exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 948 discussion

Actual exam question from CompTIA's SY0-501
Question #: 948
Topic #: 1
[All SY0-501 Questions]

An analyst has determined that a server was not patched and an external actor exfiltrated data on port 139. Which of the following sources should the analyst review to BEST ascertain how the incident could have been prevented?

  • A. The vulnerability scan output
  • B. The security logs
  • C. The baseline report
  • D. The correlation of events
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Big_ram
1 year, 6 months ago
I choose A because an analyst has determined a server was not patched, it means a vulnerability, it is from internal. If a system was attacked, it will have recorded on security log. If you haven't gotten attacked, how can security log have such thing? Just a vulnerability from internal system, should use vulnerability scan.
upvoted 1 times
...
hrncgl
1 year, 8 months ago
Why not D?
upvoted 1 times
...
SophyQueenCR82
2 years, 1 month ago
a---To best ascertain how the incident could have been prevented, the analyst should review the vulnerability scan. The fact that the server was not patched indicates that there was a vulnerability that was not addressed, which allowed the external actor to exfiltrate data. Reviewing the vulnerability scan will help identify the specific vulnerability that was exploited and determine why it was not patched. The security logs may provide additional information about the attack itself, but they are unlikely to reveal the underlying vulnerability that allowed the attack to occur.
upvoted 3 times
...
Ahmed_aldouky
2 years, 2 months ago
Selected Answer: B
The question indicates which of the following the security administrator will "REVIEW" (meaning the breach has already occurred) to determine how the attack occurred. Review the security logs as everything that happens inside the system is logged and it will be a productive point to determine what happened.
upvoted 2 times
...
[Removed]
2 years, 3 months ago
Selected Answer: A
A vulnerability scan report is another important source when determining how an attack might have been made. The scan engine might log or alert when a scan report contains vulnerabilities. The report can be analyzed to identify vulnerabilities that have not been patched or configuration weaknesses that have not been remediated. These can be correlated to recently developed exploits.
upvoted 1 times
...
StickyMac
3 years, 11 months ago
Main keywords are here: what should admin review.
upvoted 2 times
...
LJ32
4 years, 2 months ago
Wouldn't it be A. I know he determined that the system was not patched but wouldn't that be only option that could have prevented the attack?
upvoted 4 times
L1singh
4 years, 1 month ago
Attack has already happened, if an attack happens you view the security logs, to prevent an attack you would check vulnerability scan results
upvoted 5 times
KenCW
3 years, 10 months ago
I agree with your statement. That's make sense to me tho.
upvoted 1 times
...
leesuh
4 years, 1 month ago
So it would be A. Since the question is asking preventative measures.
upvoted 3 times
...
...
ekinzaghi
3 years, 9 months ago
they didn't ask abt preventing the attack, the question rightly points out that which of the following would the analyst " REVIEW" (meaning the breach has already occurred) in order to determine how the attack occurred. the provided answer is correct. review security logs since everything that occurs within the system is logged and that would be a fertile spot to determine what happened.
upvoted 2 times
MoMurt
2 years, 7 months ago
The question asks "how the incident could have been prevented" which is by checking "The vulnerability scan output"
upvoted 1 times
...
...
...
mcNik
4 years, 3 months ago
Which security logs is not mentioned.. though all of them will be security anyhow
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago