SY0-501 · Question #384
The Chief Information Security Officer (CISO) is asking for ways to protect against zero-day exploits. The CISO is concerned that an unrecognized threat could compromise corporate data and result in…
The correct answer is D. Behavior-based IPS with a communication link to a cloud-based vulnerability and threat feed. To protect against unknown zero-day exploits, the most effective solution is a behavior-based Intrusion Prevention System integrated with a cloud-based threat intelligence feed for real-time threat analysis.
Question
The Chief Information Security Officer (CISO) is asking for ways to protect against zero-day exploits. The CISO is concerned that an unrecognized threat could compromise corporate data and result in regulatory fines as well as poor corporate publicity. The network is mostly flat, with split staff/guest wireless functionality. Which of the following equipment MUST be deployed to guard against unknown threats?
Options
- ACloud-based antivirus solution, running as local admin, with push technology for definition
- BImplementation of an off-site datacenter hosting all company data, as well as deployment of VDI
- CHost-based heuristic IPS, segregated on a management VLAN, with direct control of the
- DBehavior-based IPS with a communication link to a cloud-based vulnerability and threat feed
How the community answered
(56 responses)- A2% (1)
- B4% (2)
- C11% (6)
- D84% (47)
Why each option
To protect against unknown zero-day exploits, the most effective solution is a behavior-based Intrusion Prevention System integrated with a cloud-based threat intelligence feed for real-time threat analysis.
Antivirus solutions primarily rely on signatures and known heuristics, which are less effective against truly novel zero-day exploits compared to behavior-based IPS, and running as local admin creates an unnecessary security risk.
An off-site datacenter and VDI deployment primarily address business continuity, disaster recovery, and centralized management, but do not inherently provide direct protection against zero-day exploits.
The option's description is incomplete ("with direct control of the"), making it technically ambiguous and thus an unsuitable answer, though a host-based heuristic IPS could be part of a broader security strategy.
A behavior-based Intrusion Prevention System (IPS) actively monitors network and system activities for anomalous patterns and deviations from normal behavior, which is crucial for detecting and preventing novel, previously unseen zero-day exploits. Its communication link to a cloud-based vulnerability and threat feed provides continuous, real-time intelligence on emerging threats and attack indicators, significantly enhancing its ability to identify and respond to unknown threats effectively.
Concept tested: Zero-day exploit mitigation with behavior-based IPS and threat intelligence
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/next-generation-protection?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.