exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 330 discussion

Actual exam question from CompTIA's SY0-501
Question #: 330
Topic #: 1
[All SY0-501 Questions]

A security administrator needs an external vendor to correct an urgent issue with an organization's physical access control system (PACS). The PACS does not currently have internet access because it is running a legacy operation system.
Which of the following methods should the security administrator select the best balances security and efficiency?

  • A. Temporarily permit outbound internet access for the pacs so desktop sharing can be set up
  • B. Have the external vendor come onsite and provide access to the PACS directly
  • C. Set up VPN concentrator for the vendor and restrict access to the PACS using desktop sharing
  • D. Set up a web conference on the administrator's pc; then remotely connect to the pacs
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SimonR2
Highly Voted 4 years, 10 months ago
In terms of balancing efficiency and security assuming 10 points to be balanced on A - efficiency 10/10 and security 0/10 Very insecure to open up to the internet and could cause a network breach but very easy to do. B - efficiency 0/10 and security 10/10 Would be a lot of hassle for the vendor to a remote location but very secure as there is no network exposure. C - efficiency 2/10 and security 9/10 Setting up a vpn concentrator, authentication mechanisms and configuring all the rules for a one off fix to a legacy system for it to only be used once would be a lot of effort. However, the VPN would be a very secure and tightly controlled way for them to access the network. D - efficiency 10/10 and security 9/10 Barely any effort to setup teamviewer or a similar app which is already widely used for them to view your computer screen. The app will only be viewable and accessible via your already established connection. Just keep in mind too, D is typically done by most third party software support companies for their support contract on behalf of the IT dept!
upvoted 13 times
Megatron
4 years, 8 months ago
What if the vendor needs to access the (PACS) off hour to minimize downtime.? Allowing vendors access to a computer without supervision could pose a risk by using teamviewr or RDP without supervision.
upvoted 1 times
SimonR2
4 years, 8 months ago
Off-hour connectivity requirements are not mentioned in the question. It says it’s urgent too, so it’s likely that the engineers will remain on site to work with the vendor until the issue is fixed as opposed to leaving the vendor and going home. It is also very safe to assume the vendor of the product doesn’t have malicious intentions against our systems. It’s not a complicated question, don’t try to overthink it. I work in the security team for an IT dept. One of our vendors always connects to assist us using specialised zoom sessions whenever we have ongoing issues or need assistance with software upgrades. The last things we would ever do is setup a VPN for them, ask them to come on site from another country or open up external access on the firewall to some application with security flaws!
upvoted 2 times
...
...
...
forward
Highly Voted 5 years, 1 month ago
As difficult as it is to keep everything straight, details matter. For the question to state that they have no internet, and suggest an answer that supports the use of an internet is confusing to the tester. Comptia make it plain and help us out!
upvoted 12 times
DookyBoots
4 years, 6 months ago
The PACS does not currently have internet access because it is running a legacy operation system. It does not say "they have no internet" It says the PACS currently doesn't have internet access, which are 2 very different things. Maybe the interpretation should be, the PACS is only offline due to the OS and not because it cannot connect to the internet. You wouldn't want a legacy system to have a constant connection to the web.
upvoted 2 times
...
...
Manojk
Most Recent 4 years, 2 months ago
It should D
upvoted 1 times
...
paulyd
4 years, 6 months ago
Comptia is driving me nuts with these questions.
upvoted 4 times
...
DookyBoots
4 years, 7 months ago
The other source says the answer is A. It doesn't say the organization doesn't have internet access, it says the PACS doesn't have internet access because of the legacy operating system. A VPN seems the most secure though.
upvoted 1 times
...
Teza
4 years, 8 months ago
C. Set up VPN concentrator for the vendor and restrict access to the PACS using desktop sharing The answer selected is correct in that the VPN you are setting up is to ensure that the vendor's access to your network is secure. Using the VPN will make the vendor appear like he is physically present on your network. You the administrator can now log in to the PACS and use desktop sharing or directly enable desktop sharing on the PACS so the vendor can do hi job, Remember: you will be restricting his access to the PACS only (security) and solving the issue does not require you waiting for the vendor to be physically present nor are people denied access in/out of the premises (efficiency)
upvoted 2 times
...
MagicianRecon
4 years, 10 months ago
D sounds much better an option to support both security and efficiency
upvoted 1 times
...
MNC
4 years, 11 months ago
Why not A? Can anyone Explain? It can temporary give access to outbound Internet Service
upvoted 1 times
...
covfefe
5 years ago
How is it not D? You can set up a web conference on the admin's PC, remote into the PACS (you don't need internet access for that if on the same LAN), and then use screen sharing via the web conference app.
upvoted 3 times
Dante_Dan
4 years, 12 months ago
Indeed. I think is the most convenient and secure way. No internet access to the legacy device, you don’t have to make the provider to come over and you can actually see everything he has to do. Answer D
upvoted 1 times
...
...
Dante_Dan
5 years ago
I think it says it does not currently have internet connection because it is not safe to provide internet access to a Legacy system.
upvoted 5 times
...
MelvinJohn
5 years, 2 months ago
Note that to use VPN services you must have internet access. ... Virtual Private Network encrypts your traffic that flows through the VPN server you connect to, and makes your connection untraceable, however, to access the server you must have internet connection.
upvoted 5 times
brandonl
5 years ago
agreed but it says they have no internet connection
upvoted 1 times
...
...
Basem
5 years, 8 months ago
Why not B ?
upvoted 1 times
Tyger
5 years, 7 months ago
"select the best balances security and *efficiency*"
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago