Security+ (2021) Practice Questions
Prepare for SY0-601 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 425 questions Locked
- SY0-501Legacy Security+ (2020) 980 questions Locked
- SY0-601Legacy Security+ (2021) 78 questions Current
- 1
On which of the following is the live acquisition of data for forensic analysis MOST dependent? (Choose two.)
Show answer details
Correct answer: E, F
E, F
E, F
- 2
Which of the following incident response steps involves actions to protect critical systems while maintaining business operations?
Show answer details
Correct answer: B
B
- 3
A security auditor is reviewing vulnerability scan data provided by an internal security team. Which of the following BEST indicates that valid credentials were used?
Show answer details
Correct answer: B
B
- 4
Which of the following will MOST likely adversely impact the operations of unpatched traditional programmable-logic controllers, running a back-end LAMP server and OT systems with human- management interfaces that are accessible over the Internet via a web interface? (Choose two.)
Show answer details
Correct answer: D, F
Weak encryption is a critical vulnerability for unpatched programmable logic controllers and OT systems accessible over the internet, as these legacy systems often use outdated or no encryption protocols, making them vulnerable to man-in-the-middle attacks and data interception. Server-side request forgery (SSRF) is also highly impactful as the LAMP server backend can be exploited to make unauthorized requests to internal OT systems.
Server-side request forgery (SSRF) attacks are particularly dangerous for LAMP servers managing OT systems, as attackers can exploit the web interface to make internal requests to programmable logic controllers and other industrial systems. Combined with weak encryption on unpatched systems, SSRF can lead to complete compromise of operational technology infrastructure.
- 5
A company recently transitioned to a strictly BYOD culture due to the cost of replacing lost or damaged corporate-owned mobile devices. Which of the following technologies would be BEST to balance the BYOD culture while also protecting the company’s data?
Show answer details
Correct answer: C
Full-disk encryption is the best solution for BYOD environments as it protects company data stored on personal devices even if the device is lost, stolen, or compromised. Unlike other options, full-disk encryption ensures data remains secure regardless of device ownership while allowing employees to use their personal devices freely.
