SY0-701 exam dumps

SY0-701 practice question 106 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 106

Single answerZero-day

A security team detects suspicious outbound connections from several employee workstations to an unfamiliar IP range. Endpoint protection did not generate any signatures, and a review shows all affected systems are fully patched against known vulnerabilities. The team confirms attackers are exploiting a previously unknown flaw in a widely used document viewer. Management wants the most effective immediate action to reduce risk while the vendor develops a fix. Which of the following is the BEST response?

  1. A

    Disable the vulnerable application's ability to execute active content or open untrusted document types, and isolate affected hosts

  2. B

    Wait for the vendor to release an official patch before making changes, to avoid disrupting business operations

  3. C

    Run a full vulnerability scan and rely on the scanner to identify and remediate the issue automatically

  4. D

    Reimage all user workstations immediately and restore the same document viewer configuration afterward

Show answer and explanation

Correct answer: A

Explanation

A zero-day refers to a previously unknown vulnerability that attackers exploit before a patch or established detection is available. In this scenario, the strongest immediate response is to apply compensating controls and contain impacted systems rather than wait for traditional remediation. Security best practices from common incident response guidance, including NIST incident handling principles, emphasize containment, mitigation, and recovery in that order during active exploitation. Practical controls can include disabling macros or active content, blocking risky file types, restricting application execution, applying network filtering, and isolating affected endpoints. Waiting for a patch is too slow during active exploitation, and vulnerability scanners are not a dependable primary control for unknown flaws. Reimaging may be part of recovery, but only after the organization has reduced the ongoing attack surface.

  • A. Correct.

    This is the best answer because a zero-day is being actively exploited before a vendor fix or reliable signature is available. Immediate mitigation should focus on reducing exposure through compensating controls, such as disabling risky features, restricting file types, tightening application behavior, and isolating impacted systems to contain spread and data loss. This reflects real-world incident response for zero-day exploitation: contain first, then eradicate and recover when better detection or patches become available.

  • B. Incorrect.

    This is incorrect because waiting for a patch leaves the organization exposed during active exploitation. Although patching is the long-term corrective action once available, zero-day events require compensating controls and containment measures immediately. The misconception is that change control or business continuity should override urgent risk reduction during an active compromise.

  • C. Incorrect.

    This is incorrect because vulnerability scanners primarily detect known weaknesses and generally cannot automatically identify or remediate a previously unknown zero-day vulnerability. A scan may still be useful for broader exposure assessment or identifying vulnerable software versions, but it is not the best immediate response to stop an ongoing zero-day attack. The misconception is equating vulnerability management tools with real-time zero-day containment.

  • D. Incorrect.

    This is incorrect because reimaging affected systems may help with recovery, but restoring the same vulnerable application configuration would not address the underlying exposure. In addition, immediate mass reimaging is often operationally disruptive and does not by itself provide a compensating control for systems that have not yet been compromised. The misconception is treating recovery as the first step instead of containment and mitigation.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam