Please log in to purchase this document.

CompTIA Security SY0-601 Study Guide

CAREER EXAMS Aug 4, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

1 / 18

CompTIA Security+ SY0-601 Study Guide 1.What type of certificate does a CA have ANS Root Certificate; used to sign keys 2.If I am going to use a CA internally, what type of CA should I use ANS Private CA 3.If I want to carry out a B2B activity with third-party companies or sell products on the web, what type of certificate should I use ANS Public CA 4.Why would I make my CA offline when not in use ANS Military, Security, or Banking Organizations; preventing data from being compromised.

5.Who signs X.509 certificates ANS Central Authorities (CA) 6.Who builds the CA or intermediate authorities ANS Architect 7.What can I use to prevent my CA from being compromised and fraudulent certificates being issued ANS Certificate Pinning 1 / 4

2 / 18

8.If two entities what to set up a cross-certification, what must they set up first ANS Root CAs using a bridge trust model 9.What type of trust model does PGP use ANS Web of Trust 10.How can I tell if my certificate is valid ANS Certificate Revocation List (CRL) 11.If the CRL is going slow, what should I implement ANS Online Certification Status Protocol (OCSP)

12.Explain certificate stapling/OCSP stapling: Web servers use an OCSP

for faster authentication bypassing the CRL

13.What is the process of obtaining a new certificate: Certificate

Signing Request (CSR) 14.What is the purpose of key escrow ANS Holds an provides access to 3rd party keys provided the need.

15.What is the purpose of Hardware Security Model (HSM): Used by

key escrow to store and manage keys 16.What is the purpose of DRA and what does it require in order to complete its role effectively ANS When a users private key becomes corrupt, the DRA recov- ers data by obtaining a copy of the private key 2 / 4

3 / 18

from the key escrow.

17.How can I identify each certificate: Object Identifier (OID) or the

serial number 18.What format is a private certificate ANS P12 19.What file extension is a private certificate ANS .pfx extension 20.What format is a public certificate ANS P7B 3 / 4

4 / 18

21.What file extension is a public certificate ANS .cer extension 22.What format is a PEM certificate ANS Base64 23.What type of certificate can be used on multiple servers in the

same domain: Wildcard (denoted by a *)

24.What type of certificate can be used on multiple domains ANS Subject Alter- native Name (SAN) 25.What should I do with my software to verify that it is original and not a fake copy (verify integrity) ANS Code Signing 26.What is the purpose of extended validation of an X.509 certificate ANS Pro- vides Financial institutions with a higher level of trust.

27.What is the purpose of DH ANS Creates a secure tunnel; during a VPN connec- tion (on port 500), used during IKE 28.What two things does digitally signing an email provide ANS Integrity and Non-repudiation 29.What asymmetric encryption algorithm should I use to encrypt data on a smartphone ANS ECC (Elliptic Curve Cryptography) 30.What shall I use to encrypt a military mobile phone ANS AES-256

  • / 4

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: CAREER EXAMS
Added: Aug 4, 2025
Description:

CompTIA Security+ SY0-601 Study Guide 1.What type of certificate does a CA have ANS Root Certificate; used to sign keys 2.If I am going to use a CA internally, what type of CA should I use ANS Priv...

Get this document $30.00