SY0-701 exam dumps

SY0-701 practice question 313 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 313

Single answerAlert response and remediation/validation: Quarantine , Alert tuning

A security analyst is investigating repeated endpoint detection and response (EDR) alerts for a finance department workstation. The alerts indicate that a signed software updater is launching PowerShell and making outbound connections to a known content delivery network. The analyst confirms with the desktop team that this behavior is part of a recently approved application update process, but the same alert rule has generated hundreds of tickets this week and delayed response to actual malware events. The SOC manager wants to reduce this noise without weakening protection if the updater begins behaving abnormally in the future. Which action is the BEST response?

  1. A

    Disable the alert rule globally because the activity has been verified as legitimate

  2. B

    Quarantine the workstation each time the alert appears until the update process is complete

  3. C

    Tune the alert by creating an exception for the approved updater based on validated attributes such as signer, path, and expected network destinations, and then monitor for deviations

  4. D

    Lower the severity of all PowerShell-related alerts so the SOC can focus on more dangerous malware

Show answer and explanation

Correct answer: C

Explanation

The best answer is to tune the alert with a narrowly defined exception after confirming the behavior is legitimate. In incident response and security operations, quarantine is appropriate when an endpoint is believed to be compromised and needs containment. Once the analyst has validated the activity as expected, continuing to quarantine the host creates unnecessary business impact. At the same time, disabling the detection or broadly reducing severity would create dangerous blind spots. Best practice is to reduce false positives by tuning detections using multiple validated attributes and preserving the ability to detect abnormal behavior outside the approved pattern. This aligns with standard SOC practices for alert triage, validation, and continuous detection improvement, as reflected in common vendor guidance for SIEM, EDR, and detection engineering workflows: verify legitimacy, scope exceptions as tightly as possible, document the rationale, and monitor for deviations rather than suppressing entire classes of alerts.

  • A. Incorrect.

    This is incorrect because disabling the rule globally removes visibility for similar behavior across the environment, including genuinely malicious abuse of PowerShell by other processes. A validated false positive should usually lead to scoped tuning, not elimination of the detection entirely.

  • B. Incorrect.

    This is incorrect because quarantine is a containment action used when malicious activity is suspected and immediate isolation is needed to prevent spread or further compromise. In this scenario, the behavior has been validated as part of an approved business process, so repeatedly quarantining the host would disrupt operations without improving security.

  • C. Correct.

    This is correct because it applies alert tuning in a controlled manner after validation. Creating a narrowly scoped exception using reliable indicators such as the approved executable's digital signature, expected installation path, parent-child process relationship, and known update destinations reduces false positives while preserving the rule's ability to detect suspicious variants or deviations. Monitoring for changes maintains detection coverage if the updater is abused or replaced.

  • D. Incorrect.

    This is incorrect because broadly lowering the severity of all PowerShell alerts weakens detection for a common attacker technique. PowerShell is frequently used in legitimate administration and malicious activity, so the better approach is to tune the specific noisy use case rather than reduce the importance of the entire detection category.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam