CompTIA
SY0-501 · Question #386
An organization identifies a number of hosts making outbound connections to a known malicious IP over port TCP 80. The organization wants to identify the data being transmitted and prevent future conn
Sign in or unlock SY0-501 to reveal the answer and full explanation for question #386. The question stem and answer options stay visible for context.
Submitted by katya_ua· Mar 4, 2026Security operations
Question
An organization identifies a number of hosts making outbound connections to a known malicious IP over port TCP 80. The organization wants to identify the data being transmitted and prevent future connections to this IP. Which of the following should the organization do to achieve this outcome?
Options
- AUse a protocol analyzer to reconstruct the data and implement a web-proxy.
- BDeploy a web-proxy and then blacklist the IP on the firewall.
- CDeploy a web-proxy and implement IPS at the network edge.
- DUse a protocol analyzer to reconstruct the data and blacklist the IP on the firewall.
Unlock SY0-501 to see the answer
You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#protocol analyzer#malicious traffic#network forensics#firewall blacklisting