Skip to content

Security+ (2021) Practice Questions

Prepare for SY0-601 with more than an answer.

78 questions in the full set10 sample questionsUpdated Jan 18, 2026

Unlock the full exam and previous versions

  • v1Version 1 425 questions Locked
  • SY0-501Legacy Security+ (2020) 980 questions Locked
  • SY0-601Legacy Security+ (2021) 78 questions Current
  1. 1

    Phishing and spear-phishing attacks have been occurring more frequently against a company’s staff. Which of the following would MOST likely help mitigate this issue?

    Show answer details

    Correct answer: C

    C

  2. 2

    On which of the following is the live acquisition of data for forensic analysis MOST dependent? (Choose two.)

    Show answer details

    Correct answer: E, F

    E, F

    E, F

  3. 3

    Which of the following incident response steps involves actions to protect critical systems while maintaining business operations?

    Show answer details

    Correct answer: B

    B

  4. 4

    A security auditor is reviewing vulnerability scan data provided by an internal security team. Which of the following BEST indicates that valid credentials were used?

    Show answer details

    Correct answer: B

    B

  5. 5

    Which of the following will MOST likely adversely impact the operations of unpatched traditional programmable-logic controllers, running a back-end LAMP server and OT systems with human- management interfaces that are accessible over the Internet via a web interface? (Choose two.)

    Show answer details

    Correct answer: D, F

    Weak encryption is a critical vulnerability for unpatched programmable logic controllers and OT systems accessible over the internet, as these legacy systems often use outdated or no encryption protocols, making them vulnerable to man-in-the-middle attacks and data interception. Server-side request forgery (SSRF) is also highly impactful as the LAMP server backend can be exploited to make unauthorized requests to internal OT systems.

    Server-side request forgery (SSRF) attacks are particularly dangerous for LAMP servers managing OT systems, as attackers can exploit the web interface to make internal requests to programmable logic controllers and other industrial systems. Combined with weak encryption on unpatched systems, SSRF can lead to complete compromise of operational technology infrastructure.

Create an account to continue.