Free SY0-601 Exam Braindumps

Pass your CompTIA Security+ Exam exam with these free Questions and Answers

Page 14 of 107
QUESTION 61

- (Exam Topic 3)
A security manager for a retailer needs to reduce the scope of a project to comply with PCI DSS. The PCI data is located in different offices than where credit cards are accepted. All the offices are connected via MPLS back to the primary datacenter. Which of the following should the security manager implement to achieve the objective?

  1. A. Segmentation
  2. B. Containment
  3. C. Geofencing
  4. D. Isolation

Correct Answer: A

QUESTION 62

- (Exam Topic 6)
Which of the following authentication methods sends out a unique password to be used within a specific number of seconds?

  1. A. TOTP
  2. B. Biometrics
  3. C. Kerberos
  4. D. LDAP

Correct Answer: A

QUESTION 63

- (Exam Topic 1)
As part of a security compliance assessment, an auditor performs automated vulnerability scans. In addition, which of the following should the auditor do to complete the assessment?

  1. A. User behavior analysis
  2. B. Packet captures
  3. C. Configuration reviews
  4. D. Log analysis

Correct Answer: D
A vulnerability scanner is essentially doing that. It scans every part of your network configuration that it can, and determines if known vulnerabilities are known at any point of that.

QUESTION 64

- (Exam Topic 5)
A security analyst is investigating a phishing email that contains a malicious document directed to the company's Chief Executive Officer (CEO). Which of the following should the analyst perform to understand the threat and retrieve possible IoCs?

  1. A. Run a vulnerability scan against the CEOs computer to find possible vulnerabilities
  2. B. Install a sandbox to run the malicious payload in a safe environment
  3. C. Perform a traceroute to identify the communication path
  4. D. Use netstat to check whether communication has been made with a remote host

Correct Answer: B

QUESTION 65

- (Exam Topic 3)
A company wants to deploy PKI on its Internet-facing website. The applications that are currently deployed are:
www.company.com (main website) contactus.company.com (for locating a nearby location) quotes.company.com (for requesting a price quote)
The company wants to purchase one SSL certificate that will work for all the existing applications and any future applications that follow the same naming conventions, such as store.company.com. Which of the following certificate types would BEST meet the requirements?

  1. A. SAN
  2. B. Wildcard
  3. C. Extended validation
  4. D. Self-signed

Correct Answer: B

Page 14 of 107

Post your Comments and Discuss CompTIA SY0-601 exam with other Community members: