exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 272 discussion

Actual exam question from CompTIA's SY0-601
Question #: 272
Topic #: 1
[All SY0-601 Questions]

A company’s security team received notice of a critical vulnerability affecting a high-profile device within the web infrastructure. The vendor patch was just made available online but has not yet been regression tested in development environments. In the interim, firewall rules were implemented to reduce the access to the interface affected by the vulnerability. Which of the following controls does this scenario describe?

  • A. Deterrent
  • B. Compensating
  • C. Detective
  • D. Preventive
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Imanism
Highly Voted 2 years, 6 months ago
Selected Answer: B
compensating control, also called an alternative control
upvoted 16 times
...
comeragh
Highly Voted 2 years, 6 months ago
Selected Answer: B
Compensating control looks to be correct here. Open to correction however A compensating control, also called an alternative control, is a mechanism that is put in place to satisfy the requirement for a security measure that is deemed too difficult or impractical to implement at the present time.
upvoted 9 times
...
val4
Most Recent 1 year, 7 months ago
if compensated, then no need in patch?
upvoted 1 times
...
sujon_london
1 year, 8 months ago
Selected Answer: B
Compensating controls are designed to provide an equivalent level of protection or to compensate for the absence or failure of the primary control. They are typically implemented until the primary control can be fully implemented or restored.
upvoted 1 times
...
ApplebeesWaiter1122
1 year, 10 months ago
Selected Answer: B
A compensating control is a security measure or countermeasure that is implemented as an alternative or substitute when the primary control is not feasible or effective. In this case, the primary control would be the vendor patch, which is not yet regression tested in development environments. To mitigate the risk posed by the critical vulnerability in the high-profile device, the security team has implemented firewall rules to restrict access to the vulnerable interface. This compensating control helps reduce the exposure and potential impact of the vulnerability until the vendor patch can be properly tested and implemented.
upvoted 4 times
...
seagnull
2 years, 2 months ago
Selected Answer: B
while you are still testing out the patch, firewall rules were implemented to reduce access to the interface affected by the vulnerability. - hence this is a compensating control.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago