exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 47 discussion

Actual exam question from CompTIA's SY0-601
Question #: 47
Topic #: 1
[All SY0-601 Questions]

Which of the following is the MOST effective control against zero-day vulnerabilities?

  • A. Network segmentation
  • B. Patch management
  • C. Intrusion prevention system
  • D. Multiple vulnerability scanners
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ay_ma
Highly Voted 2 years, 7 months ago
Selected Answer: A
IPS can only protect against known host and application-based attacks and exploits. IPS inspects traffic against signatures and anomalies, it does cover a broad spectrum of attack types, most of them signature-based, and signatures alone cannot protect against zero-day attacks. (www.rawcode7.medium.com) However, with network segmentation, you're able to isolate critical assets into different segments. And when a zero-day attack occurs, you're not at risk of losing all and are able to isolate the attack's effect to one segment.
upvoted 38 times
CTE_Instructor
2 years, 2 months ago
But the question isn't about protecting other data, the question directly says how to "control zero-day vulnerabilities". If there is a zero-day vulnerability in a new piece of software on a device, the BEST control against this is patch management to ensure the vulnerability is patched out as soon as possible.
upvoted 3 times
BD69
1 year, 2 months ago
Since there are no patches for a zero-day exploit (it's called Zero day, for a reason), patch management is useless.
upvoted 5 times
...
DriftandLuna
1 year, 11 months ago
the mention of zero day implies they mean attacks for which there is no patch yet. Patch management wont protect against something that there isn't a patch for which is the definition of a zero day exploit.
upvoted 7 times
...
Secplas
1 year, 5 months ago
Zero-day means there's no patch. There is 0 to patch against.
upvoted 8 times
233Matis
1 year, 4 months ago
That is the MAIN REASON FOR PATHING THE SYSTEM! it means UPDATES!! Patching=update to prevent 0 days
upvoted 1 times
dhaksbro
1 year, 2 months ago
There is NO UPDATE for the vulnerability. That's why it is called a Zero Day
upvoted 4 times
BD69
1 year, 2 months ago
Exactly! Patch management is ONLY good for vulnerabilities that have patches. Zero-Day vulnerabilities are patched after a patch is created, AFTER the zero-day exploit was executed. Why is this so difficult to understand? (25 years experience here and have had systems compromised with full patch management systems in place)
upvoted 1 times
...
...
...
...
...
AzureG0d
1 year, 6 months ago
I don't know who yo are @ay_ma but this is a cold answer lol. I'm with yo in selecting A here, makes the most sense.
upvoted 2 times
...
...
beardsly
Highly Voted 2 years, 7 months ago
Had to look this up myself as there is no real clear answer here. One of the Sec+ books I have suggested IPS and segmenting. Google search even says IPS in this regard as well. I would personally say Network Segmentation but otherwise not sure. My comment is not all that helpful I know but just wanted to throw my thoughts out there.
upvoted 24 times
mascot45
2 years, 2 months ago
I believe it's B, patch management. I don't really get how segmenting network can defend or prevent a zero day for being exploited on your network. I put this questions to chatGPT and it gave me B as the answer, so that's what I'm going with.
upvoted 11 times
sarah2023
1 year, 8 months ago
Wrong, the essence of a zero day vulnerability is that you can't prevent or protect against something you have not encountered in the past.
upvoted 3 times
...
rondo24
2 years, 2 months ago
I did the same and then I pointed out to chat GPT that a Zero Day is by definition not known and it changed its answer and said "However, even though the vendor may be unaware of the vulnerability, there are still ways to mitigate the risks posed by zero-day vulnerabilities. For example, network segmentation, intrusion prevention systems, and multiple vulnerability scanners can help to reduce the attack surface and limit the damage that can be done if a zero-day vulnerability is exploited."
upvoted 3 times
Sanj
2 years, 2 months ago
Regular software updates: Installing the latest software updates can help protect against known vulnerabilities and fix security holes that could be exploited by zero-day attacks.
upvoted 4 times
daddylonglegs
1 year, 6 months ago
Do you understand what a zero-day is? It's a vulnerability that is unknown to security researchers or the vendor or the product. You can't fix a vulnerability that you don't know about, therefore there would not be a patch for a zero-day vulnerability until it is discovered, at which point it is no longer a zero-day vulnerability.
upvoted 3 times
...
...
...
...
hieptran
2 years, 3 months ago
To be more clear, zero days is an unknown exploit. There are a few chances that the IPS will detect the attack payloads/signature. But segregating the network would eventually prevent lateral movement even if the attacker has Remote Code Execution privilege on the compromised server.
upvoted 13 times
DriftandLuna
1 year, 11 months ago
Agreed, i chose IPS but was thinking segmentation as well for the reasons you stated.
upvoted 1 times
...
thefoque
1 year, 6 months ago
I think its also in the official course a question like this somewhere. IPS is the only way to actually protect against zero days, since it uses baselines to detect any anomalies in the system. IPS is not only signature based, it's not an antivirus. Segmentation would just prevent the spread of the infection throughout the network.
upvoted 2 times
...
...
TinyTrexArmz
2 years, 3 months ago
I agree, there is no clear answer here. And though I don't think it's what the test would want us to answer I will say in my 20 years of IT expereince that a good Patch management process is the most helpful when it comes to zero-day exploits. I say this because once a Zero Day becomes public knowledge then the vendor normally rushes to put out some kind of patch or workaround. Having a way to deploy that in a quick and reliable manner is key to getting things back to secure as soon as possible. But I would say IPS would be most effective against zero day vulnerabilities because you might be able to detect the usual traffic or activity. Network segmentation will only help slow the intruder down. If you don't have anything to detect the oddity then the attacker could install a back door and then work their way across the segments. What's the old saying? An once on prevention is worth a pound of cure. But in a perfect world, both would be implemented. My vote is C.
upvoted 11 times
...
...
e2ba0ff
Most Recent 5 months ago
Selected Answer: C
security solutions like IPS(host-based IPS) can help detect and block suspicious activities.
upvoted 1 times
...
Eromons
11 months, 1 week ago
Selected Answer: A
A network Segmentation in other to avoid the spread of any attack on other network
upvoted 1 times
...
BD69
1 year, 1 month ago
Selected Answer: C
IPSes don't just use known malware definitions to prevent intrusions, they all use heuristics, behavior analysis, baselines, broad signatures (similar to already known ones), and are coupled with threat intelligence. Patch management is useless for zero-day exploits. Vulnerability scanners do not prevent attacks. segmentation may help, but it's not the most effective Network Segmentation is always a good idea, but only effective at preventing spread of malware
upvoted 4 times
...
lekiam
1 year, 1 month ago
IPS can potentially detect a zero-day attack in real-time using anomaly or behavior analysis, or even by using euristic analysis which can and take automated action to block or prevent it
upvoted 2 times
...
BD69
1 year, 2 months ago
Selected Answer: C
Going with C: here as most modern day IPS systems use heuristics and AI (anomaly detection) and is the only thing that might work B: Patch Management will have no effect on Zero-Day exploits as everyone knows C: Vulnerability scanners will also be useless of Zero-Day exploits A: Network segmentation may help a tad bit, but doesn't identify intrusions. so no go
upvoted 3 times
...
alicia2024
1 year, 2 months ago
Selected Answer: C
An intrusion prevention system is designed to monitor network traffic and detect and block malicious activities, including those associated with zero-day exploits, based on known attack patterns or abnormal behavior.
upvoted 2 times
...
Benrosan
1 year, 2 months ago
Selected Answer: C
It's a tough one but I believe the answer is IPS. Specifically an IPS using heuristic or behavior-based detection. That's usually mentioned as one of the few ways to mitigate Zero-Day attacks. Network segmentation makes sense to an extent, but I think what Comptia is testing here is your understanding of detection methods are how they're leveraged.
upvoted 2 times
...
Yomzie
1 year, 3 months ago
While the precise methods of a zero-day exploit can’t be known in advance, a network intrusion protection system (IPS) will continuously monitor the network for unusual activity. The advantage of IPS over a traditional antivirus-only system is that, it doesn't rely on checking suspicious software against known databases of threats. This means it does not make software vendors need updates or patches to learn about the latest attacks. IPS works by monitoring the day-to-day patterns of network activity across the network. When there is anomaly detection or events, the IPS/IDS alerts system administrators and lock down the network/firewall.
upvoted 1 times
...
hyabasa
1 year, 3 months ago
I think it's IPS. Zero Day again is there is no patch. Network segmenting is an approach to slowing down a bad actor and mitigating damage. The only way to prevent or protect against an unknown vulnerability would be to use a good Next Gen firewall. A vulnerability is only exploitable if it is accessible. IPS, as part of a Next Gen firewall or edge protection, would have a chance at blocking the bad actor for even getting into the network. It's C, final answer.
upvoted 1 times
...
johnabayot
1 year, 3 months ago
Selected Answer: B
Patch management.
upvoted 1 times
...
Modiggs2004
1 year, 3 months ago
The correct answer is "A." Network Segmentation. There are no known patches for a zero day attack which is a characteristic of a zero day attack, so that rules out the patches answer. Intrusion prevention systems will not prevent a zero day attack because the nature of a zero day attack is malware that has been present for a while and has not been detected, therefore that implies that the malware has already made it past your IPS. Vulnerability scanners would imply the same thing as the IPS that the zero day attack has already made it past your scanners and has been on your system for a while. The only logical/possible answer is "A."
upvoted 2 times
...
12f1a9a
1 year, 4 months ago
I believe the answer is network segmentation. When we read the question carefully it says "which would be the most effective CONTROL...." The question is not asking for most effective way to prevent the zero day vulnerability. By segregation you can control the situation to prevent a big loss in my opinion.
upvoted 2 times
...
ykt
1 year, 4 months ago
Selected Answer: C
IPS is not just about signatures. There are behavior-based IPS and AI-based IPS. So the answer is IPS.
upvoted 1 times
...
Enzoxx
1 year, 4 months ago
Selected Answer: B
Look this site: https://www.imperva.com/learn/application-security/zero-day-exploit/#:~:text=One%20of%20the% Patch management: Another strategy is to deploy software patches as soon as possible for newly discovered software vulnerabilities. While this cannot prevent zero-day attacks, quickly applying patches and software upgrades can significantly reduce the risk of an attack.
upvoted 1 times
...
saucehozz
1 year, 5 months ago
Selected Answer: C
IPS can be effective in detecting and blocking anomalous behavior
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago