exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 731 discussion

Actual exam question from CompTIA's SY0-601
Question #: 731
Topic #: 1
[All SY0-601 Questions]

HOTSPOT
-

You are a security administrator investigating a potential infection on a network.


INSTRUCTIONS
-

Click on each host and firewall. Review all logs to determine which host originated the infection and then identify if each remaining host is clean or infected.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Narobi
Highly Voted 1 year, 5 months ago
192.168.10.22 - origin - scans disabled on this host by svchost 192.168.10.37 - clean - scan found and quarantined svchost 192.168.10.41 - infected - heuristic pattern match but failed to quarantine svchost 10.10.9.12 - clean - scan found and quarantined svchost 10.10.9.18 - infected - heuristic pattern match but failed to quarantine svchost I came to this conclusion for origin because the time stamp on this host disabling its scan is 14:31. This is also the time it opened a connection to an 8080 HTTP port. All other hosts scans detected svchost at the exact same time of 14:37:37. The two infected computers opened connections over 8080 a few minutes later. So based on the logs, the timeframes, and the port connections, 22 would have been the first one making it the origin. If someone's got better let me know.
upvoted 46 times
BD69
1 year ago
10.10.9.18 looks like originator - it's the very first host to connect to the nasty IP (57.203.54.*) range.
upvoted 1 times
BD69
1 year ago
192.168.10.22 is the first to be successfully infected, but it doesn't mean it's the originator. If it were me, I'd start w/the first machines tapping that address range.
upvoted 2 times
BD69
1 year ago
"originated the infection" -- kind of vague, but perhaps they do mean the first spreader.
upvoted 1 times
...
...
...
...
Benrosan
Highly Voted 1 year, 2 months ago
Passed my test with a score of 821 yesterday. All PBQs and 95% of the questions were from this dump. Review the last 250 or so questions closely. Can't overstate how helpful this site (and you all) were. Good luck guys!
upvoted 33 times
...
cyberani
Most Recent 2 months ago
🟢 all this PBQ in this website with the logs and correct answer , Cyberani. org , enjoy
upvoted 1 times
...
Sareena13
10 months, 1 week ago
I am not able to locate the logs. Could any one can post here for reference?
upvoted 1 times
NB2024
10 months, 1 week ago
https://www.examtopics.com/discussions/comptia/view/140250-exam-sy0-701-topic-1-question-77-discussion/
upvoted 5 times
...
...
durel
11 months, 1 week ago
where are the details of the question. How do I view the logs
upvoted 6 times
...
_deleteme_
1 year ago
Passed my exam this morning, this simulation was there. I chose what Narobi added. When I opened the PC I was able to confirm the findings by scrolling all the way to the bottom where some clearly showed "quarantined".
upvoted 7 times
...
staticisthemix
1 year ago
04/09/24 this question was on the exam. I have a free account so I only went up to 400 questions barely any of those MQ's showed up. I highly suggest you go over the comments and understand it to apply logic.
upvoted 4 times
...
BD69
1 year ago
the hard part, initially, was finding the origin. At first I thought it was 10.10.9.18 since it connected to the nasty server first in the log, however, the first address (in the log) to connect using RPC (a vector found on MS systems) was 192.168.10.22 to 10.10.9.12, then 10.10.9.12 via rpc to 192.168.10.41 The only thing weird is that 10.10.9.18 made an RPC connection, but had not been tapped by 192.168.10.22 first (meaning it had to already be infected). Hmmm. Maybe I'm wrong again.
upvoted 1 times
...
maggie22
1 year, 2 months ago
Was on the exam today. My first PBQ
upvoted 5 times
maggie22
1 year, 2 months ago
Heads up. 80% of the Questions I had were from 700-849, including the PBQs 156, 731,733 & 734
upvoted 16 times
TimBogao
11 months, 2 weeks ago
It's on SY0-601 or SY0-701?
upvoted 1 times
...
...
...
79dc014
1 year, 3 months ago
This was on the exam 1/21/24
upvoted 5 times
...
TamaraN
1 year, 3 months ago
Just passed the exam. PBQ 153, 731, 733, 734 were on there.
upvoted 4 times
TimBogao
11 months, 2 weeks ago
It's on SY0-601 or SY0-701?
upvoted 1 times
...
...
Andrii1137
1 year, 3 months ago
This was on my exam 29.12.23
upvoted 2 times
...
Soleandheel
1 year, 5 months ago
192.168.10.22 – Origin & Infected 10.10.9.18 – Infected 192.168.10.37 & 10.10.9.12 & 192.168.10.41- Clean
upvoted 4 times
Soleandheel
1 year, 5 months ago
Actually, 192.168.10.41 looks like it's infested as well. So i would amend my answer to: 192.168.10.22 – Origin & Infected 10.10.9.18 & 192.168.10.41– Infected 192.168.10.37 & 10.10.9.12 - Clean
upvoted 3 times
...
...
bzona
1 year, 5 months ago
What is origin? And where are the logs from the servers and firewall? How did some of you answered the question without any provided information?
upvoted 7 times
...
DChilds
1 year, 5 months ago
There is some missing info with this question.
upvoted 3 times
...
Rowdy_47
1 year, 5 months ago
Based on the logs, it seems that the host that originated the infection is 192.168.10.22. This host has a suspicious process named svchost.exe running on port 443, which is unusual for a Windows service. It also has a large number of outbound connections to different IP addresses on port 443, indicating that it is part of a botnet. The firewall log shows that this host has been communicating with 10.10.9.18, which is another infected host on the engineering network. This host also has a suspicious process named svchost.exe running on port 443, and a large number of outbound connections to different IP addresses on port 443. The other hosts on the R&D network (192.168.10.37 and 192.168.10.41) are clean, as they do not have any suspicious processes or connections.
upvoted 2 times
...
DashRyde
1 year, 6 months ago
Where is the F logs?
upvoted 8 times
LinkinTheStinkin
1 year, 1 month ago
I don't see them either.
upvoted 1 times
...
qwes333
1 year, 6 months ago
The origin is also missing
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago