CompTIA Security+ SY0-601 Practice Questions
with 100% correct Answers
The user installed Trojan horse malware. -Answer- A user used an administrator
account to download and install a software application. After the u
...
CompTIA Security+ SY0-601 Practice Questions
with 100% correct Answers
The user installed Trojan horse malware. -Answer- A user used an administrator
account to download and install a software application. After the user launched the .exe
extension installer file, the user experienced frequent crashes, slow computer
performance, and strange services running when turning on the computer. What most
likely happened to cause these issues?
A worm -Answer- A security operations center (SOC) analyst investigates the
propagation of a memory-resident virus across the network and notices a rapid
consumption of network bandwidth, causing a Denial of Service (DoS). What type of
virus is this?
PUP (potentially unwanted program) -Answer- A user purchased a laptop from a local
computer shop. After powering on the laptop for the first time, the user noticed a few
programs like Norton Antivirus asking for permission to install. How would an IT security
specialist classify these programs?
-Uses lightweight shellcode
-Uses low observable characteristic attacks -Answer- A fileless malicious software can
replicate between processes in memory on a local host or over network shares. What
other behaviors and techniques would classify malware as fileless rather than a normal
virus? (Select all that apply.)
-Computer Bots,
-Command & Control -Answer- An attacker is planning to set up a backdoor that will
infect a set of specific computers at an organization, to inflict a set of other intrusion
attacks remotely. Which of the following will support the attackers' plan? (Select all that
apply.)
-Launch a Distributed Denial of Service (DDoS) attack
-Establish a connection with a Command and Control server
-Launch a mass-mail spam attack -Answer- If a user's computer becomes infected with
a botnet, which of the following can this compromise allow the attacker to do? (Select all
that apply.)
Have up-to-date backups. -Answer- If a user's device becomes infected with cryptomalware, which of the following is the best way to mitigate this compromise?
A logic bomb -Answer- A security specialist discovers a malicious script on a computer.
The script is set to execute if the administrator's account becomes disabled. What type
of malware did the specialist discover?
Spyware infected the computers. -Answer- End-users at an organization contact the
cybersecurity department. After downloading a file, they are being redirected toshopping websites they did not intend to navigate to, and built-in webcams turn on. The
security team confirms the issue as malicious, and notes modified DNS (Domain Name
System) queries that go to nefarious websites hosting malware. What most likely
happened to the users' computers?
A Remote Access Trojan (RAT) -Answer- An attacker installs Trojan malware that can
execute remote backdoor commands, such as the ability to upload files and install
software to a victim PC. What type of Trojan malware is this?
Password spraying attack -Answer- A hacker is trying to gain remote access to a
company computer by trying brute force password attacks using a few common
passwords in conjunction with multiple usernames. What specific type of password
attack is the hacker most likely performing?
-A rainbow table
-A dictionary word -Answer- An attacker can exploit a weakness in a password protocol
to calculate the hash of a password. Which of the following can the attacker match the
hash to, as a means to obtain the password? (Select all that apply.)
A rainbow table attack -Answer- Which of the following attacks do security professionals
expose themselves to, if they do not salt passwords with a random value?
Clone it. -Answer- How can an attacker make unauthorized use of acquired user and
account details from a user's smart card?
Skimming -Answer- What type of attack is occurring when a counterfeit card reader is in
use?
Cross-site scripting (XSS) -Answer- An attacker discovered an input validation
vulnerability on a website, crafted a URL with additional HTML code, and emailed the
link to a victim. The victim unknowingly defaced (vandalized) the web site after clicking
on the malicious URL. No other malicious operations occurred outside of the web
application's root directory. This scenario is describing which type of attack?
DLL injection -Answer- An attacker escalated privileges to a local administrator and
used code refactoring to evade antivirus detection. The attacker then allowed one
process to attach to another and forced the operating system to load a malicious binary
package. What did the attacker successfully perform?
LDAP injection -Answer- Using an open connection to a small company's network, an
attacker submitted arbitrary queries on port 389 to the domain controllers. The attacker
initiated the query from a client computer. What type of injection attack did the attacker
perform?A malicious process can alter the execution environment to create a null pointer, and
crash the program. -Answer- How can the lack of logic statement tests on memory
location variables be detrimental to software in development?
A buffer overflow -Answer- An attacker gained remote access to a user's computer by
exploiting a vulnerability in a piece of software on the device. The attacker sent data
that was able to manipulate the memory size that the application reserved to store
expected data. Which vulnerability exploit resulted from the attacker's actions?
Race condition -Answer- Developers found a "time of check to time of use" (TOCTTOU)
vulnerability in their application. The vulnerability made it possible to change temporary
data created within the app before the app uses the data later. This vulnerability is
taking advantage of what process in the application?
Revealing database server configuration -Answer- A web application's code prevents
the output of any type of information when an error occurs during a request. The
development team cited security reasons as to why they developed the application in
this way. What sort of security issues did the team have concerns about in this case?
Replay attack -Answer- An intruder monitors an admin's unsecure connection to a
server and finds some required data, like a cookie file, that legitimately establishes a
session with a web server. Knowing the admin's logon credentials, what type of attack
can the intruder perform with the cookie file?
Server-side request forgery -Answer- An attacker submitted a modified uniform
resource locator (URL) link to a website that eventually established connections to
back-end databases and exposed internal service configurations. The attacker did not
hijack a user to perform this attack. This describes which of the following types of
attacks?
Cross-site Request Forgery (XSRF) -Answer- An attacker modified the HTML code of a
legitimate password-change web form, then hosted the .html file on the attacker's web
server. The attacker then emailed a URL link of the hosted file to a real user of the web
page. Once the user clicked the link, it changed the user's password to a value the
attacker set. Based on this information, what type of attack is the website vulnerable to?
-Key discovery
-Improper error handling -Answer- The latest web application, using default settings, is
currently accepting application programming interface (API) calls over HyperText
Transfer Protocol (HTTP). The environment has a moderate key management system.
Even with basic server security, the API connection is vulnerable to which of the
following? (Select all that apply.)
-Resource exhaustion
-Denial of service (DoS)-Amplification -Answer- Which of the following conditions are results of a SYN
(synchronize) flood attack? (Select all that apply.)
A shim -Answer- By compromising a Windows XP application that ran on a Windows 10
machine, an attacker installed persistent malware on a victim computer with local
administrator privileges. What should the attacker add to the registry, along with its files
added to the system folder, to execute this malware?
Refactoring -Answer- Through what method can malware evade antivirus software
detection, so that the software no longer identifies the malware by its signature?
-A pass-the-hash attack
-A replay attack -Answer- A security engineer implemented once-only tokens and
timestamping sessions. What type of attacks can this type of security prevent? (Select
all that apply.)
A rogue access point (AP) -Answer- A security analyst's scans and network logs show
that unauthorized devices are connecting to the network. After tracing this down, the
analyst discovered a tethered smartphone creating a backdoor to gain access to the
network. Which of the following describes this device?
Bluesnarfing -Answer- An attacker used an exploit to steal information from a mobile
device, which allowed the attacker to circumvent the authentication process. The mobile
device is vulnerable to which of the following attacks?
-Locate the offending radio source and disable it.
-Boost the signal of the legitimate equipment. -Answer- An attacker used an illegal
access point (AP) with a very strong signal near a wireless network. If the attacker
performed a jamming attack, which of the following would mitigate this type of network
disruption? (Select all that apply.)
IV attacks -Answer- Wi-Fi Protected Access (WPA) fixes critical vulnerabilities in the
earlier wired equivalent privacy (WEP) standard. Understanding that WPA uses a
combination of an RC4 stream cipher and Temporal Key Integrity Protocol (TKIP), this
makes a wireless access point NOT vulnerable to which of the following attacks when
related to encrypted wireless packets?
A Man-in-the-Middle attack -Answer- A malicious user sniffed credentials exchanged
between two computers by intercepting communications between them. What type of
attack did the attacker execute?
Domain Name System (DNS) client cache poisoning -Answer- A hacker corrupted the
name:IP records held on the HOSTS file on a client, to divert traffic for a legitimate
domain to a malicious IP address. What type of attack did the hacker perform?
-Domain reputation-URL redirections -Answer- External hackers have some access to a company's website
and made some changes. Customers have submitted multiple complaints via email for
wrong orders and inappropriate images on the website. The Chief Information Officer
(CIO) is now worried about the distribution of malware. The company should prepare for
which of the following other issues or concerns? (Select all that apply.)
Network -Answer- A low level distributed denial of service (DDoS) attack that involves
SYN or SYN/ACK flooding describes what type of attack?
Application attack -Answer- An attacker is preparing to perform what type of attack
when the target vulnerabilities include headers and payloads of specific application
protocols?
PowerShell script -Answer- A security engineer examined some suspicious error logs
on a Windows server that showed attempts to run shellcode to a web application. The
shellcode showed multiple lines beginning with Invoke-Command. What type of script is
the suspicious code trying to run?
Python script -Answer- A Linux systems admin reported a suspicious .py file that ran on
a daily schedule after business hours. The file includes shellcode that would automate
Application Programming Interface (API) calls to a web application to get information.
What type of script is executing this shellcode?
By using VBA code -Answer- A malicious actor is preparing a script to run with an Excel
spreadsheet as soon as the target opens the file. The script includes a few macros
designed to secretly gather and send information to a remote server. How is the
malicious actor accomplishing this task?
Geographical dispersal -Answer- An application requires continuity of operations within
a 24 hour period due to the command and control capabilities it maintains. The failover
site must be physically separated from the program office and be available within the
required timeframe with live data. Which of the following redundancy solutions best
meets the failover requirement?
RAID-10 -Answer- Which Redundant Array of Independent Disks (RAID) combines
mirroring and striping and is the better option for mission critical applications?
UPS -Answer- A data center needs to ensure that data is not lost at the system level in
the event of a blackout. Servers must stay operable for at least an eight-hour window as
part of the response and recovery controls implemented. Which redundancy effort
should be put in place to ensure the data remains available?
Managed PDUs -Answer- A system engineer can monitor and control voltage factors in
a data center. The engineer can make critical decisions on the center's energy
consumption and load balancing. Which device is the engineer likely using to make
these decisions?SAN -Answer- A company requires a means of managing storage centrally and the
ability to share the storage with multiple hosts where users can access data quickly,
with little to no latency. Which of the following storage architectures would best meet the
company's needs?
Revert to known state -Answer- A company has implemented a Virtual Desktop
Infrastructure (VDI) where the user's desktop operates as a Virtual Machine (VM) on a
centralized server. When users log off the machine, any changes made at the VM level
are not saved. Which means for ensuring non-persistence has been implemented?
Take a snapshot of the server before installing on the server. -Answer- A system
engineer has tested a new application in the lab, and wants to deploy the application on
a production server. The server is a virtual machine that processes and stores live data
for company employees. Which of the following is the BEST approach for deploying the
new application on the server?
Tape -Answer- A system engineer is researching backup solutions that are inexpensive
and can store large amounts of data offline. The backup solution must be portable and
maintainable for a certain length of time defined in the company's backup recovery plan.
Which of the following is the best backup solution?
NAS -Answer- A network administrator is installing a device that uses Redundant Array
of Independent Disks (RAID) technologies for redundancy and provides employees
remote access so that files can be accessed anywhere. The device does not require
licensing and stores data at the file level. Which device is the employee likely installing
in the infrastructure?
Offline -Answer- An aviation tracking system maintains flight records for equipment and
personnel. The system is a critical command and control system that must maintain an
availability rate of 99% for key parameter performance. The cloud service provider
(CSP) guarantees a failover to multiple zones if an outage occurs. In addition to the
multi-zonal cloud failover, what backup solution would allow the system to maintain data
locally?
Scalability -Answer- When workload heavily increased, a company maintained service
performance by manually installing an additional load balanced server. What feature of
the IT architecture allowed this to occur?
Vendor diversity -Answer- A system engineer enhances the security of a network by
adding firewalls to both the external network and the internal company network. The
firewalls are products of two separate companies. This is an example of what type of
security control practice?
Control diversity -Answer- A startup company adds a firewall, an IDS, and a HIPS to its
infrastructure. At the end of the week, they will install HVAC in the server room. Thecompany has scheduled penetration testing every month. Which type of layered security
does this represent?
DNS Security Extensions -Answer- An authoritative server for a zone creates a
Resource Records Set (RRSet) signed with a zone signing key. From the following
Domain Name System (DNS) traits and functions, what does this scenario
demonstrate?
S/MIME -Answer- The administrator in an exchange server needs to send digitally
signed and encrypted messages. What should the administrator u
[Show More]