100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

CompTIA Security+ (SY0-601) Practice Exam 1 QUESTIONS WITH ANSWERS

Rating
-
Sold
-
Pages
80
Grade
A+
Uploaded on
19-01-2026
Written in
2025/2026

CompTIA Security+ (SY0-601) Practice Exam 1 QUESTIONS WITH ANSWERS

Institution
CompTIA Security+ SY0-601
Course
CompTIA Security+ SY0-601











Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
CompTIA Security+ SY0-601
Course
CompTIA Security+ SY0-601

Document information

Uploaded on
January 19, 2026
Number of pages
80
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

CompTIA Security+ (SY0-601) Practice |\ |\ |\ |\




Exam 1 QUESTIONS WITH ANSWERS |\ |\ |\ |\




Dion Training wants to install a new accounting system
|\ |\ |\ |\ |\ |\ |\ |\ |\



and is considering moving to a cloud-based solution to
|\ |\ |\ |\ |\ |\ |\ |\ |\



reduce cost, reduce the information technology overhead
|\ |\ |\ |\ |\ |\ |\



costs, improve reliability, and improve availability. Your
|\ |\ |\ |\ |\ |\ |\



Chief Information Officer is supportive of this move since
|\ |\ |\ |\ |\ |\ |\ |\ |\



it will be more fiscally responsible. Still, the Chief Risk
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\



Officer is concerned with housing all of the company's
|\ |\ |\ |\ |\ |\ |\ |\ |\



confidential financial data in a cloud provider's network |\ |\ |\ |\ |\ |\ |\ |\



that might be shared with other companies. Since the
|\ |\ |\ |\ |\ |\ |\ |\ |\



Chief Information Officer is determined to move to the
|\ |\ |\ |\ |\ |\ |\ |\ |\



cloud, what type of cloud-based solution would you
|\ |\ |\ |\ |\ |\ |\ |\



recommend to account for the Chief Risk Officer's |\ |\ |\ |\ |\ |\ |\ |\



concerns?
PaaS in a hybrid cloud|\ |\ |\ |\




SaaS in a private cloud
|\ |\ |\ |\




SaaS in a public cloud|\ |\ |\ |\




PaaS in a community cloud - CORRECT ANSWERS ✔✔SaaS
|\ |\ |\ |\ |\ |\ |\ |\



in a private cloud
|\ |\ |\ |\




A SaaS (Software as a Service) solution best describes an
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\



accounting system or software used as part of a cloud |\ |\ |\ |\ |\ |\ |\ |\ |\ |\



service. This meets the CIO's requirements. To mitigate
|\ |\ |\ |\ |\ |\ |\ |\

,the concerns of the Chief Risk Officer, you should use a
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\



private cloud solution. This type of solution ensures that
|\ |\ |\ |\ |\ |\ |\ |\ |\



the cloud provider does not comingle your data with other
|\ |\ |\ |\ |\ |\ |\ |\ |\



customers' data and providers dedicated servers and
|\ |\ |\ |\ |\ |\ |\ |\



resources for your company's use only. |\ |\ |\ |\ |\




You are developing a containment and remediation
|\ |\ |\ |\ |\ |\ |\



strategy to prevent the spread of an APT within your
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\



network. Your plan suggests creating a mirror of the
|\ |\ |\ |\ |\ |\ |\ |\ |\



company's databases, routing all externally sourced |\ |\ |\ |\ |\ |\



network traffic to it, and gradually updating with pseudo-
|\ |\ |\ |\ |\ |\ |\ |\



realistic data to confuse and deceive the APT as they
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\



attempt to exfiltrate the data. Once the attacker has
|\ |\ |\ |\ |\ |\ |\ |\ |\



downloaded the corrupted database, your company |\ |\ |\ |\ |\ |\



would then conduct remediation actions on the network
|\ |\ |\ |\ |\ |\ |\ |\



and restore the correct database information to the
|\ |\ |\ |\ |\ |\ |\ |\



production system. Which of the following types of |\ |\ |\ |\ |\ |\ |\ |\



containment strategies does the plan utilize? |\ |\ |\ |\ |\




Isolation-based containment by disconnecting the APT |\ |\ |\ |\ |\ |\



from the affected network
|\ |\ |\




Segmentation-based containment that deceives the |\ |\ |\ |\ |\



attack into believing their attack was successful
|\ |\ |\ |\ |\ |\




Segmentation-based containment disrupts the APT by |\ |\ |\ |\ |\ |\



using a hack-back approach
|\ |\ |\




Isolation-based containment by removing the affect - |\ |\ |\ |\ |\ |\ |\



CORRECT ANSWERS ✔✔Segmentation-based containment |\ |\ |\



that deceives the attack into believing their attack was
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\



successful

,There are two types of containment: segmentation and
|\ |\ |\ |\ |\ |\ |\ |\



isolation. This is an example of a segmentation-based
|\ |\ |\ |\ |\ |\ |\ |\



containment strategy that utilizes deception. |\ |\ |\ |\ |\



Segmentation-based containment is a means of achieving |\ |\ |\ |\ |\ |\



the isolation of a host or group of hosts using network
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\



technologies and architecture. As opposed to completely |\ |\ |\ |\ |\ |\ |\



isolating the hosts, you might configure the protected
|\ |\ |\ |\ |\ |\ |\ |\



segment to deceive him or her into thinking the attack is
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\



progressing successfully, such as in the database |\ |\ |\ |\ |\ |\ |\



modification example. The scenario is not a hack-back |\ |\ |\ |\ |\ |\ |\ |\



approach since the APT is not directly attacked, only |\ |\ |\ |\ |\ |\ |\ |\ |\



deceived. Isolation-based containment involves removing |\ |\ |\ |\ |\



an affected component from whatever larger environment
|\ |\ |\ |\ |\ |\



it is a part of. In this scenario, the original database was
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\



never isolated from the network, nor were any other
|\ |\ |\ |\ |\ |\ |\ |\ |\



affected assets during the deception. |\ |\ |\ |\




Which of the following features is supported by Kerberos
|\ |\ |\ |\ |\ |\ |\ |\ |\



but not by RADIUS?
|\ |\ |\




XML for cross-platform interoperability
|\ |\ |\




Tickets used to identify authenticated users
|\ |\ |\ |\ |\




Single sign-on capability |\ |\




Services for authentication - CORRECT ANSWERS |\ |\ |\ |\ |\ |\



✔✔Tickets used to identify authenticated users |\ |\ |\ |\ |\

, Whether you learned the in-depth details of each of these
|\ |\ |\ |\ |\ |\ |\ |\ |\



protocols during your studies or not, you should be able
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\



to answer this question by remembering that Kerberos is
|\ |\ |\ |\ |\ |\ |\ |\ |\



all about 'tickets.' Kerberos uses a system of tickets to
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\



allow nodes to communicate over a non-secure network
|\ |\ |\ |\ |\ |\ |\ |\



and securely prove their identity. Kerberos is a computer
|\ |\ |\ |\ |\ |\ |\ |\ |\



network authentication protocol that works based on
|\ |\ |\ |\ |\ |\ |\



tickets to allow nodes communicating over a non-secure
|\ |\ |\ |\ |\ |\ |\ |\



network to prove their identity to one another in a secure
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\



manner. Kerberos is used in Windows Active Directory
|\ |\ |\ |\ |\ |\ |\ |\



domains for authentication. Single sign-on (SSO) is a type
|\ |\ |\ |\ |\ |\ |\ |\



of mutual authentication for multiple services that can
|\ |\ |\ |\ |\ |\ |\ |\ |\



accept the credential from one domain or service as
|\ |\ |\ |\ |\ |\ |\ |\ |\



authentication for other services. The Remote |\ |\ |\ |\ |\ |\



Authentication Dial-in User Service (RADIUS) is used to |\ |\ |\ |\ |\ |\ |\ |\



manage remote and wireless authentication
|\ |\ |\ |\ |\



infrastructure. Users supply authentication information to |\ |\ |\ |\ |\ |\



RADIUS client devices, such as wireless access points.
|\ |\ |\ |\ |\ |\ |\ |\



The client device then passes the authentication data to
|\ |\ |\ |\ |\ |\ |\ |\ |\



an AAA (Authentication, Authorization, and Accounting)
|\ |\ |\ |\ |\ |\



server that processes the request.
|\ |\ |\ |\




Which type of agreement between companies and
|\ |\ |\ |\ |\ |\ |\



employees is used as a legal basis for protecting |\ |\ |\ |\ |\ |\ |\ |\ |\



information assets? |\




ISA
NDA
SLA

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
EXAMSTUDYPLUG Stanford University
View profile
Follow You need to be logged in order to follow users or courses
Sold
309
Member since
3 year
Number of followers
107
Documents
18416
Last sold
6 hours ago
GRADE BUDDY

Welcome to My Page! Are you looking for high-quality study resources to ace your exams or better understand your coursework? You've come to the right place! I'm passionate about sharing my knowledge and helping students succeed academically. Here, you'll find a wide range of well-organized notes, study guides, and helpful materials across various subjects, including Maths ,nursig, Biology, History, etc.. Each resource is carefully crafted with detailed explanations, clear examples, and relevant key points to help simplify complex concepts. Whether you're preparing for a test, reviewing lectures, or need extra support, my resources are designed to make your learning experience smoother and more effective. Let me be a part of your academic journey, and feel free to reach out if you have any questions or need personalized assistance!

Read more Read less
4.5

230 reviews

5
155
4
50
3
13
2
5
1
7

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions