CompTIA Security+ - SY0-601 Exam Practice Test
A security analyst is concerned about traffic initiated to the dark web from the corporate LAN. Which of the following networks should the analyst monitor?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
An attacker is attempting to harvest user credentials on a client's website. A security analyst notices multiple attempts of random usernames and passwords. When the analyst types in a random username and password, the logon screen displays the following message:
The username you entered does not exist.
Which of the following should the analyst recommend be enabled?
The username you entered does not exist.
Which of the following should the analyst recommend be enabled?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A security analyst needs to centrally manage credentials and permissions to the company's network devices. The following security requirements must be met:
* All actions performed by the network staff must be logged.
* Per-command permissions must be possible.
* The authentication server and the devices must communicate through TCP.
Which of the following authentication protocols should the analyst choose?
* All actions performed by the network staff must be logged.
* Per-command permissions must be possible.
* The authentication server and the devices must communicate through TCP.
Which of the following authentication protocols should the analyst choose?
Correct Answer: D
While investigating a recent security breach an analyst finds that an attacker gained access by SQL injection through a company website Which of the following should the analyst recommend to the website developers to prevent this from reoccurring?
Correct Answer: D
A company has numerous employees who store PHI data locally on devices. The Chief Information Officer wants to implement a solution to reduce external exposure of PHI but not affect the business.
The first step the IT team should perform is to deploy a DLP solution:
The first step the IT team should perform is to deploy a DLP solution:
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A security administrator is compiling information from all devices on the local network in order to gain better visibility into user activities. Which of the following is the best solution to meet this objective?
Correct Answer: C
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A network engineer receives a call regarding multiple LAN-connected devices that are on the same switch. The devices have suddenly been experiencing speed and latency issues while connecting to network resources. The engineer enters the command show mac address-table and reviews the following output

Which of the following best describes the attack that is currently in progress?

Which of the following best describes the attack that is currently in progress?
Correct Answer: C
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A security analyst is reviewing the vulnerability scan report for a web server following an incident. The vulnerability that was used to exploit the server is present in historical vulnerability scan reports, and a patch is available for the vulnerability. Which of the following is the MOST likely cause?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A company recently experienced a significant data loss when proprietary information was leaked to a competitor. The company took special precautions by using proper labels; however, email filter logs do not have any record of the incident. An investigation confirmed the corporate network was not breached, but documents were downloaded from an employee's COPE tablet and passed to the competitor via cloud storage. Which of the following is the best mitigation strategy to prevent this from happening in the future?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
During a recent cybersecurity audit, the auditors pointed out various types of vulnerabilities in the production are a. The production area hardware runs applications that are critical to production Which of the following describes what the company should do first to lower the risk to the Production the hardware.
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Which of the following are common VoIP-associated vulnerabilities? (Select two).
Correct Answer: C,F
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Audit logs indicate an administrative account that belongs to a security engineer has been locked out multiple times during the day. The security engineer has been on vacation (or a few days. Which of the following attacks can the account lockout be attributed to?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A security analyst is investigating a SIEM event concerning invalid log-ins The system logs that match the time frame of the event show the following:

Which of the following best describes this type of attack?

Which of the following best describes this type of attack?
Correct Answer: B