exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 151 discussion

Actual exam question from CompTIA's SY0-601
Question #: 151
Topic #: 1
[All SY0-601 Questions]

A SOC operator is analyzing a log file that contains the following entries:

Which of the following explains these log entries?

  • A. SQL injection and improper input-handling attempts
  • B. Cross-site scripting and resource exhaustion attempts
  • C. Command injection and directory traversal attempts
  • D. Error handling and privilege escalation attempts
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
stoneface
Highly Voted 2 years, 8 months ago
Selected Answer: C
C. Command injection and directory traversal attempts
upvoted 21 times
ScottT
2 years, 8 months ago
https://www.professormesser.com/security-plus/sy0-401/directory-traversal-and-command-injection-2/
upvoted 13 times
VendorPTS
2 years, 7 months ago
Thank you. This was super helpful.
upvoted 4 times
...
...
...
rodwave
Highly Voted 2 years, 6 months ago
Selected Answer: C
Answer: Command injection and directory traversal attempts Directory traversal is when an attacker uses the software on a web server to access data in a directory other than the server's root directory. If the attempt is successful, the threat actor can view restricted files or execute commands on the server. Command injection is an attack that involves executing commands on a host. Typically, the threat actor injects the commands by exploiting an application vulnerability, such as insufficient input validation. The attacker is attempting to traverse the directory of the host and execute the cat command which could be used to print the contents of a file.
upvoted 10 times
...
Soleandheel
Most Recent 1 year, 6 months ago
This video explains more clearly about directory traversal: https://www.youtube.com/watch?v=NQwUDLMOrHo
upvoted 2 times
...
Protract8593
1 year, 9 months ago
Selected Answer: C
The log entries show attempts to perform command injection and directory traversal attacks. In a command injection attack, the attacker tries to execute arbitrary commands on the target system by injecting malicious input into the application. In this case, the GET requests in the log entries include sequences like "../../../../../../etc/passwd" and "../../../../../../etc/shadow," which are attempts to traverse directories and access sensitive files on the system. Directory traversal attacks are an attempt to access files and directories that are outside of the web application's intended directory structure. By using "../" sequences, the attacker tries to navigate to parent directories and access files that should not be publicly accessible.
upvoted 3 times
...
Yawannawanka
2 years ago
The log entries suggest command injection and directory traversal attempts. The attacker is attempting to execute commands on the web server by entering special characters, such as semicolons and forward slashes, in the input fields. They are also trying to access directories outside of the web root by using "../" in the URI. Therefore, the correct answer is C.
upvoted 1 times
...
J_Ark1
2 years, 6 months ago
Selected Answer: C
When I saw 'Get' instantly I went for cmd injection and traversal attempts.
upvoted 4 times
...
Jossie_C
2 years, 6 months ago
Selected Answer: C
The cat command traverses files in a directory.
upvoted 1 times
Sandon
2 years, 3 months ago
Negative ghost rider. The cat command displays the contents of a file.
upvoted 3 times
Protract8593
1 year, 9 months ago
Correct. cat = concatenate.
upvoted 1 times
...
...
...
RonWonkers
2 years, 7 months ago
Selected Answer: C
Agree with C
upvoted 3 times
...
comeragh
2 years, 8 months ago
Selected Answer: C
Agree with C for this one
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago