SY0-701 exam dumps

SY0-701 practice question 395 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 395

Single answer4.9 Given a scenario, use data sources to support an investigation.

A security analyst is investigating a suspected compromise of a file server after several users reported their files were encrypted overnight. The analyst needs to identify the initial access vector and determine whether the attacker used stolen credentials or exploited a vulnerable service. Which data source would provide the MOST direct evidence to answer this question first?

  1. A

    Firewall logs showing allowed and denied inbound connections to the file server

  2. B

    Vulnerability scan results from the previous quarter

  3. C

    The organization's written incident response policy

  4. D

    A screenshot of the ransom note displayed on an affected workstation

Show answer and explanation

Correct answer: A

Explanation

When investigating a ransomware incident, analysts should prioritize data sources that provide direct evidence of attacker behavior. In this scenario, the goal is to determine initial access and distinguish between credential abuse and service exploitation. Firewall logs are the best first source among the options because they can show suspicious inbound connections, source IP addresses, destination ports, and connection timing that align with the compromise window. In a real investigation, the analyst would likely correlate firewall logs with other sources such as authentication logs, VPN logs, server security logs, EDR alerts, and IDS/IPS events to confirm whether valid credentials were used or whether a public-facing service was targeted. Best practices from incident response guidance such as NIST SP 800-61 emphasize collecting and correlating relevant log data to establish scope, timeline, and attack vector before moving into containment and recovery.

  • A. Correct.

    Correct. Firewall logs are one of the most useful initial data sources for determining whether the file server was accessed from an external source and which ports/protocols were used. They can help an analyst see whether suspicious inbound connections targeted exposed services such as RDP, SMB, or a web management interface. This provides direct investigative evidence about whether exploitation of a service is likely. Firewall and network security appliance logs are commonly used in Security+ investigations to reconstruct attack paths and identify suspicious communication patterns.

  • B. Incorrect.

    Incorrect. Vulnerability scan results can help identify whether the server had known weaknesses, but they do not show what actually happened during the incident. They are useful for context and remediation planning, but they are not the most direct evidence of the initial access method. A prior scan may also be outdated and miss recent configuration changes or newly introduced vulnerabilities.

  • C. Incorrect.

    Incorrect. The incident response policy explains how the organization should respond to an event, including roles and escalation procedures, but it is not an evidentiary data source for determining how the attacker gained access. Candidates may choose this because policies are important during incidents, but they do not answer forensic questions about attacker activity.

  • D. Incorrect.

    Incorrect. The ransom note confirms that ransomware executed, but it does not reveal the initial access vector. It may include payment instructions or a threat actor name, but it generally does not provide reliable evidence showing whether the attacker used stolen credentials or exploited a vulnerable service. This is a common mistake: focusing on visible impact rather than the logs that show the intrusion path.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam