exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 451 discussion

Actual exam question from CompTIA's SY0-601
Question #: 451
Topic #: 1
[All SY0-601 Questions]

A small, local company experienced a ransomware attack. The company has one web-facing server and a few workstations. Everything is behind an ISP firewall. A single web-facing server is set up on the router to forward all polls so that the server is viewable from the internet. The company uses an older version of third-party software to manage the website. The assets were never patched. Which of the following should be done to prevent an attack like this from happening again? (Choose three.)

  • A. install DLP software to prevent data loss
  • B. Use the latest version of software
  • C. Install a SIEM device
  • D. Implement MDM
  • E. Implement a screened subnet for the web server
  • F. Install an endpoint security solution
  • G. Update the website certificate and revoke the existing ones
  • H. Deploy additional network sensors
Show Suggested Answer Hide Answer
Suggested Answer: BEF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
fouserd
Highly Voted 2 years, 1 month ago
Selected Answer: BEF
B. Use the latest version of software: The company should upgrade to the latest version of the third-party software that is used to manage the website. Older versions of software often have known vulnerabilities that can be exploited by attackers. Upgrading to the latest version can help ensure that the company is using software that has the latest security patches and fixes. E. Implement a screened subnet for the web server: The company should implement a screened subnet, also known as a DMZ (demilitarized zone), to separate the web-facing server from the internal network. This will provide an additional layer of security by limiting the potential attack surface and reducing the risk of lateral movement by attackers. F. Install an endpoint security solution: An endpoint security solution should be installed on all workstations to protect against malware and ransomware. This can include anti-virus software, host-based firewalls, and other endpoint security controls.
upvoted 13 times
...
ApplebeesWaiter1122
Highly Voted 2 years, 1 month ago
Selected Answer: BEF
The following are the three actions that should be taken to prevent a ransomware attack from happening again: B. Use the latest version of software: Using the latest version of software will help to patch any vulnerabilities that may exist in older versions of the software. E. Implement a screened subnet for the web server: A screened subnet, or demilitarized zone (DMZ), can be used to isolate the web-facing server from the internal network and to restrict inbound and outbound traffic. F. Install an endpoint security solution: An endpoint security solution can help to protect workstations from malware and ransomware attacks.
upvoted 8 times
...
amilcar73
Most Recent 1 year, 4 months ago
Agreed with B, E and F
upvoted 1 times
...
DrCo6991
1 year, 5 months ago
Why not DLP? Asking so I can make the mental note to choose it over the DMZ. Is it because of the conversation being about a web server in the question?
upvoted 4 times
...
cyberPunk28
1 year, 6 months ago
Selected Answer: BEF
B. Use the latest version of software E. Implement a screened subnet for the web server F. Install an endpoint security solution
upvoted 1 times
...
staoic
2 years, 1 month ago
Selected Answer: BEF
To prevent an attack like this from happening again, the company should: B. Use the latest version of software to ensure that all known vulnerabilities are patched. E. Implement a screened subnet for the web server to add an additional layer of security between the web-facing server and the internet. F. Install an endpoint security solution to protect against malware and other threats. These measures can help improve the security of the company’s network and reduce the risk of future ransomware attacks. Is there anything else you would like to know?
upvoted 3 times
...
mouettespaghetti
2 years, 2 months ago
-BEF is correct B. Use the latest version of software: Using outdated third-party software can make the company vulnerable to ransomware attacks, as attackers can exploit vulnerabilities in the software. Updating to the latest version of the software can help to address known vulnerabilities and improve security. E. Implement a screened subnet for the web server: Placing the web-facing server in a screened subnet (also known as a DMZ) can help to isolate it from the rest of the network and prevent attackers from moving laterally within the network in case of a breach. A screened subnet typically includes a firewall that restricts access to and from the server, as well as additional security measures such as intrusion detection and prevention systems (IDS/IPS) and web application firewalls (WAFs). F. Install an endpoint security solution: Endpoint security solutions can help to protect the workstations from malware infections and detect and block malicious activities. This can include solutions such as antivirus, anti-malware, and host-based intrusion detection and prevention systems (HIDS/HIPS).
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...