CompTIA Security+ SY0-701 Security Monitoring and Alerting Practice Test 2

 

Topic 17 Practice Test 2 covers Security Monitoring and Alerting for CompTIA Security+ SY0-701 and maps to objective 4.4: Explain security alerting and monitoring concepts and tools. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

To bring significant events to analysts quickly, which security approach should be selected?

  1. Security alerting
  2. Security benchmark
  3. Log archiving
  4. Security reporting

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Security alerting means generation and delivery of notifications when monitoring detects conditions requiring attention. This matches the requirement as written. Log archiving can be valid in another context, but it is used for long-term preservation of telemetry according to retention and investigation requirements.

Incorrect Answers

 

Answer B is incorrect because Security benchmark refers to a documented set of recommended secure configuration settings for a technology. The scenario instead requires generation and delivery of notifications when monitoring detects conditions requiring attention, which is why Security alerting is the better answer; this option serves the different function defined above.

Answer C is incorrect because Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements. The scenario instead requires generation and delivery of notifications when monitoring detects conditions requiring attention, which is why Security alerting is the better answer; this option serves the different function defined above.

Answer D is incorrect because Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data. The key mismatch is functional: Security alerting addresses generation and delivery of notifications when monitoring detects conditions requiring attention, the need stated by the question.

 

Question 2

To detect application abuse, failures, or unauthorized activity, which security approach should be selected?

  1. Security reporting
  2. Log aggregation
  3. System monitoring
  4. Application monitoring

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Application monitoring means collection of application events, transactions, errors, and security-relevant behavior. This is the precise fit for the scenario. System monitoring serves the different purpose of collection of operating-system and host telemetry for security and operational analysis.

Incorrect Answers

 

Answer A is incorrect because Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data. The scenario instead requires collection of application events, transactions, errors, and security-relevant behavior, which is why Application monitoring is the better answer; this option serves the different function defined above.

Answer B is incorrect because Log aggregation refers to central collection of logs from many systems into a common platform. The scenario instead requires collection of application events, transactions, errors, and security-relevant behavior, which is why Application monitoring is the better answer; this option serves the different function defined above.

Answer C is incorrect because System monitoring refers to collection of operating-system and host telemetry for security and operational analysis. This could be appropriate elsewhere, but the required function is collection of application events, transactions, errors, and security-relevant behavior; that makes Application monitoring the precise choice.

 

Question 3

The control set for a monitoring and alerting engineering review must address both central collection of logs from many systems into a common platform and long-term preservation of telemetry according to retention and investigation requirements. Which TWO choices map directly to those needs? Choose TWO.

  1. Log archiving
  2. Security alerting
  3. System monitoring
  4. Alert tuning
  5. Log aggregation

Correct Answers: A, E

Correct Answers

 

 

Answer A is correct because Log archiving means long-term preservation of telemetry according to retention and investigation requirements. This option satisfies a specific requirement in the stem; Security alerting serves generation and delivery of notifications when monitoring detects conditions requiring attention and therefore is not interchangeable with it.

Answer E is correct because Log aggregation means central collection of logs from many systems into a common platform. This selection maps directly to one of the named needs. Alert tuning addresses adjustment of detection logic, thresholds, suppressions, and context to improve useful signal, so it does not satisfy the same slot.

Incorrect Answers

 

Answer B is incorrect because Security alerting means generation and delivery of notifications when monitoring detects conditions requiring attention. The fixed-count answer set is Log archiving, Log aggregation; this option does not fill one of those named functions. For example, Log aggregation is required for central collection of logs from many systems into a common platform.

Answer C is incorrect because System monitoring means collection of operating-system and host telemetry for security and operational analysis. The fixed-count answer set is Log archiving, Log aggregation; this option does not fill one of those named functions. For example, Log aggregation is required for central collection of logs from many systems into a common platform.

Answer D is incorrect because Alert tuning means adjustment of detection logic, thresholds, suppressions, and context to improve useful signal. Every answer slot must map to a stated requirement. The correct set is Log archiving, Log aggregation, so this option cannot replace one of those selections.

 

Question 4

What is a documented set of recommended secure configuration settings for a technology?

  1. Quarantine
  2. Security benchmark
  3. Log archiving
  4. Agentless monitoring

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Security benchmark means a documented set of recommended secure configuration settings for a technology. The deciding point is functional fit: this option covers the stated need, while Quarantine addresses isolation of a suspicious file, endpoint, account, or workload from normal operation.

Incorrect Answers

 

Answer A is incorrect because Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation. This could be appropriate elsewhere, but the required function is a documented set of recommended secure configuration settings for a technology; that makes Security benchmark the precise choice.

Answer C is incorrect because Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements. That concept can be valid in another scenario, but this question is testing a documented set of recommended secure configuration settings for a technology; Security benchmark therefore fits the requirement more directly.

Answer D is incorrect because Agentless monitoring refers to monitoring that collects information remotely without installing a dedicated local agent. The concept is valid, but it does not match this stem. The required function is a documented set of recommended secure configuration settings for a technology, which maps to Security benchmark.

 

Question 5

Two requirements remain open in a monitoring and alerting engineering review: network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes; unsolicited network-management notification sent by a managed device. Which TWO options close those specific gaps? Choose TWO.

  1. SNMP trap
  2. System monitoring
  3. Infrastructure monitoring
  4. Security scanning
  5. NetFlow

Correct Answers: A, E

Correct Answers

 

 

Answer A is correct because SNMP trap means an unsolicited network-management notification sent by a managed device. One required function is exactly what this option provides. Security scanning may be useful elsewhere, but it is used for automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Answer E is correct because NetFlow means network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes. One required function is exactly what this option provides. Security scanning may be useful elsewhere, but it is used for automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Incorrect Answers

 

Answer B is incorrect because System monitoring means collection of operating-system and host telemetry for security and operational analysis. The required choices are NetFlow, SNMP trap. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer C is incorrect because Infrastructure monitoring means observation of network, cloud, hardware, and platform components. The scenario calls for NetFlow, SNMP trap. Selecting this option would leave one of those required functions uncovered. For example, NetFlow is required for network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.

Answer D is incorrect because Security scanning means automated examination of systems, networks, or content for vulnerabilities or malicious conditions. The required choices are NetFlow, SNMP trap. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 6

Which term describes observation of network, cloud, hardware, and platform components?

  1. Security reporting
  2. Infrastructure monitoring
  3. Alert tuning
  4. Security benchmark

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Infrastructure monitoring means observation of network, cloud, hardware, and platform components. That is the function the question is testing. Alert tuning would instead be used for adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

Incorrect Answers

 

Answer A is incorrect because Security reporting refers to production of summarized findings, trends, metrics, and evidence from monitoring data. That concept can be valid in another scenario, but this question is testing observation of network, cloud, hardware, and platform components; Infrastructure monitoring therefore fits the requirement more directly.

Answer C is incorrect because Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal. That concept can be valid in another scenario, but this question is testing observation of network, cloud, hardware, and platform components; Infrastructure monitoring therefore fits the requirement more directly.

Answer D is incorrect because Security benchmark refers to a documented set of recommended secure configuration settings for a technology. The question is not asking for this function. It is testing observation of network, cloud, hardware, and platform components, so Infrastructure monitoring is the stronger fit.

 

Question 7

To identify weaknesses or suspicious objects at scale, which security approach should be selected?

  1. Quarantine
  2. Log archiving
  3. NetFlow
  4. Security scanning

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Security scanning means automated examination of systems, networks, or content for vulnerabilities or malicious conditions. The deciding point is functional fit: this option covers the stated need, while NetFlow addresses network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.

Incorrect Answers

 

Answer A is incorrect because Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation. The question is not asking for this function. It is testing automated examination of systems, networks, or content for vulnerabilities or malicious conditions, so Security scanning is the stronger fit.

Answer B is incorrect because Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements. That concept can be valid in another scenario, but this question is testing automated examination of systems, networks, or content for vulnerabilities or malicious conditions; Security scanning therefore fits the requirement more directly.

Answer C is incorrect because NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes. This could be appropriate elsewhere, but the required function is automated examination of systems, networks, or content for vulnerabilities or malicious conditions; that makes Security scanning the precise choice.

 

Question 8

The control set for a monitoring and alerting engineering review must address both collection of operating-system and host telemetry for security and operational analysis and collection of application events, transactions, errors, and security-relevant behavior. Which TWO choices map directly to those needs? Choose TWO.

  1. SCAP
  2. System monitoring
  3. Security scanning
  4. Quarantine
  5. Application monitoring

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because System monitoring means collection of operating-system and host telemetry for security and operational analysis. One required function is exactly what this option provides. SCAP may be useful elsewhere, but it is used for a family of standards for expressing and exchanging security configuration and vulnerability information.

Answer E is correct because Application monitoring means collection of application events, transactions, errors, and security-relevant behavior. One required function is exactly what this option provides. Security scanning may be useful elsewhere, but it is used for automated examination of systems, networks, or content for vulnerabilities or malicious conditions.

Incorrect Answers

 

Answer A is incorrect because SCAP means a family of standards for expressing and exchanging security configuration and vulnerability information. The scenario calls for System monitoring, Application monitoring. Selecting this option would leave one of those required functions uncovered.

Answer C is incorrect because Security scanning means automated examination of systems, networks, or content for vulnerabilities or malicious conditions. The scenario calls for System monitoring, Application monitoring. Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because Quarantine means isolation of a suspicious file, endpoint, account, or workload from normal operation. The question requires exactly 2 selections: System monitoring, Application monitoring. This option falls outside that required set. For example, Application monitoring is required for collection of application events, transactions, errors, and security-relevant behavior.

 

Question 9

Which term describes isolation of a suspicious file, endpoint, account, or workload from normal operation?

  1. Quarantine
  2. SIEM
  3. Infrastructure monitoring
  4. SNMP trap

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Quarantine means isolation of a suspicious file, endpoint, account, or workload from normal operation. The requirement maps directly to this function, whereas Infrastructure monitoring is aimed at observation of network, cloud, hardware, and platform components.

Incorrect Answers

 

Answer B is incorrect because SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections. The concept is valid, but it does not match this stem. The required function is isolation of a suspicious file, endpoint, account, or workload from normal operation, which maps to Quarantine.

Answer C is incorrect because Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components. This could be appropriate elsewhere, but the required function is isolation of a suspicious file, endpoint, account, or workload from normal operation; that makes Quarantine the precise choice.

Answer D is incorrect because SNMP trap refers to an unsolicited network-management notification sent by a managed device. That concept can be valid in another scenario, but this question is testing isolation of a suspicious file, endpoint, account, or workload from normal operation; Quarantine therefore fits the requirement more directly.

 

Question 10

To detect or block inappropriate disclosure of protected information, which security approach should be selected?

  1. SNMP trap
  2. NetFlow
  3. Data loss prevention (DLP)
  4. Quarantine

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Data loss prevention (DLP) means technology that identifies and controls movement or use of sensitive data according to policy. That is the function the question is testing. NetFlow would instead be used for network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes.

Incorrect Answers

 

Answer A is incorrect because SNMP trap refers to an unsolicited network-management notification sent by a managed device. The key mismatch is functional: Data loss prevention (DLP) addresses technology that identifies and controls movement or use of sensitive data according to policy, the need stated by the question.

Answer B is incorrect because NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes. The scenario instead requires technology that identifies and controls movement or use of sensitive data according to policy, which is why Data loss prevention (DLP) is the better answer; this option serves the different function defined above.

Answer D is incorrect because Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation. The scenario instead requires technology that identifies and controls movement or use of sensitive data according to policy, which is why Data loss prevention (DLP) is the better answer; this option serves the different function defined above.

 

Question 11

To investigate communication patterns without storing full packet contents, which security approach should be selected?

  1. Log archiving
  2. System monitoring
  3. NetFlow
  4. Data loss prevention (DLP)

Correct Answer: C

Correct Answer

 

 

Answer C is correct because NetFlow means network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes. That makes it the best answer here; System monitoring addresses collection of operating-system and host telemetry for security and operational analysis, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements. The question is not asking for this function. It is testing network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes, so NetFlow is the stronger fit.

Answer B is incorrect because System monitoring refers to collection of operating-system and host telemetry for security and operational analysis. The concept is valid, but it does not match this stem. The required function is network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes, which maps to NetFlow.

Answer D is incorrect because Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy. The question is not asking for this function. It is testing network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes, so NetFlow is the stronger fit.

 

Question 12

During a monitoring and alerting engineering review, three requirements must be addressed: (1) central collection of logs from many systems into a common platform; (2) generation and delivery of notifications when monitoring detects conditions requiring attention; and (3) production of summarized findings, trends, metrics, and evidence from monitoring data. Which THREE choices best satisfy them? Choose THREE.

  1. Application monitoring
  2. Log aggregation
  3. Security alerting
  4. Security benchmark
  5. Security reporting
  6. Infrastructure monitoring

Correct Answers: B, C, E

Correct Answers

 

 

Answer B is correct because Log aggregation means central collection of logs from many systems into a common platform. The fixed-count item needs this function in the answer set. Infrastructure monitoring covers observation of network, cloud, hardware, and platform components, a different requirement.

Answer C is correct because Security alerting means generation and delivery of notifications when monitoring detects conditions requiring attention. It belongs in the fixed-count answer set because it covers one of the stated requirements. Security benchmark instead serves a documented set of recommended secure configuration settings for a technology and cannot replace this function.

Answer E is correct because Security reporting means production of summarized findings, trends, metrics, and evidence from monitoring data. The fixed-count item needs this function in the answer set. Security benchmark covers a documented set of recommended secure configuration settings for a technology, a different requirement.

Incorrect Answers

 

Answer A is incorrect because Application monitoring means collection of application events, transactions, errors, and security-relevant behavior. The required choices are Security alerting, Security reporting, Log aggregation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Security benchmark means a documented set of recommended secure configuration settings for a technology. Every answer slot must map to a stated requirement. The correct set is Security alerting, Security reporting, Log aggregation, so this option cannot replace one of those selections.

Answer F is incorrect because Infrastructure monitoring means observation of network, cloud, hardware, and platform components. The required choices are Security alerting, Security reporting, Log aggregation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 13

To automate standardized assessment and configuration checking, which security approach should be selected?

  1. SCAP
  2. Quarantine
  3. SNMP trap
  4. SIEM

Correct Answer: A

Correct Answer

 

 

Answer A is correct because SCAP means a family of standards for expressing and exchanging security configuration and vulnerability information. The requirement maps directly to this function, whereas SIEM is aimed at a platform that centralizes security data, correlates events, supports searches, and generates detections.

Incorrect Answers

 

Answer B is incorrect because Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation. This could be appropriate elsewhere, but the required function is a family of standards for expressing and exchanging security configuration and vulnerability information; that makes SCAP the precise choice.

Answer C is incorrect because SNMP trap refers to an unsolicited network-management notification sent by a managed device. The key mismatch is functional: SCAP addresses a family of standards for expressing and exchanging security configuration and vulnerability information, the need stated by the question.

Answer D is incorrect because SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections. This could be appropriate elsewhere, but the required function is a family of standards for expressing and exchanging security configuration and vulnerability information; that makes SCAP the precise choice.

 

Question 14

Which term describes production of summarized findings, trends, metrics, and evidence from monitoring data?

  1. Security alerting
  2. Security reporting
  3. Log aggregation
  4. SNMP trap

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Security reporting means production of summarized findings, trends, metrics, and evidence from monitoring data. The requirement maps directly to this function, whereas Log aggregation is aimed at central collection of logs from many systems into a common platform.

Incorrect Answers

 

Answer A is incorrect because Security alerting refers to generation and delivery of notifications when monitoring detects conditions requiring attention. This could be appropriate elsewhere, but the required function is production of summarized findings, trends, metrics, and evidence from monitoring data; that makes Security reporting the precise choice.

Answer C is incorrect because Log aggregation refers to central collection of logs from many systems into a common platform. The key mismatch is functional: Security reporting addresses production of summarized findings, trends, metrics, and evidence from monitoring data, the need stated by the question.

Answer D is incorrect because SNMP trap refers to an unsolicited network-management notification sent by a managed device. The concept is valid, but it does not match this stem. The required function is production of summarized findings, trends, metrics, and evidence from monitoring data, which maps to Security reporting.

 

Question 15

Which term describes technology that identifies and controls movement or use of sensitive data according to policy?

  1. NetFlow
  2. Application monitoring
  3. Data loss prevention (DLP)
  4. SCAP

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Data loss prevention (DLP) means technology that identifies and controls movement or use of sensitive data according to policy. That is the function the question is testing. NetFlow would instead be used for network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes. This question specifically tests the requirement represented by Data loss prevention (DLP).

Incorrect Answers

 

Answer A is incorrect because NetFlow refers to network-flow telemetry summarizing communicating endpoints, ports, protocols, and traffic volumes. The question is not asking for this function. It is testing technology that identifies and controls movement or use of sensitive data according to policy, so Data loss prevention (DLP) is the stronger fit.

Answer B is incorrect because Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior. This could be appropriate elsewhere, but the required function is technology that identifies and controls movement or use of sensitive data according to policy; that makes Data loss prevention (DLP) the precise choice.

Answer D is incorrect because SCAP refers to a family of standards for expressing and exchanging security configuration and vulnerability information. The question is not asking for this function. It is testing technology that identifies and controls movement or use of sensitive data according to policy, so Data loss prevention (DLP) is the stronger fit.

 

Question 16

To gain detailed host visibility that network-only tools may not provide, which security approach should be selected?

  1. Agent-based monitoring
  2. Security scanning
  3. Infrastructure monitoring
  4. Application monitoring

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Agent-based monitoring means monitoring that uses software installed on the endpoint or workload to collect local telemetry. The requirement maps directly to this function, whereas Application monitoring is aimed at collection of application events, transactions, errors, and security-relevant behavior.

Incorrect Answers

 

Answer B is incorrect because Security scanning refers to automated examination of systems, networks, or content for vulnerabilities or malicious conditions. This could be appropriate elsewhere, but the required function is monitoring that uses software installed on the endpoint or workload to collect local telemetry; that makes Agent-based monitoring the precise choice.

Answer C is incorrect because Infrastructure monitoring refers to observation of network, cloud, hardware, and platform components. This could be appropriate elsewhere, but the required function is monitoring that uses software installed on the endpoint or workload to collect local telemetry; that makes Agent-based monitoring the precise choice.

Answer D is incorrect because Application monitoring refers to collection of application events, transactions, errors, and security-relevant behavior. The concept is valid, but it does not match this stem. The required function is monitoring that uses software installed on the endpoint or workload to collect local telemetry, which maps to Agent-based monitoring.

 

Question 17

During a monitoring and alerting engineering review, the team has two independent requirements: (1) isolation of a suspicious file, endpoint, account, or workload from normal operation; and (2) technology that identifies and controls movement or use of sensitive data according to policy. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Agent-based monitoring
  2. Log aggregation
  3. Quarantine
  4. SNMP trap
  5. Data loss prevention (DLP)

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because Quarantine means isolation of a suspicious file, endpoint, account, or workload from normal operation. One required function is exactly what this option provides. Agent-based monitoring may be useful elsewhere, but it is used for monitoring that uses software installed on the endpoint or workload to collect local telemetry.

Answer E is correct because Data loss prevention (DLP) means technology that identifies and controls movement or use of sensitive data according to policy. The fixed-count item needs this function in the answer set. SNMP trap covers an unsolicited network-management notification sent by a managed device, a different requirement.

Incorrect Answers

 

Answer A is incorrect because Agent-based monitoring means monitoring that uses software installed on the endpoint or workload to collect local telemetry. The required choices are Quarantine, Data loss prevention (DLP). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer B is incorrect because Log aggregation means central collection of logs from many systems into a common platform. Every answer slot must map to a stated requirement. The correct set is Quarantine, Data loss prevention (DLP), so this option cannot replace one of those selections.

Answer D is incorrect because SNMP trap means an unsolicited network-management notification sent by a managed device. The required choices are Quarantine, Data loss prevention (DLP). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 18

Which term describes automated examination of systems, networks, or content for vulnerabilities or malicious conditions?

  1. Log archiving
  2. Data loss prevention (DLP)
  3. Alert tuning
  4. Security scanning

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Security scanning means automated examination of systems, networks, or content for vulnerabilities or malicious conditions. The requirement maps directly to this function, whereas Alert tuning is aimed at adjustment of detection logic, thresholds, suppressions, and context to improve useful signal.

Incorrect Answers

 

Answer A is incorrect because Log archiving refers to long-term preservation of telemetry according to retention and investigation requirements. This could be appropriate elsewhere, but the required function is automated examination of systems, networks, or content for vulnerabilities or malicious conditions; that makes Security scanning the precise choice.

Answer B is incorrect because Data loss prevention (DLP) refers to technology that identifies and controls movement or use of sensitive data according to policy. The scenario instead requires automated examination of systems, networks, or content for vulnerabilities or malicious conditions, which is why Security scanning is the better answer; this option serves the different function defined above.

Answer C is incorrect because Alert tuning refers to adjustment of detection logic, thresholds, suppressions, and context to improve useful signal. This could be appropriate elsewhere, but the required function is automated examination of systems, networks, or content for vulnerabilities or malicious conditions; that makes Security scanning the precise choice.

 

Question 19

An architect working on a monitoring and alerting engineering review needs one capability that provides production of summarized findings, trends, metrics, and evidence from monitoring data and another that provides platform that centralizes security data, correlates events, supports searches, and generates detections. Which TWO selections are the best match? Choose TWO.

  1. SIEM
  2. Application monitoring
  3. Security alerting
  4. Quarantine
  5. Security reporting

Correct Answers: A, E

Correct Answers

 

 

Answer A is correct because SIEM means a platform that centralizes security data, correlates events, supports searches, and generates detections. It belongs in the fixed-count answer set because it covers one of the stated requirements. Quarantine instead serves isolation of a suspicious file, endpoint, account, or workload from normal operation and cannot replace this function.

Answer E is correct because Security reporting means production of summarized findings, trends, metrics, and evidence from monitoring data. This option satisfies a specific requirement in the stem; Quarantine serves isolation of a suspicious file, endpoint, account, or workload from normal operation and therefore is not interchangeable with it.

Incorrect Answers

 

Answer B is incorrect because Application monitoring means collection of application events, transactions, errors, and security-relevant behavior. Every answer slot must map to a stated requirement. The correct set is SIEM, Security reporting, so this option cannot replace one of those selections.

Answer C is incorrect because Security alerting means generation and delivery of notifications when monitoring detects conditions requiring attention. Every answer slot must map to a stated requirement. The correct set is SIEM, Security reporting, so this option cannot replace one of those selections.

Answer D is incorrect because Quarantine means isolation of a suspicious file, endpoint, account, or workload from normal operation. Every answer slot must map to a stated requirement. The correct set is SIEM, Security reporting, so this option cannot replace one of those selections.

 

Question 20

To support later forensic, legal, or compliance review, which security approach should be selected?

  1. Quarantine
  2. SIEM
  3. System monitoring
  4. Log archiving

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Log archiving means long-term preservation of telemetry according to retention and investigation requirements. The deciding point is functional fit: this option covers the stated need, while Quarantine addresses isolation of a suspicious file, endpoint, account, or workload from normal operation.

Incorrect Answers

 

Answer A is incorrect because Quarantine refers to isolation of a suspicious file, endpoint, account, or workload from normal operation. The concept is valid, but it does not match this stem. The required function is long-term preservation of telemetry according to retention and investigation requirements, which maps to Log archiving.

Answer B is incorrect because SIEM refers to a platform that centralizes security data, correlates events, supports searches, and generates detections. The question is not asking for this function. It is testing long-term preservation of telemetry according to retention and investigation requirements, so Log archiving is the stronger fit.

Answer C is incorrect because System monitoring refers to collection of operating-system and host telemetry for security and operational analysis. The scenario instead requires long-term preservation of telemetry according to retention and investigation requirements, which is why Log archiving is the better answer; this option serves the different function defined above.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!