CompTIA Security+ SY0-701 Security Monitoring and Alerting Practice Test
Topic 17 focuses on Security Monitoring and Alerting for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
Which term describes collection of operating-system and host telemetry for security and operational analysis?
Correct Answer: D
Correct Answer
Answer D is correct because System monitoring means collection of operating-system and host telemetry for security and operational analysis.
Incorrect Answers
Answer A is incorrect because Agentless monitoring would fit a different scenario. Agentless monitoring refers to monitoring that collects information remotely without installing a dedicated local agent.
Answer B is incorrect because Security benchmark represents a different security function. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.
Answer C is incorrect because SNMP trap addresses a different requirement. SNMP trap refers to an unsolicited network-management notification sent by a managed device.
Question 2
To detect application abuse, failures, or unauthorized activity, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Application monitoring means collection of application events, transactions, errors, and security-relevant behavior.
Incorrect Answers
Answer B is incorrect because System monitoring would fit a different scenario. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.
Answer C is incorrect because Security reporting addresses a different security requirement. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.
Answer D is incorrect because Log aggregation addresses a different requirement. Log aggregation refers to central collection of logs from many systems into a common platform.
Question 3
Which term describes observation of network, cloud, hardware, and platform components?
Correct Answer: D
Correct Answer
Answer D is correct because Infrastructure monitoring means observation of network, cloud, hardware, and platform components.
Incorrect Answers
Answer A is incorrect because Alert tuning represents a different security function. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.
Answer B is incorrect because Security benchmark addresses a different requirement. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.
Answer C is incorrect because Security reporting would fit a different scenario. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.
Question 4
To correlate events and preserve searchable security telemetry, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Log aggregation means central collection of logs from many systems into a common platform.
Incorrect Answers
Answer B is incorrect because Log archiving addresses a different security requirement. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.
Answer C is incorrect because Agentless monitoring would fit a different scenario. Agentless monitoring refers to monitoring that collects information remotely without installing a dedicated local agent.
Answer D is incorrect because Security scanning addresses a different requirement. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.
Question 5
Which term describes generation and delivery of notifications when monitoring detects conditions requiring attention?
Correct Answer: D
Correct Answer
Answer D is correct because Security alerting means generation and delivery of notifications when monitoring detects conditions requiring attention.
Incorrect Answers
Answer A is incorrect because SCAP would fit a different scenario. SCAP refers to a family of standards for expressing and exchanging security configuration and vulnerability information.
Answer B is incorrect because SNMP trap addresses a different requirement. SNMP trap refers to an unsolicited network-management notification sent by a managed device.
Answer C is incorrect because Data loss prevention (DLP) represents a different security function. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.
Question 6
To identify weaknesses or suspicious objects at scale, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Security scanning means automated examination of systems, networks, or content for vulnerabilities or malicious conditions.
Incorrect Answers
Answer B is incorrect because Quarantine addresses a different requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.
Answer C is incorrect because Log archiving would fit a different scenario. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.
Answer D is incorrect because NetFlow addresses a different security requirement. NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.
Question 7
Which term describes production of summarized findings, trends, metrics, and evidence from monitoring data?
Correct Answer: A
Correct Answer
Answer A is correct because Security reporting means production of summarized findings, trends, metrics, and evidence from monitoring data.
Incorrect Answers
Answer B is incorrect because Log aggregation would fit a different scenario. Log aggregation refers to central collection of logs from many systems into a common platform.
Answer C is incorrect because SNMP trap addresses a different requirement. SNMP trap refers to an unsolicited network-management notification sent by a managed device.
Answer D is incorrect because Security alerting represents a different security function. Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention.
Question 8
To support later forensic, legal, or compliance review, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Log archiving means long-term preservation of telemetry according to retention and investigation requirements.
Incorrect Answers
Answer A is incorrect because Quarantine addresses a different requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.
Answer C is incorrect because System monitoring would fit a different scenario. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.
Answer D is incorrect because SIEM addresses a different security requirement. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.
Question 9
Which term describes isolation of a suspicious file, endpoint, account, or workload from normal operation?
Correct Answer: B
Correct Answer
Answer B is correct because Quarantine means isolation of a suspicious file, endpoint, account, or workload from normal operation.
Incorrect Answers
Answer A is incorrect because SIEM represents a different security function. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.
Answer C is incorrect because SNMP trap would fit a different scenario. SNMP trap refers to an unsolicited network-management notification sent by a managed device.
Answer D is incorrect because Infrastructure monitoring addresses a different requirement. Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components.
Question 10
To reduce false positives without hiding meaningful malicious activity, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Alert tuning means adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.
Incorrect Answers
Answer A is incorrect because Agent-based monitoring would fit a different scenario. Agent-based monitoring refers to monitoring that uses software installed on the endpoint or workload to collect local telemetry.
Answer B is incorrect because Security scanning addresses a different requirement. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.
Answer D is incorrect because Data loss prevention (DLP) addresses a different security requirement. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.
Question 11
What is a family of standards for expressing and exchanging security configuration and vulnerability information?
Correct Answer: D
Correct Answer
Answer D is correct because SCAP means a family of standards for expressing and exchanging security configuration and vulnerability information.
Incorrect Answers
Answer A is incorrect because Infrastructure monitoring addresses a different requirement. Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components.
Answer B is incorrect because Alert tuning represents a different security function. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.
Answer C is incorrect because Data loss prevention (DLP) would fit a different scenario. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.
Question 12
To compare deployed systems against a recognized hardening baseline, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Security benchmark means a documented set of recommended secure configuration settings for a technology.
Incorrect Answers
Answer A is incorrect because Infrastructure monitoring addresses a different requirement. Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components.
Answer C is incorrect because Data loss prevention (DLP) would fit a different scenario. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.
Answer D is incorrect because SIEM addresses a different security requirement. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.
Question 13
Which term describes monitoring that uses software installed on the endpoint or workload to collect local telemetry?
Correct Answer: D
Correct Answer
Answer D is correct because Agent-based monitoring means monitoring that uses software installed on the endpoint or workload to collect local telemetry.
Incorrect Answers
Answer A is incorrect because Security scanning represents a different security function. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.
Answer B is incorrect because Security benchmark addresses a different requirement. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.
Answer C is incorrect because SIEM would fit a different scenario. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.
Question 14
To reduce endpoint footprint when supported remote interfaces provide enough visibility, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Agentless monitoring means monitoring that collects information remotely without installing a dedicated local agent.
Incorrect Answers
Answer A is incorrect because Alert tuning addresses a different security requirement. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.
Answer B is incorrect because Security scanning would fit a different scenario. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.
Answer D is incorrect because Quarantine addresses a different requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.
Question 15
Which platform centralizes security data, correlates events, supports searches, and generates detections?
Correct Answer: B
Correct Answer
Answer B is correct because SIEM means a platform that centralizes security data, correlates events, supports searches, and generates detections.
Incorrect Answers
Answer A is incorrect because Security reporting would fit a different scenario. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.
Answer C is incorrect because Security benchmark addresses a different requirement. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.
Answer D is incorrect because Application monitoring represents a different security function. Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior.
Question 16
To detect or block inappropriate disclosure of protected information, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Data loss prevention (DLP) means technology that identifies and controls movement or use of sensitive data according to policy.
Incorrect Answers
Answer B is incorrect because NetFlow would fit a different scenario. NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.
Answer C is incorrect because SNMP trap addresses a different requirement. SNMP trap refers to an unsolicited network-management notification sent by a managed device.
Answer D is incorrect because Quarantine addresses a different security requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.
Question 17
Which term describes network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes?
Correct Answer: B
Correct Answer
Answer B is correct because NetFlow means network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.
Incorrect Answers
Answer A is incorrect because Security scanning represents a different security function. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.
Answer C is incorrect because Security reporting addresses a different requirement. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.
Answer D is incorrect because Alert tuning would fit a different scenario. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.
Question 18
To alert monitoring systems to device events without waiting for the next poll, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because SNMP trap means an unsolicited network-management notification sent by a managed device.
Incorrect Answers
Answer A is incorrect because SIEM addresses a different security requirement. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.
Answer B is incorrect because Security scanning addresses a different requirement. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.
Answer D is incorrect because Agentless monitoring would fit a different scenario. Agentless monitoring refers to monitoring that collects information remotely without installing a dedicated local agent.
Question 19
To identify suspicious processes, authentication events, configuration changes, or resource anomalies, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because System monitoring means collection of operating-system and host telemetry for security and operational analysis.
Incorrect Answers
Answer A is incorrect because Alert tuning addresses a different security requirement. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.
Answer B is incorrect because Security scanning represents a different security function. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.
Answer C is incorrect because Agentless monitoring would fit a different scenario. Agentless monitoring refers to monitoring that collects information remotely without installing a dedicated local agent.
Question 20
Which term describes collection of application events, transactions, errors, and security-relevant behavior?
Correct Answer: B
Correct Answer
Answer B is correct because Application monitoring means collection of application events, transactions, errors, and security-relevant behavior.
Incorrect Answers
Answer A is incorrect because Data loss prevention (DLP) addresses a different security requirement. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.
Answer C is incorrect because Log archiving addresses a different requirement. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.
Answer D is incorrect because Quarantine represents a different security function. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.
Question 21
To identify outages, suspicious traffic patterns, and infrastructure changes, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Infrastructure monitoring means observation of network, cloud, hardware, and platform components.
Incorrect Answers
Answer A is incorrect because SCAP addresses a different security requirement. SCAP refers to a family of standards for expressing and exchanging security configuration and vulnerability information.
Answer B is incorrect because Log archiving represents a different security function. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.
Answer D is incorrect because Security alerting would fit a different scenario. Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention.
Question 22
Which term describes central collection of logs from many systems into a common platform?
Correct Answer: C
Correct Answer
Answer C is correct because Log aggregation means central collection of logs from many systems into a common platform.
Incorrect Answers
Answer A is incorrect because SCAP represents a different security function. SCAP refers to a family of standards for expressing and exchanging security configuration and vulnerability information.
Answer B is incorrect because Log archiving addresses a different requirement. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.
Answer D is incorrect because Data loss prevention (DLP) addresses a different security requirement. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.
Question 23
To bring significant events to analysts quickly, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Security alerting means generation and delivery of notifications when monitoring detects conditions requiring attention.
Incorrect Answers
Answer B is incorrect because Log archiving would fit a different scenario. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.
Answer C is incorrect because Security benchmark addresses a different security requirement. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.
Answer D is incorrect because Security reporting represents a different security function. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.
Question 24
Which term describes automated examination of systems, networks, or content for vulnerabilities or malicious conditions?
Correct Answer: A
Correct Answer
Answer A is correct because Security scanning means automated examination of systems, networks, or content for vulnerabilities or malicious conditions.
Incorrect Answers
Answer B is incorrect because Data loss prevention (DLP) addresses a different security requirement. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.
Answer C is incorrect because Log archiving represents a different security function. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.
Answer D is incorrect because Alert tuning addresses a different requirement. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.
Question 25
To communicate security status and support operational or compliance decisions, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Security reporting means production of summarized findings, trends, metrics, and evidence from monitoring data.
Incorrect Answers
Answer A is incorrect because Security alerting would fit a different scenario. Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention.
Answer C is incorrect because Application monitoring represents a different security function. Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior.
Answer D is incorrect because Log aggregation addresses a different security requirement. Log aggregation refers to central collection of logs from many systems into a common platform.
Question 26
Which term describes long-term preservation of telemetry according to retention and investigation requirements?
Correct Answer: A
Correct Answer
Answer A is correct because Log archiving means long-term preservation of telemetry according to retention and investigation requirements.
Incorrect Answers
Answer B is incorrect because SIEM represents a different security function. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.
Answer C is incorrect because Security scanning addresses a different security requirement. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.
Answer D is incorrect because System monitoring addresses a different requirement. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.
Question 27
To contain risk while analysis or remediation occurs, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Quarantine means isolation of a suspicious file, endpoint, account, or workload from normal operation.
Incorrect Answers
Answer A is incorrect because Security alerting would fit a different scenario. Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention.
Answer B is incorrect because Agent-based monitoring represents a different security function. Agent-based monitoring refers to monitoring that uses software installed on the endpoint or workload to collect local telemetry.
Answer C is incorrect because Security reporting addresses a different security requirement. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.
Question 28
Which term describes adjustment of detection logic, thresholds, suppressions, and context to improve useful signal?
Correct Answer: C
Correct Answer
Answer C is correct because Alert tuning means adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.
Incorrect Answers
Answer A is incorrect because Security alerting addresses a different requirement. Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention.
Answer B is incorrect because Log archiving addresses a different security requirement. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.
Answer D is incorrect because NetFlow represents a different security function. NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.
Question 29
To automate standardized assessment and configuration checking, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because SCAP means a family of standards for expressing and exchanging security configuration and vulnerability information.
Incorrect Answers
Answer A is incorrect because SNMP trap would fit a different scenario. SNMP trap refers to an unsolicited network-management notification sent by a managed device.
Answer B is incorrect because SIEM represents a different security function. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.
Answer D is incorrect because Quarantine addresses a different security requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.
Question 30
What is a documented set of recommended secure configuration settings for a technology?
Correct Answer: D
Correct Answer
Answer D is correct because Security benchmark means a documented set of recommended secure configuration settings for a technology.
Incorrect Answers
Answer A is incorrect because Log archiving represents a different security function. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.
Answer B is incorrect because Agentless monitoring addresses a different requirement. Agentless monitoring refers to monitoring that collects information remotely without installing a dedicated local agent.
Answer C is incorrect because Quarantine addresses a different security requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.
Question 31
To gain detailed host visibility that network-only tools may not provide, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Agent-based monitoring means monitoring that uses software installed on the endpoint or workload to collect local telemetry.
Incorrect Answers
Answer A is incorrect because Infrastructure monitoring represents a different security function. Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components.
Answer C is incorrect because Application monitoring would fit a different scenario. Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior.
Answer D is incorrect because Security scanning addresses a different security requirement. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.
Question 32
Which term describes monitoring that collects information remotely without installing a dedicated local agent?
Correct Answer: C
Correct Answer
Answer C is correct because Agentless monitoring means monitoring that collects information remotely without installing a dedicated local agent.
Incorrect Answers
Answer A is incorrect because System monitoring represents a different security function. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.
Answer B is incorrect because Infrastructure monitoring addresses a different security requirement. Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components.
Answer D is incorrect because Security benchmark addresses a different requirement. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.
Question 33
To analyze activity across many sources in one security operations workflow, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because SIEM means a platform that centralizes security data, correlates events, supports searches, and generates detections.
Incorrect Answers
Answer B is incorrect because Application monitoring would fit a different scenario. Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior.
Answer C is incorrect because Alert tuning addresses a different security requirement. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.
Answer D is incorrect because System monitoring represents a different security function. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.
Question 34
Which term describes technology that identifies and controls movement or use of sensitive data according to policy?
Correct Answer: C
Correct Answer
Answer C is correct because Data loss prevention (DLP) means technology that identifies and controls movement or use of sensitive data according to policy.
Incorrect Answers
Answer A is incorrect because SCAP addresses a different requirement. SCAP refers to a family of standards for expressing and exchanging security configuration and vulnerability information.
Answer B is incorrect because NetFlow addresses a different security requirement. NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.
Answer D is incorrect because Application monitoring represents a different security function. Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior.
Question 35
To investigate communication patterns without storing full packet contents, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because NetFlow means network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.
Incorrect Answers
Answer A is incorrect because Data loss prevention (DLP) represents a different security function. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.
Answer C is incorrect because System monitoring addresses a different security requirement. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.
Answer D is incorrect because Log archiving would fit a different scenario. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.
Popular posts
Recent Posts
