exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 539 discussion

Actual exam question from CompTIA's SY0-701
Question #: 539
Topic #: 1
[All SY0-701 Questions]

A SOC analyst establishes a remote control session on an end user’s machine and discovers the following in a file:

gmail.com[ENT][email protected][ENT]NoOneCanGuessThis123! [ENT]Hello Susan, it was great to see you the other day! Let’s plan a followup[BACKSPACE]follow-up meeting soon. Here is the link to register. [RTN][CTRL]c [CTRL]v [RTN]after[BACKSPACE]After you register give me a call on my cellphone.

Which of the following actions should the SOC analyst perform first?

  • A. Advise the user to change passwords.
  • B. Reimage the end user’s machine.
  • C. Check the policy on personal email at work.
  • D. Check host firewall logs.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nocwyn
1 month, 3 weeks ago
Selected Answer: B
If they have a keylogger, you cant be sure what type of malware or if its just 1. You reimage the machine.
upvoted 1 times
nocwyn
1 month, 3 weeks ago
It also says what should you do first? If you change your password with the keylogger installed you have accomplished nothing aside from giving them the new password too.
upvoted 1 times
...
...
cab08df
2 months, 3 weeks ago
Selected Answer: A
A. Only because the user could use a different device to change their password that is currently exposed.
upvoted 1 times
...
fc040c7
3 months, 1 week ago
Selected Answer: A
Keylogger present. First priority should be to tell them to change their password. Afterwards, take care of the keylogger issue.
upvoted 1 times
...
AriGarcia
3 months, 1 week ago
Selected Answer: A
Although the SOC analyst should reimage the computer to get rid of the keyloger. The first thing to do is have the user change passwordl.
upvoted 1 times
...
Bunaventi
3 months, 1 week ago
Selected Answer: A
I think a) advise to change pw is better than B) reimage the end user because changing the exposed password immediately prevents unauthorized access, whereas reimaging the machine is a more drastic step that comes later after confirming a compromise.
upvoted 1 times
...
b422ce6
3 months, 1 week ago
Selected Answer: B
Changing the password on an infected machine would do no good, as the password could still be leaked with a keylogger, etc. Reimaging the system FIRST would be best in this scenario.
upvoted 2 times
...
1eccfc0
3 months, 2 weeks ago
Selected Answer: A
The correct answer is A. Advise the user to change passwords. Here's why: The file contains sensitive information, including an email address and a password ("NoOneCanGuessThis123!"), along with a suspicious message that includes commands like "[CTRL]c" and "[CTRL]v" (which may indicate attempts to copy/paste content, possibly in a malicious context). The immediate concern is the password being exposed. Given that the password appears in plaintext, the first action should be to advise the user to change their password—especially since it may be associated with a critical account (e.g., Gmail) that could be used for further attacks. It’s also important to ensure that the user is aware of the potential compromise and that the password isn't being used elsewhere.
upvoted 3 times
...
Clau95
3 months, 2 weeks ago
Selected Answer: B
Answer B - To ensure the integrity of the system and prevent any further compromise, the first priority should be to reimage the end user's machine. Reimaging will remove any potential malware or unauthorized software that may be affecting the system.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago