exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 601 discussion

Actual exam question from CompTIA's SY0-601
Question #: 601
Topic #: 1
[All SY0-601 Questions]

Which of the following has been implemented when a host-based firewall on a legacy Linux system allows connections from only specific internal IP addresses?

  • A. Compensating control
  • B. Network segmentation
  • C. Transfer of risk
  • D. SNMP traps
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ApplebeesWaiter1122
Highly Voted 1 year, 9 months ago
*On Exam, Taken On July 31, 2023*
upvoted 24 times
mpengly88
1 year, 8 months ago
Ok……. What was your answer????
upvoted 2 times
klinkklonk
1 year, 3 months ago
Does it matter? They don't know which questions they got correct or incorrect.
upvoted 5 times
...
jbreezy89
1 year, 6 months ago
Brother scroll down....
upvoted 9 times
...
...
...
ApplebeesWaiter1122
Highly Voted 1 year, 9 months ago
Selected Answer: B
Network segmentation refers to the practice of dividing a network into smaller, isolated segments to improve security and control the flow of network traffic. In the scenario described, the host-based firewall on the legacy Linux system is configured to allow connections only from specific internal IP addresses. This is a form of network segmentation because it restricts access to the host from specific parts of the internal network while blocking access from other segments or external sources. This helps to isolate and protect the host from potential threats and unauthorized access.
upvoted 9 times
ApplebeesWaiter1122
1 year, 9 months ago
Coming back to the is questions.... It could also be A. I think the key word in the question is "Legacy." A compensating control is an alternative measure implemented to mitigate the risk when a required security control cannot be implemented as specified. In the scenario described, the host-based firewall on a legacy Linux system allows connections only from specific internal IP addresses. This configuration acts as a compensating control if the ideal network segmentation cannot be implemented due to it being a legacy system. Compensating controls are put in place to address security gaps and reduce risk in situations where the primary security control cannot be applied. Network segmentation might be the ideal solution, but if it cannot be implemented due to certain limitations or constraints like it being a legacy system, the host-based firewall with specific IP address restrictions can serve as a compensating control to achieve a similar level of security.
upvoted 16 times
...
...
Commando9800
Most Recent 2 months, 2 weeks ago
Selected Answer: A
Using a host-based firewall instead of replacing Legacy System = Compensating Control
upvoted 1 times
...
xBrynlee
10 months, 2 weeks ago
Selected Answer: A
Compensating control because you are implementing host-based firewall for the reason of it being a legacy Linux system. The reason I decided not to choose network segmentation is because based on COMPTIA Student Guide, it specifically mentions that the NOS firewall functions as a network segment, not the host-based firewall: • Host-based firewall (or personal firewall)—implemented as a software application running on a single host designed to protect that host only. As well as enforcing packet filtering ACLs, a personal firewall can be used to allow or deny software processes from accessing the network. • Network operating system (NOS) firewall—a software-based firewall running under a network server OS, such as Windows or Linux. The server would function as a gateway or proxy for a network segment.
upvoted 1 times
...
CG22
11 months, 4 weeks ago
Selected Answer: B
B is correct
upvoted 1 times
...
c56e966
1 year ago
B. Network segmentation. Network segmentation is a security strategy that involves dividing a computer network into smaller subnetworks, each with its own security measures. By implementing a host-based firewall on a legacy Linux system to allow connections only from specific internal IP addresses, you are essentially segmenting the network to control and restrict access based on predefined criteria. This helps in minimizing the potential attack surface and containing any security breaches within specific segments of the network.
upvoted 1 times
...
spearous
1 year ago
Selected Answer: B
legacy system doesn't mean they don't have segmentation control
upvoted 1 times
...
spearous
1 year ago
B, legacy system doesn't mean they don't have network segmentation.
upvoted 1 times
...
Geronemo
1 year ago
Selected Answer: B
When a host-based firewall on a legacy Linux system allows connections from only specific internal IP addresses, the security measure implemented is: B. Network segmentation. Network segmentation involves dividing a network into smaller, isolated segments to enhance security. By configuring the firewall to permit connections only from specific internal IP addresses, the network is effectively segmented, restricting access to authorized hosts while isolating the system from unauthorized or external sources. This enhances security by reducing the attack surface and controlling access within the network.
upvoted 2 times
...
ps1hacker
1 year, 2 months ago
Selected Answer: A
legacy always = compensate
upvoted 3 times
...
subaie503
1 year, 2 months ago
Selected Answer: A
LEGACY ==== COMPENSATE.
upvoted 4 times
...
caseymd85
1 year, 3 months ago
Selected Answer: A
Compensating controls are measures taken to address any weaknesses of existing controls or to compensate for the inability to meet specific security requirements due to various different constraints.
upvoted 1 times
...
ganymede
1 year, 4 months ago
Selected Answer: B
B. Network segmentation Both A and B are correct. But B is more specific so B is the best answer.
upvoted 1 times
...
SusAdmin
1 year, 5 months ago
In this scenario they're using a compensating control by segmenting the network. The answer is literally both A and B. Based on the information that is provided in the question, there is no way to tell which of the two is the right answer.
upvoted 1 times
...
touisuzuki
1 year, 8 months ago
Selected Answer: A
A. Compensating control In a legacy system where modern security practices or network segmentation may not be fully implemented, a compensating control could be used to provide additional security or restrict access. In this case, the host-based firewall rule allowing connections from specific internal IP addresses serves as a compensating control to restrict access and enhance security within the limitations of the legacy environment.
upvoted 2 times
...
John_Ferguson
1 year, 8 months ago
Selected Answer: A
Key word being legacy here, so it's compensating
upvoted 6 times
...
Abdul2107
1 year, 9 months ago
Selected Answer: A
A. Compensating. It's legacy device, and it allows only specific IPs to be connected with, so it's compensating.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago