exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 922 discussion

Actual exam question from CompTIA's SY0-501
Question #: 922
Topic #: 1
[All SY0-501 Questions]

Joe, a user at a company, clicked an email link that led to a website that infected his workstation. Joe was connected to the network, and the virus spread to the network shares. The protective measures failed to stop this virus, and it has continued to evade detection. Which of the following should a security administrator implement to protect the environment from this malware?

  • A. Install a definition-based antivirus.
  • B. Implement an IDS/IPS.
  • C. Implement a heuristic behavior-detection solution.
  • D. Implement CASB to protect the network shares.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Cindan
Highly Voted 4 years, 3 months ago
Fire Joe and Ann. No more questigons
upvoted 15 times
...
Joker20
Highly Voted 4 years, 4 months ago
keywords : protect B will prevent , stop , block if we talking with IPS C answer will just detect will not prevent or protect
upvoted 10 times
Joker20
4 years, 4 months ago
Implement a heuristic behavior-DETECTION solution.
upvoted 6 times
...
...
ID77
Most Recent 1 year, 3 months ago
Selected Answer: C
Implement a heuristic behavior detection solution.
upvoted 1 times
...
SophyQueenCR82
2 years, 3 months ago
C--EXAM TIP Heuristic scanning is a method of detecting potentially malicious or “virus-like” behavior by examining what a program or section of code does. Anything that is “suspicious” or potentially “malicious” is closely examined to determine whether or not it is a threat to the system. Using heuristic scanning, an antivirus product attempts to identify new viruses or heavily modified versions of existing viruses before they can damage your system.
upvoted 1 times
...
SophyQueenCR82
2 years, 3 months ago
C. Implement a heuristic behavior-detection solution. Most Voted heuristic behavior detects unknowns virus
upvoted 1 times
...
RRabbit_111
2 years, 7 months ago
Heuristic analysis is also one of the few methods capable of combating polymorphic viruses -- the term for malicious code that constantly changes and adapts. Heuristic analysis is incorporated into advanced security solutions offered by companies like Kaspersky Labs to detect new threats before they cause harm, without the need for a specific signature.
upvoted 1 times
...
adrian202221
3 years ago
The question says that the protective measures failed to stop the virus, here, the protective measures were not mentioned and could have been IDS/IPS. Again, the fact that the virus has continuously evaded detection means that there is a detection system in place, perhaps an IDS. This is where a heuristic behavior-detection becomes necessary because it makes use of AI to monitor strange behaviors. I would go for C.
upvoted 2 times
...
[Removed]
4 years, 2 months ago
B seems correct because it has IDS and IPS. We are trying to DETECT because the question says it has continued to evade detection. To detect, IDS makes sense.
upvoted 1 times
...
zadams16
4 years, 3 months ago
i feel like this would be B becuase cant you include Heuristic based detection system in an IDS solution. In which case option B would include option C and would be the better answer since it has more options for protection
upvoted 1 times
...
stibadd
4 years, 3 months ago
… and it has continued to evade detection. Which of the following should a security administrator implement to protect the environment …? So it continues to avoid detection (IDS) and the administrator was to protect (IPS). The other argument is if it is avoiding detection then C with a follow-up to prevent it from continuing to happen. IMO answer B sounds stronger, but this seems like it could be a toss-up. Sticking with B because it satisfies both issues, detect and protect.
upvoted 1 times
...
Lumeya
4 years, 5 months ago
"The protective measures failed to stop this virus." The question doesn't specify the type of protective measures implemented. Maybe the security measures implemented did not include IDS/IPS. So, I would go with B.
upvoted 1 times
...
Groove120
4 years, 5 months ago
Concurring with SQLinjector - focusing on the keywords "protect the environment" leaves B over C IMO. Wouldn't Inline IPS trump heuristic detection in terms of actually blocking malicious packets from Joe's WS (or other infected workstations) to the SAN?
upvoted 1 times
...
idoIL
4 years, 6 months ago
way not C?
upvoted 3 times
SQLinjector
4 years, 6 months ago
it's probably because the question is about "protect the environment" which is not necessarily the host that got infected first
upvoted 1 times
...
Herbie1995
4 years, 6 months ago
i am only guessing but i think because it would only detect the virus not protect it where a ips may protect it?
upvoted 1 times
...
JasonSignupHappy
4 years, 5 months ago
The answer IS in fact C. Go look it up. Many of the answers on this site are wrong. You are required to do your own research. The wrong answers are meant to fail people for cheating by pattern matching for people who just memorize all the answers
upvoted 5 times
skuppper_12
4 years ago
The question is not only focussed on detection. Had that been the case, Option C is right. They want to detect and protect - I can have Heuristics based IDS and IPS systems in play which has not been explicitly stated in Option B. They have left it as just IDS /IPS. This is my justification for choosing the stated option. Moreover, we all are trying to help each other to better understand the concepts.
upvoted 1 times
...
bobthebuilder55110
4 years, 4 months ago
Well, please explain how heuristic based Intrusion detection system can prevent an attack? I think as per Darriel Gibson and professor Messer it shows that it would detect using AI and next gen tech but not prevent anything
upvoted 4 times
...
Heymannicerouter
4 years, 1 month ago
No. C only detects, doesn't protect.
upvoted 1 times
...
...
whitehathehe
4 years, 1 month ago
B is correct. C wont stop the attack, it will only detect.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...