SY0-701 exam dumps

SY0-701 practice question 397 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 397

Single answerLog data: Firewall logs , Application logs , Endpoint logs , OS-specific security logs , IPS/IDS logs , Network logs , Metadata

A security analyst is investigating a suspected data exfiltration incident from a finance department workstation. The endpoint detection tool shows that a spreadsheet application launched an unsigned child process shortly before the user's system connected to an unfamiliar external IP over HTTPS. The analyst needs to determine whether the connection was likely part of malicious activity and identify the most useful additional evidence. Which log source would provide the BEST next evidence to correlate the suspicious process with the outbound connection?

  1. A

    Firewall logs showing allowed outbound connections, including source IP, destination IP, port, and timestamp

  2. B

    Application logs from the spreadsheet software showing successful file saves earlier in the day

  3. C

    OS-specific security logs showing the user's last successful interactive logon that morning

  4. D

    Metadata from the spreadsheet document showing the author name and document creation date

Show answer and explanation

Correct answer: A

Explanation

The key task is log correlation: the analyst already has endpoint evidence of suspicious process execution and now needs to confirm the related network activity. Firewall logs are the best next source because they provide direct visibility into whether the host made the outbound HTTPS connection, to which destination, and at what time. This allows analysts to correlate endpoint logs with network controls and determine whether execution was followed by communication that may indicate malware, command-and-control, or exfiltration. In practice, investigators often correlate endpoint telemetry, firewall logs, IDS/IPS alerts, proxy logs, and DNS/network logs to build a complete timeline. Best practices from common incident response guidance, including NIST incident handling recommendations, emphasize collecting and correlating multiple log sources with synchronized timestamps to validate suspicious activity and reduce false positives.

  • A. Correct.

    Correct. Firewall logs are the best next source because they can confirm whether the workstation established the outbound HTTPS session to the unfamiliar external IP and when it occurred. In a real investigation, correlating the endpoint alert timestamp and host details with firewall log data helps determine whether the suspicious child process was followed by actual network communication consistent with command-and-control or data exfiltration. Firewall logs commonly record source and destination addresses, ports, action taken, and timestamps, which are directly relevant to validating the suspected malicious connection.

  • B. Incorrect.

    Incorrect. Application logs showing normal spreadsheet activity such as file saves may provide user context, but they do not usually establish whether a suspicious spawned process initiated external network communications. This is a plausible distractor because analysts often review application behavior during investigations, but in this scenario the highest-priority question is whether the process was tied to the outbound connection.

  • C. Incorrect.

    Incorrect. OS-specific security logs, such as Windows Security event logs, can help confirm who was logged on and what authentication events occurred. However, a successful logon earlier in the day does not directly link the suspicious child process to the external HTTPS session. This option reflects a common misconception that any security log is equally useful; in reality, the most useful log source is the one that directly answers the network-correlation question.

  • D. Incorrect.

    Incorrect. File metadata such as author and creation date can help with document provenance, ownership, or timeline reconstruction, but it does not show whether the workstation actually communicated with the external IP. This distractor is plausible because metadata can be valuable in forensic review, yet it is not the best source for correlating process activity to outbound network traffic.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam