B. nslookup -port=80 comtia.org
  • C. nmp comptia, org -p 80 -aV
  • D. Nc -1 -v comptia, org -p 80

Answer: C

Explanation:
Explanation
Nmap is used to discover hosts and services on a computer network by sending packets and analyzing the responses. Nmap provides a number of features for probing computer networks, including host discovery and service and operating system detection.


NEW QUESTION # 204
A security administrator examines the ARP table of an access switch and sees the following output:

Which of the following is a potential threat that is occurring on this access switch?

  • A. ARP poisoning on Fa0/1 port
  • B. DNS poisoning on port Fa0/1
  • C. DDoSonFa02 port
  • D. MAG flooding on Fa0/2 port

Answer: A

Explanation:
Explanation
ARP poisoning is a type of attack that exploits the ARP protocol to associate a malicious MAC address with a legitimate IP address on a network1. This allows the attacker to intercept, modify or drop traffic between the victim and other hosts on the same network. In this case, the ARP table of the access switch shows that the same MAC address (00-0c-29-58-35-3b) is associated with two different IP addresses (192.168.1.100 and
192.168.1.101) on port Fa0/12. This indicates that an attacker has poisoned the ARP table to redirect traffic intended for 192.168.1.100 to their own device with MAC address 00-0c-29-58-35-3b. The other options are not related to this scenario. DDoS is a type of attack that overwhelms a target with excessive traffic from multiple sources3. MAC flooding is a type of attack that floods a switch with fake MAC addresses to exhaust its MAC table and force it to operate as a hub4. DNS poisoning is a type of attack that corrupts the DNS cache with fake entries to redirect users to malicious websites.
References: 1: https://www.imperva.com/learn/application-security/arp-spoofing/ 2:
https://community.cisco.com/t5/networking-knowledge-base/network-tables-mac-routing-arp/ta-p/4184148 3:
https://www.imperva.com/learn/application-security/ddos-attack/ 4:
https://www.imperva.com/learn/application-security/mac-flooding/ :
https://www.imperva.com/learn/application-security/dns-spoofing-poisoning/


NEW QUESTION # 205
......

Pass CompTIA SY0-601 exam Dumps 100 Pass Guarantee With Latest Demo: https://www.testkingfree.com/CompTIA/SY0-601-practice-exam-dumps.html

Free CompTIA SY0-601 Exam Files Downloaded Instantly: https://drive.google.com/open?id=1njSr2QhFOrGxHSR4SWdRmLWmdZa03sTK