exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 202 discussion

Actual exam question from CompTIA's SY0-601
Question #: 202
Topic #: 1
[All SY0-601 Questions]

A user reports falling for a phishing email to an analyst. Which of the following system logs would the analyst check FIRST?

  • A. DNS
  • B. Message gateway
  • C. Network
  • D. Authentication
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Gino_Slim
Highly Voted 2 years, 2 months ago
This is a also a dumb question
upvoted 91 times
...
stoneface
Highly Voted 2 years, 4 months ago
Selected Answer: A
We want to see DNS logs to see where the users was taken
upvoted 40 times
Alcpt
4 months, 1 week ago
Yes but this is not the FIRST step. First check the gateway logs.
upvoted 1 times
...
i_bird
2 years, 3 months ago
any elaboration will be appreciated..
upvoted 2 times
...
db97
2 years, 3 months ago
But your assuming that he clicked on a link and the question does not specify that
upvoted 4 times
RonWonkers
2 years, 3 months ago
User report falling for the phishing mail
upvoted 11 times
...
Sandon
2 years, 2 months ago
It does specify that
upvoted 6 times
hamchook
1 year, 5 months ago
you don't have to click a link to fall for a phishing email, you can reply to it with sensitive info not having clicked anything. i go with message gateway; i also did this kind of work and that's the first thing i would check (see the sender, check header info, check to see if that sender sent emails to anyone else to get ahead of it before anybody else falls for it)
upvoted 9 times
...
...
...
examcrammer
1 year, 3 months ago
DNS would only be useful if the link in the phishing email used a FQDN. If the link used an IP address, DNS is of no use.
upvoted 5 times
...
...
Alcpt
Most Recent 4 months, 1 week ago
Selected Answer: B
Gateway logs first. Then DNS, etc
upvoted 1 times
...
csentry007
5 months, 3 weeks ago
Selected Answer: A
Are we assuming, b falling for it, the clicked a link? DNS logs
upvoted 1 times
...
JFS_23
5 months, 3 weeks ago
Selected Answer: B
Message gateway is the right answer since if we consider the context of investigating a reported phishing email
upvoted 1 times
...
JasonMunoz
7 months ago
The Authentication logs would be the first system logs that the analyst should check in this scenario. These logs provide information about user authentication events, including login attempts, successful logins, and failed logins. By examining authentication logs, the analyst can identify any suspicious or unauthorized access attempts related to the user who fell for the phishing email.
upvoted 1 times
...
Shouqq_examtopics
8 months, 2 weeks ago
Selected Answer: B
Massage gateway logs
upvoted 2 times
...
AspiringNerd
8 months, 3 weeks ago
Selected Answer: B
The analyst would first check: B. Message gateway logs. Message gateway logs, such as those from email servers or email security appliances, often contain valuable information about incoming and outgoing emails, including details about email delivery, sender and recipient information, and any actions taken by the gateway, such as quarantining or blocking suspicious emails. These logs can help the analyst identify and investigate the phishing email reported by the user.
upvoted 1 times
...
Imjusthere00
9 months, 3 weeks ago
Selected Answer: A
I would say DNS
upvoted 1 times
...
DrakeMallard
10 months, 1 week ago
Selected Answer: A
I'm leaning toward DNS because unless I'm mistaken Message Gateway is not in the objectives for the exam.
upvoted 2 times
...
kewokil120
11 months, 1 week ago
Selected Answer: B
Email issue. Check Email logs. The closet option is Mail gateway and I would hope it would keep a log of that email for admin inspection. Ironport and o365 does this.
upvoted 1 times
...
[Removed]
11 months, 2 weeks ago
From all sources, I can gather it is either Authentication, Message Gateway, or DNS. Except for this site, DNS is out. I cannot find a straignt correct answer. Chat GPT answers both, another site has the question listed twice with two different answers.
upvoted 1 times
...
Susan4041
11 months, 3 weeks ago
I have to say GPT does help at times but I have found it has been wrong as well. Please do't always trust it.
upvoted 2 times
...
klinkklonk
11 months, 4 weeks ago
Selected Answer: B
Message gateway. The message gateway logs would provide information about the incoming and outgoing emails, including details about the phishing email. It may include information about the sender, recipient, subject, attachments, and other relevant details related to the email's entry point into the organization's email system.
upvoted 2 times
...
thecheat97
1 year ago
The answer is authentication on the actual exam and prep exam
upvoted 1 times
sosa4547
8 months, 1 week ago
That's what I have down also from another Exam prep course, Authentication.
upvoted 1 times
...
kevgjo
1 year ago
you sure about that
upvoted 2 times
...
...
Arpilir
1 year, 1 month ago
Selected Answer: B
Phishing emails doesnt always have to contain links. Sometimes attacker would pretend someone who needs to verify an identity to update an account and victim needs to reply the requested information. DNS does not apply to that scenario. So to gain some context about the phishing attack, you have to check the email gateway first.
upvoted 3 times
...
Cloudninja117
1 year, 1 month ago
Selected Answer: A
check the logs for the dns
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago