SY0-701 exam dumps

SY0-701 practice question 312 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 312

Single answerAlert response and remediation/validation: Quarantine , Alert tuning

A security analyst notices that the EDR platform is repeatedly generating high-severity alerts for a finance application that launches PowerShell as part of a signed, approved nightly reconciliation job. Last week, an analyst quarantined the application server after seeing the alert, which disrupted payroll processing. Management now wants the SOC to reduce these false positives without weakening protection against real malicious PowerShell activity. Which action should the analyst take FIRST?

  1. A

    Create an alert-tuning rule that suppresses or lowers the severity of alerts only when the signed finance application launches PowerShell from the approved server during the documented job window, then validate the change through monitoring

  2. B

    Disable all PowerShell-related detections on the application server so the reconciliation job can run without interruption

  3. C

    Continue quarantining the server whenever the alert appears because repeated alerts indicate the activity is suspicious

  4. D

    Add the entire finance application directory to the EDR exclusion list and close future related alerts automatically

Show answer and explanation

Correct answer: A

Explanation

The key skill being tested is balancing response actions with remediation and validation. When an alert is confirmed to be a false positive tied to legitimate business activity, the correct response is not to keep quarantining the host or to broadly disable detections. Instead, the analyst should tune the alert as narrowly as possible using specific contextual factors such as parent process, digital signature, host, user, command-line pattern, and time window. After tuning, the SOC should validate effectiveness by monitoring for recurrence and confirming that truly suspicious PowerShell behavior would still generate alerts. This aligns with common security operations best practices: use quarantine for credible malicious activity requiring containment, and use targeted alert tuning to reduce noise without creating blind spots. Vendor documentation for SIEM, EDR, and detection engineering workflows consistently recommends narrow scoping, change control, and post-change validation when addressing recurring false positives.

  • A. Correct.

    Correct. This is the best first step because it applies precise alert tuning based on verified benign behavior: approved parent process, known server, and expected execution window. That reduces false positives while preserving detection for unexpected PowerShell use outside those conditions. Validation through continued monitoring is also important to confirm the tuning works as intended and does not hide real attacks.

  • B. Incorrect.

    Incorrect. Disabling all PowerShell-related detections is overly broad and would create a significant detection gap. PowerShell is commonly abused by attackers, so turning off monitoring for it on a server is not an appropriate tuning action. This reflects the misconception that operational stability should be solved by removing visibility instead of refining detections.

  • C. Incorrect.

    Incorrect. Quarantine is a containment action used when malicious activity is likely and immediate isolation is necessary. In this scenario, the activity is tied to a signed, approved job that has already been identified as legitimate. Repeatedly quarantining the server would continue business disruption and shows a failure to validate and tune alerts after confirming a false positive.

  • D. Incorrect.

    Incorrect. Excluding the entire application directory is broader than necessary and could allow malicious files or abuse within that path to go undetected. Candidates might choose this because exclusions seem like a quick fix, but best practice is to use the narrowest possible exception or tuning rule based on specific, validated indicators of benign activity.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam