SY0-701 exam dumps

SY0-701 practice question 310 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 310

Single answerActivities: Log aggregation , Alerting , Scanning , Reporting , Archiving

A security analyst at a healthcare company is investigating a suspected phishing campaign that may have led to unauthorized access to several user accounts over the past 90 days. The company has firewalls, email security gateways, domain controllers, VPN concentrators, and endpoint detection agents from different vendors. Management also requires weekly summaries of high-risk events and long-term retention of security records for possible legal review. The analyst needs a solution that will centralize logs, correlate related events across systems, generate immediate notifications for suspicious activity, and preserve older data in a cost-effective manner without losing the ability to retrieve it later. Which solution BEST meets these requirements?

  1. A

    Deploy a SIEM to aggregate logs and correlate events, configure alerting rules for suspicious activity, generate scheduled reports for management, and archive older logs to long-term storage based on retention policy

  2. B

    Run weekly vulnerability scans on all systems and rely on the scanner's findings as the primary source for detecting phishing-related account compromise and historical user activity

  3. C

    Enable verbose logging separately on each device and have administrators manually review local logs when an incident is suspected, keeping all data on the original systems indefinitely

  4. D

    Use a packet sniffer at the network perimeter to capture traffic continuously and replace log collection, reporting, and archival processes with full packet capture

Show answer and explanation

Correct answer: A

Explanation

The best answer is the SIEM-based approach because it directly addresses all five activity areas in the scenario: log aggregation, alerting, reporting, and archiving, while also supporting investigations that may be informed by scanning data from other tools. In practice, organizations centralize logs from identity systems, email gateways, firewalls, VPN devices, and endpoints to improve visibility and correlation. This aligns with common security operations best practices and guidance from sources such as NIST SP 800-92 on log management and NIST SP 800-61 on incident handling, which emphasize centralized collection, analysis, retention, and timely response. Weekly management summaries are handled through scheduled reporting, while older records are typically moved to archival storage to balance cost, retention, and retrieval requirements. Vulnerability scanners and packet capture tools can support a security program, but they do not substitute for centralized logging and SIEM-driven monitoring in this scenario.

  • A. Correct.

    Correct. A SIEM is designed to perform log aggregation across heterogeneous sources, normalize and correlate events, and support real-time alerting for defined conditions such as suspicious logins, impossible travel, repeated failed authentication, or unusual VPN activity. SIEM platforms also commonly support scheduled reporting for management and compliance use cases. Archiving older logs to lower-cost long-term storage aligns with retention and e-discovery needs while preserving searchability or retrieval capability depending on implementation.

  • B. Incorrect.

    Incorrect. Vulnerability scanning is useful for identifying missing patches, misconfigurations, and exposed services, but it is not the primary tool for investigating phishing-related account misuse or reconstructing historical authentication events. Scans do not replace centralized log collection, event correlation, alerting, or retention of audit records.

  • C. Incorrect.

    Incorrect. Keeping logs only on individual devices creates operational and investigative gaps. Manual review is slow, inconsistent, and poorly suited for detecting multi-stage attacks spanning email, endpoint, identity, and VPN systems. Retaining all logs indefinitely on production devices is also inefficient and can affect performance, storage capacity, and log availability if a device fails or is compromised.

  • D. Incorrect.

    Incorrect. Full packet capture can provide valuable forensic detail in some environments, but it does not replace log aggregation, alerting, reporting, or archival strategy. Continuous packet capture at scale is expensive and operationally complex, and it may not provide the normalized identity and application audit trail needed for account compromise investigations.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam