SY0-701 Question 244
Single answerCapacity planning: People , Technology , InfrastructureA healthcare company is expanding from one clinic to eight regional sites and must maintain 24/7 security monitoring to meet internal policy and regulatory requirements. Over the past two months, the security team has seen a sharp increase in firewall, endpoint detection, and authentication logs. Analysts are missing alerts during overnight shifts, the SIEM is approaching its licensed ingestion limit, and the VPN concentrators at two sites are near maximum concurrent sessions during morning logins. The CISO asks for the MOST effective capacity-planning action to reduce security risk before the remaining sites go live.
- A
Conduct a capacity assessment across staffing, log ingestion/storage, and network/VPN utilization, then adjust analyst coverage, SIEM licensing/retention, and concentrator capacity before onboarding additional sites
- B
Reduce SIEM log collection to only critical firewall events so the current license is not exceeded, and postpone staffing changes until after all sites are deployed
- C
Purchase a larger backup solution because increased backup storage will prevent missed alerts and reduce VPN saturation during peak usage
- D
Disable nonessential endpoint security telemetry at the regional sites and rely on weekly manual log reviews to keep infrastructure costs low
Show answer and explanation
Correct answer: A
Explanation
The best answer is to perform integrated capacity planning before expansion and scale the environment across people, technology, and infrastructure. In Security+, capacity planning is not limited to hardware sizing; it also includes ensuring enough trained personnel are available, that monitoring and security tools can handle expected volume, and that supporting infrastructure such as bandwidth, remote-access services, and storage can sustain growth without degrading security operations. In this scenario, all three areas are under strain already, so adding more sites without remediation would increase the likelihood of missed incidents, delayed response, and policy or regulatory violations. This aligns with common best practices from NIST guidance, including planning for adequate logging and monitoring resources, ensuring operational resilience, and maintaining sufficient staffing and system capacity to support security functions. Practical capacity planning should include trend analysis, projected onboarding volumes, peak-use modeling, licensing review, storage and retention requirements, and staffing models for continuous monitoring coverage.
- A. Correct.
Correct. This is the best capacity-planning response because it addresses all three required dimensions: people, technology, and infrastructure. The scenario shows clear warning signs of capacity strain: analysts missing alerts (people), SIEM ingestion approaching licensed limits (technology), and VPN concentrators nearing session capacity (infrastructure). A formal capacity assessment lets the organization forecast expected demand before adding more sites and then scale staffing, monitoring platform capacity, storage/retention, and remote-access infrastructure accordingly. This reduces operational and compliance risk before the rollout expands the problem.
- B. Incorrect.
Incorrect. While reducing log volume may temporarily avoid a licensing threshold, it weakens security visibility and can create compliance and detection gaps, especially in a healthcare environment with 24/7 monitoring expectations. Postponing staffing changes ignores the existing operational failure: analysts are already missing alerts. Capacity planning should not rely on cutting essential telemetry as the primary fix when growth is predictable.
- C. Incorrect.
Incorrect. Backup capacity is important for resilience and recovery, but it does not solve the immediate security operations problem described in the scenario. Missed alerts are caused by insufficient analyst coverage and monitoring-system constraints, not by lack of backup storage. Likewise, VPN saturation is a network access capacity issue, not a backup issue. This option confuses business continuity infrastructure with security monitoring and remote-access capacity planning.
- D. Incorrect.
Incorrect. Disabling endpoint telemetry reduces detection capability and increases the chance of missing malicious activity. Weekly manual reviews are far too slow for a 24/7 monitoring requirement and would not support timely detection and response. This option reflects a common but risky misconception that reducing monitoring data is an acceptable substitute for scaling security operations.