exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 64 discussion

Actual exam question from CompTIA's SY0-501
Question #: 64
Topic #: 1
[All SY0-501 Questions]

A user clicked an email link that led to a website than infected the workstation with a virus. The virus encrypted all the network shares to which the user had access. The virus was not deleted or blocked by the company's email filter, website filter, or antivirus. Which of the following describes what occurred?

  • A. The user's account was over-privileged.
  • B. Improper error handling triggered a false negative in all three controls.
  • C. The email originated from a private email server with no malware protection.
  • D. The virus was a zero-day attack.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Basem
Highly Voted 5 years, 3 months ago
The question states there was a virus infection. Why would it be false negative ? it is D for sure. Since non of the defenses were able to detect the virus.
upvoted 11 times
...
MSZ
Highly Voted 5 years, 6 months ago
It should be D
upvoted 9 times
...
MortG7
Most Recent 3 years, 9 months ago
"The virus was not deleted or blocked by the company's email filter, website filter, or antivirus" they are hinting that the environment is fairly secure..since it was not caught by any of these system, it is something new...that is my logic for zero-day....and we can respectfully disagree :)
upvoted 3 times
...
exiledwl
3 years, 11 months ago
D...not an ideal answer, but kind of a vague question and given the other choices, it is most appropriate
upvoted 3 times
...
maxjak
4 years, 3 months ago
KEY words: The virus was not deleted or blocked email filter, website filter, or antivirus so what do you think is known malware or unknown Virus ?
upvoted 1 times
...
Tauhid
4 years, 4 months ago
Answer: D A zero-day vulnerability is a weakness or bug that is unknown to trusted sources, such as operating system and antivirus vendors. A zeroday attack exploits an undocumented vulnerability. Many times, the vendor isn’t aware of the issue. At some point, the vendor learns of the vulnerability and begins to write and test a patch to eliminate it. However, until the vendor releases the patch, the vulnerability is still a zero-day vulnerability.
upvoted 2 times
...
renegade_xt
4 years, 6 months ago
D. There is no way to know if the user should have had access to all those locations or not, so no way to know if he or she was over-privileged. We do know that none of the software designed to detect a virus was triggered, so that suggests that it could be a zero-day attack.
upvoted 2 times
renegade_xt
4 years, 6 months ago
Cannot be B, because failure of 3 systems is highly unlikely.
upvoted 2 times
MagicianRecon
4 years, 5 months ago
Its very likely when its a zero day. You can have a failure of vendor diversity as well since no one knows the malware signatures yet
upvoted 2 times
...
...
...
majid94
4 years, 7 months ago
D is the most proper answer in this situation. Because it says a virus
upvoted 1 times
...
nickyjohn
5 years ago
improper error handling is generally a function of secure coding concepts, this is question poses a virus that's signature was not held in the database for the filters or antivirus. Its D
upvoted 1 times
...
macshild
5 years ago
most sources will say B but guys let's use common sense , the attack was a virus but the anti virus couldn't detected ,typically company anti virus are always up to date with the latest definitions and heuristics , the fact that the anti virus didn't recognize it means it was a zero-day virus this means the virus is unknown to any antivirus therefore it couldn't detect it
upvoted 2 times
...
K123
5 years ago
Aren't zero day attacks specific to software vulnerabilities unknown to the software vendors? The only software in use here is email which phished the user to a site that infected the user AND all of the network resources the user had access too. So, it would seem to me that this is a case of the user being over authorized, so A should be the answer.
upvoted 1 times
...
bk45
5 years ago
The answer is D, because the virus wasn't deleted or blocked by the company filters/antivirus. That is the definition of a zero-day attack... The vendors don't know what to patch yet. Hence *zero day*
upvoted 2 times
...
mysecurity
5 years ago
The virus was a Zero-day attack.
upvoted 1 times
...
mysecurity
5 years ago
The virus was a zero-day attack.
upvoted 1 times
...
AnAverageUser3656
5 years, 1 month ago
D is correct. The clue here is "The virus was not deleted or blocked by the company’s email filter, website filter, or antivirus."
upvoted 4 times
...
mrlee
5 years, 3 months ago
so most secure way to protect the system is having different anti virus vendor on each different place. B seems like a less chance to get infected with strong security implemented
upvoted 1 times
...
Abner89
5 years, 6 months ago
In fact, I'm almost certain. There's no proof that there was an escalation while it explicitly states the case for B.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago