exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 215 discussion

Actual exam question from CompTIA's SY0-601
Question #: 215
Topic #: 1
[All SY0-601 Questions]

While investigating a recent security incident, a security analyst decides to view all network connections on a particular server. Which of the following would provide the desired information?

  • A. arp
  • B. nslookup
  • C. netstat
  • D. nmap
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Gino_Slim
Highly Voted 2 years, 6 months ago
Selected Answer: C
The reason why it's nestat and not nmap for this question: Nmap is a Network mapping tool. That means it's used to discover information about hosts on a network (their ip, open ports, etc). Where netstat is a network statistic tool used to list active connections. The question is asking about seeing active connections.
upvoted 38 times
Oval61251
2 years, 6 months ago
Very helpful, thank you
upvoted 4 times
...
...
rodwave
Highly Voted 2 years, 5 months ago
Selected Answer: C
Answer: netstat The netstat command shows all active network connections, network interface information, and ports that are listening. The question is asking to view all the connections on the server which the netstat command will do. ================================== Nmap or network mapper is a network discovery and security auditing tool mainly used to find services, hosts, and open ports on a network. Nslookup - This command queries DNS servers to obtain DNS records ARP Command is a TCP/IP utility used for viewing and modifying the local Address Resolution Protocol (ARP) cache.
upvoted 20 times
...
LordJaraxxus
Most Recent 1 year, 2 months ago
Selected Answer: C
Netstat allows you to view statistics for TCP/IP protocols and view all active network connections. This can be useful if you suspect malware is causing a computer to connect with a remote computer.
upvoted 1 times
...
irtaza909
1 year, 3 months ago
Netstat: open connections Nmap: open ports and services on hosts
upvoted 1 times
...
ApplebeesWaiter1122
1 year, 9 months ago
Selected Answer: C
The netstat command is used to view all network connections on a system, displaying information about active connections, listening ports, and related network statistics. It is a commonly used tool for network analysis and troubleshooting.
upvoted 1 times
...
ronniehaang
2 years, 3 months ago
Selected Answer: C
C. netstat Netstat (Network Statistics) is a command-line utility that can be used to display the current network connections on a server, including incoming and outgoing connections, as well as network statistics, such as the number of packets sent and received, and the number of errors. Netstat can be used to view the status of TCP and UDP connections, including information about the local and remote addresses, the state of the connection, and the process ID (PID) associated with the connection. This information can be used by the security analyst to identify any suspicious connections or traffic patterns, and to help determine the source of the security incident.
upvoted 1 times
...
andrizo
2 years, 6 months ago
Wouldnt nmap also work?
upvoted 2 times
RevolutionaryAct
1 year, 8 months ago
easy way to remember - nmap is a map view of the entire network , netstat is the network status of the connections of the host system you are querying
upvoted 2 times
...
...
omodara
2 years, 7 months ago
Ans A. netstat -a will display all the current active connections, the internet protocol type, IP addresses, port numbers, and the state of the connection
upvoted 1 times
omodara
2 years, 7 months ago
I meant answer is C, Netstat sorry for the typo
upvoted 5 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago