SY0-601 — Frequently Asked Questions
Community-vetted answers to 206 common questions about this exam.
Questions from real practice questions
Each Q&A comes from a specific community question — follow the link for its full analysis.
Air Gap Isolation for Externally Exposed Network Segments
A screened subnet still routes traffic but filters it between zones, while an air gap removes the network path entirely, so no packet can pass between the isolated segment and the internal network.
A Faraday cage blocks electromagnetic emanations and interference, so it defends against signal leakage and some wireless attacks, but a caged server still uses its network interface and can reach the corporate LAN.
Blocking Malware Command and Control With IP-Based Firewall Rules
Segmentation is effective but it is an architectural change that takes planning and rollout, so it is slower than pushing a firewall rule that blocks the command-and-control addresses already in use.
A firewall rule can deny specific destination IP addresses immediately, while a content filter works at the application and web layer and cannot cut established traffic to a known malicious IP as directly.
Enforcing a SaaS Usage Policy With a Cloud Access Security Broker
SSO consolidates how users authenticate, but once authenticated a user can still open any cloud application, so SSO provides no allow list of sanctioned SaaS services.
It inspects cloud application traffic to discover which services are in use, then applies policy that permits sanctioned applications and blocks unsanctioned ones while reporting on both.
Successful Privilege Escalation From a Local User to System
Because the question asks what the analyst discovered, and the transcript ends with the operator holding the System account, so the completed privilege escalation describes the finding better than the technique used.
It confirms the outcome: the first whoami showed domain localuser, and after psexec -s the same check returns nt authority system, proving the privilege change took effect.
Remediating Excessive Domain Admin Rights With PAM and RBAC
It is a one-time cleanup with no ongoing control, so excess administrative access can return and the rotated passwords will age, whereas a PAM vault keeps rotating and RBAC keeps restricting access.
PAM stores the credentials centrally and rotates them on a defined schedule without manual effort, so staff never need to know or reuse the underlying password.
Switching From Tape to Cloud Backup for Disaster Availability
A SAN provides block storage for production systems and sits in the same data center, so it offers no geographic separation; backups can be written to it, but that copy is still on-premises.
No. Cloud describes where the copy is stored, while full, incremental, and differential describe how much data each job captures, so a cloud backup still needs a schedule and retention.
Data Masking With Asterisks in a Banking Web Application
Masking hides part of a value at the presentation layer while the real data still exists behind it, whereas anonymization permanently removes identifiers so no record can be tied to an individual.
No. Display masking only limits what is rendered to the user, so the underlying value still needs encryption at rest, access control, and auditing to meet storage requirements.
IaaS vs PaaS When the Business Owns the Operating System
IaaS leaves the operating system, middleware, runtime, and application with the customer, while the provider runs virtualization, servers, storage, and networking; in PaaS it also takes the OS.
XaaS is an umbrella term meaning anything as a service and is not a defined model, so on the exam it is a distractor whenever the scenario clearly matches IaaS, PaaS, or SaaS.
Full Weekly and Differential Daily Backup Strategy
Two: the most recent full backup and the most recent differential taken after it. The differential holds every change since that full, so earlier differentials in the same week are not needed.
Choose incremental when the constraint is storage space, backup window, or bandwidth, because each job copies only what changed since the last job; a restore replays the full plus every incremental.
Access Auditing as the SaaS Vendor Risk to Focus On
In IaaS the customer builds and hardens the host, so exposed ports and unused services are its own misconfiguration to fix; in SaaS the provider runs the OS and network layer, so it cannot close them.
No. Auditing continuously governs access to the data, while due diligence such as SOC 2 reports, penetration test results, and right-to-audit clauses assesses the vendor during the contract.
Threat Hunting Data Sources for Exploitable Systems
Vulnerability scanning identifies static weaknesses (flaws) in systems. Threat hunting actively searches for evidence of current attacks using external intelligence, making it a different, more dynamic process.
Threat feeds supply real-time data on attacker TTPs and IOCs. Hunters use this intel to form hypotheses and search their environment for signs that these specific threats are present.
Determining Phishing Link Success via Log Sources
Application logs track software events, but network logs directly show if the device reached the server, which is the core requirement.
DNS is part of network activity. General network logs often encompass or correlate with DNS query results to show resolution and connection.
Compromising Credentials via Offline Brute-Force
Creating a rainbow table is often impractical due to storage requirements and salt usage. Directly brute-forcing the specific stolen hashes is faster and more efficient.
Online attacks interact with the live system and risk detection/lockouts. Offline attacks use stolen data locally, allowing unlimited attempts without immediate detection.
Device Identification and Policy Management
Network diagrams are static visual representations. They cannot interact with configuration management software to automatically apply settings to specific devices.
Consistent names allow admins to create dynamic groups in management tools. Policies can then be assigned to these groups based on the naming pattern.
Detecting Fraud via Job Rotation
Separation of duties is a preventive control designed to stop fraud before it happens by splitting tasks. It does not actively detect existing fraud.
By taking over a role, a new employee reviews the previous worker's actions and records, often spotting irregularities or unauthorized transactions that were hidden.
MDM Features for Lost Mobile Device Security
Encryption protects data at rest, but if the device has no screen lock, an attacker can access it immediately upon finding it, bypassing encryption benefits until the device locks.
Yes, by erasing corporate data, it removes the information an attacker might use to impersonate employees or gain trust during a social engineering attack.
Hash Algorithm for Data Integrity Verification
Checkums detect accidental errors but lack cryptographic security. They cannot reliably verify that data was not intentionally modified by an attacker.
Encryption protects confidentiality by scrambling data with a key. Hashing creates a fixed digest to verify integrity; it is one-way and does not use a key for decryption.
Identifying Rogue Access Points Bypassing Content Filters
Hiding an SSID is a security measure, but it doesn't explain how the device provides internet access outside the corporate filter. The core issue is the unauthorized network bridge.
Yes, if it connects directly to the internet (e.g., via cellular or home broadband) without passing through the corporate firewall, it bypasses all content filtering rules.
Cloud Service Models for Outsourced Patching
Yes. In SaaS, the vendor manages the entire stack including physical hardware and firmware. The customer only accesses the software via a browser.
PaaS requires the customer to manage the applications they deploy. SaaS includes the application layer, allowing full outsourcing of application patching.
Protecting Unsupported Application Servers
Air gapping physically disconnects the device, making an 'application server' unable to serve any requests. It is too extreme for a system that needs to operate.
It is a DMZ (Demilitarized Zone) isolated by one or more firewalls, used to host public-facing services so they don't expose the internal network if compromised.
SOAR vs SIEM for Reducing SOC Manual Work
SIEM can correlate logs and use rules to flag threats, but it does not inherently automate the response or reduce the manual effort required to investigate those alerts without additional SOAR integration.
SIEM focuses on collecting and analyzing security data for detection, while SOAR focuses on automating workflows and coordinating responses across different security tools.
Mitigating MFP Document Confidentiality Risks
Encryption protects data at rest on the hard drive or in transit, but it does not stop someone from walking away with a printed page left in the output tray.
No. While education helps, it is a compensating control. Technical controls like pull-printing or authentication are required to actively prevent unauthorized physical access.
Why Resetting Local Passwords Blocks Pass-the-Hash Attacks
Password compromise is a broad outcome, but the scenario explicitly highlights stored hash values. Rotating these hashes specifically breaks the replay mechanism used in pass-the-hash attacks.
No, hashing alone does not stop hash replay, but regular password resets force new hashes, rendering previously stolen hash values useless for authentication.
Tokenization Characteristics for Credit Card Protection
Yes, tokenization is reversible if you have access to the token vault or mapping database. It is not cryptographically reversible like encryption without a key, nor is it irreversible like hashing.
Irreversibility is a trait of hashing or anonymization. Tokenization allows for the recovery of original data via a vault, so it is not inherently irreversible.
Identifying Remote Access Trojan Infection Vectors
Brute-force attacks generate excessive failed login attempts in security logs. The scenario states no such failures occurred.
No. Stealthy RATs are designed to be lightweight to avoid detection and may not cause noticeable performance issues.
Why Are Only Internal Kiosk Credentials Compromised?
ARP operates at Layer 2 and is confined to a single broadcast domain. The presence of multiple routers prevents ARP spoofing from affecting kiosks on different floors.
No. If the web application contained malicious code, every visitor—including remote employees—would have their credentials stolen, contradicting the scenario.
Ransomware Backup Recovery Strategy
While off-site, cloud backups often remain connected via APIs or mounts. If compromised, ransomware can encrypt them. Offline media is physically isolated.
Incremental backups take longer to restore because they require chaining multiple files. For strict RTO requirements, full backups are faster to recover.
Troubleshooting Application Access to Internal Resources
The issue is access to a 'specific' resource, implying authorization failure, not a transport layer compatibility issue.
No, 'allow/deny list' is a general term for access controls including ACLs, firewall rules, and application-level permissions.
MFA and Patch Management Control Type and Category
While MFA uses technical tools, the control is defined by the policy requiring its use. CompTIA classifies policy-driven security measures under Administrative controls.
It is Preventative. Patching fixes vulnerabilities to prevent exploitation before an attack occurs, rather than detecting an attack already in progress.
Identifying Security Baseline Documentation for Device Hardening
A security policy is a high-level statement of management intent and rules. A configuration guide provides specific, technical instructions on how to set up systems to meet those rules.
Frameworks provide a structural approach to managing risk (like NIST or ISO). They do not contain the specific technical settings needed to harden individual servers or devices.
Staging Environment Purpose in System Upgrades
Test environments are for functional verification and often use synthetic data. They do not necessarily mirror production infrastructure or use realistic customer data subsets needed to assess upgrade impacts.
Production handles live traffic and real customer data. Staging mirrors production exactly but uses a subset of data and restricted access to allow safe testing of upgrades before they go live.
SIP Server Security Weaknesses and Unsolicited Calls
Provider duplication doesn't explain who is placing the calls. Weak SIP settings (B) provide the mechanism for unauthorized usage.
While possible, B is the broader technical cause. Weak settings enable both insider and outsider abuse, making it the primary security finding.
Penetration Test Types: Unknown vs Known Environment
An unknown environment gives the tester zero prior information (black-box), while a partially known environment provides some details like network diagrams or limited credentials (gray-box).
A bug bounty is a crowdsourced security program model. While it may involve testing, it is not a defined technical methodology like black-box or white-box testing used in professional assessments.
PKI Flaw Remediation: Patching the CA
Updating the CRL only revokes existing compromised certificates. It does not fix the software flaw allowing attackers to create new fraudulent certificates.
Yes, patching often requires maintenance windows. However, it is necessary to permanently close the vulnerability exploited by the attacker.
Social Engineering Authority Exploitation in SY0-601
Spam filters are technical controls. The question asks why the attacks were successful in deceiving users, which is a psychological issue of authority, not just a technical bypass.
Authority involves impersonating someone with power or expertise (e.g., Director, Legal). Urgency involves time pressure (e.g., 'act now or lose access'). These often overlap, but the prompt emphasizes the role of the sender.
Identifying Sandbox Environments with Obfuscated Data
QA typically involves structured testing against specific requirements using defined test cases. A sandbox is more about open-ended experimentation and exploration with realistic data.
Obfuscated data is real data that has been altered or masked to remove sensitive information, allowing it to be used safely in non-production environments like sandboxes.
Guidelines for Information Security Risk Management
NIST CSF is a framework that provides guidelines and best practices. It is voluntary and does not require certification, unlike ISO 27001.
ISO 27001 is an international standard that requires formal certification and auditing. The question asks for 'guidelines,' which aligns with the voluntary nature of the NIST CSF.
Mobile Data Security After Device Theft
FDE protects data at rest, but since the attacker successfully logged in, the device is likely unlocked and the data is accessible in memory or via active sessions.
No, remote wipe destroys data. It is a recovery action, not a protection mechanism that allows continued secure operation or prevents immediate access.
Outsourcing Payment Processing Compliance Requirements
ISO 27001 is a general ISMS framework. It lacks the specific technical controls for credit card encryption and transmission mandated by PCI DSS.
No. SOC 2 focuses on trust principles like security and availability. It does not validate adherence to the specific Payment Card Industry Data Security Standard.
Identifying Invoice Scams in Accounting
Pretexting is the broad method of creating a false scenario. The specific execution here—demanding payment for fake services—is an invoice scam.
Ransomware encrypts files and demands crypto. Invoice scams trick you into voluntarily paying a fake bill via wire or check.
Identifying Fileless Malware via PowerShell Execution
Macros are associated with Office documents (VBA). This is a direct PowerShell CLI invocation, characteristic of fileless malware, not a document macro crash.
It sets the ExecutionPolicy to 'Bypass', allowing scripts to run without warnings or prompts, a key tactic for fileless attacks to avoid triggering security alerts.
Smart Card MFA Additional Factor
A hardware token is also 'something you have'. MFA requires factors from different categories, so it does not add a new type of proof.
No, a User ID is an identifier used to locate an account, not a secret or biological trait used to verify identity.
Identifying ARP Poisoning from MAC and Traffic Clues
MAC flooding overflows the switch's CAM table to force hub mode, while ARP poisoning spoofs IP-to-MAC mappings to intercept traffic between specific hosts.
DHCP snooping is a defensive configuration feature, not an attack. It prevents rogue DHCP servers from distributing incorrect IP configurations.
Forensic Checksums and Data Integrity
Non-repudiation proves the identity of the sender (who did it). Checksums only prove the file content hasn't changed (what happened).
Integrity is about the data's technical state (unchanged). Chain of custody is the legal documentation of who handled the evidence.
Identifying Dead Code in Software Development
Dead code is unused and unexecuted, while obfuscated code is intentionally made difficult to understand for security.
It increases the attack surface and may contain undiscovered vulnerabilities that attackers can exploit.
Threat Actor Using Public Repository Commands
State actors typically possess advanced capabilities and develop custom tools. Relying on public scripts indicates a lower skill level characteristic of script kiddies.
In the context of SY0-601, yes. The term 'script kiddie' specifically refers to those who use pre-made tools without understanding the underlying code or mechanics.
Mitigating Client-Side Bypass in Web Applications
Client-side validation runs in the user's browser, which an attacker can disable or manipulate using tools like Burp Suite, rendering it unreliable for security.
No, code signing ensures the software itself hasn't been tampered with, but it does not validate the data entered by users into the application.
Vulnerability Prioritization Tools
A risk register is a document that lists all identified risks. A risk matrix is a tool used to analyze and prioritize those risks based on impact and probability.
No. The scanner provides the raw data (vulnerabilities), while the matrix helps the security team interpret that data to decide which ones to fix first.
Preventing Burnout and Ensuring Continuity
Mandatory vacations are a detective control for fraud. They do not provide training in other roles or help with daily burnout from monotony.
By rotating staff, multiple employees gain experience in various roles. If one leaves, others can immediately step in without needing extensive retraining.
Identifying Threat Actors Using Zero-Day Exploits
While possible, it is rare. Hacktivists typically prioritize speed and visibility over stealth, so they prefer using known, easily exploitable vulnerabilities to achieve their political goals quickly.
An APT is defined by its persistence (long-term presence), advanced techniques (like zero-days), and specific objectives (usually espionage or data theft) often backed by nation-state resources.
Implementing SAML for Cloud Vendor SSO
RADIUS is designed for network access authentication (like Wi-Fi or VPN), not for web application identity federation and Single Sign-On.
No, SAML enables Single Sign-On, so users authenticate against their existing directory once and do not need separate passwords for the vendor tool.
Tracking Changes Between Software Deployments
Continuous monitoring tracks system state and security events in real-time, whereas version control records historical changes to code files.
While it provides an audit trail, non-repudiation is a broader security goal often achieved via digital signatures, not just version tracking.
Identifying Operational Controls in Code Deployment
While the repository is a technical tool, the control itself is the policy requiring human agreement. Technical controls enforce security via software/hardware, not manual policy.
Administrative controls are high-level policies and guidelines. Operational controls are the specific daily procedures and practices implemented to execute those policies.
Identifying ARP Poisoning via Command Output
It causes blackholing or man-in-the-middle attacks, leading to dropped packets or slow responses as traffic is intercepted or misrouted.
ARP poisoning involves one MAC owning multiple IPs maliciously; IP conflicts usually involve two different MACs claiming the same IP, causing network stack errors.
Categorizing and Sharing Threat Actor TTPs
CVEs identify specific software vulnerabilities, not the attacker's methods or behaviors (TTPs).
Yes, the MITRE ATT&CK framework is publicly available and free to use for threat intelligence sharing.
Implementing Second Factor for Single Sign-On
A secondary PIN is still 'something you know.' MFA requires two distinct categories, so adding another knowledge factor does not meet the strict definition.
TOTP is generated locally on an app (Google Authenticator), while SMS relies on network transmission. Both are 'something you have,' but TOTP is generally more secure against SIM swapping.
Data Retention Policy for Compliance and Destruction
Security policies are broad frameworks for protecting assets. They do not typically include specific operational directives on how long data must be retained or the technical steps for its destruction.
Yes, retention policies are primarily driven by legal and regulatory requirements. They ensure data is kept only as long as necessary to satisfy these laws before being destroyed.
Video Camera Security Control Classification
While cameras use technology, the term 'Technical control' usually refers to logical safeguards like access controls or encryption. In this context, we classify by operational effect.
Yes. A visible alarm system is a classic example. It deters criminals by its presence and detects intrusions by sounding an alert or logging the event.
Determining Vulnerability Severity with CVSS
CVE is an identifier (like a name) for a vulnerability, while CVSS is a scoring system that measures its severity.
No, SOAR automates response workflows but does not calculate the inherent severity score of a vulnerability itself.
Image Geolocation Coordinates as Metadata
Metadata is 'data about data.' Geolocation describes the file's creation context, not its visual content.
No. While the whole file could be encrypted, the coordinate tags themselves are metadata fields, not encryption algorithms.
Identifying USB Baiting Social Engineering Attacks
Baiting uses a physical lure (like a USB) to trick the victim into connecting it. Pretexting relies on a fabricated story or identity to manipulate the victim into revealing information.
Yes, if the device was intentionally left by an attacker to exploit curiosity. It is a subset of baiting often called 'USB dropping'.
Password Security: Salting vs Hashing
Hashing is the transformation algorithm. Salting is the specific act of adding random data to the input before hashing to increase security against precomputed attacks.
Rainbow tables rely on precomputed hashes of common passwords. Since each salted password has a unique random prefix/suffix, the resulting hash is unique, rendering generic rainbow tables useless.
What is adding a value to the end of a password called?
Key stretching adds iterations to make cracking slower, while salting adds random data to make hashes unique.
No, salting ensures unique hashes for identical passwords but does not encrypt or hide the original password itself.
Protecting MFA from Carrier Social Engineering
SMS relies on the telecommunications network and the SIM card. Attackers can perform SIM swapping by socially engineering carrier support staff to transfer your number to their device, allowing them to receive your verification codes.
While it prevents carrier-specific attacks like SIM swapping, it is still susceptible to phishing or malware if the device itself is compromised. However, it is significantly more secure than SMS for this specific threat model.
Enforcing Role-Based Security Policies for SaaS Applications
NG-SWG filters web traffic but doesn't integrate deeply with SaaS APIs for granular role-based access control.
No, it's primarily for SaaS and IaaS where you need visibility and policy enforcement beyond basic network controls.
Mitigating Risk for Unpatchable Legacy SCADA Controllers
VLANs provide logical separation but still allow network communication. For unpatchable critical assets, stricter isolation is needed to prevent lateral movement.
No. Blocking internet doesn't stop internal attackers or malware from spreading laterally to the controller from other compromised devices on the same network.
Data Types Subject to Regulations and Laws
Trade secrets are protected by civil law and contracts, not specific government privacy statutes like HIPAA or GDPR.
PII identifies an individual (name, SSN), while PHI is specifically health-related information tied to an individual.
HVAC Impact on Hardware Availability
A UPS provides electrical power continuity during outages. HVAC ensures the physical environment remains cool and dry; failure causes overheating even if power is stable.
TPM is a security chip for encryption keys. It has no role in regulating temperature or ventilation, which are the environmental factors mentioned in the question.
Legal Hold Definition in Forensics
No, it applies to all relevant evidence, including physical documents, emails, and communication logs.
It is initiated when litigation is reasonably anticipated or has already begun to prevent spoliation of evidence.
Cloud Service Model with Maximum Control
PaaS abstracts the OS and runtime, so you cannot customize the underlying infrastructure or install arbitrary software outside the provided platform.
No, the provider manages the physical hardware, but you have root/administrator access to the virtual machines and their configurations.
Linux File Permission Remediation Command
chmod stands for 'change mode'. It is used in Unix-like systems to change the access permissions of file system objects.
Grep is a search tool used to find text patterns within files. It does not have the capability to modify file attributes or permissions.
Security Concerns with Legacy Systems in Production
No. While insecure protocols are risky, they can sometimes be mitigated with network controls. Lack of vendor support means you cannot fix the root cause of vulnerabilities.
Instability affects availability, but neither is a direct security vulnerability like an unpatched exploit. Security focuses on confidentiality, integrity, and protection from attacks.
Securing Finance Data with Offshore Teams via VDI
MDM manages devices but doesn't inherently keep data off them. If the device is unowned, enforcing strict data containment is harder than with VDI.
No, a VPN only encrypts the connection. Data can still be downloaded or cached locally on the user's device during the session.
Password Spraying vs Brute-Force Attack Identification
Brute-force targets one account with many passwords. Spraying targets many accounts with few passwords.
To bypass account lockout policies by keeping failed attempts low per individual account.
DNS Logging Tool Control Type
Preventive controls stop actions before they occur. Since DNS logging only records activity after it happens without blocking it, it cannot prevent the visit.
No. Corrective controls fix damage or restore normal operations. A report merely informs administrators so they can decide on further actions, but the tool itself does not correct anything.
Spoofed Identity Digital Certificate Key Type
Public keys are shared openly and cannot be used to sign certificates or decrypt data, which are necessary actions to spoof an identity.
Self-signed certificates are not verified by a trusted Certificate Authority (CA), allowing attackers to easily create fake identities without detection.
Protecting Source Code from Reverse Engineering
Version control tracks changes and stores source code in plain text, making it easier to access, not harder. It has no security function against reverse engineering.
While it can slightly increase file size or execution time due to added complexity, modern obfuscators minimize impact while maximizing protection against analysis.
Prioritizing Vulnerability Patching with CVSS
CVE is just a unique identifier (like a name) for a vulnerability. It does not contain information about severity or impact, so you cannot prioritize based on it alone.
SIEM collects logs and alerts, while CVSS provides the actual severity score. A security director uses CVSS data to decide which alerts require immediate patching.
Protecting Sensitive Data with DLP and Classification
S/MIME encrypts email messages specifically. It does not scan documents or other data types against classification labels across the entire network.
It is widely considered a typo for PHI (Protected Health Information) or PII (Personally Identifiable Information), both of which are standard DLP targets.
Identifying Decoy Systems for Reconnaissance Detection
A honeypot is a single decoy system, while a honeynet is a network containing multiple honeypots to simulate a larger environment.
Yes, honeypots are an active defense mechanism because they interact with and mislead attackers, unlike passive monitoring tools.
What is the Final Step of the Incident Response Process?
Recovery restores systems to normal operation, but the lifecycle requires a formal post-incident review to document findings and improve future responses.
Yes, while sometimes grouped operationally, they both precede recovery and lessons learned in the official SY0-601 exam objectives.
Which Protocol Supports Certificate Authentication and Device Quarantine?
RADIUS handles backend authentication and accounting but lacks the port-level access control and policy enforcement required for device quarantine and compliance checks.
802.1X uses EAP-TLS to exchange internal PKI certificates between the supplicant and authenticator, ensuring mutual authentication before granting network access.
Duplicate MAC Addresses in Network Audits | SY0-601
DHCP handles Layer 3 IP assignments, while MAC addresses are hardcoded at Layer 2; identical MACs on separate hostnames confirm intentional hardware ID replication, not network configuration faults.
Modern 802.1X implementations use EAP-TLS with machine certificates rather than relying solely on MAC authentication, making cloned hardware addresses ineffective against credential-based validation.
Which Backup Type Recovers the Entire OS and System?
No, incremental backups only store changes made after a full backup and lack the foundational OS files needed to boot a crashed system.
No, a Storage Area Network is a dedicated high-speed storage infrastructure, not a data protection methodology or backup strategy.
Which MFA Method Supports Seamless BYOD Integration?
Backup codes are static and require manual retrieval and entry, breaking workflow continuity and increasing exposure to theft or unauthorized access.
Yes, when deployed through enterprise-managed mobile authenticator apps that verify device compliance before granting access tokens.
Which WLAN Installation Step Resolves Frequency Interference?
Physical relocation is less effective than optimizing channel assignments when identical frequencies and high power create immediate RF interference.
They visualize signal strength and interference patterns, helping technicians pinpoint overlapping channels before making configuration changes.
How to Route Multiple Internal Web Servers Through One External IP?
Source NAT only modifies outbound packet headers to hide internal IPs; it cannot route inbound HTTP requests to different backend servers based on URLs or hostnames.
It inspects the Host header in incoming HTTP/HTTPS requests and forwards traffic to the appropriate internal server, enabling virtual hosting without additional public IPs.
First Step in Creating an Anomaly Detection Process?
Logging collects raw data, but without a baseline defining normal patterns, the collected logs lack context for deviation analysis.
Baselines provide statistical averages that directly inform alert thresholds, ensuring detections trigger only on genuine anomalies rather than routine spikes.
Why is SMS OTP More Risky Than TOTP?
No. Both methods rely on identical hashing standards and shared secrets. The security gap stems solely from how messages travel across cellular networks versus local device storage.
TOTP intervals typically last thirty seconds to reduce window exposure, while SMS codes often allow two-minute validity to accommodate delayed carrier delivery.
What Should Be Implemented First to Standardize OS Variations?
Naming organizes assets but does not define technical OS settings, software versions, or security controls required for image standardization.
Hashing verifies file integrity after deployment but cannot establish the initial standardized configuration needed before pushing a system image.
First Step Before Patching a High-Availability Production VM
Verifying a backup service only checks tool status, whereas a snapshot creates an actual point-in-time image required for rapid reversion under SLA pressure.
No. CompTIA exam doctrine mandates a verified recovery point before any production change, regardless of perceived risk, to prevent SLA violations.
Application Risk Assessment Questions
RCSA is the process of gathering data via questionnaires to identify risks. A Risk Matrix is a tool used later to visualize and score those risks based on probability and impact.
While similar, RCSA is typically self-initiated by the team or department for internal governance, whereas an audit is often independent and retrospective.
Identifying CSRF from Account Lockout and Password Change
XSS injects malicious scripts into a trusted site. CSRF uses the trusted site itself to make requests. Here, the user visited a different site that talked back to the target site.
SQL Injection requires manipulating database queries through input fields. Clicking a link to another domain cannot execute SQL code against the target database directly.
Standardizing Security Programs During M&A
CIS Baselines are technical configuration guides. They do not provide the overarching governance, risk management, and policy structure needed to align two entire security programs.
They should select one common framework (e.g., NIST CSF) and map both companies' existing controls to it to create a unified view and standard.
Protecting Remote Data Without VPN
NGFWs are typically perimeter appliances. SWGs are better suited for remote users as they can be deployed as agents or proxies specifically for web traffic filtering.
A VPN creates a tunnel for all traffic, while an SWG specifically filters and secures web traffic, often allowing non-web traffic to bypass the corporate network.
Secure Command-Line File Transfer Protocols
RDP is designed for graphical remote desktop sessions, not for command-line file transfers. It does not natively support the secure, scriptable file transfer mechanisms required here.
SFTP runs over the SSH protocol. It uses the same encryption and authentication mechanisms as SSH but adds commands specifically for file manipulation and transfer.
SaaS Identity Integration for Separate Logins
A unified standard applies the same rules everywhere, but the question explicitly requires different complexity requirements for each SaaS solution.
No, geofencing restricts access by location but does not manage user identities, separate logins, or password complexity policies.
CEO Invoice Email Attack Principle
While urgency is used, the primary reason the intern complies is the fear/disrespect of disobeying the CEO. Authority overrides the scarcity tactic.
It is often called Business Email Compromise (BEC) or Executive Impersonation, relying heavily on the Authority principle.
Identifying Backdoors from External Network Traffic
Keyloggers typically send data outbound to a collector. An inbound connection or a persistent channel for remote control is characteristic of a backdoor.
Fileless malware operates in memory, but the scenario specifies downloading and installing software, making a standard infected executable with a backdoor the more likely root cause.
SOC 2 Type II Audit Duration and Scope
Type I assesses the design of controls at a specific point in time. Type II assesses the operating effectiveness of those controls over a period of time, typically 6-12 months.
ISO 27001 is a certification standard for an ISMS. While it involves audits, it is not defined by the specific 6-12 month continuous observation period characteristic of a SOC 2 Type II report.
Identifying Unknown Wi-Fi Signals as Rogue Access Points
A rogue AP is unauthorized hardware added to the network, while an evil twin mimics a legitimate SSID to trick users into connecting.
No, jamming disrupts signals so they cannot be received or scanned properly, whereas rogue APs broadcast clear, usable signals.
Resolving TLS Errors Due to OCSP Blocking
Adding the root certificate establishes trust in the issuer. It does not help if the browser cannot contact the OCSP server to check revocation status.
No, but strict security policies or misconfigurations may block outbound HTTP/HTTPS traffic to OCSP responders, causing validation failures.
Hiding Server Count and Addresses with Virtual IP
IPSec encrypts traffic but does not hide the number of servers or their individual IP addresses from the public.
It presents a single IP to the client while a load balancer distributes traffic to multiple backend servers transparently.