SY0-601 Exam Questions Get Updated [2023] with Correct Answers [Q217-Q237]

Share

SY0-601 Exam Questions Get Updated [2023] with Correct Answers

Practice SY0-601 Questions With Certification guide Q&A from Training Expert Actualtests4sure

NEW QUESTION 217
Which of the following BEST describes a technique that compensates researchers for finding vulnerabilities?

  • A. Bug bounty
  • B. Penetration testing
  • C. Code review
  • D. Wardriving

Answer: B

 

NEW QUESTION 218
A company posts a sign indicating its server room is under video surveillance. Which of the following control types is represented?

  • A. Administrative
  • B. Deterrent
  • C. Technical
  • D. Detective

Answer: A

 

NEW QUESTION 219
A security analyst is investigating some users who are being redirected to a fake website that resembles www.comptia.org. The following output was found on the naming server of the organization:

Which of the following attacks has taken place?

  • A. Domain reputation
  • B. Domain hijacking
  • C. DNS poisoning
  • D. Disassociation

Answer: B

 

NEW QUESTION 220
A security analyst is performing a forensic investigation compromised account credentials. Using the Event Viewer, the analyst able to detect the following message, ''Special privileges assigned to new login.'' Several of these messages did not have a valid logon associated with the user before these privileges were assigned. Which of the following attacks is MOST likely being detected?

  • A. Buffer overflow
  • B. Session replay
  • C. Pass-the-hash
  • D. Cross-site scripting

Answer: C

 

NEW QUESTION 221
A security engineer obtained the following output from a threat intelligence source that recently performed an attack on the company's server:

Which of the following BEST describes this kind of attack?

  • A. API
  • B. Request forgery
  • C. SQL injection
  • D. Directory traversal

Answer: B

 

NEW QUESTION 222
Which of the following is a team of people dedicated testing the effectiveness of organizational security programs by emulating the techniques of potential attackers?

  • A. Purple team
  • B. While team
  • C. Blue team
  • D. Red team

Answer: D

Explanation:
Red team-performs the offensive role to try to infiltrate the target.

 

NEW QUESTION 223
A security analyst wants to fingerprint a web server. Which of the following tools will the security analyst MOST likely use to accomplish this task?

  • A. curl --head http://192.168.0.10
  • B. nmap -p1-65535 192.168.0.10
  • C. ping 192.168.0.10
  • D. dig 192.168.0.10

Answer: A

Explanation:
Explanation
curl - Identify remote web server
Type the command as follows:$ curl -I http://www.remote-server.com/$
curl -I http://vivekgite.com/
Output:
HTTP/1.1 200 OK
Content-type: text/html
Content-Length: 0
Date: Mon, 28 Jan 2008 08:53:54 GMT
Server: lighttpd

 

NEW QUESTION 224
An analyst is working onan email incident in which target opened an attachment containing a worm. The analyst wants to implement mitigation techniques to prevent further spread. Which of the following is the BEST course of action for the analyst to take?

  • A. Apply a DLP solution
  • B. Isolate the infected attachment.
  • C. Utilize email content filtering.
  • D. Implement network segmentation.

Answer: D

 

NEW QUESTION 225
A company has decovered unauthorized devices are using its WiFi network, and it wants to harden the access point to imporve security. Which f the following configuration shoujld an analysis enable To improve security? (Select TWO.)

  • A. SSL
  • B. WEP-EKIP
  • C. WPA2-PSK
  • D. PEAP
  • E. WPS
  • F. RADIUS

Answer: B,C

 

NEW QUESTION 226
A security analyst receives a SIEM alert that someone logged in to the appadmin test account, which is only used for the early detection of attacks. The security analyst then reviews the following application log:

Which of the following can the security analyst conclude?

  • A. A credentialed vulnerability scanner attack is testing several CVEs against the application.
  • B. An injection attack is being conducted against a user authentication system.
  • C. A replay attack is being conducted against the application.
  • D. A service account password may have been changed, resulting in continuous failed logins within the application.

Answer: D

 

NEW QUESTION 227
The IT department at a university is concerned about professors placing servers on the university network in an attempt to bypass security controls. Which of the following BEST represents this type of threat?

  • A. A script kiddie
  • B. Shadow IT
  • C. Hacktivism
  • D. White-hat

Answer: B

Explanation:
Shadow IT is the use of information technology systems, devices, software, applications, and services without explicit IT department approval.

 

NEW QUESTION 228
A newly purchased corporate WAP needs to be configured in the MOST secure manner possible.
INSTRUCTIONS
Please click on the below items on the network diagram and configure them accordingly:
WAP
DHCP Server
AAA Server
Wireless Controller
LDAP Server
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Answer:

Explanation:

 

NEW QUESTION 229
A security analyst Is investigating a malware incident at a company. The malware is accessing a command-and-control website at www.comptia.com. All outbound Intemet traffic is logged to a syslog server and stored in / logfiles/messages. Which of the following commands would be BEST for the analyst to use on the syslog server to search for recent traffic to the command-and-control website?

  • A. cat /logfiles/messages | tail -500 wew.comptia.com
  • B. grep -500 /logfiles/messages | cat www.comptia.com
  • C. tail -500 /legfiles/messages | grep www.comptia.com
  • D. head -500 www.comptia.com | grep /logfiles/messages

Answer: A

 

NEW QUESTION 230
The security team received a report of copyright infringement from the IP space of lire corporate network. The report provided a precise time stamp for the incident as well as the name of the copyrighted file. The analyst has been tasked with determining the infringing source machine and instructed to implement measures to prevent such incidents from occurring again.
Which of the following is MOST capable of accomplishing both tasks?

  • A. TPM
  • B. NGFW
  • C. HIDS
  • D. Allow list

Answer: B

 

NEW QUESTION 231
A network engineer notices the VPN concentrator overloaded and crashes on days when there are a lot of remote workers. Senior management has placed greater importance on the availability of VPN resources for the remote workers than the security of the end users' traffic. Which of the following would be BEST to solve this issue?

  • A. Always On
  • B. L2TP
  • C. Split tunneling
  • D. iPSec

Answer: A

 

NEW QUESTION 232
A security analyst has been asked by the Chief Information Security Officer to
* develop a secure method of providing centralized management of infrastructure
* reduce the need to constantly replace aging end user machines
* provide a consistent user desktop expenence
Which of the following BEST meets these requirements?

  • A. Containers ation
  • B. BYOD
  • C. Mobile device management
  • D. VDI

Answer: D

 

NEW QUESTION 233
As part of a company's ongoing SOC maturation process, the company wants to implement a method to share cyberthreat intelligence data with outside security partners. Which of the following will the company MOST likely implement?

  • A. TTP
  • B. STIX
  • C. TAXII
  • D. TLP

Answer: A

Explanation:
TTPs Within Cyber Threat Intelligence
Tactics, techniques and procedures (TTPs) are the "patterns of activities or methods associated with a specific threat actor or group of threat actors."
Analysis of TTPs aids in counterintelligence and security operations by describing how threat actors perform attacks.
Top threats facing an organization should be given priority for TTP maturation. Smaller organizations may benefit strategically by outsourcing research and response.
One acronym everyone working on a cybersecurity team should be familiar with is TTPs - tactics, techniques and procedures - but not everyone understands how to use them properly within a cyber threat intelligence solution. TTPs describe how threat actors (the bad guys) orchestrate, execute and manage their operations attacks. ("Tactics" is also sometimes called "tools" in the acronym.) Specifically, TTPs are defined as the "patterns of activities or methods associated with a specific threat actor or group of threat actors," according to the Definitive Guide to Cyber Threat Intelligence.

 

NEW QUESTION 234
An organization implemented a process that compares the settings currently configured on systems against secure configuration guidelines in order to identify any gaps Which of the following control types has the organization implemented?

  • A. Preventive
  • B. Compensating
  • C. Detective
  • D. Corrective

Answer: A

Explanation:
Explanation
the control acts to eliminate or reduce the likelihood that an attack can succeed. A preventative control operates before an attack can take place. Compensating means to substitute one control with another (not happened here), Corrective means the attack has already happened (no mentioning), and detective is incorrect because the detective control detects ATTACKS, not vulnerabilities.

 

NEW QUESTION 235
A company recently experienced an attack in which a malicious actor was able to exfiltrate data by cracking stolen passwords, using a rainbow table the sensitive data.
Which of the following should a security engineer do to prevent such an attack in the future?

  • A. Use password hashing.
  • B. Implement password salting.
  • C. Disable password reuse.
  • D. Enforce password complexity.

Answer: B

 

NEW QUESTION 236
A customer called a company's security team to report that all invoices the customer has received over the last five days from the company appear to have fraudulent banking details. An investigation into the matter reveals the following
* The manager of the accounts payable department is using the same password across multiple external websites and the corporate account.
* One of the websites the manager used recently experienced a data breach.
* The manager's corporate email account was successfully accessed in the last five days by an IP address located in a foreign country Which of the following attacks has MOST likely been used to compromise the manager's corporate account?

  • A. Dictionary
  • B. Brute-force
  • C. Credential stuffing
  • D. Remote access Trojan
  • E. Password spraying

Answer: C

 

NEW QUESTION 237
......

Prepare Top CompTIA SY0-601 Exam Audio Study Guide Practice Questions Edition: https://www.actualtests4sure.com/SY0-601-test-questions.html

Free CompTIA SY0-601 Test Practice Test Questions Exam Dumps: https://drive.google.com/open?id=1DRxQRH923HPYE-a_QONzwg_meA2OFxqt