SY0-701 Question 414
Single answerMonitoring and revisionA company recently completed a security audit after discovering that several critical Windows servers had been excluded from centralized logging for more than two months. The security manager wants to reduce the chance of this happening again without creating excessive administrative overhead. Which action would BEST improve monitoring and revision of the logging process?
- A
Implement a scheduled control review that compares the current asset inventory against the SIEM log source list and investigates exceptions
- B
Increase firewall rule logging verbosity on all network segments to capture more traffic details
- C
Configure endpoint antivirus to perform hourly scans on all servers and send malware alerts to administrators
- D
Require system administrators to manually confirm each week by email that their servers are forwarding logs properly
Show answer and explanation
Correct answer: A
Explanation
The best choice is to establish a periodic review that validates logging coverage against an authoritative source such as the asset inventory or configuration management database. In Security+ terms, monitoring and revision means not only deploying a control, but regularly assessing whether it still operates as intended and updating the process when gaps are found. Centralized logging is only effective when all in-scope systems are actually forwarding logs. A review that reconciles assets with SIEM log sources is a practical detective and governance control that supports continuous improvement. This approach is consistent with widely accepted best practices in frameworks such as NIST SP 800-137 for Information Security Continuous Monitoring and NIST SP 800-53 control families related to audit logging, configuration management, and ongoing assessment.
- A. Correct.
This is the best answer because it addresses both monitoring and revision of the control itself. Comparing the authoritative asset inventory to the SIEM's active log sources helps identify coverage gaps, such as newly deployed or misconfigured servers that are not sending logs. Investigating exceptions creates a formal review process and supports continuous improvement. This aligns with common security governance practices that require periodic validation of control effectiveness rather than assuming controls continue to work after deployment.
- B. Incorrect.
This is incorrect because increasing firewall log verbosity may generate more data, but it does not verify whether all required servers are actually sending logs to the centralized platform. It could also increase noise and storage costs without solving the underlying control gap. A candidate might choose this because it sounds like stronger monitoring, but the issue is coverage validation, not lack of detail in existing logs.
- C. Incorrect.
This is incorrect because antivirus scans are useful for endpoint protection, not for validating centralized logging coverage. Malware alerts do not confirm that systems are integrated into the SIEM or that security logs are being collected consistently. This distractor targets the misconception that adding more security tools automatically improves all areas of security monitoring.
- D. Incorrect.
This is incorrect because manual email attestations are weak evidence and create avoidable administrative burden. They are prone to human error, inconsistent follow-through, and false assurance. Although some organizations use manual checks as a temporary compensating control, they are not the best long-term method for monitoring and revising a logging process when an automated comparison against inventory is available.