SY0-701 exam dumps

SY0-701 practice question 308 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 308

Single answerMonitoring computing resources: Systems , Applications , Infrastructure

A security administrator is tuning monitoring controls after a recent incident in which a compromised web application server consumed excessive CPU, filled local storage with log data, and caused the backend database service to become unavailable. Management wants earlier warning signs across systems, applications, and infrastructure so the team can respond before customer-facing outages occur. Which monitoring approach would BEST meet this requirement?

  1. A

    Configure centralized monitoring and alerting for server CPU, memory, disk utilization, application log error rates, and database/network service availability with defined thresholds and escalation procedures

  2. B

    Rely on weekly vulnerability scans and monthly patch reports to identify resource issues before they affect production availability

  3. C

    Increase log retention on each individual server and disable alerts to reduce false positives while administrators manually review logs during outages

  4. D

    Focus monitoring on perimeter firewall deny logs because infrastructure attacks are most likely to appear there before affecting applications or hosts

Show answer and explanation

Correct answer: A

Explanation

The best answer is the centralized monitoring and alerting approach because the scenario explicitly requires coverage across systems, applications, and infrastructure. In practice, security and operations teams should monitor host metrics such as CPU, memory, and disk utilization; application indicators such as error rates and abnormal logging patterns; and infrastructure dependencies such as database availability, network reachability, and service health. Security+ expects candidates to understand that effective monitoring is layered and supports both security detection and availability objectives. This aligns with common guidance from NIST, including NIST SP 800-137 on Information Security Continuous Monitoring and NIST SP 800-61 on incident handling, which emphasize ongoing visibility, event analysis, and timely response. Centralized logging and alerting through SIEM, log management, or observability platforms are standard best practices because they reduce detection time and improve correlation across affected components.

  • A. Correct.

    Correct. This option addresses all three layers named in the objective: systems, applications, and infrastructure. Monitoring CPU, memory, and disk utilization covers host/system health; tracking application log error rates helps detect abnormal behavior in the web application; and monitoring database/network service availability covers supporting infrastructure dependencies. Centralized alerting with thresholds and escalation procedures is a best practice because it enables timely detection and response before an outage becomes severe.

  • B. Incorrect.

    Incorrect. Vulnerability scans and patch reports are important security activities, but they are not resource monitoring controls and do not provide near-real-time visibility into system performance, application failures, or infrastructure availability. A candidate might choose this because scans are associated with security hygiene, but they do not meet the requirement for early operational warning signs.

  • C. Incorrect.

    Incorrect. Increasing local log retention may preserve evidence, but disabling alerts directly conflicts with the requirement for earlier warning. Manual review during outages is reactive, not proactive. This reflects a common misconception that collecting more logs alone is sufficient; effective monitoring requires analysis, thresholding, and alerting, not just storage.

  • D. Incorrect.

    Incorrect. Firewall logs can be useful for detecting certain network events, but focusing only on perimeter deny logs leaves major blind spots. The incident involved host resource exhaustion, application behavior, and backend service impact. Infrastructure monitoring must include service availability and performance, not just perimeter events. Someone might select this option because firewalls are a common security data source, but they are not enough by themselves for full-stack resource monitoring.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam