SY0-501 Sample Questions

SY0-501 Sample Questions & Answers

Free Security+ (2020) practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full SY0-501 simulator →

Showing 11 of 22 free samples.

  1. Question 1

    A security engineer is configuring a system that requires the X.509 certificate information to be pasted into a form field in Base64 encoded format to import it into the system.

    Which of the following certificate formats should the engineer use to obtain the information in the required format?

    Show answer & explanation

    Correct answer: B

    PEM (Privacy-Enhanced Mail) format is the correct choice for pasting X.509 certificate information in Base64 encoded format. PEM certificates use Base64 encoding with BEGIN/END certificate markers, making them suitable for copying and pasting into form fields. PFX is a binary format used for certificate bundles with private keys, DER is a binary ASN.1 encoding that cannot be pasted as text, and P7B is used for certificate chains but not typically for single certificate imports in web forms.

  2. Question 2

    Which of the following attacks specifically impacts data availability?

    Show answer & explanation

    Correct answer: A

    A Distributed Denial of Service (DDoS) attack specifically impacts data availability by overwhelming the target system with traffic from multiple sources, making resources unavailable to legitimate users. DDoS attacks use botnets or multiple compromised systems to generate massive traffic volumes that exhaust system resources. Unlike Trojans which focus on unauthorized access, MITM attacks that intercept communications, or rootkits that hide malicious activity, DDoS attacks directly target the availability component of the CIA triad by denying service to legitimate users through resource exhaustion.

  3. Question 3Select 2

    A security analyst is hardening a server with the directory services role installed. The analyst must ensure LDAP traffic cannot be monitored or sniffed and maintains compatibility with LDAP clients.

    Which of the following should the analyst implement to meet these requirements? (Choose two.)

    Show answer & explanation

    Correct answers: A, D

    To secure LDAP traffic from monitoring and sniffing while maintaining client compatibility, you must generate an X.509-compliant certificate signed by a trusted CA and ensure port 636 is open for LDAPS communication. LDAPS (LDAP over SSL/TLS) encrypts LDAP communications using SSL/TLS on port 636, preventing eavesdropping and man-in-the-middle attacks. The X.509 certificate provides authentication and establishes the encrypted tunnel. This approach maintains compatibility with modern LDAP clients that support LDAPS while securing directory service communications against network sniffing attacks.

    To secure LDAP traffic from monitoring and sniffing while maintaining client compatibility, you must generate an X.509-compliant certificate signed by a trusted CA and ensure port 636 is open for LDAPS communication. LDAPS (LDAP over SSL/TLS) encrypts LDAP communications using SSL/TLS on port 636, preventing eavesdropping and man-in-the-middle attacks. The X.509 certificate provides authentication and establishes the encrypted tunnel. This approach maintains compatibility with modern LDAP clients that support LDAPS while securing directory service communications against network sniffing attacks.

  4. Question 4

    Which of the following threat actors is MOST likely to steal a company’s proprietary information to gain a market edge and reduce time to market?

    Show answer & explanation

    Correct answer: A

    When conducting threat modeling and risk assessment, competitors represent external threat actors who may attempt to gain unauthorized access to sensitive business information, trade secrets, or intellectual property. Competitors have clear motivation to access confidential data that could provide business advantages such as pricing strategies, product development plans, or customer lists. This threat differs from nation-state actors, hacktivists, or insider threats as the motivation is primarily competitive business advantage rather than political, ideological, or personal gain.

  5. Question 5

    A penetration tester is crawling a target website that is available to the public.

    Which of the following represents the actions the penetration tester is performing?

    Show answer & explanation

    Correct answer: B

    Reconnaissance is the first phase of the cyber kill chain where attackers gather information about the target organization, systems, and potential vulnerabilities. This passive intelligence gathering includes techniques like social engineering, dumpster diving, network scanning, OSINT collection, and footprinting to map the attack surface. Reconnaissance helps attackers identify entry points, understand the target environment, and plan subsequent attack phases like weaponization and delivery.

  6. Question 6Select 2

    Which of the following characteristics differentiate a rainbow table attack from a brute force attack? (Choose two.)

    Show answer & explanation

    Correct answers: B, E

    Rainbow tables are distinguished from brute force attacks by requiring precomputed hashes and bypassing maximum failed login restrictions. Rainbow tables use time-memory trade-offs with precomputed hash chains to crack passwords faster than brute force, but require significant storage space for the precomputed data. Unlike brute force attacks that generate hash attempts in real-time and can be blocked by account lockout policies, rainbow table attacks work offline against captured hash databases without triggering login attempt limits. This makes rainbow tables faster for known hash algorithms but limited by available precomputed tables.

    Rainbow tables are distinguished from brute force attacks by requiring precomputed hashes and bypassing maximum failed login restrictions. Rainbow tables use time-memory trade-offs with precomputed hash chains to crack passwords faster than brute force, but require significant storage space for the precomputed data. Unlike brute force attacks that generate hash attempts in real-time and can be blocked by account lockout policies, rainbow table attacks work offline against captured hash databases without triggering login attempt limits. This makes rainbow tables faster for known hash algorithms but limited by available precomputed tables.

  7. Question 7

    Which of the following best describes routine in which semicolons, dashes, quotes, and commas are removed from a string?

    Show answer & explanation

    Correct answer: C

    Input validation is the primary defense against SQL injection attacks by ensuring that user-supplied data is properly sanitized before being processed by database queries. Proper input validation includes parameterized queries, stored procedures, whitelist validation, and escaping special characters to prevent malicious SQL code from being executed. Without input validation, attackers can manipulate database queries to extract sensitive data, modify records, or gain unauthorized access to the database system.

  8. Question 8

    A security analyst wishes to increase the security of an FTP server. Currently, all traffic to the FTP server is unencrypted. Users connecting to the FTP server use a variety of modern FTP client software.

    The security analyst wants to keep the same port and protocol, while also still allowing unencrypted connections.

    Which of the following would BEST accomplish these goals?

    Show answer & explanation

    Correct answer: C

    Using explicit FTPS (File Transfer Protocol Secure) provides encrypted file transfers by adding TLS/SSL encryption to standard FTP communication. Explicit FTPS starts as a normal FTP connection on port 21 and then upgrades to secure communication, unlike implicit FTPS which uses port 990 from the beginning. This ensures data confidentiality and integrity during file transfers, protecting against eavesdropping and man-in-the-middle attacks that could compromise sensitive file contents.

  9. Question 9

    Which of the following explains why vendors publish MD5 values when they provide software patches for their customers to download over the Internet?

    Show answer & explanation

    Correct answer: A

    Digital signatures on software patches allow recipients to verify the integrity and authenticity of the patch by confirming it has not been tampered with and originates from the legitimate vendor. The digital signature uses cryptographic hashing and public key cryptography to create a unique fingerprint that changes if the patch is modified. This prevents supply chain attacks where malicious actors distribute compromised patches and ensures administrators can trust that patches are genuine and unaltered.

  10. Question 10

    Refer to the following code below.

    Which of the following vulnerabilities would occur if this is executed?

    SY0-501 sample question 10
    Show answer & explanation

    Correct answer: D

    Based on the Java code shown in the image, this code contains a critical null pointer vulnerability. The code declares 'object blue = null;' and then immediately calls 'blue.hashcode()' without checking if blue is null first. This will throw a NullPointerException at runtime, causing the application to crash. The missing null check represents a common security vulnerability that can lead to denial of service conditions and application instability. Proper defensive programming requires null validation before calling methods on object references to prevent unexpected program termination and potential security exploits.

Ready for the real thing?

The full SY0-501 simulator has every exam-style question, timed mode, and instant scoring.