exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 225 discussion

Actual exam question from CompTIA's SY0-601
Question #: 225
Topic #: 1
[All SY0-601 Questions]

A new vulnerability in the SMB protocol on the Windows systems was recently discovered, but no patches are currently available to resolve the issue. The security administrator is concerned that servers in the company’s DMZ will be vulnerable to external attack; however, the administrator cannot disable the service on the servers, as SMB is used by a number of internal systems and applications on the LAN. Which of the following TCP ports should be blocked for all external inbound connections to the DMZ as a workaround to protect the servers? (Choose two.)

  • A. 135
  • B. 139
  • C. 143
  • D. 161
  • E. 443
  • F. 445
Show Suggested Answer Hide Answer
Suggested Answer: BF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ha9ate
Highly Voted 2 years, 8 months ago
Selected Answer: BF
SMB use TCP Port 139 445、UDP Port 137 138
upvoted 19 times
...
Mirdautas
Highly Voted 2 years ago
Got this question 20 june 2023. Answer is BF 📍
upvoted 16 times
gametreckers
2 years ago
did you pass?
upvoted 6 times
...
...
kewokil120
Most Recent 1 year, 4 months ago
Selected Answer: BF
With NGFW. Just choose the SMB app ID and set the rule to log and drop. Old stuff 139 445 will need to be blocked.
upvoted 1 times
...
fercho2023
1 year, 8 months ago
B and F. Please check this link: https://builtin.com/software-engineering-perspectives/smb-port
upvoted 2 times
...
ApplebeesWaiter1122
1 year, 11 months ago
Selected Answer: BF
Port 139 and Port 445 are commonly associated with the SMB protocol in Windows systems. Blocking these ports from external inbound connections will help prevent potential attacks exploiting the SMB vulnerability from reaching the servers in the DMZ. However, it is important to note that this is a temporary workaround until a proper patch or mitigation is available for the SMB vulnerability.
upvoted 2 times
...
Yawannawanka
2 years, 2 months ago
Selected Answer: BF
The two TCP ports that should be blocked for all external inbound connections to the DMZ as a workaround to protect the servers are 139 and 445. SMB uses port 139 and 445 to communicate, and blocking these ports will prevent external attackers from exploiting the vulnerability in the SMB protocol. It is important to note that blocking these ports will also prevent legitimate external access to SMB services on the servers in the DMZ. Ports 135, 143, 161, and 443 are not typically associated with SMB, so blocking them would not provide any protection against the SMB vulnerability. Port 135 is used for Remote Procedure Call (RPC) traffic, port 143 is used for IMAP traffic, port 161 is used for Simple Network Management Protocol (SNMP) traffic, and port 443 is used for HTTPS traffic. Therefore, the correct answer is B. 139 and F. 445.
upvoted 7 times
...
ronniehaang
2 years, 5 months ago
Selected Answer: BF
The security administrator should block TCP ports 445 and 139 for all external inbound connections to the DMZ as a workaround to protect the servers from the SMB protocol vulnerability. These ports are commonly used by SMB for communication. Blocking these ports for external inbound connections can prevent external attackers from exploiting the vulnerability, while still allowing the internal systems and applications to use SMB for communication.
upvoted 3 times
...
serginljr
2 years, 8 months ago
Selected Answer: BF
BF correct
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...