CompTIA Security+ SY0-701 Security Monitoring and Alerting Practice Test

 

Topic 17 focuses on Security Monitoring and Alerting for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which term describes collection of operating-system and host telemetry for security and operational analysis?

  1. Agentless monitoring
  2. Security benchmark
  3. SNMP trap
  4. System monitoring

Correct Answer: D

 

Correct Answer

Answer D is correct because System monitoring means collection of operating-system and host telemetry for security and operational analysis.

Incorrect Answers

Answer A is incorrect because Agentless monitoring would fit a different scenario. Agentless monitoring refers to monitoring that collects information remotely without installing a dedicated local agent.

Answer B is incorrect because Security benchmark represents a different security function. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.

Answer C is incorrect because SNMP trap addresses a different requirement. SNMP trap refers to an unsolicited network-management notification sent by a managed device.

 

Question 2

To detect application abuse, failures, or unauthorized activity, which security approach should be selected?

  1. Application monitoring
  2. System monitoring
  3. Security reporting
  4. Log aggregation

Correct Answer: A

 

Correct Answer

Answer A is correct because Application monitoring means collection of application events, transactions, errors, and security-relevant behavior.

Incorrect Answers

Answer B is incorrect because System monitoring would fit a different scenario. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.

Answer C is incorrect because Security reporting addresses a different security requirement. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.

Answer D is incorrect because Log aggregation addresses a different requirement. Log aggregation refers to central collection of logs from many systems into a common platform.

 

Question 3

Which term describes observation of network, cloud, hardware, and platform components?

  1. Alert tuning
  2. Security benchmark
  3. Security reporting
  4. Infrastructure monitoring

Correct Answer: D

 

Correct Answer

Answer D is correct because Infrastructure monitoring means observation of network, cloud, hardware, and platform components.

Incorrect Answers

Answer A is incorrect because Alert tuning represents a different security function. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

Answer B is incorrect because Security benchmark addresses a different requirement. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.

Answer C is incorrect because Security reporting would fit a different scenario. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.

 

Question 4

To correlate events and preserve searchable security telemetry, which security approach should be selected?

  1. Log aggregation
  2. Log archiving
  3. Agentless monitoring
  4. Security scanning

Correct Answer: A

 

Correct Answer

Answer A is correct because Log aggregation means central collection of logs from many systems into a common platform.

Incorrect Answers

Answer B is incorrect because Log archiving addresses a different security requirement. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.

Answer C is incorrect because Agentless monitoring would fit a different scenario. Agentless monitoring refers to monitoring that collects information remotely without installing a dedicated local agent.

Answer D is incorrect because Security scanning addresses a different requirement. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

 

Question 5

Which term describes generation and delivery of notifications when monitoring detects conditions requiring attention?

  1. SCAP
  2. SNMP trap
  3. Data loss prevention (DLP)
  4. Security alerting

Correct Answer: D

 

Correct Answer

Answer D is correct because Security alerting means generation and delivery of notifications when monitoring detects conditions requiring attention.

Incorrect Answers

Answer A is incorrect because SCAP would fit a different scenario. SCAP refers to a family of standards for expressing and exchanging security configuration and vulnerability information.

Answer B is incorrect because SNMP trap addresses a different requirement. SNMP trap refers to an unsolicited network-management notification sent by a managed device.

Answer C is incorrect because Data loss prevention (DLP) represents a different security function. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.

 

Question 6

To identify weaknesses or suspicious objects at scale, which security approach should be selected?

  1. Security scanning
  2. Quarantine
  3. Log archiving
  4. NetFlow

Correct Answer: A

 

Correct Answer

Answer A is correct because Security scanning means automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Incorrect Answers

Answer B is incorrect because Quarantine addresses a different requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.

Answer C is incorrect because Log archiving would fit a different scenario. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.

Answer D is incorrect because NetFlow addresses a different security requirement. NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.

 

Question 7

Which term describes production of summarized findings, trends, metrics, and evidence from monitoring data?

  1. Security reporting
  2. Log aggregation
  3. SNMP trap
  4. Security alerting

Correct Answer: A

 

Correct Answer

Answer A is correct because Security reporting means production of summarized findings, trends, metrics, and evidence from monitoring data.

Incorrect Answers

Answer B is incorrect because Log aggregation would fit a different scenario. Log aggregation refers to central collection of logs from many systems into a common platform.

Answer C is incorrect because SNMP trap addresses a different requirement. SNMP trap refers to an unsolicited network-management notification sent by a managed device.

Answer D is incorrect because Security alerting represents a different security function. Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention.

 

Question 8

To support later forensic, legal, or compliance review, which security approach should be selected?

  1. Quarantine
  2. Log archiving
  3. System monitoring
  4. SIEM

Correct Answer: B

 

Correct Answer

Answer B is correct because Log archiving means long-term preservation of telemetry according to retention and investigation requirements.

Incorrect Answers

Answer A is incorrect because Quarantine addresses a different requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.

Answer C is incorrect because System monitoring would fit a different scenario. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.

Answer D is incorrect because SIEM addresses a different security requirement. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.

 

Question 9

Which term describes isolation of a suspicious file, endpoint, account, or workload from normal operation?

  1. SIEM
  2. Quarantine
  3. SNMP trap
  4. Infrastructure monitoring

Correct Answer: B

 

Correct Answer

Answer B is correct because Quarantine means isolation of a suspicious file, endpoint, account, or workload from normal operation.

Incorrect Answers

Answer A is incorrect because SIEM represents a different security function. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.

Answer C is incorrect because SNMP trap would fit a different scenario. SNMP trap refers to an unsolicited network-management notification sent by a managed device.

Answer D is incorrect because Infrastructure monitoring addresses a different requirement. Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components.

 

Question 10

To reduce false positives without hiding meaningful malicious activity, which security approach should be selected?

  1. Agent-based monitoring
  2. Security scanning
  3. Alert tuning
  4. Data loss prevention (DLP)

Correct Answer: C

 

Correct Answer

Answer C is correct because Alert tuning means adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

Incorrect Answers

Answer A is incorrect because Agent-based monitoring would fit a different scenario. Agent-based monitoring refers to monitoring that uses software installed on the endpoint or workload to collect local telemetry.

Answer B is incorrect because Security scanning addresses a different requirement. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Answer D is incorrect because Data loss prevention (DLP) addresses a different security requirement. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.

 

Question 11

What is a family of standards for expressing and exchanging security configuration and vulnerability information?

  1. Infrastructure monitoring
  2. Alert tuning
  3. Data loss prevention (DLP)
  4. SCAP

Correct Answer: D

 

Correct Answer

Answer D is correct because SCAP means a family of standards for expressing and exchanging security configuration and vulnerability information.

Incorrect Answers

Answer A is incorrect because Infrastructure monitoring addresses a different requirement. Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components.

Answer B is incorrect because Alert tuning represents a different security function. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

Answer C is incorrect because Data loss prevention (DLP) would fit a different scenario. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.

 

Question 12

To compare deployed systems against a recognized hardening baseline, which security approach should be selected?

  1. Infrastructure monitoring
  2. Security benchmark
  3. Data loss prevention (DLP)
  4. SIEM

Correct Answer: B

 

Correct Answer

Answer B is correct because Security benchmark means a documented set of recommended secure configuration settings for a technology.

Incorrect Answers

Answer A is incorrect because Infrastructure monitoring addresses a different requirement. Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components.

Answer C is incorrect because Data loss prevention (DLP) would fit a different scenario. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.

Answer D is incorrect because SIEM addresses a different security requirement. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.

 

Question 13

Which term describes monitoring that uses software installed on the endpoint or workload to collect local telemetry?

  1. Security scanning
  2. Security benchmark
  3. SIEM
  4. Agent-based monitoring

Correct Answer: D

 

Correct Answer

Answer D is correct because Agent-based monitoring means monitoring that uses software installed on the endpoint or workload to collect local telemetry.

Incorrect Answers

Answer A is incorrect because Security scanning represents a different security function. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Answer B is incorrect because Security benchmark addresses a different requirement. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.

Answer C is incorrect because SIEM would fit a different scenario. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.

 

Question 14

To reduce endpoint footprint when supported remote interfaces provide enough visibility, which security approach should be selected?

  1. Alert tuning
  2. Security scanning
  3. Agentless monitoring
  4. Quarantine

Correct Answer: C

 

Correct Answer

Answer C is correct because Agentless monitoring means monitoring that collects information remotely without installing a dedicated local agent.

Incorrect Answers

Answer A is incorrect because Alert tuning addresses a different security requirement. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

Answer B is incorrect because Security scanning would fit a different scenario. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Answer D is incorrect because Quarantine addresses a different requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.

 

Question 15

Which platform centralizes security data, correlates events, supports searches, and generates detections?

  1. Security reporting
  2. SIEM
  3. Security benchmark
  4. Application monitoring

Correct Answer: B

 

Correct Answer

Answer B is correct because SIEM means a platform that centralizes security data, correlates events, supports searches, and generates detections.

Incorrect Answers

Answer A is incorrect because Security reporting would fit a different scenario. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.

Answer C is incorrect because Security benchmark addresses a different requirement. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.

Answer D is incorrect because Application monitoring represents a different security function. Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior.

 

Question 16

To detect or block inappropriate disclosure of protected information, which security approach should be selected?

  1. Data loss prevention (DLP)
  2. NetFlow
  3. SNMP trap
  4. Quarantine

Correct Answer: A

 

Correct Answer

Answer A is correct because Data loss prevention (DLP) means technology that identifies and controls movement or use of sensitive data according to policy.

Incorrect Answers

Answer B is incorrect because NetFlow would fit a different scenario. NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.

Answer C is incorrect because SNMP trap addresses a different requirement. SNMP trap refers to an unsolicited network-management notification sent by a managed device.

Answer D is incorrect because Quarantine addresses a different security requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.

 

Question 17

Which term describes network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes?

  1. Security scanning
  2. NetFlow
  3. Security reporting
  4. Alert tuning

Correct Answer: B

 

Correct Answer

Answer B is correct because NetFlow means network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.

Incorrect Answers

Answer A is incorrect because Security scanning represents a different security function. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Answer C is incorrect because Security reporting addresses a different requirement. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.

Answer D is incorrect because Alert tuning would fit a different scenario. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

 

Question 18

To alert monitoring systems to device events without waiting for the next poll, which security approach should be selected?

  1. SIEM
  2. Security scanning
  3. SNMP trap
  4. Agentless monitoring

Correct Answer: C

 

Correct Answer

Answer C is correct because SNMP trap means an unsolicited network-management notification sent by a managed device.

Incorrect Answers

Answer A is incorrect because SIEM addresses a different security requirement. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.

Answer B is incorrect because Security scanning addresses a different requirement. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Answer D is incorrect because Agentless monitoring would fit a different scenario. Agentless monitoring refers to monitoring that collects information remotely without installing a dedicated local agent.

 

Question 19

To identify suspicious processes, authentication events, configuration changes, or resource anomalies, which security approach should be selected?

  1. Alert tuning
  2. Security scanning
  3. Agentless monitoring
  4. System monitoring

Correct Answer: D

 

Correct Answer

Answer D is correct because System monitoring means collection of operating-system and host telemetry for security and operational analysis.

Incorrect Answers

Answer A is incorrect because Alert tuning addresses a different security requirement. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

Answer B is incorrect because Security scanning represents a different security function. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Answer C is incorrect because Agentless monitoring would fit a different scenario. Agentless monitoring refers to monitoring that collects information remotely without installing a dedicated local agent.

 

Question 20

Which term describes collection of application events, transactions, errors, and security-relevant behavior?

  1. Data loss prevention (DLP)
  2. Application monitoring
  3. Log archiving
  4. Quarantine

Correct Answer: B

 

Correct Answer

Answer B is correct because Application monitoring means collection of application events, transactions, errors, and security-relevant behavior.

Incorrect Answers

Answer A is incorrect because Data loss prevention (DLP) addresses a different security requirement. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.

Answer C is incorrect because Log archiving addresses a different requirement. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.

Answer D is incorrect because Quarantine represents a different security function. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.

 

Question 21

To identify outages, suspicious traffic patterns, and infrastructure changes, which security approach should be selected?

  1. SCAP
  2. Log archiving
  3. Infrastructure monitoring
  4. Security alerting

Correct Answer: C

 

Correct Answer

Answer C is correct because Infrastructure monitoring means observation of network, cloud, hardware, and platform components.

Incorrect Answers

Answer A is incorrect because SCAP addresses a different security requirement. SCAP refers to a family of standards for expressing and exchanging security configuration and vulnerability information.

Answer B is incorrect because Log archiving represents a different security function. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.

Answer D is incorrect because Security alerting would fit a different scenario. Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention.

 

Question 22

Which term describes central collection of logs from many systems into a common platform?

  1. SCAP
  2. Log archiving
  3. Log aggregation
  4. Data loss prevention (DLP)

Correct Answer: C

 

Correct Answer

Answer C is correct because Log aggregation means central collection of logs from many systems into a common platform.

Incorrect Answers

Answer A is incorrect because SCAP represents a different security function. SCAP refers to a family of standards for expressing and exchanging security configuration and vulnerability information.

Answer B is incorrect because Log archiving addresses a different requirement. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.

Answer D is incorrect because Data loss prevention (DLP) addresses a different security requirement. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.

 

Question 23

To bring significant events to analysts quickly, which security approach should be selected?

  1. Security alerting
  2. Log archiving
  3. Security benchmark
  4. Security reporting

Correct Answer: A

 

Correct Answer

Answer A is correct because Security alerting means generation and delivery of notifications when monitoring detects conditions requiring attention.

Incorrect Answers

Answer B is incorrect because Log archiving would fit a different scenario. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.

Answer C is incorrect because Security benchmark addresses a different security requirement. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.

Answer D is incorrect because Security reporting represents a different security function. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.

 

Question 24

Which term describes automated examination of systems, networks, or content for vulnerabilities or malicious conditions?

  1. Security scanning
  2. Data loss prevention (DLP)
  3. Log archiving
  4. Alert tuning

Correct Answer: A

 

Correct Answer

Answer A is correct because Security scanning means automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Incorrect Answers

Answer B is incorrect because Data loss prevention (DLP) addresses a different security requirement. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.

Answer C is incorrect because Log archiving represents a different security function. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.

Answer D is incorrect because Alert tuning addresses a different requirement. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

 

Question 25

To communicate security status and support operational or compliance decisions, which security approach should be selected?

  1. Security alerting
  2. Security reporting
  3. Application monitoring
  4. Log aggregation

Correct Answer: B

 

Correct Answer

Answer B is correct because Security reporting means production of summarized findings, trends, metrics, and evidence from monitoring data.

Incorrect Answers

Answer A is incorrect because Security alerting would fit a different scenario. Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention.

Answer C is incorrect because Application monitoring represents a different security function. Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior.

Answer D is incorrect because Log aggregation addresses a different security requirement. Log aggregation refers to central collection of logs from many systems into a common platform.

 

Question 26

Which term describes long-term preservation of telemetry according to retention and investigation requirements?

  1. Log archiving
  2. SIEM
  3. Security scanning
  4. System monitoring

Correct Answer: A

 

Correct Answer

Answer A is correct because Log archiving means long-term preservation of telemetry according to retention and investigation requirements.

Incorrect Answers

Answer B is incorrect because SIEM represents a different security function. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.

Answer C is incorrect because Security scanning addresses a different security requirement. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Answer D is incorrect because System monitoring addresses a different requirement. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.

 

Question 27

To contain risk while analysis or remediation occurs, which security approach should be selected?

  1. Security alerting
  2. Agent-based monitoring
  3. Security reporting
  4. Quarantine

Correct Answer: D

 

Correct Answer

Answer D is correct because Quarantine means isolation of a suspicious file, endpoint, account, or workload from normal operation.

Incorrect Answers

Answer A is incorrect because Security alerting would fit a different scenario. Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention.

Answer B is incorrect because Agent-based monitoring represents a different security function. Agent-based monitoring refers to monitoring that uses software installed on the endpoint or workload to collect local telemetry.

Answer C is incorrect because Security reporting addresses a different security requirement. Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data.

 

Question 28

Which term describes adjustment of detection logic, thresholds, suppressions, and context to improve useful signal?

  1. Security alerting
  2. Log archiving
  3. Alert tuning
  4. NetFlow

Correct Answer: C

 

Correct Answer

Answer C is correct because Alert tuning means adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

Incorrect Answers

Answer A is incorrect because Security alerting addresses a different requirement. Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention.

Answer B is incorrect because Log archiving addresses a different security requirement. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.

Answer D is incorrect because NetFlow represents a different security function. NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.

 

Question 29

To automate standardized assessment and configuration checking, which security approach should be selected?

  1. SNMP trap
  2. SIEM
  3. SCAP
  4. Quarantine

Correct Answer: C

 

Correct Answer

Answer C is correct because SCAP means a family of standards for expressing and exchanging security configuration and vulnerability information.

Incorrect Answers

Answer A is incorrect because SNMP trap would fit a different scenario. SNMP trap refers to an unsolicited network-management notification sent by a managed device.

Answer B is incorrect because SIEM represents a different security function. SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections.

Answer D is incorrect because Quarantine addresses a different security requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.

 

Question 30

What is a documented set of recommended secure configuration settings for a technology?

  1. Log archiving
  2. Agentless monitoring
  3. Quarantine
  4. Security benchmark

Correct Answer: D

 

Correct Answer

Answer D is correct because Security benchmark means a documented set of recommended secure configuration settings for a technology.

Incorrect Answers

Answer A is incorrect because Log archiving represents a different security function. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.

Answer B is incorrect because Agentless monitoring addresses a different requirement. Agentless monitoring refers to monitoring that collects information remotely without installing a dedicated local agent.

Answer C is incorrect because Quarantine addresses a different security requirement. Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation.

 

Question 31

To gain detailed host visibility that network-only tools may not provide, which security approach should be selected?

  1. Infrastructure monitoring
  2. Agent-based monitoring
  3. Application monitoring
  4. Security scanning

Correct Answer: B

 

Correct Answer

Answer B is correct because Agent-based monitoring means monitoring that uses software installed on the endpoint or workload to collect local telemetry.

Incorrect Answers

Answer A is incorrect because Infrastructure monitoring represents a different security function. Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components.

Answer C is incorrect because Application monitoring would fit a different scenario. Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior.

Answer D is incorrect because Security scanning addresses a different security requirement. Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

 

Question 32

Which term describes monitoring that collects information remotely without installing a dedicated local agent?

  1. System monitoring
  2. Infrastructure monitoring
  3. Agentless monitoring
  4. Security benchmark

Correct Answer: C

 

Correct Answer

Answer C is correct because Agentless monitoring means monitoring that collects information remotely without installing a dedicated local agent.

Incorrect Answers

Answer A is incorrect because System monitoring represents a different security function. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.

Answer B is incorrect because Infrastructure monitoring addresses a different security requirement. Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components.

Answer D is incorrect because Security benchmark addresses a different requirement. Security benchmark refers to a documented set of recommended secure configuration settings for a technology.

 

Question 33

To analyze activity across many sources in one security operations workflow, which security approach should be selected?

  1. SIEM
  2. Application monitoring
  3. Alert tuning
  4. System monitoring

Correct Answer: A

 

Correct Answer

Answer A is correct because SIEM means a platform that centralizes security data, correlates events, supports searches, and generates detections.

Incorrect Answers

Answer B is incorrect because Application monitoring would fit a different scenario. Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior.

Answer C is incorrect because Alert tuning addresses a different security requirement. Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

Answer D is incorrect because System monitoring represents a different security function. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.

 

Question 34

Which term describes technology that identifies and controls movement or use of sensitive data according to policy?

  1. SCAP
  2. NetFlow
  3. Data loss prevention (DLP)
  4. Application monitoring

Correct Answer: C

 

Correct Answer

Answer C is correct because Data loss prevention (DLP) means technology that identifies and controls movement or use of sensitive data according to policy.

Incorrect Answers

Answer A is incorrect because SCAP addresses a different requirement. SCAP refers to a family of standards for expressing and exchanging security configuration and vulnerability information.

Answer B is incorrect because NetFlow addresses a different security requirement. NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.

Answer D is incorrect because Application monitoring represents a different security function. Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior.

 

Question 35

To investigate communication patterns without storing full packet contents, which security approach should be selected?

  1. Data loss prevention (DLP)
  2. NetFlow
  3. System monitoring
  4. Log archiving

Correct Answer: B

 

Correct Answer

Answer B is correct because NetFlow means network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.

Incorrect Answers

Answer A is incorrect because Data loss prevention (DLP) represents a different security function. Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy.

Answer C is incorrect because System monitoring addresses a different security requirement. System monitoring refers to collection of operating-system and host telemetry for security and operational analysis.

Answer D is incorrect because Log archiving would fit a different scenario. Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements.

img