ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 331 - SY0-601 discussion

Report
Export

A security engineer learns that a non-critical application was compromised. The most recent version of the application includes a malicious reverse proxy while the application is running. Which of the following should the engineer is to quickly contain the incident with the least amount of impact?

A.
Configure firewall rules to block malicious inbound access.
Answers
A.
Configure firewall rules to block malicious inbound access.
B.
Manually uninstall the update that contains the backdoor.
Answers
B.
Manually uninstall the update that contains the backdoor.
C.
Add the application hash to the organization's blocklist.
Answers
C.
Add the application hash to the organization's blocklist.
D.
Tum off all computers that have the application installed.
Answers
D.
Tum off all computers that have the application installed.
Suggested answer: C

Explanation:

A reverse proxy backdoor is a malicious reverse proxy that can intercept and manipulate the traffic between the client and the web server3. This can allow an attacker to access sensitive data or execute commands on the web server.

One possible way to quickly contain the incident with the least amount of impact is to add the application hash to the organization’s blocklist. A blocklist is a list of applications or files that are not allowed to run on a system or network. By adding the application hash to the blocklist, the security engineer can prevent the malicious application from running and communicating with the reverse proxy backdoor.

asked 02/10/2024
mustapha amraui
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first