SY0-701 exam dumps

SY0-701 practice question 107 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 107

Single answerZero-day

A security analyst notices several engineering workstations making unusual outbound connections to random internet hosts over TCP 443. Endpoint detection shows a signed PDF reader process spawning PowerShell, but the vendor has not released a patch and no antivirus signatures currently detect the activity. The affected systems must remain online for business operations. Which action should the analyst take FIRST to most effectively reduce risk from this likely zero-day exploit while preserving operations?

  1. A

    Immediately reimage all affected workstations and restore user data from last week's backups

  2. B

    Implement network-based blocking and endpoint isolation controls for the observed indicators, such as restricting the PDF reader's outbound access and blocking known malicious destinations

  3. C

    Wait for the software vendor to publish a patch so remediation does not disrupt production systems

  4. D

    Disable TLS inspection so the unusual encrypted traffic can pass without interfering with the application

Show answer and explanation

Correct answer: B

Explanation

The key concept with a zero-day is that defenders often lack an official patch or signature at the time of discovery or exploitation. In those cases, Security+ expects candidates to recognize the importance of compensating controls: containment, isolation, segmentation, application control, indicator-based blocking, and enhanced monitoring. In this scenario, the analyst has clear suspicious behavior: a document reader spawning PowerShell and making unusual outbound connections. That points to likely exploitation and post-exploitation activity. The most effective first step is to reduce exposure immediately using network and endpoint controls while preserving business function. This aligns with common incident response guidance from NIST, especially NIST SP 800-61 on incident handling, which emphasizes containment as an early priority, and with general best practices from vendors and security frameworks that recommend temporary mitigations when patches are unavailable.

  • A. Incorrect.

    Reimaging may eventually be appropriate for confirmed-compromised hosts, but it is not the best first step in this scenario because the organization must keep systems operational and there is no patch yet. It also does not address the immediate spread or command-and-control risk across other systems. Jumping straight to full rebuilds can cause unnecessary downtime before containment measures are in place.

  • B. Correct.

    This is the best answer. A zero-day means a vulnerability is being exploited before a vendor fix or signature-based detection is available. In that situation, compensating controls are the most effective immediate response. Blocking known malicious destinations, limiting the vulnerable application's outbound communications, segmenting or isolating affected endpoints, and creating detections based on indicators of compromise can reduce attacker access while allowing business operations to continue.

  • C. Incorrect.

    Waiting for a patch is a common but dangerous mistake. With a likely zero-day under active exploitation, delaying action allows continued command-and-control traffic, possible lateral movement, and data loss. Security best practices prioritize containment and mitigation through compensating controls when no vendor patch is yet available.

  • D. Incorrect.

    Disabling TLS inspection would reduce security visibility and make it harder to identify malicious outbound communications. It does not mitigate the exploit and could worsen the incident by allowing encrypted command-and-control traffic to go uninspected. This option reflects a misunderstanding of how to respond to suspicious encrypted traffic.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam