SY0-701 exam dumps

SY0-701 practice question 400 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 400

Single answerData sources: Vulnerability scans , Automated reports , Dashboards , Packet captures

A security analyst sees a spike in failed logon attempts on the SOC dashboard for a public-facing web application. An automated weekly report also shows the number of critical findings from the last authenticated vulnerability scan has not changed since the previous month. The analyst needs to determine whether the failed logons are most likely part of an active password-spraying attempt or simply noise from an unrelated scanner. Which data source would provide the MOST direct evidence to validate what is happening in real time?

  1. A

    Review a packet capture from the web application segment to examine the source patterns, request timing, and authentication attempts

  2. B

    Rely on the automated vulnerability report because it summarizes recent security issues across the environment

  3. C

    Use the dashboard alone because it already shows the trend in failed logons and severity

  4. D

    Run another authenticated vulnerability scan and compare the new list of findings to the previous report

Show answer and explanation

Correct answer: A

Explanation

The best answer is to review a packet capture. In this scenario, the analyst is trying to distinguish between two causes of failed logons: an active password-spraying attack or noise from scanner activity. Vulnerability scans and their automated reports are useful for identifying missing patches, insecure configurations, and exposure over time, but they are not designed to prove what is happening in a live authentication event. Dashboards help identify trends and prioritize alerts, but they often lack the packet-level detail needed for high-confidence validation. Packet captures provide direct evidence such as repeated attempts against many accounts from one or more sources, timing intervals, headers, and protocol behavior. This aligns with common incident response and network security best practices: use summarized sources like dashboards and automated reports for detection and prioritization, then use detailed evidence sources such as packet captures to validate and investigate suspicious activity. This approach is consistent with guidance from NIST incident response practices, which emphasize collecting and analyzing detailed event data to confirm and scope active incidents.

  • A. Correct.

    Correct. A packet capture provides the most direct, low-level evidence of what is occurring on the network. The analyst can inspect connection frequency, source IP distribution, request cadence, protocol details, and repeated authentication attempts to distinguish password spraying from general scanner activity. Packet captures are especially useful when validating whether traffic is active, coordinated, and targeted in real time.

  • B. Incorrect.

    Incorrect. Automated vulnerability reports are useful for summarizing scan results, trends, and outstanding weaknesses, but they do not directly validate whether the current failed logons are part of an active attack. They focus on exposure and findings rather than live authentication behavior.

  • C. Incorrect.

    Incorrect. Dashboards are valuable for visibility and alert triage, but they are typically aggregated and summarized views of data. They can indicate that failed logons are increasing, but by themselves they usually do not provide enough protocol-level detail to determine whether the activity matches password spraying or benign scanner traffic.

  • D. Incorrect.

    Incorrect. Running another vulnerability scan may generate additional traffic and still would not be the best source for confirming the nature of the current login failures. Vulnerability scans identify weaknesses; they are not the primary tool for validating live attack behavior against authentication services.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam