
CompTIASecurity+
Domain 4Objective 9
Data Sources SY0-701 Practice Questions (Page 3)
Part of the Security operations domain, which accounts for 28% of the SY0-701 exam. CompTIA does not publish an official question count, but from its 90-minute exam (~35–60 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
10concepts
28%of the exam
Questions 11–15
- 11
An analyst is reviewing network traffic and sees a workstation communicating with an IP address that is not on any internal allowlist. The traffic is encrypted and uses a non-standard port. The analyst checks threat intelligence and finds the IP is associated with a known command-and-control (C2) server. What is the most appropriate next step?
Select an answer first - 12
Which ethical principle should guide an analyst when accessing log data during an investigation?
Select an answer first - 13
An analyst finds a file hash in a log and wants to know if it is associated with known malware. What is the best source of information?
Select an answer first - 14
Why is it important to ensure the integrity of log data used in a security investigation?
Select an answer first - 15
A company's security team needs to centralize logs from a mix of on-premises Linux servers, a cloud-based SaaS application, and network firewalls. The compliance team requires 18 months of retention for firewall logs but only 6 months for application logs. The team wants to minimize the number of tools they must learn and maintain. Which approach best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “SY0-701” is a trademark of its owner, used for identification only.