SY0-701 exam dumps

SY0-701 practice question 307 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 307

Single answer4.4 Explain security alerting and monitoring concepts and tools.

A security analyst is reviewing overnight alerts and sees that a domain controller generated hundreds of failed logon events from multiple internal hosts within 10 minutes. At the same time, the SIEM shows a successful logon to a disabled service account from one workstation, followed by access to several file shares. The analyst wants to quickly determine whether this is a true attack and identify the affected systems without manually checking each log source. Which action would BEST support this goal?

  1. A

    Configure the SIEM to correlate authentication, endpoint, and file access logs into a single incident view

  2. B

    Increase the domain password length requirement to reduce future brute-force attempts

  3. C

    Run a vulnerability scan on all internal hosts to identify missing patches

  4. D

    Disable file share auditing to reduce the number of SIEM alerts

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use SIEM correlation to combine related security telemetry into a unified incident view. In Security+ terms, this tests understanding of security alerting and monitoring concepts such as log aggregation, correlation, event analysis, and incident triage. A SIEM is specifically intended to ingest logs from multiple sources and identify meaningful patterns that would be difficult to detect manually. In this case, failed logons across hosts, a successful logon with a disabled account, and file share access together suggest credential abuse or lateral movement. Correlation rules, dashboards, and timelines help the analyst distinguish a true positive from isolated noise and quickly identify affected assets. This aligns with common best practices from vendors and standards bodies that recommend centralized logging, time synchronization, and correlation across identity, endpoint, and network data sources for effective detection and response.

  • A. Correct.

    Correct. SIEM correlation is designed to aggregate and analyze events from multiple log sources, such as domain controllers, endpoints, and file servers, so an analyst can determine whether separate alerts are related. In this scenario, correlation helps validate whether the failed logons, successful use of a disabled account, and subsequent file share access are part of the same attack chain. This supports faster triage, scoping, and incident response.

  • B. Incorrect.

    Incorrect. Strengthening password policy may help reduce future password attacks, but it does not help the analyst quickly determine whether the current activity is a true positive or identify which systems are affected. This is a preventive control, not an alerting and monitoring action for immediate investigation.

  • C. Incorrect.

    Incorrect. Vulnerability scanning is useful for exposure management and finding missing patches or weak configurations, but it does not directly correlate the current authentication and access events. It would not be the best action to validate this suspected incident in real time.

  • D. Incorrect.

    Incorrect. Disabling file share auditing would reduce visibility at exactly the point when the analyst needs more evidence. Best practice in monitoring is to preserve and correlate relevant logs during suspected malicious activity, not reduce logging that could confirm lateral movement or unauthorized access.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam