
CompTIASecurity+
Domain 4Objective 9
Data Sources SY0-701 Practice Questions (Page 5)
Part of the Security operations domain, which accounts for 28% of the SY0-701 exam. CompTIA does not publish an official question count, but from its 90-minute exam (~35–60 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
10concepts
28%of the exam
Questions 21–25
- 21
What type of information would an endpoint detection and response (EDR) tool provide?
Select an answer first - 22
A security operations center (SOC) is overwhelmed by thousands of daily alerts from their SIEM. Most are false positives. The team wants to reduce noise and focus on high-priority events. Which SIEM feature should they configure first?
Select an answer first - 23
A company is legally required to preserve logs for a pending lawsuit. The IT team has a process to archive logs to a WORM (Write Once, Read Many) storage system. However, the SIEM administrator has the ability to modify logs in the SIEM. What is the most important control to ensure the archived logs are admissible as evidence?
Select an answer first - 24
During a forensic investigation, an analyst needs to prove that a log file has not been altered since it was originally collected. Which control would provide the strongest evidence of log integrity?
Select an answer first - 25
How does integrating threat intelligence into a security investigation enhance the analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SY0-701
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “SY0-701” is a trademark of its owner, used for identification only.