SY0-701 Security Architecture Practice Question
A company is implementing a defense-in-depth strategy for its internal network. The security team wants to detect and respond to malicious activities that might bypass perimeter defenses. Which two controls should be implemented to provide continuous monitoring and analysis of network traffic and endpoint activities? (Choose two.)
⚠ Common exam trap
The trap here is selecting preventive controls like host-based firewalls or DLP, which do not provide the continuous monitoring and analysis required for detecting bypassed threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Intrusion detection system (IDS) sensors placed on critical network segments.
The correct answers are IDS sensors and a SIEM system. IDS sensors detect suspicious network traffic, while a SIEM aggregates and correlates logs for comprehensive analysis. Together, they provide continuous monitoring and detection of malicious activities that bypass perimeter defenses. The other options are preventive or availability controls, not detection and analysis tools.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Intrusion detection system (IDS) sensors placed on critical network segments.
Why this is correct
IDS sensors monitor network traffic for suspicious patterns and known attack signatures, providing visibility into potential intrusions that bypass perimeter defenses. Placing them on critical segments ensures that internal malicious activities are detected. This directly supports continuous monitoring and analysis of network traffic, making it a correct choice for defense-in-depth.
- ✗
Host-based firewall on each employee workstation.
Why it's wrong here
A host-based firewall controls inbound and outbound traffic on individual workstations, but it does not provide continuous monitoring and analysis of network traffic or endpoint activities across the enterprise. It is a preventive control, not a detection or analysis tool. While useful for defense-in-depth, it does not fulfill the requirement for monitoring and analysis.
- ✓
Security information and event management (SIEM) system aggregating logs from multiple sources.
Why this is correct
A SIEM aggregates and correlates logs from various sources such as firewalls, IDS, and endpoints, enabling continuous monitoring and analysis of security events. It helps detect complex attacks that might otherwise go unnoticed. By centralizing log data and applying analytics, the SIEM provides the required visibility and response capability, making it a correct choice.
- ✗
Uninterruptible power supply (UPS) for network devices.
Why it's wrong here
A UPS provides backup power to network devices during outages, ensuring availability, but it has no role in detecting or analyzing malicious activities. It is an availability control, not a monitoring or detection control. Therefore, it does not satisfy the requirement for continuous monitoring and analysis of network traffic and endpoint activities.
- ✗
Data loss prevention (DLP) endpoint agent.
Why it's wrong here
A DLP endpoint agent monitors and controls sensitive data transfers, but its primary focus is preventing data exfiltration, not detecting malicious network activities or analyzing endpoint behavior for intrusions. It does not provide the broad continuous monitoring and analysis of network traffic and endpoint activities that the scenario requires.
Go deeper
Related to this question
Learn chapter
Network Segmentation and Isolation
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.