exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 766 discussion

Actual exam question from CompTIA's SY0-601
Question #: 766
Topic #: 1
[All SY0-601 Questions]

A security audit of an organization revealed that most of the IT staff members have domain administrator credentials and do not change the passwords regularly. Which of the following solutions should the security team propose to resolve the findings in the most complete way?

  • A. Creating group policies to enforce password rotation on domain administrator credentials
  • B. Reviewing the domain administrator group, removing all unnecessary administrators, and rotating all passwords
  • C. Integrating the domain administrator's group with an IdP and requiring SSO with MFA for all access
  • D. Securing domain administrator credentials in a PAM vault and controlling access with role-based access control
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
johnabayot
Highly Voted 1 year, 4 months ago
I took the exam today and 90% from came from this dump I scored 800 so study this dump at least twice and you are good to go.
upvoted 23 times
Turbulence
1 year ago
Theres 860 questions, quite a bit to do it twice.
upvoted 6 times
...
...
psowrong
Highly Voted 1 year, 5 months ago
Selected Answer: B
It's B. since the question said that "most of the IT staff members have domain administrator credentials and do not change the passwords regularly". It probably means that there has not been an auditing to limit the access control and also passwords needs to be changed regularly. so. Option B fits perfect!
upvoted 8 times
...
pmarios
Most Recent 7 months, 3 weeks ago
Selected Answer: D
PAM with RBAC covers all question's requirements
upvoted 1 times
...
korj
7 months, 3 weeks ago
Selected Answer: D
While enforcing password rotation (Option A) or removing unnecessary administrators (Option B) addresses parts of the issue, PAM with RBAC covers both, along with added controls.
upvoted 1 times
...
korj
7 months, 3 weeks ago
Selected Answer: B
It's B because D doesn't directly address the fact that unnecessary admins should be removed.
upvoted 1 times
...
Jooomam
12 months ago
Selected Answer: B
B fits the question
upvoted 1 times
...
spearous
1 year, 1 month ago
Selected Answer: B
It's B. i think the focus is, most of IT stuff memeber has admin account, is this a good practice? No, we change it --->B yes, we keep it --->D that's why i chose B
upvoted 3 times
...
65333d6
1 year, 1 month ago
My immediate thought process was that it's definitely between B & D; however, after of bit I started to believe B may indeed be the most complete answer before doing some additional research on PAM and finally concluding that D is in fact the best answer. Why? Well, there's no doubt that D does in fact provide the best answer in regard to Admin privilege access, but I wondered if it did anything regarding the need for Password management/rotation. This brought me back to B, but it turns out that a PAM has some impressive capabilities that cover passwords. - Allows users to access the privileged account w/out knowing the password - Automatically change privilege account passwords periodically With this knowledge, it's definitely D.
upvoted 2 times
...
russian
1 year, 2 months ago
Selected Answer: D
D. Securing domain administrator credentials in a PAM vault and controlling access with role-based access control. Explanation: PAM (Privileged Access Management) solutions provide a centralized platform for securely storing, managing, and rotating privileged credentials, such as domain administrator credentials. By storing domain administrator credentials in a PAM vault, organizations can enforce strong access controls, audit trails, and session monitoring to ensure that only authorized personnel can access these credentials when necessary. Role-based access control (RBAC) allows organizations to assign specific permissions and privileges based on users' roles and responsibilities. By implementing RBAC, organizations can limit access to domain administrator credentials to only those who require them for their job duties, reducing the risk of unauthorized access.
upvoted 3 times
...
CircaG
1 year, 3 months ago
Selected Answer: B
This is from ChatGPT so take this with a grain of salt (I know ChatGPT can have wrong answers). However, I agree with it. D does not necessarily tackle the fact that the passwords need to continue changing. Now, let's discuss why option D may not be the correct choice: Option D suggests securing domain administrator credentials in a PAM vault and controlling access with role-based access control (RBAC). While using a PAM vault to secure privileged credentials is a good practice, and RBAC helps enforce access controls, the option may not fully address the issue of domain administrator credentials not being changed regularly.
upvoted 2 times
...
pinkdog
1 year, 4 months ago
Selected Answer: D
Privileged Access Management (PAM) solutions help organizations manage and secure privileged credentials, such as domain administrator credentials, by placing them in a centralized vault. PAM solutions enforce tight access controls, monitoring, and session recording for privileged accounts to mitigate the risks associated with misuse or compromise of such credentials.
upvoted 1 times
...
zecomeia_007
1 year, 4 months ago
Selected Answer: D
Better, most complete
upvoted 2 times
...
klinkklonk
1 year, 4 months ago
Selected Answer: D
in B why would you need to rotate the passwords for people you are removing privileges for? The word passwords in the question is a trap. Implementing RBA would remove the users who don't need access.
upvoted 2 times
...
caseymd85
1 year, 4 months ago
Selected Answer: B
D doesn't solve the issue of the extra people with admin privs.
upvoted 2 times
klinkklonk
1 year, 4 months ago
Yes it does because a role-based access control would be implemented.
upvoted 2 times
...
...
Cosmin1
1 year, 4 months ago
Selected Answer: D
'most complete way'
upvoted 2 times
...
johnabayot
1 year, 5 months ago
Selected Answer: D
B solves the issues the best
upvoted 5 times
...
Hs1208
1 year, 5 months ago
Selected Answer: D
PAM solutions are designed to secure, manage, and monitor privileged accounts.
upvoted 3 times
Hs1208
1 year, 5 months ago
it should be B
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...