SY0-701 exam dumps

SY0-701 practice question 315 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 315

Select 3

A security team must quickly improve visibility across a hybrid environment that includes on-premises servers, network devices, and a growing number of remote laptops that are frequently off the corporate network. Leadership wants centralized alerting for suspicious activity, the ability to identify large outbound data transfers, and confirmation that Windows and Linux systems are configured according to recognized hardening guidance. Which THREE actions best meet these requirements?

  1. A

    Deploy a SIEM to aggregate logs and alerts, collect NetFlow from core network devices, and correlate events centrally

  2. B

    Use SCAP benchmark content to assess system configurations against recognized baselines on Windows and Linux hosts

  3. C

    Rely only on agentless scanning for remote laptops because it provides continuous visibility even when devices are off the corporate network

  4. D

    Configure SNMP traps from switches and routers as the primary method to measure detailed session-level bandwidth usage and data exfiltration volume

  5. E

    Install endpoint agents for remote laptops so telemetry can be collected even when devices are outside the corporate network

Show answer and explanation

Correct answers: A, B, E

Explanation

The best solution is a combination of centralized analytics, flow visibility, configuration assessment, and endpoint coverage for remote systems. A SIEM provides centralized log aggregation and correlation, which is a core best practice for detecting suspicious activity across diverse sources. NetFlow complements the SIEM by providing traffic-flow metadata that helps identify unusually large outbound transfers or suspicious communication patterns. To validate hardening, SCAP benchmark content is appropriate because SCAP supports standardized security configuration and compliance assessment against recognized baselines. Finally, remote laptops that are often off-network are better served by endpoint agents, since agentless methods depend on network reachability and typically provide only point-in-time visibility. SNMP traps are valuable for operational alerting from network devices but are not a substitute for NetFlow when the goal is detailed traffic analysis. These uses align with common security operations practices and the intended purposes of SIEM, SCAP, NetFlow, SNMP traps, and agent-based versus agentless monitoring.

  • A. Correct.

    Correct. A SIEM is designed to centralize log collection, normalize events, and correlate alerts across multiple data sources. Pairing the SIEM with NetFlow from network devices helps the team identify unusual outbound traffic patterns and investigate possible data exfiltration. This combination is practical for centralized monitoring and incident detection in mixed environments.

  • B. Correct.

    Correct. SCAP benchmark content is used to assess systems against recognized configuration baselines, such as secure configuration guidance. This directly addresses the requirement to verify that Windows and Linux systems follow accepted hardening standards. SCAP is commonly used for automated compliance and configuration assessment rather than general traffic monitoring.

  • C. Incorrect.

    Incorrect. Agentless approaches can be useful for periodic assessment, especially for reachable on-premises systems, but they do not provide continuous visibility for laptops that are frequently off the corporate network. Remote devices often need local agents to maintain telemetry and policy enforcement when disconnected from internal scanning infrastructure.

  • D. Incorrect.

    Incorrect. SNMP traps are useful for asynchronous alerts from network devices, such as interface status changes or threshold events, but they are not the primary tool for detailed flow-level analysis or measuring session-level exfiltration volume. NetFlow is specifically designed to summarize traffic flows and is more appropriate for identifying large outbound transfers.

  • E. Correct.

    Correct. Endpoint agents are well suited for remote laptops because they can continue collecting security telemetry and enforcing controls when devices are not connected to the corporate network. In hybrid environments, agents help close visibility gaps that agentless scans cannot reliably cover.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam