SY0-701 exam dumps

SY0-701 practice question 306 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 306

Single answer4.4 Explain security alerting and monitoring concepts and tools.

A security analyst is overwhelmed by thousands of daily alerts from multiple tools, including the firewall, endpoint protection platform, and cloud security logs. Several recent phishing incidents were buried in the noise because each tool generated separate low-priority alerts that were not tied together. Management wants faster detection of real threats without adding more staff. Which solution would BEST improve visibility by combining related events into a more actionable alert?

  1. A

    Implement a SIEM with correlation rules and centralized log aggregation

  2. B

    Increase the retention period on all log sources from 30 days to 1 year

  3. C

    Configure each security tool to send email alerts directly to all administrators

  4. D

    Deploy full-disk encryption on analyst workstations

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement a SIEM with correlation rules and centralized log aggregation. In real environments, individual tools often generate many isolated alerts that are low value on their own. A SIEM improves monitoring by collecting logs from diverse sources, normalizing events, and correlating related activity into higher-confidence alerts. This directly addresses alert fatigue and missed incidents. Retention, broader email distribution, or unrelated endpoint protections do not provide the same operational benefit. This aligns with common security operations best practices and vendor-agnostic guidance such as NIST SP 800-61 for incident handling and NIST SP 800-137 for information security continuous monitoring, both of which emphasize centralized monitoring, analysis, and timely detection.

  • A. Correct.

    Correct. A Security Information and Event Management (SIEM) platform centralizes logs from multiple sources and uses correlation rules to identify related events across systems. In this scenario, separate low-priority alerts from the firewall, endpoint protection, and cloud logs need to be tied together into a higher-fidelity incident. SIEM correlation improves signal-to-noise ratio, helps prioritize investigation, and is a core monitoring concept in enterprise security operations.

  • B. Incorrect.

    Incorrect. Longer log retention may help with historical investigations, compliance, and forensic review, but it does not solve the immediate problem of too many disconnected alerts. Retention affects how long data is stored, not whether events are correlated into actionable detections.

  • C. Incorrect.

    Incorrect. Sending more email alerts to more people usually increases alert fatigue rather than improving detection quality. The issue is not lack of notification; it is lack of centralized analysis and event correlation. Emailing all administrators can also create operational noise and accountability gaps.

  • D. Incorrect.

    Incorrect. Full-disk encryption protects data at rest on analyst endpoints, which is a valid security control, but it does not address alerting, monitoring, event aggregation, or threat correlation. It is unrelated to the stated problem.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam