exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 602 discussion

Actual exam question from CompTIA's SY0-701
Question #: 602
Topic #: 1
[All SY0-701 Questions]

A security analyst receives an alert that there was an attempt to download known malware. Which of the following actions would allow the best chance to analyze the malware?

  • A. Review the IPS logs and determine which command-and-control IPs were blocked.
  • B. Analyze application logs to see how the malware attempted to maintain persistence.
  • C. Run vulnerability scans to check for systems and applications that are vulnerable to the malware
  • D. Obtain and execute the malware in a sandbox environment and perform packet captures.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
21bc1a0
1 week, 4 days ago
Selected Answer: D
A sandbox is a isolated environment where you can safely run suspicious files without affecting your actual system. This allows the analyst to observe the malware's behavior and behavior without risking harm to the system
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago