CompTIA SY0-501 CompTIA Security+ Online Training
CompTIA SY0-501 Online Training
The questions for SY0-501 were last updated at Nov 22,2024.
- Exam Code: SY0-501
- Exam Name: CompTIA Security+
- Certification Provider: CompTIA
- Latest update: Nov 22,2024
Which of the following types of keys is found in a key escrow?
- A . Public
- B . Private
- C . Shared
- D . Session
B
Explanation:
https:/ /www.professormesser.com/security – plus/sy0-401/key-escrow-3/
A security analyst is reviewing the following output from an IPS:
Given this output, which of the following can be concluded? (Choose two.)
- A . The source IP of the attack is coming from 250.19.18.22.
- B . The source IP of the attack is coming from 250.19.18.71.
- C . The attacker sent a malformed IGAP packet, triggering the alert.
- D . The attacker sent a malformed TCP packet, triggering the alert.
- E . The TTL value is outside of the expected range, triggering the alert.
Despite having implemented password policies, users continue to set the same weak passwords and reuse old passwords.
Which of the following technical controls would help prevent these policy violations? (Choose two.)
- A . Password expiration
- B . Password length
- C . Password complexity
- D . Password history
- E . Password lockout
Which of the following types of cloud infrastructures would allow several organizations with similar structures and interests to realize the benefits of shared storage and resources?
- A . Private
- B . Hybrid
- C . Public
- D . Community
A company is currently using the following configuration:
– IAS
server with certificate-based EAP-PEAP and MSCHAP
– Unencrypted authentication via PAP
A security administrator needs to configure a new wireless setup with the following configurations:
– PAP authentication method
– PEAP and EAP provide two-factor authentication
Which of the following forms of authentication are being used? (Choose two.)
- A . PAP
- B . PEAP
- C . MSCHAP
- D . PEAP- MSCHAP
- E . EAP
- F . EAP-PEAP
An auditor wants to test the security posture of an organization by running a tool that will display the following:
Which of the following commands should be used?
- A . nbtstat
- B . nc
- C . arp
- D . ipconfig
A company determines that it is prohibitively expensive to become compliant with new credit card regulations. Instead, the company decides to purchase insurance to cover the cost of any potential loss.
Which of the following is the company doing?
- A . Transferring the risk
- B . Accepting the risk
- C . Avoiding the risk
- D . Migrating the risk
A company is using a mobile device deployment model in which employees use their personal devices for work at their own discretion.
Some of the problems the company is encountering include the following:
– There is no standardization.
– Employees ask for reimbursement for their devices.
– Employees do not replace their devices often enough to keep them running efficiently.
– The company does not have enough control over the devices.
Which of the following is a deployment model that would help the company overcome these problems?
- A . BYOD
- B . VDI
- C . COPE
- D . CYOD
A botnet has hit a popular website with a massive number of GRE-encapsulated packets to perform a DDoS attack. News outlets discover a certain type of refrigerator was exploited and used to send outbound packets to the website that crashed.
To which of the following categories does the refrigerator belong?
- A . SoC
- B . ICS
- C . IoT
- D . MFD
Users report the following message appears when browsing to the company’s secure site: This website cannot be trusted.
Which of the following actions should a security analyst take to resolve these messages? (Choose two.)
- A . Verify the certificate has not expired on the server.
- B . Ensure the certificate has a .pfx extension on the server.
- C . Update the root certificate into the client computer certificate store.
- D . Install the updated private key on the web server.
- E . Have users clear their browsing history and relaunch the session.