nerdexam
CompTIA

SY0-301 · Question #621

Which of the following may cause Jane, the security administrator, to seek an ACL work around?

The correct answer is A. Zero day exploit. A zero-day exploit has no available patch or signature, forcing administrators to use ACL-based compensating controls to mitigate traffic until a fix is available.

Threats, vulnerabilities, and mitigations

Question

Which of the following may cause Jane, the security administrator, to seek an ACL work around?

Options

  • AZero day exploit
  • BDumpster diving
  • CVirus outbreak
  • DTailgating

How the community answered

(42 responses)
  • A
    74% (31)
  • B
    5% (2)
  • C
    7% (3)
  • D
    14% (6)

Why each option

A zero-day exploit has no available patch or signature, forcing administrators to use ACL-based compensating controls to mitigate traffic until a fix is available.

AZero day exploitCorrect

A zero-day exploit targets an unknown vulnerability with no existing patch or antivirus signature. Because traditional defenses cannot detect or block it directly, a security administrator may configure ACL rules to block suspicious traffic patterns or isolate affected segments as a compensating control while a proper fix is developed.

BDumpster diving

Dumpster diving is a physical information-gathering attack and is not mitigated by network ACLs.

CVirus outbreak

A virus outbreak is addressed by antivirus and endpoint controls, not ACL workarounds.

DTailgating

Tailgating is a physical security breach that ACLs cannot prevent.

Concept tested: Zero-day compensating controls using ACLs

Source: https://www.nist.gov/publications/guide-intrusion-detection-and-prevention-systems-idps

Topics

#zero day exploit#ACL bypass#vulnerability management#threat mitigation

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice