exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 396 discussion

Actual exam question from CompTIA's SY0-601
Question #: 396
Topic #: 1
[All SY0-601 Questions]

A host was infected with malware. During the incident response, Joe, a user, reported that he did not receive any emails with links, but he had been browsing the internet all day. Which of the following would MOST likely show where the malware originated?

  • A. The DNS logs
  • B. The web server logs
  • C. The SIP traffic logs
  • D. The SNMP logs
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
pmmg
Highly Voted 2 years, 4 months ago
Selected Answer: A
We would not have access to the web server logs of someone on the internet. Only DNS would show where he visited.
upvoted 19 times
soootired
1 year, 7 months ago
what do you mean we would not have access to the web server logs?
upvoted 1 times
StevenHN25
1 year, 2 months ago
The web server logs belong to the individual websites. In this case, what we're after is which websites the user was visiting and than can be found in the DNS logs
upvoted 3 times
...
...
...
ApplebeesWaiter1122
Highly Voted 2 years ago
Selected Answer: A
DNS logs could also be useful in determining the origin of malware in some cases. DNS logs can provide information about the domain names that the infected host attempted to resolve or communicate with. By analyzing the DNS logs, the incident response team can identify any suspicious or malicious domain names that the infected host may have interacted with.
upvoted 8 times
...
LordJaraxxus
Most Recent 1 year, 3 months ago
Selected Answer: A
DNS log files record DNS queries, such as each request to resolve a hostname to an IP address. These log entries would include the system that sent the request and the IP address returned for the hostname. These log entries can be useful in identifying potentially malicious websites. As an example, imagine Bart spends a few hours browsing the Internet using his company computer. One of the websites downloaded malware onto his system, but he doesn’t know which one and can’t remember all of the sites he visited. By searching the DNS log files, administrators can identify all of the sites he visited based on his DNS queries.
upvoted 2 times
...
Malkhofash
1 year, 6 months ago
Of course, A it's not possible to search on the web server logs as it's on internet
upvoted 1 times
klinkklonk
1 year, 5 months ago
Most companies have their own web server.
upvoted 1 times
...
...
Soleandheel
1 year, 7 months ago
The best answer is B. The web server logs If Joe did not receive emails with links but had been browsing the internet, the malware may have been delivered through a web-based attack. Checking the web server logs can help identify suspicious or malicious activity originating from websites or web servers Joe visited, which can provide insights into the source of the malware infection. DNS logs primarily track domain resolution, SIP traffic logs are related to VoIP communication, and SNMP logs are related to network management and monitoring and may not directly show the source of web-based malware infections. DNS logs will not provide the granular level of information as the web server logs.
upvoted 1 times
...
asum
2 years, 1 month ago
Selected Answer: A
DNS server logs provide rich information about what sites users visit, and they show whether any malicious applications reach out to command-and-control sites.
upvoted 1 times
...
asum
2 years, 1 month ago
Selected Answer: D
DNS server logs provide rich information about what sites users visit, and they show whether any malicious applications reach out to command-and-control sites.
upvoted 1 times
...
fouserd
2 years, 2 months ago
Selected Answer: B
The web server logs would be the most likely to show where the malware originated. They can help identify any suspicious URLs that were accessed by the host and determine whether they are associated with malware12. DNS logs would show the DNS resolution requests made by the host, SIP traffic logs would show traffic related to VoIP calls, and SNMP logs would show network device statistics and performance metrics1.
upvoted 1 times
...
SophyQueenCR82
2 years, 3 months ago
A. The DNS logs Why is DNS Monitoring Important? An effective system of DNS monitoring is critical to the reliability of your website, as well as the security and trust of your users. Because the DNS is a popular target for hackers, it's important to keep a close eye for any malicious attacks on your domains and services.
upvoted 3 times
SophyQueenCR82
2 years, 3 months ago
hat gpt corrected me: B. The web server logs would most likely show where the malware originated. Since Joe had been browsing the internet, it is possible that he visited a malicious website or clicked on a malicious link that infected the host with malware. The web server logs can help identify any suspicious URLs that were accessed by the host and determine whether they are associated with malware. DNS logs would show the DNS resolution requests made by the host, SIP traffic logs would show traffic related to VoIP calls, and SNMP logs would show network device statistics and performance metrics.
upvoted 2 times
SophyQueenCR82
2 years, 3 months ago
The DNS logs would be useful to identify if the malware was attempting to resolve any malicious domains or if it was communicating with a command and control server using a domain name. However, since the user did not receive any emails with links, it is unlikely that the malware was delivered via email. Therefore, the web server logs would be more useful in this scenario, as they could show if the user visited any websites that were known to host or distribute malware. Additionally, the logs could show if any malicious files were downloaded to the infected host.
upvoted 1 times
...
...
...
skorza
2 years, 3 months ago
Selected Answer: B
Web Server Logs ChatGPT says:In the scenario given, the user reported that they did not receive any emails with links, but they had been browsing the internet all day. This suggests that the malware may have been downloaded or delivered through a web-based attack, rather than through email. DNS logs are useful for tracking network traffic, but they do not provide information on what specifically happened on the web server. On the other hand, web server logs can provide more detailed information about web-based activity, such as which websites were visited, which files were downloaded, and which IPs accessed the server. Therefore, in this scenario, the web server logs would be more useful for identifying the source of the malware. By analyzing the logs, the incident response team can potentially identify which websites or web-based applications the user interacted with, which may have been compromised and delivered the malware.
upvoted 3 times
Nishkurup
2 years, 3 months ago
A web server log is a text document that contains a record of all activity related to a specific web server over a defined period of time. The web server gathers data automatically and constantly to provide administrators with insight into how and when a server is used, as well as the users that correspond with that activity.
upvoted 2 times
...
...
ganymede
2 years, 3 months ago
Selected Answer: A
DNS logs
upvoted 2 times
...
NeoSam999
2 years, 4 months ago
Selected Answer: A
A. The DNS logs
upvoted 2 times
...
hsdj
2 years, 4 months ago
Selected Answer: A
A is better than B
upvoted 2 times
...
Sailorjohnny
2 years, 4 months ago
Selected Answer: A
A. The DNS Logs
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...