SY0-701 exam dumps

SY0-701 practice question 311 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 311

Single answerActivities: Log aggregation , Alerting , Scanning , Reporting , Archiving

A security administrator is improving the company’s monitoring program after an incident in which suspicious authentication failures were discovered weeks late. The environment includes firewalls, Windows servers, Linux servers, and cloud workloads, each storing logs locally for different lengths of time. Leadership has asked for faster detection of brute-force activity, centralized visibility for investigations, and retention of historical records to support quarterly audits without overloading production systems. Which solution BEST meets these requirements?

  1. A

    Configure each system to keep more local logs, and have administrators manually review them weekly for failed logon patterns

  2. B

    Implement a centralized log aggregation platform with correlation and alerting for repeated authentication failures, and archive older logs to lower-cost storage according to retention requirements

  3. C

    Run authenticated vulnerability scans more frequently and use scan reports to identify accounts that may be experiencing brute-force attacks

  4. D

    Enable full packet capture on all network segments and retain the captures indefinitely as the primary source for audit and authentication review

Show answer and explanation

Correct answer: B

Explanation

The best answer is to use centralized log aggregation with alerting and archiving. In practice, organizations commonly use a SIEM or log management platform to collect logs from endpoints, servers, network devices, and cloud services. This supports log aggregation for visibility, alerting for timely detection of suspicious activity such as repeated failed logons, reporting for investigations and audits, and archiving for long-term retention. Vulnerability scanning is an important security activity, but it does not replace event monitoring. Likewise, relying only on local logs or packet capture does not efficiently meet the combined needs of centralized analysis, rapid detection, and cost-effective retention. This approach is consistent with broadly accepted security operations practices and guidance such as NIST recommendations for log management and event monitoring, including centralized collection, analysis, retention, and review of security-relevant events.

  • A. Incorrect.

    This is incorrect because increasing local log retention and relying on manual weekly review does not provide timely detection or centralized visibility. Local-only logging makes investigations slower because analysts must access each individual host or device. Weekly review is also too delayed for brute-force detection, which is better handled by near-real-time alerting. While local logs are still useful, they do not satisfy the stated need for centralized monitoring and efficient historical retention on their own.

  • B. Correct.

    This is correct because it addresses all stated requirements. Centralized log aggregation supports visibility across firewalls, servers, and cloud workloads in one place. Correlation and alerting can detect repeated authentication failures across multiple systems and notify analysts quickly, improving mean time to detect. Archiving older logs to lower-cost storage supports audit and retention needs without placing unnecessary storage and performance burden on production systems. This aligns with common SIEM and log management best practices: collect logs centrally, normalize and correlate events, alert on suspicious patterns, and archive data according to retention and compliance requirements.

  • C. Incorrect.

    This is incorrect because vulnerability scanning is designed to identify weaknesses such as missing patches, misconfigurations, or exposed services, not to serve as the primary mechanism for detecting active brute-force attempts. Scan reports may improve security posture, but they do not provide event-level monitoring of authentication failures. Choosing this option reflects a common misconception that scanning can replace logging and alerting functions.

  • D. Incorrect.

    This is incorrect because full packet capture can be valuable in limited forensic use cases, but it is not the best primary solution for centralized authentication monitoring and long-term audit retention. Packet capture at enterprise scale is storage-intensive, operationally complex, and often unnecessary when the requirement is to detect repeated failed logins and retain historical records. Authentication events are typically more effectively tracked through system, application, identity, and firewall logs collected by a centralized logging or SIEM platform.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam