CompTIA SY0-301 Exam Overview:
| Certification Vendor: | CompTIA |
|---|---|
| Exam Name: | CompTIA Security+ Certification Exam (SY0-301) |
| Exam Number: | SY0-301 |
| Passing Score: | 750 (on a scale of 100-900) |
| Exam Duration: | 90 minutes |
| Real Exam Qty: | Maximum 90 |
| Exam Price: | USD 311 (historical pricing, varies by region) |
| Available Languages: | Spanish, Portuguese, Japanese, English |
| Related Certifications: | CompTIA Security+ (SY0-401) CompTIA Security+ (SY0-501) |
| Exam Format: | Multiple-choice questions, Performance-based questions |
| Certificate Validity Period: | 3 years |
| Sample Questions: | CompTIA SY0-301 Sample Questions |
| Exam Way: | Testing center or online proctored exam |
| Pre Condition: | No mandatory prerequisites, but CompTIA Network+ and basic IT knowledge are recommended |
| Official Syllabus URL: | https://www.comptia.org/certifications/security |
CompTIA SY0-301 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Cryptography | 10% | - Encryption standards and algorithms - PKI and certificate management |
| Threats and Vulnerabilities | 21% | - Vulnerability assessment and mitigation - Types of malware and attacks |
| Network Security | 21% | - Secure network architecture concepts - Secure network components and devices |
| Access Control and Identity Management | 13% | - Account management and access control models - Authentication and authorization methods |
| Application, Data, and Host Security | 17% | - Host security and endpoint protection - Secure application development concepts |
| Compliance and Operational Security | 18% | - Risk management and security policies - Incident response procedures |
CompTIA Security+ Certification Exam (SY0-301) Sample Questions:
Question 1
Which of the following assessment techniques would a security administrator implement to ensure that systems and software are developed properly?
A. Input validation
B. Baseline reporting
C. Determine attack surface
D. Design reviews
Question 2
DRAG DROP
A Security administrator wants to implement strong security on the company smart phones and terminal servers located in the data center. Drag and Drop the applicable controls to each asset type.
Instructions: Controls can be used multiple times and not all placeholders needs to be filled. When you have completed the simulation, Please select Done to submit.
Question 3
Which of the following devices is BEST suited for servers that need to store private keys?
A. Hardened network firewall
B. Hardware security module
C. Solid state disk drive
D. Hardened host firewall
Question 4
A system administrator is using a packet sniffer to troubleshoot remote authentication. The administrator detects a device trying to communicate to TCP port 49. Which of the following authentication methods is MOST likely being attempted?
A. Kerberos
B. RADIUS
C. LDAP
D. TACACS+
Question 5
Which of the following BEST explains the use of an HSM within the company servers?
A. Data loss by removable media can be prevented with DLP.
B. Thumb drives present a significant threat which is mitigated by HSM.
C. Software encryption can perform multiple functions required by HSM.
D. Hardware encryption is faster than software encryption.
Solutions:
| Question 1 Answer: D | Question 2 Answer: Only visible for members | Question 3 Answer: B | Question 4 Answer: D | Question 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Miles

