Updated CompTIA Security+ SY0-501 Exam Questions


CompTIA Security+ SY0-501 English Language exam will be retired on July 31, 2021, the new one for CompTIA Security+ certification is SY0-601. CompTIA Security+ is the first security certification a candidate should earn. It establishes the core knowledge required of any cybersecurity role and provides a springboard to intermediate-level cybersecurity jobs.

CompTIA Security+ certification is for Security Administrator, Systems Administrator, Helpdesk Manager/Analyst, Network/Cloud Engineer, Security Engineer/Analyst, DevOps/Software Developer, IT Auditors and IT Project Manager. The updated CompTIA Security+ SY0-501 exam questions can help you study this SY0-501 exam well.

Page 1 of 60

1. During an incident, a company’s CIRT determines it is necessary to observe the continued network-based transactions between a callback domain and the malware running on an enterprise PC.

Which of the following techniques would be BEST to enable this activity while reducing the risk of lateral spread and the risk that the adversary would notice any changes?

2. An organization has a policy in place that states the person who approves firewall controls/changes cannot be the one implementing the changes.

Which of the following is this an example of?

3. An organization just experienced a major cyberattack incident. The attack was well coordinated, sophisticated, and highly skilled.

Which of the following targeted the organization?

4. HOTSPOT

The security administration has installed a new firewall which implements an implicit DENY policy by default.



INSTRUCTIONS

Click on the firewall and configure it to allow ONLY the following communication:

- The Accounting workstation can ONLY access the web server on the public network over the default HTTPS port. The accounting workstation should not access other networks.

- The HR workstation should be restricted to communicate with the Financial server ONLY, over the default SCP port.

- The Admin workstation should ONLY be able to access the server on the secure network over the default TFTP port.

The firewall will process the rules in a top-down manner in order as a first match. The port number must be typed in and only one port number can be entered per rule. Type ANY for all ports.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.









5. An organization has decided to host its web application and database in the cloud.

Which of the following BEST describes the security concerns for this decision?

6. Which of the following describes the ability of code to target a hypervisor from inside a guest OS?

7. An auditor is performing an assessment of a security appliance with an embedded OS that was vulnerable during the last two assessments.

Which of the following BEST explains the appliance’s vulnerable state?

8. Which of the following BEST describes a security exploit for which a vendor patch is not readily available?

9. A systems administrator needs to install the same X.509 certificate on multiple servers.

Which of the following should the administrator use?

10. A network administrator has been alerted that web pages are experiencing long load times.

After determining it is not a routing or DNS issue, the administrator logs in to the router, runs a command, and receives the following output:





Which of the following is the router experiencing?