exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 260 discussion

Actual exam question from CompTIA's SY0-501
Question #: 260
Topic #: 1
[All SY0-501 Questions]

Ann a security analyst is monitoring the IDS console and noticed multiple connections from an internal host to a suspicious call back domain.
Which of the following tools would aid her to decipher the network traffic?

  • A. Vulnerability Scanner
  • B. NMAP
  • C. NETSTAT
  • D. Packet Analyzer
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Death2QuestionWriters
Highly Voted 4 years, 9 months ago
Enjoy your word play exam masquerading as one on cyber security. Thanks CompTIA, you're the best.
upvoted 26 times
...
Basem
Highly Voted 5 years, 7 months ago
Shouldn't this be Packet analyzer ?
upvoted 13 times
kyky
4 years, 10 months ago
sorry the good answer is NETSTAT
upvoted 2 times
...
kyky
4 years, 10 months ago
yes the answer is packet analyser
upvoted 2 times
...
...
slackbot
Most Recent 2 months, 3 weeks ago
Selected Answer: D
people see the answer provided and start thinking of ways to defend it instead of thinking what the question is and what the closest answer is - D
upvoted 1 times
...
jemusu
3 years, 9 months ago
netstat -ao
upvoted 1 times
...
bek123
3 years, 9 months ago
D is the answer. Nestat shows only what is the established connections between source and .destination,mostly TCP.
upvoted 1 times
...
MortG7
4 years, 2 months ago
network traffic..netstat? no no my dear...netsta will give you the IP's, ports and state of the connections but won't help you decipher network traffic..wireshark (protocol analyzer)
upvoted 2 times
...
kaheri
4 years, 2 months ago
tricky question.. again... I believe the answer is C under the question context. It mention "multiple connections" how can we "decipher the network traffic" to discover what are those "multiple connections"
upvoted 1 times
...
mhpmyt7
4 years, 6 months ago
NESTAT is probably the right answer. This seems like one of those typical Comptia questions whose aim is to confuse, however, the key to the answer is this: "and noticed multiple connections from an internal host" while she was monitoring. So the main question is to get information about a host and not the IDS she was monitoring. In order to get that information, NETSTAT seems like the best option, since she will have to run it on the particular host
upvoted 5 times
...
macera8796
4 years, 9 months ago
Answer the question, not the previous sentence. They provide information that she noticed multiple connections, and then they ASK how to decipher network traffic.
upvoted 1 times
...
kdce
4 years, 10 months ago
C. NETSTAT show current connection status/info
upvoted 1 times
...
MagicianRecon
4 years, 10 months ago
With IDS she was already able to confirm multiple connections. You will run netstat on the source node but cannot decipher network traffic. Has to be protocol analyzer
upvoted 3 times
...
SimonR2
4 years, 10 months ago
Answer is D. The question specifically asks for the examination of network traffic, not connections. If we run netstat we will get I formation about open connections, but will get no information on the traffic or it’s contents. Connections = netstat Traffic = packet analyser
upvoted 4 times
...
CYBRSEC20
4 years, 10 months ago
Don't let the " decipher the network traffic" get you. a callback domain is not a full url, but a domain name, IP address or hostname: localhost. Hence, Ann needs netstat command to figure things out first. The fact that it is a suspicious callback not necessary means that it is malicious. It might just be an external site processing a payment.
upvoted 1 times
...
MelvinJohn
5 years, 1 month ago
C. NETSTAT. Does she need to analyze the CONTENTS (packets) of the network traffic or the incoming and outgoing connections and routing? The question doesn't indicate that she wants to see the contents of the traffic, so she doesn't need a packet analyazer.
upvoted 5 times
Nicker92
4 years, 11 months ago
The key word is "decipher, so she has to use a packet analyzer. Netstat provide only with who the connection is established.
upvoted 3 times
SimonR2
4 years, 10 months ago
Exactly, I do this sort of thing for my job daily and you can get no traffic information with netstat in comparison to tcp dump viewing every packet on the wire.
upvoted 2 times
...
...
...
The_Temp
5 years, 1 month ago
Netstat analyses network connections, and a packet analyser analyses network traffic. As Ann wants to decipher network traffic, D is the correct answer.
upvoted 1 times
...
Kt45
5 years, 1 month ago
I suppose the keyword here is 'connections' which implies TCP. netstat would be a valid answer.
upvoted 3 times
...
MelvinJohn
5 years, 2 months ago
D. The keyword is decipher. The normal meaning of decipher is decrypt. Maybe "analyze" was the intent of the question. But cipher implies encrypted. Synonyms for decipher: decode, decrypt, decipher(verb) convert code into ordinary language. Synonyms: decrypt, decode, trace.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago