nerdexam
CompTIA

SY0-501 · Question #384

The Chief Information Security Officer (CISO) is asking for ways to protect against zero-day exploits. The CISO is concerned that an unrecognized threat could compromise corporate data and result in…

The correct answer is D. Behavior-based IPS with a communication link to a cloud-based vulnerability and threat feed. To protect against unknown zero-day exploits, the most effective solution is a behavior-based Intrusion Prevention System integrated with a cloud-based threat intelligence feed for real-time threat analysis.

Submitted by kavita_s· Mar 4, 2026Security architecture

Question

The Chief Information Security Officer (CISO) is asking for ways to protect against zero-day exploits. The CISO is concerned that an unrecognized threat could compromise corporate data and result in regulatory fines as well as poor corporate publicity. The network is mostly flat, with split staff/guest wireless functionality. Which of the following equipment MUST be deployed to guard against unknown threats?

Options

  • ACloud-based antivirus solution, running as local admin, with push technology for definition
  • BImplementation of an off-site datacenter hosting all company data, as well as deployment of VDI
  • CHost-based heuristic IPS, segregated on a management VLAN, with direct control of the
  • DBehavior-based IPS with a communication link to a cloud-based vulnerability and threat feed

How the community answered

(56 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    11% (6)
  • D
    84% (47)

Why each option

To protect against unknown zero-day exploits, the most effective solution is a behavior-based Intrusion Prevention System integrated with a cloud-based threat intelligence feed for real-time threat analysis.

ACloud-based antivirus solution, running as local admin, with push technology for definition

Antivirus solutions primarily rely on signatures and known heuristics, which are less effective against truly novel zero-day exploits compared to behavior-based IPS, and running as local admin creates an unnecessary security risk.

BImplementation of an off-site datacenter hosting all company data, as well as deployment of VDI

An off-site datacenter and VDI deployment primarily address business continuity, disaster recovery, and centralized management, but do not inherently provide direct protection against zero-day exploits.

CHost-based heuristic IPS, segregated on a management VLAN, with direct control of the

The option's description is incomplete ("with direct control of the"), making it technically ambiguous and thus an unsuitable answer, though a host-based heuristic IPS could be part of a broader security strategy.

DBehavior-based IPS with a communication link to a cloud-based vulnerability and threat feedCorrect

A behavior-based Intrusion Prevention System (IPS) actively monitors network and system activities for anomalous patterns and deviations from normal behavior, which is crucial for detecting and preventing novel, previously unseen zero-day exploits. Its communication link to a cloud-based vulnerability and threat feed provides continuous, real-time intelligence on emerging threats and attack indicators, significantly enhancing its ability to identify and respond to unknown threats effectively.

Concept tested: Zero-day exploit mitigation with behavior-based IPS and threat intelligence

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/next-generation-protection?view=o365-worldwide

Topics

#zero-day exploits#behavior-based IPS#threat intelligence#unknown threats

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice