exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 240 discussion

Actual exam question from CompTIA's SY0-601
Question #: 240
Topic #: 1
[All SY0-601 Questions]

During a recent security assessment, a vulnerability was found in a common OS. The OS vendor was unaware of the issue and promised to release a patch within the next quarter. Which of the following BEST describes this type of vulnerability?

  • A. Legacy operating system
  • B. Weak configuration
  • C. Zero day
  • D. Supply chain
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Kashim
Highly Voted 2 years, 8 months ago
Selected Answer: C
"OS vendor was unaware" it indicates Zero Day
upvoted 23 times
Xynned
1 year, 12 months ago
But if the vendor promises to release the patch, then there is already an available solution, just that the vendor have not rolled-out/applied it to their product because they are not aware of it. The VA would not have scanned the vulnerability if it is a zero day. It seems that the vulnerabilty here is with the Supply chain = vendor. Just my though.
upvoted 2 times
cybertechb
1 year, 6 months ago
wrong. the vendor states a patch will be released within the next quarter indicating it will be developed. if it was already a patch available it would have been stated released immediately. read and understand the context cues. this is definitely a zero day. the answer is C
upvoted 4 times
...
...
...
JohnMangley
Highly Voted 2 years, 8 months ago
Selected Answer: C
It sounds like a Zero day as the OS vendor was unaware of the vulnerability.
upvoted 6 times
...
irtaza909
Most Recent 1 year, 4 months ago
How is zero day when it was detected??
upvoted 1 times
...
Grumpy_Old_Coot
1 year, 5 months ago
Selected Answer: C
Legacy Operating System = No longer supported (Windows 95, ME, 2K, XP, etc) so patches are no longer produced excluding when the vendor is under psychotically extenuating duress (Oh, you mean the SEC still uses Windows 2000 to run a transactional web-server that is vulnerable to these hard-coded administrator credentials with system level access we left in place in the built in IIS FTP module?"). So the answer is Zero Day.
upvoted 1 times
...
sujon_london
1 year, 10 months ago
Selected Answer: C
With no doubt C as long as vulnb found until patching
upvoted 1 times
...
ApplebeesWaiter1122
1 year, 11 months ago
Selected Answer: C
A "zero-day" vulnerability refers to a security flaw or weakness in software or an operating system that is unknown to the vendor or developers of that software. It is called "zero-day" because there are zero days between the time the vulnerability is discovered by attackers and the time the vendor becomes aware of it and can develop a patch to fix it. In this scenario, the vulnerability was found during a security assessment, and the vendor is unaware of it and has not yet released a patch, making it a zero-day vulnerability.
upvoted 4 times
ApplebeesWaiter1122
1 year, 11 months ago
Some of y'all are over thinking these questions. That's why I hate MC questions.
upvoted 3 times
...
...
Yawannawanka
2 years, 2 months ago
Selected Answer: C
C. This type of vulnerability is a zero day vulnerability. A zero day vulnerability is a security flaw or weakness in software or hardware that is unknown to the vendor or to security experts. This makes it particularly dangerous as there is no patch available, leaving systems open to attack. In this scenario, the OS vendor is unaware of the vulnerability and is planning to release a patch within the next quarter. A legacy operating system (option A) refers to an old or outdated operating system that is no longer supported by the vendor. A weak configuration (option B) refers to a system that is not properly configured, leaving it vulnerable to attack. A supply chain vulnerability (option D) refers to a security weakness in a product's supply chain, such as a third-party component or software that is used in the product.
upvoted 1 times
...
Action
2 years, 4 months ago
I was wondering if this can be supply chain since is coming from an OS Vendor
upvoted 1 times
Action
2 years, 4 months ago
If supply chain isn’t the answer then I’ll go with Zero day because option A means it’s an outdated OS and usually without vendor support, clear the OS in question still has vendor support
upvoted 1 times
...
...
Alizadeh
2 years, 6 months ago
Selected Answer: C
The correct answer is C. Zero day. A zero-day vulnerability is a previously unknown vulnerability in software or hardware that is exploited by attackers before the vendor becomes aware of the issue and releases a patch. In this case, the OS vendor was unaware of the vulnerability and promised to release a patch within the next quarter, indicating that it is a zero-day vulnerability.
upvoted 1 times
...
[Removed]
2 years, 6 months ago
A. Legacy is the answer…
upvoted 2 times
Sandon
2 years, 6 months ago
No, it's not
upvoted 4 times
...
...
Lv2023
2 years, 6 months ago
Selected Answer: C
Answer is "C" as per Comptia this is why "A" is not the answer: A legacy platform is one that is no longer supported with security patches by its developer or vendor. This could be a PC/laptop/smartphone, networking appliance, peripheral device, Internet of Things device, operating system, database/programming environment, or software application. By definition, legacy platforms are unpatchable.
upvoted 1 times
...
ksave
2 years, 7 months ago
Selected Answer: A
My answer would be Legacy OS. Reason: The question said the patch would be available in the next quarter. This sounds more of EOL. For zero day attacks, the solution must come in the next 2 to 3 days.
upvoted 5 times
Sandon
2 years, 5 months ago
You are incorrect sir. There is no time limit for a zero-day patch
upvoted 2 times
...
NICKJONRIPPER
2 years, 7 months ago
no widespread use, not the case, they are still using
upvoted 1 times
...
NICKJONRIPPER
2 years, 7 months ago
legacy operating system, is an operating system (OS) no longer in widespread use, or that has been supplanted by an updated version of earlier technology.
upvoted 1 times
...
...
papisam
2 years, 8 months ago
but if they promised to release a patch then it can not be Zero Day.
upvoted 6 times
Sandon
2 years, 5 months ago
Wrong, now that they know about it, it is no longer a zero-day. But it was
upvoted 4 times
...
...
Iphy23
2 years, 8 months ago
i still dont understand why the answers from this forum is wrong compared to the votes...
upvoted 2 times
Gino_Slim
2 years, 8 months ago
And we never will.
upvoted 1 times
...
SOK_I
2 years, 7 months ago
I saw on the answer threads in the early 100ish answers that Examtopics has to keep the *actual* answer hidden, otherwise CompTIA would not allow Examtopics to post their questions verbatim.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...