SY0-701 exam dumps

SY0-701 practice question 320 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 320

Single answerIDS/IPS: Trends , Signatures

A security analyst notices that an organization’s network IPS is generating repeated alerts for outbound connections to a newly identified command-and-control domain used by a recent malware campaign. The IPS is not blocking the traffic because it is deployed in alert-only mode during a pilot. Management wants to quickly improve detection for this specific threat across the environment while the team evaluates whether to move the IPS inline. Which action would BEST address this requirement?

  1. A

    Create or import a signature that matches the known indicators associated with the malware campaign, such as the command-and-control domain pattern

  2. B

    Disable trend analysis and rely only on manual review of firewall logs to reduce false positives during the pilot

  3. C

    Replace the IPS with a behavior-only system because signature-based detection cannot identify known threats

  4. D

    Reconfigure the IPS to block all outbound DNS traffic until the malware campaign is over

Show answer and explanation

Correct answer: A

Explanation

This question tests the candidate’s ability to apply IDS/IPS concepts to a realistic incident response and detection-tuning scenario. The key distinction is between trends and signatures: trend analysis helps identify recurring patterns and prioritize investigation, while signatures are used to detect known malicious activity based on predefined indicators. Because the organization has already identified a specific malware campaign and associated command-and-control domain, the best immediate improvement is to add or update a signature to detect that known activity. This aligns with common IDS/IPS operational practices and vendor guidance from platforms such as Snort, Suricata, and commercial IPS products, all of which rely on signature updates to detect known threats quickly. Trend data remains useful for validating whether detections are increasing, recurring, or spreading across systems, but it does not itself create a new detection rule.

  • A. Correct.

    Correct. When a specific threat with known indicators of compromise is identified, adding or updating a signature is the most direct way to improve detection. Signature-based IPS/IDS technologies are designed to match known malicious patterns such as domains, payloads, URLs, or protocol anomalies. This is especially appropriate when the organization wants rapid, targeted coverage for a documented malware campaign while keeping the sensor in alert-only mode during a pilot.

  • B. Incorrect.

    Incorrect. Trend analysis helps analysts identify patterns over time, such as repeated alerts, recurring destinations, or increasing activity related to a threat. Disabling it would remove useful context. Manual firewall log review alone is slower and less scalable than using IDS/IPS detections with trend data.

  • C. Incorrect.

    Incorrect. This reflects a common misconception. Signature-based detection is particularly effective for known threats, not ineffective against them. Behavior-based or anomaly-based systems can help detect unknown threats, but they do not replace the value of signatures for rapidly identifying known malware indicators.

  • D. Incorrect.

    Incorrect. Blocking all outbound DNS traffic is overly disruptive and not a practical best-practice response for most production environments. DNS is essential for normal business operations. A more appropriate response would be targeted detection or blocking based on known malicious indicators, such as a signature update or DNS filtering policy specific to the malicious domains.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam