SY0-701 exam dumps

SY0-701 practice question 390 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 390

Single answerRoot cause analysis

A security analyst is investigating why several internal file servers became unreachable for 20 minutes during business hours. Initial alerts show a sharp increase in outbound traffic from one application server just before the outage. Firewall logs indicate many internal connections were denied, and the analyst confirms a recently deployed host-based firewall policy on the application server. Management wants to know the most likely root cause so the team can prevent a recurrence. Which of the following is the BEST conclusion?

  1. A

    A denial-of-service attack from the internet exhausted the file servers' network bandwidth

  2. B

    A misconfigured host-based firewall rule on the application server generated excessive blocked connection attempts that contributed to the outage

  3. C

    The file servers failed because their operating systems were missing critical security patches

  4. D

    An insider intentionally disabled the file servers to hide data exfiltration

Show answer and explanation

Correct answer: B

Explanation

The best answer is the misconfigured host-based firewall rule on the application server. Root cause analysis in security operations focuses on identifying the underlying reason an incident occurred, not just describing the impact. In this case, the strongest indicators are the recent firewall policy deployment, the denied internal connections, and the unusual traffic pattern from the affected server. Those facts support a change-related configuration problem as the most likely root cause. This approach aligns with common incident response and troubleshooting best practices: establish a timeline, correlate logs from multiple sources, review recent changes, and distinguish root cause from symptoms. CompTIA Security+ expects candidates to identify the most evidence-based conclusion in operational scenarios. This also reflects standard guidance found in incident handling frameworks such as NIST SP 800-61, which emphasizes analysis, correlation, and determination of cause during incident investigation.

  • A. Incorrect.

    This is incorrect because the scenario does not provide evidence of an internet-based denial-of-service attack. The indicators point to abnormal outbound traffic from an internal application server and denied internal connections after a recent policy deployment. A candidate might pick this because service unavailability can resemble DoS, but root cause analysis requires tying the outage to the most directly supported evidence.

  • B. Correct.

    This is correct because the timeline and available evidence align with a configuration issue introduced by change activity. The recent deployment of a host-based firewall policy, combined with many denied internal connections and abnormal traffic from that same server, strongly suggests the outage was caused by an improperly configured rule set or policy behavior on the application server. In root cause analysis, correlating alerts, logs, and recent changes is a key method for identifying the underlying cause rather than just the symptom.

  • C. Incorrect.

    This is incorrect because missing patches could contribute to compromise risk or instability, but the scenario gives no evidence of unpatched file servers causing a 20-minute outage. The more relevant facts are the sudden outbound traffic increase, denied connections, and the recent firewall policy change. This option reflects a common mistake of defaulting to patching as the answer even when the incident evidence points to a change-management or configuration issue.

  • D. Incorrect.

    This is incorrect because there is no direct evidence of malicious insider activity, such as authentication anomalies, privilege misuse, or intentional administrative actions affecting the file servers. While insider threats are possible in general, root cause analysis should prioritize conclusions supported by logs and confirmed environmental changes. Choosing this option would be speculative.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam