Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

[Jan-2024] Free SY0-601 Exam Questions SY0-601 Actual Free Exam Questions [Q93-Q112]

Share

[Jan-2024] Free SY0-601 Exam Questions SY0-601 Actual Free Exam Questions

Verified SY0-601 dumps and 610 unique questions

NEW QUESTION # 93
During an incident, an EDR system detects an increase in the number of encrypted outbound connections from multiple hosts. A firewall is also reporting an increase in outbound connections that use random high ports. An analyst plans to review the correlated logs to find the source of the incident. Which of the following tools will best assist the analyst?

  • A. A vulnerability scanner
  • B. The Windows Event Viewer
  • C. A SIEM
  • D. A NGFW

Answer: C

Explanation:
Explanation
A security information and event management (SIEM) system will best assist the analyst to review the correlated logs to find the source of the incident. A SIEM system is a type of software or service that collects, analyzes, and correlates logs and events from multiple sources, such as firewalls, EDR systems, servers, or applications. A SIEM system can help to detect and respond to security incidents, provide alerts and reports, support investigations and forensics, and comply with regulations. References:
https://www.comptia.org/blog/what-is-a-siem
https://www.certblaster.com/wp-content/uploads/2020/11/CompTIA-Security-SY0-601-Exam-Objectives-1.0.pd


NEW QUESTION # 94
To reduce and limit software and infrastructure costs the Chief Information Officer has requested to move email services to the cloud. The cloud provider and the organization must have secunty controls to protect sensitive data Which of the following cloud services would best accommodate the request?

  • A. laaS
  • B. DaaS
  • C. PaaS
  • D. SaaS

Answer: D

Explanation:
Explanation
SaaS (Software as a Service) is a cloud model that provides clients with applications and software that are hosted and managed by a cloud provider over the internet. It can move email services to the cloud by allowing clients to access and use email applications without installing or maintaining them on their own devices or servers


NEW QUESTION # 95
After reading a security bulletin, a network security manager is concerned that a malicious actor may have breached the network using the same software flaw. The exploit code is publicly available and has been reported as being used against other industries in the same vertical.
Which of the following should the network security manager consult FIRST to determine a priority list for forensic review?

  • A. The IDS logs
  • B. The vulnerability scan output
  • C. The full packet capture data
  • D. The SIEM alerts

Answer: B


NEW QUESTION # 96
An employee received multiple messages on a mobile device. The messages instructing the employee to pair the device to an unknown device. Which of the following BEST describes What a malicious person might be doing to cause this issue to occur?

  • A. Rogue access point
  • B. Jamming
  • C. Bluesnarfing
  • D. Evil twin

Answer: C

Explanation:
Explanation
Bluesnarfing is a hacking technique that exploits Bluetooth connections to snatch data from a wireless device.
An attacker can perform bluesnarfing when the Bluetooth function is on and your device is discoverable by other devices within range. In some cases, attackers can even make calls from their victim's phone1.


NEW QUESTION # 97
An enterprise has hired an outside security firm to conduct penetration testing on its network and applications.
The firm has not received information about the internal architecture. Which of the following BEST represents the type of testing that will occur?

  • A. Gray-box
  • B. White-box
  • C. Bug bounty
  • D. Black-box

Answer: D


NEW QUESTION # 98
A secunty engineer needs to build @ solution to satisty regulatory requirements that stale certain critcal servers must be accessed using MFA However, the critical servers are older and are unable to support the addition of MFA, Which of te following will the engineer MOST likely use to achieve this objective?

  • A. A statetul frewail
  • B. A jump server
  • C. A port tap
  • D. A forward proxy

Answer: B


NEW QUESTION # 99
one of the attendees starts to notice delays in the connection. and the HTTPS site requests are reverting to HTTP. Which of the following BEST describes what is happening?

  • A. Birthday collision on the certificate key
  • B. A SSL/TLS downgrade
  • C. Brute force to the access point
  • D. DNS hacking to reroute traffic

Answer: B

Explanation:
The scenario describes a Man-in-the-Middle (MitM) attack where the attacker intercepts traffic and downgrades the secure SSL/TLS connection to an insecure HTTP connection. This type of attack is commonly known as SSL/TLS downgrade attack or a stripping attack. The attacker is able to see and modify the communication between the client and server.


NEW QUESTION # 100
A nuclear plant was the victim of a recent attack, and all the networks were air gapped. A subsequent investigation revealed a worm as the source of the issue. Which of the following BEST explains what happened?

  • A. A local machine has a RAT installed.
  • B. The HVAC was connected to the maintenance vendor.
  • C. A malicious USB was introduced by an unsuspecting employee.
  • D. The ICS firmware was outdated

Answer: C


NEW QUESTION # 101
Which of the following would BEST identify and remediate a data-loss event in an enterprise using third-party, web-based services and file-sharing platforms?

  • A. UTM
  • B. SIEM
  • C. DLP
  • D. CASB

Answer: D

Explanation:
Microsoft has a straightforward definition and it includes DLP. "is a security policy enforcement point positioned between enterprise users and cloud service providers" https://www.microsoft.com/en-us/security/business/security-101/what-is-a-cloud-access-security-broker-casb A cloud access security broker (CASB) works by securing data flowing to and from in-house IT architectures and cloud vendor environments using an organization's security policies. CASBs protect enterprise systems against cyberattacks through malware prevention and provide data security through encryption, making data streams unreadable to outside parties. CASBs were created with one thing in mind: protecting proprietary data stored in external, third-party media. CASBs deliver capabilities not generally available in traditional controls such as secure web gateways (SWGs) and enterprise firewalls. CASBs provide policy and governance concurrently across multiple cloud services and provide granular visibility into and control over user activities. https://www.forcepoint.com/cyber-edu/casb-cloud-access-security-broker


NEW QUESTION # 102
During a recent cybersecurity audit, the auditors pointed out various types of vulnerabilities in the production are a. The production area hardware runs applications that are critical to production Which of the following describes what the company should do first to lower the risk to the Production the hardware.

  • A. Install an antivirus solution.
  • B. Back up the hardware.
  • C. Apply patches.
  • D. Add a banner page to the hardware.

Answer: C

Explanation:
Applying patches is the first step to lower the risk to the production hardware, as patches are updates that fix vulnerabilities or bugs in the software or firmware. Patches can prevent attackers from exploiting known vulnerabilities and compromising the production hardware. Applying patches should be done regularly and in a timely manner, following a patch management policy and process. Reference: 1 CompTIA Security+ Certification Exam Objectives, page 9, Domain 2.0: Architecture and Design, Objective 2.3: Summarize secure application development, deployment, and automation concepts 2 CompTIA Security+ Certification Exam Objectives, page 10, Domain 2.0: Architecture and Design, Objective 2.4: Explain the importance of embedded and specialized systems security 3 https://www.comptia.org/blog/patch-management-best-practices


NEW QUESTION # 103
A security engineer has enabled two-factor authentication on all workstations. Which of the following approaches are the MOST secure? (Choose two.)

  • A. Password and CAPTCHA
  • B. Password and smart card
  • C. Password and voice
  • D. Password and fingerprint
  • E. Password and security question
  • F. Password and one-time token

Answer: B,D


NEW QUESTION # 104
A security architect is required to deploy to conference rooms some workstations that will allow sensitive data to be displayed on large screens. Due to the nature of the data, it cannot be stored in the conference rooms. The fiieshare is located in a local data center. Which of the following should the security architect recommend to BEST meet the requirement?

  • A. Fog computing and KVMs
  • B. Private cloud and DLP
  • C. VDI and thin clients
  • D. Full drive encryption and thick clients

Answer: C


NEW QUESTION # 105
A user reports constant lag and performance issues with the wireless network when working at a local coffee shop. A security analyst walks the user through an installation of Wireshark and get a five-minute pcap to analyze. The analyst observes the following output:

Which of the following attacks does the analyst MOST likely see in this packet capture?

  • A. Evil twin
  • B. Session replay
  • C. ARP poisoning
  • D. Bluejacking

Answer: A


NEW QUESTION # 106
Which Of the following vulnerabilities is exploited an attacker Overwrite a reg-ister with a malicious address that changes the execution path?

  • A. Race condition
  • B. SQL injection
  • C. VM escape
  • D. Buffer overflow

Answer: D

Explanation:
A buffer overflow is a type of vulnerability that occurs when an attacker sends more data than a buffer can hold, causing the excess data to overwrite adjacent memory locations such as registers. It can allow an attacker to overwrite a register with a malicious address that changes the execution path and executes arbitrary code on the target system


NEW QUESTION # 107
During an incident response, a security analyst observes the following log entry on the web server.

Which of the following BEST describes the type of attack the analyst is experience?

  • A. Pass-the-hash
  • B. Directory traversal
  • C. SQL injection
  • D. Cross-site scripting

Answer: B


NEW QUESTION # 108
SIMULATION
An attack has occurred against a company.
INSTRUCTIONS
You have been tasked to do the following:
Identify the type of attack that is occurring on the network by clicking on the attacker's tablet and reviewing the output.
(Answer Area 1).
Identify which compensating controls should be implemented on the assets, in order to reduce the effectiveness of future attacks by dragging them to the correct server.
(Answer area 2)
All objects will be used, but not all placeholders may be filled. Objects may only be used once.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.


Answer:

Explanation:


NEW QUESTION # 109
Given the following snippet of Python code:
Which of the following types of malware MOST likely contains this snippet?

  • A. Logic bomb
  • B. Backdoor
  • C. Ransomware
  • D. Keylogger

Answer: A

Explanation:
Explanation
A logic bomb is a type of malware that executes malicious code when certain conditions are met. A logic bomb can be triggered by various events, such as a specific date or time, a user action, a system configuration change, or a command from an attacker. A logic bomb can perform various malicious actions, such as deleting files, encrypting data, displaying messages, or launching other malware.
The snippet of Python code shows a logic bomb that executes a function called delete_all_files() when the current date is December 25th. The code uses the datetime module to get the current date and compare it with a predefined date object. If the condition is true, the code calls the delete_all_files() function, which presumably deletes all files on the system.
References: https://www.comptia.org/certifications/security#examdetails
https://www.comptia.org/content/guides/comptia-security-sy0-601-exam-objectives
https://www.kaspersky.com/resource-center/definitions/logic-bomb


NEW QUESTION # 110
Which of the following terms describes a broad range of information that is sensitive to a specific organization?

  • A. Public
  • B. Proprietary
  • C. Open-source
  • D. Top secret

Answer: D


NEW QUESTION # 111
A public relations team will be taking a group of guests on a tour through the facility of a large e-commerce company. The day before the tour, the company sends out an email to employees to ensure all whiteboards are cleaned and all desks are cleared. The company is MOST likely trying to protect against:

  • A. loss of proprietary information.
  • B. damage to the company's reputation.
  • C. credential exposure.
  • D. social engineering.

Answer: A


NEW QUESTION # 112
......

Latest 100% Passing Guarantee - Brilliant SY0-601 Exam Questions PDF: https://www.validexam.com/SY0-601-latest-dumps.html

SY0-601 Dumps for Pass Guaranteed - Pass SY0-601 Exam: https://drive.google.com/open?id=19OFoYZoc00FlboDX610JuOlVcnCtimM_