exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 139 discussion

Actual exam question from CompTIA's SY0-601
Question #: 139
Topic #: 1
[All SY0-601 Questions]

A company is receiving emails with links to phishing sites that look very similar to the company's own website address and content. Which of the following is the
BEST way for the company to mitigate this attack?

  • A. Create a honeynet to trap attackers who access the VPN with credentials obtained by phishing.
  • B. Generate a list of domains similar to the company's own and implement a DNS sinkhole for each.
  • C. Disable POP and IMAP on all Internet-facing email servers and implement SMTPS.
  • D. Use an automated tool to flood the phishing websites with fake usernames and passwords.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Josh_Feng
Highly Voted 2 years, 10 months ago
Selected Answer: B
DNS sinkhole prevents users from entering the site if they have a sinkhole for the domain name. So making a list of fake websites domain name and making a sinkhole will prevent access to these website if a user tried to search for it on accident.
upvoted 19 times
ComPCertOn
1 year, 7 months ago
Isn't that equivalent to a block list?
upvoted 2 times
...
...
MorganB
Highly Voted 2 years, 2 months ago
MorganB 0 minutes ago Awaiting moderator approval Pass my exam 27, April 23. This question was on my tested worded differently but the answer is the same.
upvoted 9 times
...
ApplebeesWaiter1122
Most Recent 1 year, 11 months ago
Selected Answer: B
The best way for the company to mitigate the phishing attack described is by generating a list of domains that are similar to the company's own domain and implementing a DNS sinkhole for each of these domains. A DNS sinkhole is a technique used to redirect malicious traffic to a controlled environment or block access to malicious domains. By implementing a DNS sinkhole for similar-looking domains, the company can prevent users from accessing phishing sites that may impersonate the company's website. When users click on links in the phishing emails, their DNS requests for those domains will be redirected to a safe location, preventing them from reaching the actual phishing sites. This approach helps protect users from falling victim to the phishing attack and helps in mitigating the risk of credential theft and other malicious activities associated with phishing.
upvoted 3 times
...
Protract8593
1 year, 11 months ago
Selected Answer: B
By generating a list of domains that are similar to the company's own and implementing a DNS sinkhole for each of these domains, the company can prevent users from accessing phishing sites that look similar to their legitimate website. A DNS sinkhole involves redirecting traffic from the malicious domains to a non-existent or controlled server, effectively blocking users from accessing the phishing sites. This approach is an effective way to mitigate the phishing attack and protect users from falling victim to the fraudulent websites. It helps in preventing data loss and protecting the company's reputation from being exploited by attackers.
upvoted 2 times
...
Dutch012
2 years, 2 months ago
If all the answers are correct, I would go with D.
upvoted 1 times
rline63
1 year, 10 months ago
I'm pretty sure D is illegal. Probably would work but takes a lot of resources, can be mitigated if the target uses proper protection, and like I said is ethically and legally questionable.
upvoted 1 times
...
...
MasterControlProgram
2 years, 3 months ago
Selected Answer: B
B. Generate a list of domains similar to the company's own and implement a DNS sinkhole for each would be the best way for the company to mitigate this attack. By generating a list of domains similar to the company's own and implementing a DNS sinkhole for each, the company can prevent users from accessing the phishing sites. A DNS sinkhole is a technique used to block access to malicious websites by redirecting requests for those sites to a non-existent IP address or a local web server that displays a warning message. This can help to prevent users from inadvertently accessing phishing sites that look similar to the company's own website.
upvoted 1 times
...
FMMIR
2 years, 6 months ago
Selected Answer: B
The best way for the company to mitigate this attack would be to implement a DNS sinkhole for domains similar to the company's own. A DNS sinkhole is a security measure that redirects traffic from known malicious or fraudulent websites to a safe location. By generating a list of domains similar to the company's own and setting up a DNS sinkhole for each, the company can prevent employees from accidentally accessing phishing websites that mimic the company's own domain. Other solutions such as disabling POP and IMAP on email servers, implementing SMTPS, or using an automated tool to flood phishing websites with fake credentials may also be effective, but a DNS sinkhole would be the most direct and effective way to prevent employees from accessing the phishing sites. Creating a honeynet would not be relevant in this scenario.
upvoted 2 times
...
RonWonkers
2 years, 9 months ago
Selected Answer: B
I agree with B
upvoted 3 times
...
stoneface
2 years, 10 months ago
This is a very confusing question -> Im inclining with D, other options will not directly try to reduce the danger associated with the fake sites
upvoted 1 times
zzzfox
2 years, 9 months ago
not sure flooding fake websites if is even a legal thing to do...
upvoted 7 times
Gino_Slim
2 years, 8 months ago
That was a very humorous answer choice to me
upvoted 3 times
...
...
stoneface
2 years, 10 months ago
After consideration Im choosing B -> I think the question implies that Typosqueatting is also on the table. So setting an internal DNS sinkhole that redirects all similar addresses (including the ones being used on the phishing campaign) to nothing will help mitigate this attack
upvoted 3 times
andrizo
2 years, 8 months ago
but boy, wouldnt it be cool to DOS phishing sites
upvoted 4 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...