exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 710 discussion

Actual exam question from CompTIA's SY0-601
Question #: 710
Topic #: 1
[All SY0-601 Questions]

A recent vulnerability scan revealed multiple servers have non-standard ports open for applications that are no longer in use. The security team is working to ensure all devices are patched and hardened. Which of the following would the security team perform to ensure the task is completed with minimal impact to production?

  • A. Enable HIDS on all servers and endpoints.
  • B. Disable unnecessary services.
  • C. Configure the deny list appropriately on the NGFW.
  • D. Ensure the antivirus is up to date.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Rowdy_47
Highly Voted 1 year, 6 months ago
Selected Answer: B
My 5c here from a networking perspective The task is to harden endpoints A deny list on a FW is not hardening endpoints so that's out Of the choices left, enabling a HIDS is not really going to harden the endpoint, its essentially just detection and logging / alerting AV would definitely harden the system but still doesn't complete the task of closing the unused ports IMO Using the vulnerability scan results and list of apps no longer in use you can disable the unnecessary services which will stop the endpoints from listening on non-standard ports. I feel B fits best here as it actually addresses the result of the scan and would most likely also be the recommendation in the scan too.
upvoted 6 times
...
Jackwasblk
Highly Voted 1 year, 5 months ago
Selected Answer: B
applications that are no longer in use = services
upvoted 5 times
...
LayinCable
Most Recent 11 months, 3 weeks ago
Selected Answer: B
It can't be 'B,' because for 1: it's a "Detection system," which is nowhere as good or sophisticated as a "Prevention system." and also 2: enabling HIDS still allows the unnecessary services/ports to still coexist with the HIDS. The HIDS will ONLY tell you when there is a problem, it doesn't do anything to stop it. Therefore, still allowing any problem to persist. If you disable unnecessary services (A.), then you stop the problem right at the source where it starts.
upvoted 1 times
...
Geronemo
1 year ago
Selected Answer: B
Here's why: Minimizing attack surface: By disabling unnecessary services, the security team reduces the attack surface of the servers. Services running on non-standard ports for applications that are no longer in use can be potential entry points for attackers. Disabling these services removes unnecessary points of vulnerability. Reducing resource utilization: Unnecessary services consume system resources such as CPU, memory, and network bandwidth. Disabling these services can free up resources, potentially improving the performance and stability of the servers without impacting production services.
upvoted 1 times
...
DChilds
1 year, 6 months ago
Selected Answer: B
B - This is because the question mentions that there are non-standard ports open for applications that are no longer in use. Disabling these unnecessary services would close these open ports and reduce potential attack vectors, without affecting the production environment.
upvoted 4 times
...
DashRyde
1 year, 7 months ago
Selected Answer: A
Answer "A" has a minimal impact rather than "B" disabling unnecessary services
upvoted 1 times
...
233Matis
1 year, 7 months ago
Try to paste same question couple times in ChatGPT. The answer is different (almost) every time
upvoted 1 times
eddy72
1 year, 2 months ago
No,it's not.I tried 4 times.
upvoted 1 times
...
...
James_Tye
1 year, 7 months ago
Selected Answer: A
I could be mistaken with what they are looking for, but from a practical standpoint, there isn't a good way to determine what services can be disabled on production servers without causing an issue. The best and fastest way to protect the environment would be to have a good end point detection and response client first.
upvoted 3 times
James_Tye
1 year, 7 months ago
I don't trust ChatGPT, but it says disable services (B). Which I can appreciate if there is a good list of safe services to disable.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago