SY0-701 exam dumps

SY0-701 practice question 272 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 272

Single answerMonitoring

A security analyst is tuning the company's monitoring program after several ransomware attempts were missed until users reported unavailable files. Management wants earlier detection of malicious activity on endpoints and better visibility for investigations, but the company cannot immediately replace its existing antivirus on every workstation. Which of the following would BEST improve monitoring to meet this goal?

  1. A

    Deploy an EDR solution on endpoints to collect telemetry and alert on suspicious behavior such as mass file changes and unusual process activity

  2. B

    Increase the password minimum length in Group Policy and require users to change passwords every 30 days

  3. C

    Disable system and security logs on endpoints to reduce noise in the SIEM and focus only on perimeter firewall logs

  4. D

    Replace full packet capture with weekly vulnerability scans to identify endpoints that might be exploited

Show answer and explanation

Correct answer: A

Explanation

The best answer is to deploy EDR because the scenario emphasizes monitoring improvements for earlier detection of ransomware behavior on endpoints and better investigative visibility. Traditional antivirus can miss newer or fileless techniques, whereas EDR focuses on behavioral detection and endpoint telemetry. Security monitoring best practices recommend collecting and correlating host-based events in addition to network logs, especially for threats like ransomware that often involve process abuse, lateral movement, credential use, and large-scale file activity. This approach is consistent with common industry guidance from sources such as NIST's recommendations on event logging and incident detection, as well as modern security operations practices that emphasize endpoint telemetry, centralized analysis, and rapid response.

  • A. Correct.

    Correct. Endpoint Detection and Response (EDR) is specifically designed to improve endpoint monitoring by collecting detailed telemetry such as process execution, command-line activity, file modifications, persistence attempts, and other behavioral indicators. In a ransomware scenario, EDR can help detect suspicious patterns like rapid file encryption, unusual parent-child process relationships, or abuse of scripting tools before users begin reporting outages. It also supports investigation and response by preserving endpoint evidence and timelines. This aligns directly with the requirement for earlier detection and better investigative visibility without necessarily replacing the current antivirus immediately.

  • B. Incorrect.

    Incorrect. Stronger password policy may improve identity security, but it does not directly address the stated problem of missed ransomware activity on endpoints or improve behavioral monitoring and investigation. A candidate might choose this because credential misuse can lead to ransomware deployment, but the scenario is specifically asking for better monitoring and visibility on endpoints, not a general hardening change.

  • C. Incorrect.

    Incorrect. Disabling endpoint system and security logs would reduce visibility, not improve it. Endpoint and host logs are often critical for identifying ransomware precursors such as service creation, suspicious PowerShell execution, privilege escalation, scheduled tasks, and authentication anomalies. Focusing only on perimeter firewall logs is a common misconception because many modern attacks involve legitimate tools and internal lateral movement that firewall logs alone may not reveal.

  • D. Incorrect.

    Incorrect. Vulnerability scans are useful for identifying missing patches and configuration weaknesses, but they are not a replacement for continuous security monitoring. Weekly scans provide a point-in-time assessment rather than real-time or near-real-time detection of malicious behavior. An analyst might select this option because unpatched systems are frequently exploited by ransomware operators, but scanning does not provide the operational telemetry needed to catch an active attack early.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam