CompTIA Security+ (SY0-601) Exam
Questions and Answers (Latest Update
2025)
A type of social engineering attack often used to steal user
data, including login credentials and credit card numbers. -
Correct Answer ✅Phishing
The act of committing text message fraud to try to lure
victims into revealing account information or installing
malware. - Correct Answer ✅Smishing
An electronic fraud tactic in which individuals are tricked into
revealing critical financial or personal information to
unauthorized entities. - Correct Answer ✅Vishing
An unsolicited bulk messages sent to multiple recipients who
did not ask for them. - Correct Answer ✅Spam
Refers to unsolicited instant messages. - Correct Answer
✅Spam over instant messaging (SPIM)
,CompTIA Security+ (SY0-601) Exam
Questions and Answers (Latest Update
2025)
An email or electronic communications scam targeted
towards a specific individual, organization or business. -
Correct Answer ✅Spear phishing
A technique used to retrieve information that could be used
to carry out an attack on a computer network. - Correct
Answer ✅Dumpster diving
A direct observation techniques, such as looking over
someone's shoulder, to get information. - Correct Answer
✅Shoulder surfing
A form of online fraud involving malicious code and
fraudulent websites. - Correct Answer ✅Pharming
A physical security breach in which an unauthorized person
follows an authorized individual to enter a secured premise. -
Correct Answer ✅Tailgating
,CompTIA Security+ (SY0-601) Exam
Questions and Answers (Latest Update
2025)
A reporting format designed to elicit as much information as
possible about individuals involved in a group or network. -
Correct Answer ✅Eliciting information
A method used by cybercriminals to masquerade as a senior
player at an organization and directly target senior
individuals, with the aim of stealing or gaining access to their
computer systems for criminal purposes. - Correct Answer
✅Whaling
A technique used to deprioritize a route in a netork. - Correct
Answer ✅Prepending
A crime in which an imposter obtains key pieces of personally
identifiable information (PII) to impersonate someone else. -
Correct Answer ✅Identity fraud
A fraudulent way of receiving money or by prompting a victim
to put their credentials into a fake login screen. - Correct
Answer ✅Invoice scams
, CompTIA Security+ (SY0-601) Exam
Questions and Answers (Latest Update
2025)
The process of gathering valid usernames, passwords, private
emails, and email addresses through infrastructure breaches.
- Correct Answer ✅Credential harvesting
A term for testing for potential vulnerabilities in a computer
network. - Correct Answer ✅Reconnaissance
A message warning the recipients of a non-existent computer
virus threat. - Correct Answer ✅Hoax
A form of fraud in which attackers pose as a known or trusted
person to dupe an employee into transferring money to a
fraudulent account, sharing sensitive information or revealing
login credentials. - Correct Answer ✅Impersonation
A targeted attack designed to compromise users within a
specific industry by infecting websites they typically visit and
luring them to a malicious site. - Correct Answer
✅Watering hole attack
Questions and Answers (Latest Update
2025)
A type of social engineering attack often used to steal user
data, including login credentials and credit card numbers. -
Correct Answer ✅Phishing
The act of committing text message fraud to try to lure
victims into revealing account information or installing
malware. - Correct Answer ✅Smishing
An electronic fraud tactic in which individuals are tricked into
revealing critical financial or personal information to
unauthorized entities. - Correct Answer ✅Vishing
An unsolicited bulk messages sent to multiple recipients who
did not ask for them. - Correct Answer ✅Spam
Refers to unsolicited instant messages. - Correct Answer
✅Spam over instant messaging (SPIM)
,CompTIA Security+ (SY0-601) Exam
Questions and Answers (Latest Update
2025)
An email or electronic communications scam targeted
towards a specific individual, organization or business. -
Correct Answer ✅Spear phishing
A technique used to retrieve information that could be used
to carry out an attack on a computer network. - Correct
Answer ✅Dumpster diving
A direct observation techniques, such as looking over
someone's shoulder, to get information. - Correct Answer
✅Shoulder surfing
A form of online fraud involving malicious code and
fraudulent websites. - Correct Answer ✅Pharming
A physical security breach in which an unauthorized person
follows an authorized individual to enter a secured premise. -
Correct Answer ✅Tailgating
,CompTIA Security+ (SY0-601) Exam
Questions and Answers (Latest Update
2025)
A reporting format designed to elicit as much information as
possible about individuals involved in a group or network. -
Correct Answer ✅Eliciting information
A method used by cybercriminals to masquerade as a senior
player at an organization and directly target senior
individuals, with the aim of stealing or gaining access to their
computer systems for criminal purposes. - Correct Answer
✅Whaling
A technique used to deprioritize a route in a netork. - Correct
Answer ✅Prepending
A crime in which an imposter obtains key pieces of personally
identifiable information (PII) to impersonate someone else. -
Correct Answer ✅Identity fraud
A fraudulent way of receiving money or by prompting a victim
to put their credentials into a fake login screen. - Correct
Answer ✅Invoice scams
, CompTIA Security+ (SY0-601) Exam
Questions and Answers (Latest Update
2025)
The process of gathering valid usernames, passwords, private
emails, and email addresses through infrastructure breaches.
- Correct Answer ✅Credential harvesting
A term for testing for potential vulnerabilities in a computer
network. - Correct Answer ✅Reconnaissance
A message warning the recipients of a non-existent computer
virus threat. - Correct Answer ✅Hoax
A form of fraud in which attackers pose as a known or trusted
person to dupe an employee into transferring money to a
fraudulent account, sharing sensitive information or revealing
login credentials. - Correct Answer ✅Impersonation
A targeted attack designed to compromise users within a
specific industry by infecting websites they typically visit and
luring them to a malicious site. - Correct Answer
✅Watering hole attack