
CompTIASecurity+
Domain 4Objective 9
Data Sources SY0-701 Practice Questions (Page 2)
Part of the Security operations domain, which accounts for 28% of the SY0-701 exam. CompTIA does not publish an official question count, but from its 90-minute exam (~35–60 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
10concepts
28%of the exam
Questions 6–10
- 6
A SOC analyst is investigating an alert for a suspicious file hash. The SIEM shows the hash was detected on one workstation. The analyst queries a threat intelligence platform and finds the hash is associated with a known ransomware family. However, the analyst also finds a blog post from a security researcher claiming the hash is a false positive and is actually a legitimate software update. What should the analyst do?
Select an answer first - 7
A company is deploying a new SIEM. They need to collect logs from Windows and Linux servers, network switches, and a cloud-based email service. Which approach is the most efficient for ensuring all sources are collected?
Select an answer first - 8
A company's SIEM collects logs from employee workstations. During an internal investigation of a policy violation, the security team wants to search the logs for a specific employee's web browsing history. What is the most important legal and ethical consideration before proceeding?
Select an answer first - 9
A security analyst is reviewing the organization's log management strategy. Which statement best describes the primary purpose of a log data retention policy?
Select an answer first - 10
A SOC analyst is investigating a potential breach. The SIEM shows the following events: (1) a successful VPN login for a user at 2:00 AM, (2) a large data transfer from a file server to the user's workstation at 2:15 AM, and (3) a connection from the workstation to an external IP at 2:20 AM. The user denies any activity at that time. Which correlation of events provides the strongest evidence of a compromised account?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “SY0-701” is a trademark of its owner, used for identification only.