SY0-701 exam dumps

SY0-701 practice question 339 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 339

Single answerEndpoint detection and response (EDR)/extended detection and response (XDR)

A security analyst is investigating a suspected phishing incident. An employee clicked a malicious link, and within minutes the analyst sees an alert from the endpoint platform showing a suspicious PowerShell process spawned by the user's browser. The SOC also wants to know whether the same activity is affecting other hosts and whether the endpoint later communicated with a known malicious domain observed in network telemetry. Which solution would BEST help the analyst correlate the endpoint activity with related events across multiple security data sources to determine the full scope of the incident?

  1. A

    Deploy an XDR solution to correlate endpoint, network, and other security telemetry across the environment

  2. B

    Rely on an EDR solution only, because EDR natively provides organization-wide correlation across all security layers

  3. C

    Use full-disk encryption on all endpoints so malicious PowerShell execution can be prevented and traced centrally

  4. D

    Implement network access control (NAC) to identify whether the user clicked the phishing link and reconstruct process execution

Show answer and explanation

Correct answer: A

Explanation

The best answer is XDR because the scenario requires more than host-level detection. The analyst already has endpoint evidence of suspicious PowerShell behavior, which fits EDR capabilities well. However, the question asks for the BEST solution to determine whether similar activity occurred on other systems and whether the endpoint also communicated with a known malicious domain seen in network telemetry. XDR extends detection and response by aggregating and correlating data across multiple security layers, improving incident scoping, triage, and response efficiency. This aligns with common industry guidance from major security vendors and frameworks that distinguish EDR as endpoint-focused and XDR as cross-domain detection and response. In practice, EDR is excellent for host investigation and containment, while XDR is better when defenders need a unified view across endpoints, network, identity, email, and cloud sources.

  • A. Correct.

    Correct. XDR is designed to collect and correlate telemetry from multiple sources such as endpoints, network tools, email security, identity systems, and cloud controls. In this scenario, the analyst needs to connect an endpoint alert with network communication and determine whether similar activity exists elsewhere. That cross-layer visibility and correlation is the core advantage of XDR over endpoint-only tooling.

  • B. Incorrect.

    Incorrect. EDR is focused primarily on endpoint visibility, detection, investigation, and response on hosts. It can provide rich process, file, and behavioral telemetry from endpoints, but the statement that it natively provides organization-wide correlation across all security layers is too broad. Some EDR products integrate with other systems, but that broader correlation capability is what XDR is specifically intended to provide.

  • C. Incorrect.

    Incorrect. Full-disk encryption protects data at rest if a device is lost or stolen, but it does not prevent malicious PowerShell execution after a user clicks a phishing link. It also does not serve as a centralized investigation platform for correlating endpoint and network events. A candidate might choose this if they confuse endpoint security controls with detection and response capabilities.

  • D. Incorrect.

    Incorrect. NAC can control or restrict device access to the network based on posture or policy, but it does not reconstruct browser-spawned PowerShell activity or correlate endpoint telemetry with malicious domain communication. NAC may help quarantine a device, but it is not the best tool for incident scoping and cross-source investigation in this case.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam