CompTIA Security+ SY0-701 Security Monitoring and Alerting Practice Test 1

 

Topic 17 Practice Test 1 covers Security Monitoring and Alerting for CompTIA Security+ SY0-701 and maps to objective 4.4: Explain security alerting and monitoring concepts and tools. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

Which term describes long-term preservation of telemetry according to retention and investigation requirements?

  1. Log archiving
  2. Security scanning
  3. System monitoring
  4. SIEM

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Log archiving means long-term preservation of telemetry according to retention and investigation requirements. This matches the requirement as written. System monitoring can be valid in another context, but it is used for collection of operating-system and host telemetry for security and operational analysis.

Incorrect Answers

 

Answer B is incorrect because Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions. This could be appropriate elsewhere, but the required function is long-term preservation of telemetry according to retention and investigation requirements; that makes Log archiving the precise choice.

Answer C is incorrect because System monitoring refers to collection of operating-system and host telemetry for security and operational analysis. This could be appropriate elsewhere, but the required function is long-term preservation of telemetry according to retention and investigation requirements; that makes Log archiving the precise choice.

Answer D is incorrect because SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections. This could be appropriate elsewhere, but the required function is long-term preservation of telemetry according to retention and investigation requirements; that makes Log archiving the precise choice.

 

Question 2

The control set for a monitoring and alerting engineering review must address both generation and delivery of notifications when monitoring detects conditions requiring attention and monitoring that uses software installed on the endpoint or workload to collect local telemetry. Which TWO choices map directly to those needs? Choose TWO.

  1. Application monitoring
  2. Security alerting
  3. Infrastructure monitoring
  4. Agent-based monitoring
  5. SIEM

Correct Answers: B, D

Correct Answers

 

 

Answer B is correct because Security alerting means generation and delivery of notifications when monitoring detects conditions requiring attention. The fixed-count item needs this function in the answer set. SIEM covers a platform that centralizes security data, correlates events, supports searches, and generates detections, a different requirement.

Answer D is correct because Agent-based monitoring means monitoring that uses software installed on the endpoint or workload to collect local telemetry. This selection maps directly to one of the named needs. Infrastructure monitoring addresses observation of network, cloud, hardware, and platform components, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because Application monitoring means collection of application events, transactions, errors, and security-relevant behavior. The required choices are Security alerting, Agent-based monitoring. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer C is incorrect because Infrastructure monitoring means observation of network, cloud, hardware, and platform components. The question requires exactly 2 selections: Security alerting, Agent-based monitoring. This option falls outside that required set. For example, Agent-based monitoring is required for monitoring that uses software installed on the endpoint or workload to collect local telemetry.

Answer E is incorrect because SIEM means a platform that centralizes security data, correlates events, supports searches, and generates detections. The scenario calls for Security alerting, Agent-based monitoring. Selecting this option would leave one of those required functions uncovered.

 

Question 3

Which term describes adjustment of detection logic, thresholds, suppressions, and context to improve useful signal?

  1. NetFlow
  2. Security alerting
  3. Log archiving
  4. Alert tuning

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Alert tuning means adjustment of detection logic, thresholds, suppressions, and context to improve useful signal. This is the precise fit for the scenario. Log archiving serves the different purpose of long-term preservation of telemetry according to retention and investigation requirements.

Incorrect Answers

 

Answer A is incorrect because NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes. That concept can be valid in another scenario, but this question is testing adjustment of detection logic, thresholds, suppressions, and context to improve useful signal; Alert tuning therefore fits the requirement more directly.

Answer B is incorrect because Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention. The concept is valid, but it does not match this stem. The required function is adjustment of detection logic, thresholds, suppressions, and context to improve useful signal, which maps to Alert tuning.

Answer C is incorrect because Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements. The scenario instead requires adjustment of detection logic, thresholds, suppressions, and context to improve useful signal, which is why Alert tuning is the better answer; this option serves the different function defined above.

 

Question 4

Which term describes collection of application events, transactions, errors, and security-relevant behavior?

  1. Application monitoring
  2. Data loss prevention (DLP)
  3. Log archiving
  4. Quarantine

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Application monitoring means collection of application events, transactions, errors, and security-relevant behavior. The requirement maps directly to this function, whereas Log archiving is aimed at long-term preservation of telemetry according to retention and investigation requirements.

Incorrect Answers

 

Answer B is incorrect because Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy. That concept can be valid in another scenario, but this question is testing collection of application events, transactions, errors, and security-relevant behavior; Application monitoring therefore fits the requirement more directly.

Answer C is incorrect because Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements. The scenario instead requires collection of application events, transactions, errors, and security-relevant behavior, which is why Application monitoring is the better answer; this option serves the different function defined above.

Answer D is incorrect because Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation. The key mismatch is functional: Application monitoring addresses collection of application events, transactions, errors, and security-relevant behavior, the need stated by the question.

 

Question 5

A review during a monitoring and alerting engineering review identifies two gaps. One requires collection of operating-system and host telemetry for security and operational analysis. The other requires monitoring that collects information remotely without installing a dedicated local agent. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Security reporting
  2. Alert tuning
  3. Security scanning
  4. System monitoring
  5. Agentless monitoring

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because System monitoring means collection of operating-system and host telemetry for security and operational analysis. It belongs in the fixed-count answer set because it covers one of the stated requirements. Security scanning instead serves automated examination of systems, networks, or content for vulnerabilities or malicious conditions and cannot replace this function.

Answer E is correct because Agentless monitoring means monitoring that collects information remotely without installing a dedicated local agent. One required function is exactly what this option provides. Security reporting may be useful elsewhere, but it is used for production of summarized findings, trends, metrics, and evidence from monitoring data.

Incorrect Answers

 

Answer A is incorrect because Security reporting means production of summarized findings, trends, metrics, and evidence from monitoring data. The required choices are System monitoring, Agentless monitoring. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer B is incorrect because Alert tuning means adjustment of detection logic, thresholds, suppressions, and context to improve useful signal. The fixed-count answer set is System monitoring, Agentless monitoring; this option does not fill one of those named functions.

Answer C is incorrect because Security scanning means automated examination of systems, networks, or content for vulnerabilities or malicious conditions. The fixed-count answer set is System monitoring, Agentless monitoring; this option does not fill one of those named functions.

 

Question 6

A review during a monitoring and alerting engineering review identifies two gaps. One requires generation and delivery of notifications when monitoring detects conditions requiring attention. The other requires family of standards for expressing and exchanging security configuration and vulnerability information. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Security alerting
  2. Log aggregation
  3. System monitoring
  4. Log archiving
  5. SCAP

Correct Answers: A, E

Correct Answers

 

 

Answer A is correct because Security alerting means generation and delivery of notifications when monitoring detects conditions requiring attention. This option satisfies a specific requirement in the stem; System monitoring serves collection of operating-system and host telemetry for security and operational analysis and therefore is not interchangeable with it.

Answer E is correct because SCAP means a family of standards for expressing and exchanging security configuration and vulnerability information. It belongs in the fixed-count answer set because it covers one of the stated requirements. System monitoring instead serves collection of operating-system and host telemetry for security and operational analysis and cannot replace this function.

Incorrect Answers

 

Answer B is incorrect because Log aggregation means central collection of logs from many systems into a common platform. Every answer slot must map to a stated requirement. The correct set is SCAP, Security alerting, so this option cannot replace one of those selections.

Answer C is incorrect because System monitoring means collection of operating-system and host telemetry for security and operational analysis. The question requires exactly 2 selections: SCAP, Security alerting. This option falls outside that required set. For example, SCAP is required for a family of standards for expressing and exchanging security configuration and vulnerability information.

Answer D is incorrect because Log archiving means long-term preservation of telemetry according to retention and investigation requirements. The fixed-count answer set is SCAP, Security alerting; this option does not fill one of those named functions. For example, SCAP is required for a family of standards for expressing and exchanging security configuration and vulnerability information.

 

Question 7

Which platform centralizes security data, correlates events, supports searches, and generates detections?

  1. Security reporting
  2. SIEM
  3. Security benchmark
  4. Application monitoring

Correct Answer: B

Correct Answer

 

 

Answer B is correct because SIEM means a platform that centralizes security data, correlates events, supports searches, and generates detections. The deciding point is functional fit: this option covers the stated need, while Security benchmark addresses a documented set of recommended secure configuration settings for a technology.

Incorrect Answers

 

Answer A is incorrect because Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data. That concept can be valid in another scenario, but this question is testing a platform that centralizes security data, correlates events, supports searches, and generates detections; SIEM therefore fits the requirement more directly.

Answer C is incorrect because Security benchmark refers to a documented set of recommended secure configuration settings for a technology. This could be appropriate elsewhere, but the required function is a platform that centralizes security data, correlates events, supports searches, and generates detections; that makes SIEM the precise choice.

Answer D is incorrect because Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior. The scenario instead requires a platform that centralizes security data, correlates events, supports searches, and generates detections, which is why SIEM is the better answer; this option serves the different function defined above.

 

Question 8

To compare deployed systems against a recognized hardening baseline, which security approach should be selected?

  1. Data loss prevention (DLP)
  2. Security benchmark
  3. Infrastructure monitoring
  4. SIEM

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Security benchmark means a documented set of recommended secure configuration settings for a technology. The requirement maps directly to this function, whereas Infrastructure monitoring is aimed at observation of network, cloud, hardware, and platform components.

Incorrect Answers

 

Answer A is incorrect because Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy. The question is not asking for this function. It is testing a documented set of recommended secure configuration settings for a technology, so Security benchmark is the stronger fit.

Answer C is incorrect because Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components. The question is not asking for this function. It is testing a documented set of recommended secure configuration settings for a technology, so Security benchmark is the stronger fit.

Answer D is incorrect because SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections. The concept is valid, but it does not match this stem. The required function is a documented set of recommended secure configuration settings for a technology, which maps to Security benchmark.

 

Question 9

To identify outages, suspicious traffic patterns, and infrastructure changes, which security approach should be selected?

  1. Security alerting
  2. SCAP
  3. Log archiving
  4. Infrastructure monitoring

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Infrastructure monitoring means observation of network, cloud, hardware, and platform components. That makes it the best answer here; SCAP addresses a family of standards for expressing and exchanging security configuration and vulnerability information, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention. The key mismatch is functional: Infrastructure monitoring addresses observation of network, cloud, hardware, and platform components, the need stated by the question.

Answer B is incorrect because SCAP refers to a family of standards for expressing and exchanging security configuration and vulnerability information. The concept is valid, but it does not match this stem. The required function is observation of network, cloud, hardware, and platform components, which maps to Infrastructure monitoring.

Answer C is incorrect because Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements. The concept is valid, but it does not match this stem. The required function is observation of network, cloud, hardware, and platform components, which maps to Infrastructure monitoring.

 

Question 10

What is a family of standards for expressing and exchanging security configuration and vulnerability information?

  1. Data loss prevention (DLP)
  2. Infrastructure monitoring
  3. Alert tuning
  4. SCAP

Correct Answer: D

Correct Answer

 

 

Answer D is correct because SCAP means a family of standards for expressing and exchanging security configuration and vulnerability information. That is the function the question is testing. Infrastructure monitoring would instead be used for observation of network, cloud, hardware, and platform components.

Incorrect Answers

 

Answer A is incorrect because Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy. The question is not asking for this function. It is testing a family of standards for expressing and exchanging security configuration and vulnerability information, so SCAP is the stronger fit.

Answer B is incorrect because Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components. The scenario instead requires a family of standards for expressing and exchanging security configuration and vulnerability information, which is why SCAP is the better answer; this option serves the different function defined above.

Answer C is incorrect because Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal. The key mismatch is functional: SCAP addresses a family of standards for expressing and exchanging security configuration and vulnerability information, the need stated by the question.

 

Question 11

A security plan created during a monitoring and alerting engineering review must provide automated examination of systems, networks, or content for vulnerabilities or malicious conditions, documented set of recommended secure configuration settings for a technology, and technology that identifies and controls movement or use of sensitive data according to policy. Which THREE options should be selected? Choose THREE.

  1. Application monitoring
  2. Security benchmark
  3. Infrastructure monitoring
  4. SIEM
  5. Security scanning
  6. Data loss prevention (DLP)

Correct Answers: B, E, F

Correct Answers

 

 

Answer B is correct because Security benchmark means a documented set of recommended secure configuration settings for a technology. The fixed-count item needs this function in the answer set. Infrastructure monitoring covers observation of network, cloud, hardware, and platform components, a different requirement.

Answer E is correct because Security scanning means automated examination of systems, networks, or content for vulnerabilities or malicious conditions. One required function is exactly what this option provides. SIEM may be useful elsewhere, but it is used for a platform that centralizes security data, correlates events, supports searches, and generates detections.

Answer F is correct because Data loss prevention (DLP) means technology that identifies and controls movement or use of sensitive data according to policy. It belongs in the fixed-count answer set because it covers one of the stated requirements. Application monitoring instead serves collection of application events, transactions, errors, and security-relevant behavior and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Application monitoring means collection of application events, transactions, errors, and security-relevant behavior. The scenario calls for Security benchmark, Security scanning, Data loss prevention (DLP). Selecting this option would leave one of those required functions uncovered.

Answer C is incorrect because Infrastructure monitoring means observation of network, cloud, hardware, and platform components. Every answer slot must map to a stated requirement. The correct set is Security benchmark, Security scanning, Data loss prevention (DLP), so this option cannot replace one of those selections.

Answer D is incorrect because SIEM means a platform that centralizes security data, correlates events, supports searches, and generates detections. The scenario calls for Security benchmark, Security scanning, Data loss prevention (DLP). Selecting this option would leave one of those required functions uncovered.

 

Question 12

To reduce false positives without hiding meaningful malicious activity, which security approach should be selected?

  1. Security scanning
  2. Data loss prevention (DLP)
  3. Alert tuning
  4. Agent-based monitoring

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Alert tuning means adjustment of detection logic, thresholds, suppressions, and context to improve useful signal. That is the function the question is testing. Security scanning would instead be used for automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Incorrect Answers

 

Answer A is incorrect because Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions. This could be appropriate elsewhere, but the required function is adjustment of detection logic, thresholds, suppressions, and context to improve useful signal; that makes Alert tuning the precise choice.

Answer B is incorrect because Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy. This could be appropriate elsewhere, but the required function is adjustment of detection logic, thresholds, suppressions, and context to improve useful signal; that makes Alert tuning the precise choice.

Answer D is incorrect because Agent-based monitoring refers to monitoring that uses software installed on the endpoint or workload to collect local telemetry. The concept is valid, but it does not match this stem. The required function is adjustment of detection logic, thresholds, suppressions, and context to improve useful signal, which maps to Alert tuning.

 

Question 13

Which term describes monitoring that collects information remotely without installing a dedicated local agent?

  1. System monitoring
  2. Security benchmark
  3. Infrastructure monitoring
  4. Agentless monitoring

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Agentless monitoring means monitoring that collects information remotely without installing a dedicated local agent. The requirement maps directly to this function, whereas Security benchmark is aimed at a documented set of recommended secure configuration settings for a technology.

Incorrect Answers

 

Answer A is incorrect because System monitoring refers to collection of operating-system and host telemetry for security and operational analysis. This could be appropriate elsewhere, but the required function is monitoring that collects information remotely without installing a dedicated local agent; that makes Agentless monitoring the precise choice.

Answer B is incorrect because Security benchmark refers to a documented set of recommended secure configuration settings for a technology. The key mismatch is functional: Agentless monitoring addresses monitoring that collects information remotely without installing a dedicated local agent, the need stated by the question.

Answer C is incorrect because Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components. The question is not asking for this function. It is testing monitoring that collects information remotely without installing a dedicated local agent, so Agentless monitoring is the stronger fit.

 

Question 14

An architect working on a monitoring and alerting engineering review needs one capability that provides collection of operating-system and host telemetry for security and operational analysis and another that provides technology that identifies and controls movement or use of sensitive data according to policy. Which TWO selections are the best match? Choose TWO.

  1. Security reporting
  2. System monitoring
  3. Data loss prevention (DLP)
  4. Agent-based monitoring
  5. SIEM

Correct Answers: B, C

Correct Answers

 

 

Answer B is correct because System monitoring means collection of operating-system and host telemetry for security and operational analysis. The fixed-count item needs this function in the answer set. Security reporting covers production of summarized findings, trends, metrics, and evidence from monitoring data, a different requirement.

Answer C is correct because Data loss prevention (DLP) means technology that identifies and controls movement or use of sensitive data according to policy. This selection maps directly to one of the named needs. Security reporting addresses production of summarized findings, trends, metrics, and evidence from monitoring data, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because Security reporting means production of summarized findings, trends, metrics, and evidence from monitoring data. The scenario calls for System monitoring, Data loss prevention (DLP). Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because Agent-based monitoring means monitoring that uses software installed on the endpoint or workload to collect local telemetry. The fixed-count answer set is System monitoring, Data loss prevention (DLP); this option does not fill one of those named functions.

Answer E is incorrect because SIEM means a platform that centralizes security data, correlates events, supports searches, and generates detections. The scenario calls for System monitoring, Data loss prevention (DLP). Selecting this option would leave one of those required functions uncovered.

 

Question 15

Which term describes network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes?

  1. NetFlow
  2. Alert tuning
  3. Security reporting
  4. Security scanning

Correct Answer: A

Correct Answer

 

 

Answer A is correct because NetFlow means network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes. That makes it the best answer here; Alert tuning addresses adjustment of detection logic, thresholds, suppressions, and context to improve useful signal, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal. This could be appropriate elsewhere, but the required function is network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes; that makes NetFlow the precise choice.

Answer C is incorrect because Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data. The key mismatch is functional: NetFlow addresses network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes, the need stated by the question.

Answer D is incorrect because Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions. That concept can be valid in another scenario, but this question is testing network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes; NetFlow therefore fits the requirement more directly.

 

Question 16

The control set for a monitoring and alerting engineering review must address both production of summarized findings, trends, metrics, and evidence from monitoring data and documented set of recommended secure configuration settings for a technology. Which TWO choices map directly to those needs? Choose TWO.

  1. Security benchmark
  2. Infrastructure monitoring
  3. SCAP
  4. Log archiving
  5. Security reporting

Correct Answers: A, E

Correct Answers

 

 

Answer A is correct because Security benchmark means a documented set of recommended secure configuration settings for a technology. One required function is exactly what this option provides. Infrastructure monitoring may be useful elsewhere, but it is used for observation of network, cloud, hardware, and platform components.

Answer E is correct because Security reporting means production of summarized findings, trends, metrics, and evidence from monitoring data. This option satisfies a specific requirement in the stem; Infrastructure monitoring serves observation of network, cloud, hardware, and platform components and therefore is not interchangeable with it.

Incorrect Answers

 

Answer B is incorrect because Infrastructure monitoring means observation of network, cloud, hardware, and platform components. The fixed-count answer set is Security benchmark, Security reporting; this option does not fill one of those named functions. For example, Security reporting is required for production of summarized findings, trends, metrics, and evidence from monitoring data.

Answer C is incorrect because SCAP means a family of standards for expressing and exchanging security configuration and vulnerability information. The scenario calls for Security benchmark, Security reporting. Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because Log archiving means long-term preservation of telemetry according to retention and investigation requirements. The question requires exactly 2 selections: Security benchmark, Security reporting. This option falls outside that required set. For example, Security benchmark is required for a documented set of recommended secure configuration settings for a technology.

 

Question 17

To analyze activity across many sources in one security operations workflow, which security approach should be selected?

  1. Application monitoring
  2. SIEM
  3. System monitoring
  4. Alert tuning

Correct Answer: B

Correct Answer

 

 

Answer B is correct because SIEM means a platform that centralizes security data, correlates events, supports searches, and generates detections. That is the function the question is testing. Alert tuning would instead be used for adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

Incorrect Answers

 

Answer A is incorrect because Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior. The key mismatch is functional: SIEM addresses a platform that centralizes security data, correlates events, supports searches, and generates detections, the need stated by the question.

Answer C is incorrect because System monitoring refers to collection of operating-system and host telemetry for security and operational analysis. This could be appropriate elsewhere, but the required function is a platform that centralizes security data, correlates events, supports searches, and generates detections; that makes SIEM the precise choice.

Answer D is incorrect because Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal. That concept can be valid in another scenario, but this question is testing a platform that centralizes security data, correlates events, supports searches, and generates detections; SIEM therefore fits the requirement more directly.

 

Question 18

To reduce endpoint footprint when supported remote interfaces provide enough visibility, which security approach should be selected?

  1. Security scanning
  2. Alert tuning
  3. Agentless monitoring
  4. Quarantine

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Agentless monitoring means monitoring that collects information remotely without installing a dedicated local agent. That makes it the best answer here; Alert tuning addresses adjustment of detection logic, thresholds, suppressions, and context to improve useful signal, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions. The scenario instead requires monitoring that collects information remotely without installing a dedicated local agent, which is why Agentless monitoring is the better answer; this option serves the different function defined above.

Answer B is incorrect because Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal. This could be appropriate elsewhere, but the required function is monitoring that collects information remotely without installing a dedicated local agent; that makes Agentless monitoring the precise choice.

Answer D is incorrect because Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation. That concept can be valid in another scenario, but this question is testing monitoring that collects information remotely without installing a dedicated local agent; Agentless monitoring therefore fits the requirement more directly.

 

Question 19

Which term describes monitoring that uses software installed on the endpoint or workload to collect local telemetry?

  1. Security benchmark
  2. Security scanning
  3. Agent-based monitoring
  4. SIEM

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Agent-based monitoring means monitoring that uses software installed on the endpoint or workload to collect local telemetry. The requirement maps directly to this function, whereas Security scanning is aimed at automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Incorrect Answers

 

Answer A is incorrect because Security benchmark refers to a documented set of recommended secure configuration settings for a technology. The concept is valid, but it does not match this stem. The required function is monitoring that uses software installed on the endpoint or workload to collect local telemetry, which maps to Agent-based monitoring.

Answer B is incorrect because Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions. The scenario instead requires monitoring that uses software installed on the endpoint or workload to collect local telemetry, which is why Agent-based monitoring is the better answer; this option serves the different function defined above.

Answer D is incorrect because SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections. The scenario instead requires monitoring that uses software installed on the endpoint or workload to collect local telemetry, which is why Agent-based monitoring is the better answer; this option serves the different function defined above.

 

Question 20

To contain risk while analysis or remediation occurs, which security approach should be selected?

  1. Security reporting
  2. Agent-based monitoring
  3. Quarantine
  4. Security alerting

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Quarantine means isolation of a suspicious file, endpoint, account, or workload from normal operation. That makes it the best answer here; Security alerting addresses generation and delivery of notifications when monitoring detects conditions requiring attention, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data. The question is not asking for this function. It is testing isolation of a suspicious file, endpoint, account, or workload from normal operation, so Quarantine is the stronger fit.

Answer B is incorrect because Agent-based monitoring refers to monitoring that uses software installed on the endpoint or workload to collect local telemetry. This could be appropriate elsewhere, but the required function is isolation of a suspicious file, endpoint, account, or workload from normal operation; that makes Quarantine the precise choice.

Answer D is incorrect because Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention. The question is not asking for this function. It is testing isolation of a suspicious file, endpoint, account, or workload from normal operation, so Quarantine is the stronger fit.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!