[Nov-2021] SYO-501 Pre-Exam Practice Tests | Exam Questions and Answers for Security+ Study Guide
CompTIA Security+ Certification Exam Certification Sample Questions
Your Job Prospects?
The CompTIA Security+ is an essential must-have if you want to start a career in cybersecurity. This certificate will place you among the top performers at the entry-level by validating foundational IT skills spanning across a wide range of IT concepts such as operational security and computer network. According to PayScale.com, a typical IT specialist with the Security+ certificate earns a mean annual salary of $75, Some of the best intermediate-level jobs that require the CompTIA Security+ certification include the following:
- IT Auditors;
- Security Engineer/Analyst;
- Helpdesk Manager/Analyst;
- Systems Administrator;
- Security Administrator;
- IT Project Manager.
- DevOps/Software Developer;
- Network/Cloud Engineer;
Who Does It Target?
The main target audience for this test is those individuals who have the skills and knowledge required to configure and install systems to protect applications, devices, or networks. They should have the CompTIA Network+ certification and at least 2 years of experience in IT administration.
NEW QUESTION 284
Users in a corporation currently authenticate with a username and password. A security administrator wishes to implement two-factor authentication to improve security. Which of the following authentication methods should be deployed to achieve this goal?
- A. PIN
- B. Security question
- C. CAPTCHA
- D. Passphrase
- E. Smart card
Answer: E
NEW QUESTION 285
A technician wants to implement PKI-based authentication on an enterprise wireless network. Which of the following should the technician configure to enforce the use of client-side certificates?
- A. RADIUS Federation
- B. WPA2-PSK
- C. EAP-TLS
- D. 802.1X with PEAP
Answer: C
NEW QUESTION 286
The security administrator has installed a new firewall which implements an implicit DENY policy by default.
INSTRUCTIONS:
Click on the firewall and configure it to allow ONLY the following communication.
1. The Accounting workstation can ONLY access the web server on the public network over the default HTTPS port. The accounting workstation should not access other networks.
2. The HR workstation should be restricted to communicate with the Financial server ONLY, over the default SCP port
3. The Admin workstation should ONLY be able to access the servers on the secure network over the default TFTP port.
Instructions: The firewall will process the rules in a top-down manner in order as a first match The port number must be typed in and only one port number can be entered per rule Type ANY for all ports. The original firewall configuration can be reset at any time by pressing the reset button. Once you have met the simulation requirements, click save and then Done to submit.
Hot Area:


Section: Network Security
Answer:
Explanation:
Implicit deny is the default security stance that says if you aren't specifically granted access or privileges for a resource, you're denied access by default.
Rule #1 allows the Accounting workstation to ONLY access the web server on the public network over the default HTTPS port, which is TCP port 443.
Rule #2 allows the HR workstation to ONLY communicate with the Financial server over the default SCP port, which is TCP Port 22 Rule #3 & Rule #4 allow the Admin workstation to ONLY access the Financial and Purchasing servers located on the secure network over the default TFTP port, which is Port 69.
References:
Stewart, James Michael, CompTIA Security+ Review Guide, Sybex, Indianapolis, 2014, pp. 26, 44 http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers
NEW QUESTION 287
Which of the following technologies would be MOST appropriate to utilize when testing a new software
patch before a company-wide deployment?
- A. Application control
- B. Redundancy
- C. Cloud computing
- D. Virtualization
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Virtualization is used to host one or more operating systems in the memory of a single host computer and
allows multiple operating systems to run simultaneously on the same hardware, reducing costs.
Virtualization offers the flexibility of quickly and easily making backups of entire virtual systems, and quickly
recovering the virtual system when errors occur. Furthermore, malicious code compromises of virtual
systems rarely affect the host system, which allows for safer testing and experimentation.
NEW QUESTION 288
SIMULATION
A company recently added a DR site and is redesigning the network. Users at the DR site are having issues browsing websites.
INSTRUCTIONS
Click on each firewall to do the following:
1. Deny cleartext web traffic
2. Ensure secure management protocols are used.
3. Resolve issues at the DR site.
The ruleset order cannot be modified due to outside constraints.
Hat any time you would like to bring back the initial state of the simulation, please dick the Reset All button.


- A. In Firewall 1, HTTP inbound Action should be DENY. As shown below

In Firewall 2, Management Service should be DNS, As shown below.
In Firewall 3, HTTP Inbound Action should be DENY, as shown below
- B. In Firewall 1, HTTP inbound Action should be DENY. As shown below

In Firewall 2, Management Service should be DNS, As shown below.
In Firewall 3, HTTP Inbound Action should be DENY, as shown below
Answer: B
NEW QUESTION 289
After a recent internal breach, a company decided to regenerate and reissue all certificates used in the transmission of confidential information. The company places the greatest importance on confidentiality and non-repudiation, and decided to generate dual key pairs for each client. Which of the following BEST describes how the company will use these certificates?
- A. One key pair will be used for internal communication, and the other will be used for external communication.
- B. One key pair will be used for encryption and decryption. The other will be used to digitally sign the data.
- C. Data will be encrypted once by each key, doubling the confidentiality and non-repudiation strength.
- D. One key pair will be used for encryption. The other key pair will provide extended validation.
Answer: B
Explanation:
Explanation
NEW QUESTION 290
You have been tasked with designing a security plan for your company. Drag and drop the appropriate security controls on the floor plan.
Instructions: All objects must be used and all place holders must be filled. Order does not matter. When you have completed the simulation, please select the Done button to submit.
Answer:
Explanation:
Explanation:
Cable locks - Adding a cable lock between a laptop and a desk prevents someone from picking it up and walking away
Proximity badge + reader
Safe is a hardware/physical security measure
Mantrap can be used to control access to sensitive areas. CCTV can be used as video surveillance.
Biometric reader can be used to control and prevent unauthorized access. Locking cabinets can be used to protect backup media, documentation and other physical artefacts.
NEW QUESTION 291
After correctly configuring a new wireless enabled thermostat to control the temperature of the company's meeting room, Joe, a network administrator determines that the thermostat is not connecting to the internet-based control system. Joe verifies that the thermostat received the expected network parameters and it is associated with the AP. Additionally, the other wireless mobile devices connected to the same wireless network are functioning properly. The network administrator verified that the thermostat works when tested at his residence.
Which of the following is the MOST likely reason the thermostat is not connecting to the internet?
- A. The company implements a captive portal
- B. The thermostat is using the incorrect encryption algorithm
- C. The company's DHCP server scope is full
- D. the WPA2 shared likely is incorrect
Answer: A
Explanation:
The thermo can't log into the captive portal.
NEW QUESTION 292
A procedure differs from a policy in that it:
- A. is a high-level statement regarding the company's position on a topic.
- B. describes adverse actions when violations occur.
- C. provides step-by-step instructions for performing a task.
- D. sets a minimum expected baseline of behavior.
Answer: C
NEW QUESTION 293
Leveraging the information supplied below, complete the CSR for the server to set up TLS (HTTPS)
* Hostname: ws01
* Domain: comptia.org
* IPv4: 10.1.9.50
* IPV4: 10.2.10.50
* Root: home.aspx
* DNS CNAME:homesite.
Instructions:
Drag the various data points to the correct locations within the CSR. Extension criteria belong in the let hand column and values belong in the corresponding row in the right hand column.
Answer:
Explanation:
NEW QUESTION 294
A cryptographer has developed a new proprietary hash function for a company and solicited employees to test the function before recommending its implementation. An employee takes the plaintext version of a document and hashes it, then changes the original plaintext document slightly and hashes it, and continues repeating this process until two identical hash values are produced from two different documents. Which of the following BEST describes this cryptographic attack?
- A. Known plaintext
- B. Replay
- C. Brute force
- D. Collision
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION 295
A security administrator has been conducting an account permissions review that has identified several users who belong to functional groups and groups responsible for auditing the functional groups' actions. Several recent outages have not been able to be traced to any user. Which of the following should the security administrator recommend to preserve future audit log integrity?
- A. Applying least privilege to user group membership
- B. Restricting audit group membership to service accounts
- C. Enforcing stricter onboarding workflow policies
- D. Following standard naming conventions for audit group users
Answer: D
NEW QUESTION 296
A security, who is analyzing the security of the company's web server, receives the following output:
Which of the following is the issue?
- A. Access violations
- B. Unencrypted credentials
- C. Stored procedures
- D. Code signing
Answer: B
NEW QUESTION 297
A company has a security policy that specifies all endpoint computing devices should be assigned a unique identifier that can be tracked via an inventory management system. Recent changes to airline security regulations have cause many executives in the company to travel with mini tablet devices instead of laptops. These tablet devices are difficult to tag and track. An RDP application is used from the tablet to connect into the company network. Which of the following should be implemented in order to meet the security policy requirements?
- A. A hardware security module (HSM)
- B. WS-security and geo-fencing
- C. MDM software
- D. RFID tagging system
- E. Virtual desktop infrastructure (IDI)
- F. Security Requirements Traceability Matrix (SRTM)
Answer: C
NEW QUESTION 298
A Chief Executive Officer (CEO) suspects someone in the lab testing environment is stealing confidential information after working hours when no one else is around. Which of the following actions can help to prevent this specific threat?
- A. Require swipe-card access to enter the lab.
- B. Audit file access times.
- C. Secretly install a hidden surveillance camera.
- D. Implement time-of-day restrictions.
Answer: D
NEW QUESTION 299
A security administrator learns that PII, which was gathered by the organization, has been found in an open forum. As a result, several C-level executives found their identities were compromised, and they were victims of a recent whaling attack. Which of the following would prevent these problems in the future? (Select TWO).
- A. Implement a host-based firewall.
- B. Implement a spam filter.
- C. Implement a reverse proxy.
- D. Implement a HIDS.
- E. Implement an email DLP.
Answer: B,E
NEW QUESTION 300
An analyst is reviewing the following web-server log after receiving an alert from the DLP system about multiple PII records being transmitted in cleartext:
Which of the following IP addresses in MOST likely involved in the data leakage attempt?
- A. 10.45.10.200
- B. 192.4.43.122
- C. 172.44.33.10
- D. 10.43.40.112
Answer: C
NEW QUESTION 301
A mobile device user is concerned about geographic positioning information being included in messages
sent between users on a popular social network platform. The user turns off the functionality in the
application, but wants to ensure the application cannot re-enable the setting without the knowledge of the
user.
Which of the following mobile device capabilities should the user disable to achieve the stated goal?
- A. GEO-Tagging
- B. Application control
- C. Location based services
- D. Device access control
Answer: A
NEW QUESTION 302
An employee on the Internet facing part of a company's website submits a 20-character phrase in a small textbox on a web form. The website returns a message back to the browser stating.
Of which of the following is this an example?
- A. Improper error handling
- B. Buffer overflow
- C. Improperly configured account
- D. Resources exhaustion
Answer: A
NEW QUESTION 303
A technician receives a device with the following anomalies:
Frequent pop-up ads
Show response-time switching between active programs
Unresponsive peripherals
The technician reviews the following log file entries:
File Name Source MD5 Target MD5
Status
antivirus.exe F794F21CD33E4F57890DDEA5CF267ED2
F794F21CD33E4F57890DDEA5CF267ED2 Automatic
iexplore.exe 7FAAF21CD33E4F57890DDEA5CF29CCEA
AA87F21CD33E4F57890DDEAEE2197333 Automatic
service.exe 77FF390CD33E4F57890DDEA5CF28881F
77FF390CD33E4F57890DDEA5CF28881F Manual
USB.exe E289F21CD33E4F57890DDEA5CF28EDC0
E289F21CD33E4F57890DDEA5CF28EDC0 Stopped
Based on the above output, which of the following should be reviewed?
- A. The removable media control
- B. The data execution prevention
- C. The web application firewall
- D. The file integrity check
Answer: D
NEW QUESTION 304
Which of the following technologies when applied to android and iOS environments, can an organization use to add security restrictions and encryption to existing mobile applications?
(Select Two)
- A. Mobile device management
- B. Mobile application store
- C. Application wrapping
- D. Application whitelisting
- E. Containerization
Answer: A,D
NEW QUESTION 305
......
CompTIA Exam Practice Test To Gain Brilliante Result: https://www.passleadervce.com/Security/reliable-SYO-501-exam-learning-guide.html
Tested Material Used To SYO-501: https://drive.google.com/open?id=1SmL-kwpj4kQgsLHZF-FlzNIKVukxzWAF