SY0-701 exam dumps

SY0-701 practice question 392 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 392

Single answerThreat hunting

A security analyst is conducting a threat hunt after receiving industry intelligence that a ransomware group commonly gains persistence by creating scheduled tasks and then uses PowerShell to download tools from newly registered domains. The organization's SIEM has collected Windows event logs, DNS logs, EDR process telemetry, and firewall logs for the last 30 days. The analyst wants to identify potentially compromised hosts before ransomware is deployed. Which action would be the BEST first step in this threat hunt?

  1. A

    Query the SIEM for endpoints that created new scheduled tasks and then initiated PowerShell connections to recently registered external domains

  2. B

    Immediately block all outbound PowerShell traffic at the firewall for every workstation in the enterprise

  3. C

    Start restoring critical servers from backup to ensure recovery if ransomware is later discovered

  4. D

    Reimage any endpoint that has executed PowerShell in the last 30 days

Show answer and explanation

Correct answer: A

Explanation

The best answer is to perform a targeted, hypothesis-based search that correlates relevant telemetry. Threat hunting differs from routine alert monitoring because the analyst starts with a behavioral hypothesis derived from threat intelligence and then searches for evidence across logs and endpoint data. In this case, the intelligence identifies a likely attack chain: scheduled task creation for persistence followed by PowerShell activity contacting newly registered domains. Correlating Windows event logs, EDR process telemetry, and DNS/network data is a practical and realistic hunting approach. This aligns with common security operations best practices and frameworks such as MITRE ATT&CK, which documents techniques like Scheduled Task/Job for persistence and PowerShell for execution, as well as network-based hunting for suspicious external communications. Broad blocking, mass reimaging, or recovery steps may be appropriate later depending on findings, but they are not the best first step when the goal is to identify potentially compromised hosts with minimal unnecessary disruption.

  • A. Correct.

    Correct. Threat hunting is a hypothesis-driven activity that uses available telemetry to look for patterns associated with known adversary behavior. In this scenario, the intelligence provides specific indicators of behavior: persistence via scheduled tasks and follow-on PowerShell activity reaching newly registered domains. Correlating these events in the SIEM is the best first step because it narrows the search to hosts exhibiting the suspicious sequence, allowing the analyst to identify likely compromises before taking disruptive containment actions.

  • B. Incorrect.

    Incorrect. Blocking all outbound PowerShell traffic is a broad containment measure, not the best first step in a hunt. It may disrupt legitimate administrative automation and does not help validate which hosts are actually compromised. Threat hunting should begin with collecting and correlating evidence based on the threat hypothesis before enterprise-wide disruptive actions are taken.

  • C. Incorrect.

    Incorrect. Restoring from backup is part of recovery after systems are confirmed to be impacted, not an initial hunting activity. At this stage, the analyst is trying to proactively identify compromised hosts before ransomware execution. Moving to recovery before validation skips the investigation and could waste time and resources.

  • D. Incorrect.

    Incorrect. Reimaging every endpoint that has executed PowerShell in the last 30 days would be excessive because PowerShell is widely used for legitimate administration and software management. This option reflects a common misconception that any use of an administrative tool is malicious. Threat hunting focuses on distinguishing benign from suspicious behavior by using context and correlations.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam