Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 153 discussion

Actual exam question from CompTIA's SY0-601
Question #: 153
Topic #: 1
[All SY0-601 Questions]

HOTSPOT -
Select the appropriate attack and remediation from each drop-down list to label the corresponding attack with its remediation.

INSTRUCTIONS -
Not all attacks and remediation actions will be used.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
cefibo
Highly Voted 3 years, 8 months ago
Botnet->Enable DDoS protection RAT->Disable remote access services Worm-> Change default passwords Keylogger->2FA using push Backdoor->Code Review
upvoted 197 times
ETQ
3 weeks, 5 days ago
There is no way that the answer to keylogging is 2FA, I would love for anyone who said this here to tell me how that works. 2FA is for login and has nothing to do with hardware keylogger being in place.
upvoted 1 times
ETQ
3 weeks, 5 days ago
I read the question again, and missed the "harvest credentials" part, duh.
upvoted 1 times
...
...
vi2
3 years, 7 months ago
I agree with this selection with exception of the third. As the example given is a SQL Database, I'd say 'Change default application password;.
upvoted 45 times
leesuh
3 years, 6 months ago
I agree. Will go with this.
upvoted 9 times
465ekm
3 years, 6 months ago
Will go with this too
upvoted 5 times
...
...
...
peymani
3 years, 8 months ago
proof for Keylogger -->2FA https://www.onelogin.com/learn/mfa-types-of-cyber-attacks
upvoted 3 times
...
gottapass1sttry
3 years, 8 months ago
To remediate the worm, do I need to change system and app PWs? Does the PBQ allow for the selection of more than one remediation option?
upvoted 1 times
...
...
hanoi92
Highly Voted 3 years, 1 month ago
I think result 1. Web server ======> Botnet ===> Enable DDoS protection 2. User => RAT =====> Implement a host-base IPS 3. Database server ======> Worm ===> Change the default application password 4. Executive =====> Keylogger > Implement 2FA using push notification 5. Application =======> Backdoor > Conduct a code review
upvoted 41 times
klinkklonk
10 months ago
But HIPS only covers one specific endpoint and not the whole network.
upvoted 1 times
Hellome123
5 months ago
Correct and if you look at target is User
upvoted 1 times
...
...
hieptran
1 year, 7 months ago
Agree on the 2. -> HIPS While disabling remote access services can be effective in preventing RAT attacks, it may not be practical or feasible in all situations, particularly in cases where remote access is necessary for legitimate business purposes. On the other hand, a host-based IPS provides real-time monitoring and protection against RAT attacks, as well as other types of threats. It can also be configured to provide alerts or take automatic actions when an attack is detected, which can help to minimize the damage caused by the attack. Therefore, I would recommend implementing a host-based IPS as the best preventative or remediation action against RATs.
upvoted 5 times
...
...
DarexTech100
Most Recent 4 months ago
some of the answers given by ExamT are not CORRECT. Please guys, check the discussions and research privately to understand everything. Best of luck.
upvoted 2 times
...
AbdullahMohammad251
6 months ago
(1) Botnet attacks involve compromising a huge number of hosts to launch massive DDOS attacks. Implementing DDOS protection. (2)RAT stands for remote access trojan. It allows attackers to control an infected host remotely. Disabling unnecessary remote access services can mitigate unauthorized access. (3) Unlike viruses which require human intervention to propagate through networks and systems, Worms are self-propagating. Changing the system's password would be the best course of action. If the system is compromised, this can undermine the security of all applications and services.
upvoted 4 times
AbdullahMohammad251
6 months ago
(4) Keyloggers are software and hardware tools to screen keystrokes, harvesting credentials, and sensitive information. keyloggers can capture keystrokes regardless of the services enabled on the system, making all running services vulnerable to keylogging. 2FA systems are designed to prevent multiple login attempts with the same passcode. (5) Backdoor malware is hidden in legitimate software to evade detection and gain unauthorized access to systems. Code review to ensure no malicious code was used.
upvoted 3 times
...
...
TingusPingus1
6 months, 4 weeks ago
Can someone help me out? Completing the rest of the words I chose Logic Bomb -> Application Fuzzing Virus -> Implement host based IPS Spyware -> Update Cryptographic Passwords Adware -> Change Default Passwords Ransomware -> Disable vulnerable service Phishing -> Patch vulnerable service Is this correct?
upvoted 2 times
TingusPingus1
6 months, 4 weeks ago
Also thinking about other Malware attacks such as Spam -> Use 2FA, change or look at privacy settings. RootKits -> Apply Anti-Malware/Virus software Trojans -> Implement HIPS Hoaxes -> Be cautious of false information Curious if the answer on how to prevent for Trojans would be preventing through HIPS this time since they are not remote. As well as just skipping preventing for RootKit and perform a secure boot. I don't think the question would answer with Spam filters because thats too easy. Then finally hoaxes, was wondering if there was a better answer I can put. These 5 answers are just regular answers I came up with and they do not have an answer sheet or multiple choice to choose from.
upvoted 2 times
...
...
staticisthemix
7 months, 1 week ago
04/09/24 This question was on the exam. I have a free account so I only went up to 400 questions. But barely any of the MQ questions were on the exam.
upvoted 3 times
...
Anu75
7 months, 2 weeks ago
This was there on exam today
upvoted 1 times
...
pgarden007
8 months, 1 week ago
I passed the exam on March, 11, 2024. This is on the exam. 1. Web server ======> Botnet ===> Enable DDoS protection 2. User => RAT =====> Disable remote access services 3. Database server ======> Worm ===> Change the default application password 4. Executive =====> Keylogger > Implement 2FA using push notification 5. Application =======> Backdoor > Conduct a code review
upvoted 12 times
csentry007
3 months, 3 weeks ago
TY but just because you passed, you do not know 100% if you got this question right.
upvoted 1 times
...
sosa4547
6 months, 1 week ago
Thank you so much!
upvoted 1 times
...
...
Glitchkaiser
8 months, 3 weeks ago
This showed up on my exams just today
upvoted 3 times
...
Vemsphere
9 months, 2 weeks ago
I just passed my exam!! All the questions were from here 99%. There was only 1 question that wasn't here. Also this was part of my test. You guys are awesome!! Thank you for your contribution!!
upvoted 15 times
akk1993
7 months ago
Were any other of the pbqs on here on your test? I take mine tomorrow Great job on passing
upvoted 1 times
...
...
MH006
9 months, 3 weeks ago
Took my exam today and I passed with 760, out of all the questions here I only got this question on my exam. But going through the questions here, help me a lot to revise and get familiar with the questions. I would highly recommend studying other materials as well.
upvoted 1 times
...
klinkklonk
10 months ago
Change Database Application Passwords: If the worm specifically targeted and compromised credentials associated with the database application, changing the application password might be a focused and appropriate response. This action helps prevent unauthorized access to the database through compromised application credentials. Change All System Passwords: If the worm has potentially compromised a broader set of credentials, including system-level accounts, changing all system passwords might be a more comprehensive approach. This action would address the possibility of the worm gaining access to various parts of the system, not just the database.
upvoted 2 times
...
Andrii1137
10 months, 3 weeks ago
This was on my exam 29.12.23
upvoted 4 times
...
olaniran22001
11 months ago
Passed my exam today with a score of 781 on my first try. Got 4 PBQs and this was one of them. Had a total of 74 questions. All my PBQs and maybe like 40% of my MCQs came from this dump. I studied with this dump, using the discussion section only. Even though most of my questions didn't come from here, it helped me learn concepts and topics that ultimately helped me in the exam. I am grateful for the team that put this together.
upvoted 5 times
...
Rumchata556
11 months, 3 weeks ago
This was on my exam, 11/29/23
upvoted 3 times
...
bzona
12 months ago
This task was on the exam. I took it on November 2, 2023. Score 786/900 ALL PBQs on the exam were from here. I got 3 PBQs and 82/83 questions total. I do not recall what I answered on this one I went with my knowledge. Make sure to get familiar with these settings, so no matter what you get you can handle the task. I got 30-40% of the questions from this dump, and only the simple ones, the questions that sweat me up, were not in the dump. So make use of what examtopics have provided us to study well and pass the exam. Good luck!
upvoted 5 times
saintbash
12 months ago
On what pages were most of your questions ?
upvoted 2 times
...
...
Soleandheel
1 year ago
I just took the exam today 11/15/23 and this question was among the 3 PBQs i got. All 3 were in this dump. I passed with a score of 800/900. 90% of the questions on the exam were from here. This was my first attempt and i have no IT background. If you study these questions, you will do well on the exam. All 3 of the PBQs were from this dump. If you've gone through these practice questions and feel comfortable with the content, i say don't wait anymore, go ahead and take the damn thing. Don't be afraid! 90% of the exam are the exact questions from this dump. It doesn't get any better than this. I used so many different resources including CompTia's Certmaster, Professor Messer, and Dione. Even though these resources are good, they don't compare to having the actual questions in front of you to study and brainstorm with others. This is the best resource period. Thanks for all your contributions and good luck if you haven't taken it yet. You have what you need to be successful. Also, thank you examtopics for this super helpful resource. You guys are awesome!
upvoted 13 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...