SY0-601 CompTIA Security+ Exam

Loading demo links...

Showing 13–15 of 20 questions

Question 13

The security team received a report of copyright infringement from the IP space of the corporate network. The report provided a precise time stamp for the incident as well as the name of the copyrighted files. The analyst has been tasked with determining the infringing source machine and instructed to implement measures to prevent such incidents from occurring again. Which of the following is MOST capable of accomplishing both tasks?

Select an option, then click Submit answer.

  • HIDS

  • Allow list

  • TPM

  • NGFW

Question 14

A client sent several inquiries to a project manager about the delinquent delivery status of some critical reports. The project manager claimed the reports were previously sent via email, but then quickly generated and backdated the reports before submitting them as plain text within the body of a new email message thread. Which of the following actions MOST likely supports an investigation for fraudulent submission?

Select an option, then click Submit answer.

  • Establish chain of custody

  • Inspect the file metadata

  • Reference the data retention policy

  • Review the email event log

Question 15

A Chief Security Officer (CSO) has asked a technician to devise a solution that can detect unauthorized execution privileges form the OS in both executable and data files and can work in conjunction with proxies or UTM. Which of the following would BEST meet the CSO’s requirements?

Select an option, then click Submit answer.

  • Fuzzing

  • Sandboxing

  • Static code analysis

  • Code review