SY0-701 Question 245
Single answerCapacity planning: People , Technology , InfrastructureA healthcare company is expanding from one clinic to eight regional locations over the next six months. The security manager expects a sharp increase in VPN usage, endpoint alerts, and after-hours support tickets. The organization currently has one firewall pair at headquarters, a small SIEM deployment sized for current log volume, and a two-person security operations team that already works at near capacity. During planning, leadership asks for the MOST effective action to reduce security risk caused by this growth while maintaining operations.
- A
Conduct a capacity-planning review that forecasts staffing, log ingestion/storage, VPN throughput, and incident-response coverage, then scale those resources before onboarding the new clinics
- B
Delay centralized logging from the new clinics until the first quarter after expansion so the existing SIEM can continue operating without changes
- C
Keep current staffing levels and rely on the firewall's default security settings because adding more personnel increases cost without improving security posture
- D
Reduce VPN multifactor authentication prompts for remote users so the help desk can handle more connections without adding infrastructure
Show answer and explanation
Correct answer: A
Explanation
The best answer is to perform proactive capacity planning across people, technology, and infrastructure before the expansion occurs. In Security+, capacity planning is not just about performance; it also supports security operations and resilience. In this scenario, growth affects analyst workload, help desk demand, VPN concentrator/firewall throughput, SIEM ingestion rates, storage retention, and incident-response coverage. If these are not scaled in advance, the organization risks dropped logs, degraded monitoring, delayed detection, user workarounds, and increased operational failure. Best practices from sources such as NIST SP 800-61 for incident handling and NIST SP 800-137 for information security continuous monitoring emphasize maintaining sufficient monitoring and response capability. In regulated sectors like healthcare, maintaining logging and visibility during expansion is especially important for security oversight and audit readiness.
- A. Correct.
Correct. This is the best capacity-planning response because it addresses all three domains in the objective: people, technology, and infrastructure. Forecasting staffing needs helps ensure adequate analyst and support coverage; forecasting SIEM log ingestion and retention helps avoid dropped logs and degraded visibility; forecasting VPN throughput helps prevent bottlenecks and availability issues during expansion. Scaling before onboarding reduces the chance of outages, missed alerts, and delayed response. This is aligned with security best practices that require organizations to plan for expected growth and ensure monitoring, authentication, and response functions remain effective under increased load.
- B. Incorrect.
Incorrect. Delaying centralized logging reduces visibility at the exact time the attack surface is expanding. New clinics should be included in monitoring from day one so suspicious activity, misconfigurations, and endpoint events can be detected centrally. A common misconception is that logging can be postponed as a convenience measure, but this creates blind spots and may also affect compliance requirements in regulated environments such as healthcare.
- C. Incorrect.
Incorrect. Staffing is a core part of capacity planning. If the team is already operating near capacity, growth in users, endpoints, and alerts will increase the likelihood of missed incidents, alert fatigue, and slower response times. Default security settings may provide baseline functionality, but they do not address increased operational workload or guarantee that security controls are tuned appropriately for a larger environment.
- D. Incorrect.
Incorrect. Reducing MFA prompts to ease help desk demand weakens security rather than solving the underlying capacity issue. MFA is an important compensating control for remote access, especially when expanding VPN use across multiple locations. The real problem is insufficient people and infrastructure planning, not that authentication is too strong.