Security+ (2020) Free Sample Questions

22 free sample questions980 in the full practice test Other versions: SY0-701(425),SY0-601(78)

Try simulator

SY0-501 Sample Questions

  1. Question 1

    Which of the following would a security specialist be able to determine upon examination of a server’s certificate?

    Answer and explanation

    Correct answer: D

    When examining a server certificate, security specialists can determine the Object Identifier (OID) which defines the certificate purpose and usage. The OID specifies what the certificate can be used for, such as SSL/TLS server authentication, code signing, or email encryption. The CA public key would be found in the CA certificate (not the server certificate), the server private key is never included in certificates (only the public key), and the CSR (Certificate Signing Request) is a separate document used during certificate creation, not embedded in the final certificate.

  2. Question 2

    A security analyst is diagnosing an incident in which a system was compromised from an external IP address. The socket identified on the firewall was traced to 207.46.130.0:6666.

    Which of the following should the security analyst do to determine if the compromised system still has an active connection?

    Answer and explanation

    Correct answer: B

    The netstat command is the correct tool to determine if the compromised connection to 207.46.130.0:6666 is still active on the local system. Netstat displays active network connections, listening ports, and routing tables, allowing the analyst to see if the socket connection is still established. Tracert traces the path to a destination, ping tests connectivity, and nslookup resolves domain names to IP addresses, but none of these show active connections like netstat does.

  3. Question 3

    Multiple organizations operating in the same vertical want to provide seamless wireless access fortheir employees as they visit the other organizations.

    Which of the following should be implemented if all the organizations use the native 802.1x client on their mobile devices?

    Answer and explanation

    Correct answer: B

    RADIUS federation is the correct solution for seamless wireless access across multiple organizations using native 802.1x clients. RADIUS federation allows organizations to establish trust relationships where employees can authenticate using their home organization credentials when visiting partner organizations. This works by federated RADIUS servers that can proxy authentication requests between trusted domains. Shibboleth, SAML, OAuth, and OpenID Connect are web-based federation protocols designed for browser applications, not native 802.1x wireless authentication which requires RADIUS infrastructure for EAP authentication protocols.

  4. Question 4

    Which of the following BEST describes an important security advantage yielded by implementing vendor diversity?

    Answer and explanation

    Correct answer: C

    Resiliency is the primary security advantage of implementing vendor diversity in security architectures. When organizations use multiple vendors for security solutions, they reduce single points of failure and minimize the impact of vendor-specific vulnerabilities or exploits. If one vendor solution is compromised, others remain functional, maintaining overall security posture. Sustainability refers to long-term viability, homogeneity means using similar systems (opposite of diversity), and configurability relates to customization options rather than security advantages.

  5. Question 5

    In a corporation where compute utilization spikes several times a year, the Chief Information Officer (CIO) has requested a cost-effective architecture to handle the variable capacity demand.

    Which of the following characteristics BEST describes what the CIO has requested?

    Answer and explanation

    Correct answer: A

    Elasticity is the optimal characteristic for handling variable capacity demand with cost-effectiveness. Elasticity allows systems to automatically scale resources up during demand spikes and scale down during low usage periods, ensuring you only pay for resources actually used. This automated provisioning and de-provisioning based on current demand is ideal for organizations with periodic spikes. Scalability refers to the ability to handle increased load but doesn't necessarily include the automatic scaling down for cost savings. High availability and redundancy focus on uptime rather than cost-effective capacity management.

  6. Question 6

    A security engineer is configuring a system that requires the X.509 certificate information to be pasted into a form field in Base64 encoded format to import it into the system.

    Which of the following certificate formats should the engineer use to obtain the information in the required format?

    Answer and explanation

    Correct answer: B

    PEM (Privacy-Enhanced Mail) format is the correct choice for pasting X.509 certificate information in Base64 encoded format. PEM certificates use Base64 encoding with BEGIN/END certificate markers, making them suitable for copying and pasting into form fields. PFX is a binary format used for certificate bundles with private keys, DER is a binary ASN.1 encoding that cannot be pasted as text, and P7B is used for certificate chains but not typically for single certificate imports in web forms.

  7. Question 7

    Which of the following attacks specifically impacts data availability?

    Answer and explanation

    Correct answer: A

    A Distributed Denial of Service (DDoS) attack specifically impacts data availability by overwhelming the target system with traffic from multiple sources, making resources unavailable to legitimate users. DDoS attacks use botnets or multiple compromised systems to generate massive traffic volumes that exhaust system resources. Unlike Trojans which focus on unauthorized access, MITM attacks that intercept communications, or rootkits that hide malicious activity, DDoS attacks directly target the availability component of the CIA triad by denying service to legitimate users through resource exhaustion.

  8. Question 8

    Multiple answers

    A security analyst is hardening a server with the directory services role installed. The analyst must ensure LDAP traffic cannot be monitored or sniffed and maintains compatibility with LDAP clients.

    Which of the following should the analyst implement to meet these requirements? (Choose two.)

    Answer and explanation

    Correct answers: A, D

    To secure LDAP traffic from monitoring and sniffing while maintaining client compatibility, you must generate an X.509-compliant certificate signed by a trusted CA and ensure port 636 is open for LDAPS communication. LDAPS (LDAP over SSL/TLS) encrypts LDAP communications using SSL/TLS on port 636, preventing eavesdropping and man-in-the-middle attacks. The X.509 certificate provides authentication and establishes the encrypted tunnel. This approach maintains compatibility with modern LDAP clients that support LDAPS while securing directory service communications against network sniffing attacks.

  9. Question 9

    Which of the following threat actors is MOST likely to steal a company’s proprietary information to gain a market edge and reduce time to market?

    Answer and explanation

    Correct answer: A

    When conducting threat modeling and risk assessment, competitors represent external threat actors who may attempt to gain unauthorized access to sensitive business information, trade secrets, or intellectual property. Competitors have clear motivation to access confidential data that could provide business advantages such as pricing strategies, product development plans, or customer lists. This threat differs from nation-state actors, hacktivists, or insider threats as the motivation is primarily competitive business advantage rather than political, ideological, or personal gain.

  10. Question 10

    A penetration tester is crawling a target website that is available to the public.

    Which of the following represents the actions the penetration tester is performing?

    Answer and explanation

    Correct answer: B

    Reconnaissance is the first phase of the cyber kill chain where attackers gather information about the target organization, systems, and potential vulnerabilities. This passive intelligence gathering includes techniques like social engineering, dumpster diving, network scanning, OSINT collection, and footprinting to map the attack surface. Reconnaissance helps attackers identify entry points, understand the target environment, and plan subsequent attack phases like weaponization and delivery.

  11. Question 11

    Multiple answers

    Which of the following characteristics differentiate a rainbow table attack from a brute force attack? (Choose two.)

    Answer and explanation

    Correct answers: B, E

    Rainbow tables are distinguished from brute force attacks by requiring precomputed hashes and bypassing maximum failed login restrictions. Rainbow tables use time-memory trade-offs with precomputed hash chains to crack passwords faster than brute force, but require significant storage space for the precomputed data. Unlike brute force attacks that generate hash attempts in real-time and can be blocked by account lockout policies, rainbow table attacks work offline against captured hash databases without triggering login attempt limits. This makes rainbow tables faster for known hash algorithms but limited by available precomputed tables.

Register free to unlock 11 more sample questions

Lifetime One

Own this practice test forever.

$64.99
$61.74
one-time
  • Full access to 1,483 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon