exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 359 discussion

Actual exam question from CompTIA's SY0-601
Question #: 359
Topic #: 1
[All SY0-601 Questions]

A large industrial system’s smart generator monitors the system status and sends alerts to third-party maintenance personnel when critical failures occur. While reviewing the network logs, the company’s security manager notices the generator’s IP is sending packets to an internal file server’s IP. Which of the following mitigations would be BEST for the security manager to implement while maintaining alerting capabilities?

  • A. Segmentation
  • B. Firewall allow list
  • C. Containment
  • D. Isolation
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ranaer
Highly Voted 2 years, 3 months ago
Selected Answer: A
Containment and Isolation can be ruled out easily. We are left with A - segmentation and B - firewall allow list. I dont believe firewall will work, since IP addresses can be dynamic and change, which would render the report functionality useless, since it wouldnt be able to send data to the new addresses. Also firewalls tend to be placed between the internet and the inside network, thus it wouldnt prevent any traffic from being sent between hosts inside the network. Thats why I think A is more appropriate answer, but I am open for discussion.
upvoted 19 times
...
ApplebeesWaiter1122
Highly Voted 1 year, 11 months ago
Selected Answer: A
Segmentation involves dividing a network into separate segments or zones based on different security requirements. By implementing network segmentation, the security manager can isolate critical systems, such as the smart generator and the internal file server, into separate network segments. This prevents direct communication between them and reduces the risk of unauthorized access or data exfiltration. However, since the smart generator needs to send alerts to third-party maintenance personnel, it is important to ensure that alerting capabilities are maintained. This can be achieved by implementing appropriate access controls and routing rules that allow the generator to communicate with the necessary systems or services while still maintaining network segmentation.
upvoted 8 times
...
Grumpy_Old_Coot
Most Recent 1 year, 4 months ago
A, C, and D are all overkill - similar to using a flamethrower, a Tesla-Coil/vandegraff, or HAARP for a killing a housefly when all you need is a flyswatter. Appropriate tools for the job. The generator is networked and the reporting application it is talking to is on the server. A firewall rule to allow the MAC & Protocol on the Generator controller to talk only to the server application is all that is needed.
upvoted 1 times
...
ImBleghk
1 year, 5 months ago
Selected Answer: A
A. Segmentation
upvoted 1 times
...
Mazi_123
1 year, 6 months ago
Selected Answer: B
Segmentation might seem like the answer but i am more certain its firewall allow list, its a far simplier option to implement and its just as effective
upvoted 2 times
...
Teleco0997
1 year, 6 months ago
Selected Answer: A
other options (firewall allow list, containment, and isolation) might provide certain levels of control or isolation, but segmentation (A) is specifically designed to address the scenario described, offering a more comprehensive and effective solution to prevent unauthorized or unexpected communication between different parts of the network
upvoted 1 times
...
Afel_Null
1 year, 8 months ago
Selected Answer: B
How is segmenting the network going to stop the engine from sending packets to a selected IP? Unless segmentation completely blocks outband traffic, I don't understand how's that going to help. Firewall will at least block traffic based on rules.
upvoted 3 times
...
zits88
1 year, 9 months ago
Selected Answer: A
Containment and isolation, while verbally tempting, refer to actions taken after a breach has already been detected.
upvoted 2 times
...
TheRoot9
2 years, 1 month ago
Selected Answer: B
The best mitigation for the security manager to implement while maintaining alerting capabilities would be to deploy a firewall rule that only permits traffic from the smart generator’s IP to the third-party maintenance personnel’s IP. This is because segmentation, containment, and isolation would not allow the generator to send alerts to third-party maintenance personnel.
upvoted 6 times
...
SophyQueenCR82
2 years, 2 months ago
B because the system status and sends alerts to third-party maintenance and we need to maintain alerting capabilities the admin will just make sure the alerts are reaching who they need to reach and making sure if they need to store the alerts on their system as well
upvoted 2 times
SophyQueenCR82
2 years, 2 months ago
The BEST mitigation for the security manager to implement while maintaining alerting capabilities would be to deploy a firewall rule that only permits traffic from the smart generator's IP to the third-party maintenance personnel's IP. This would restrict any other unauthorized traffic from the generator's IP to the internal file server's IP while maintaining the necessary alerting capabilities. Additionally, the security manager should investigate why the generator's IP is sending packets to the internal file server's IP to determine if this is a legitimate action or if there is a security incident that needs to be addressed.
upvoted 2 times
SophyQueenCR82
2 years, 2 months ago
Segmentation might be a viable option to prevent the generator from sending packets to the internal file server's IP, but it could also limit the generator's ability to send alerts to third-party maintenance personnel, potentially hindering its overall functionality. Additionally, if the generator needs to communicate with other devices on the network, such as sensors or monitoring systems, segmentation may not be feasible without significantly impacting the system's performance or creating additional security risks. Therefore, implementing access control lists (ACLs) to restrict the generator's communication with the internal file server's IP would be a more targeted and effective mitigation strategy in this case.
upvoted 2 times
...
...
...
ganymede
2 years, 3 months ago
Selected Answer: A
A. Segmentation
upvoted 2 times
...
seagnull
2 years, 3 months ago
Selected Answer: A
Segmentation. Both C and D are kind of the same thing. Isolating the generator means that the industrial system cannot monitor any alerts anymore.
upvoted 3 times
...
lambbah
2 years, 3 months ago
Selected Answer: A
Segmentation is the best answer here.
upvoted 2 times
...
sdc939
2 years, 3 months ago
Selected Answer: A
A. Segmentation would be the BEST
upvoted 2 times
...
sdc939
2 years, 3 months ago
A. Segmentation would be the BEST
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...