Courseiva
Security Architecture →mediumMultiple Select

SY0-701 Security Architecture Practice Question

A company is implementing a defense-in-depth strategy for its internal network. The security team wants to detect and respond to malicious activities that might bypass perimeter defenses. Which two controls should be implemented to provide continuous monitoring and analysis of network traffic and endpoint activities? (Choose two.)

⚠ Common exam trap

The trap here is selecting preventive controls like host-based firewalls or DLP, which do not provide the continuous monitoring and analysis required for detecting bypassed threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Intrusion detection system (IDS) sensors placed on critical network segments.

The correct answers are IDS sensors and a SIEM system. IDS sensors detect suspicious network traffic, while a SIEM aggregates and correlates logs for comprehensive analysis. Together, they provide continuous monitoring and detection of malicious activities that bypass perimeter defenses. The other options are preventive or availability controls, not detection and analysis tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Intrusion detection system (IDS) sensors placed on critical network segments.

    Why this is correct

    IDS sensors monitor network traffic for suspicious patterns and known attack signatures, providing visibility into potential intrusions that bypass perimeter defenses. Placing them on critical segments ensures that internal malicious activities are detected. This directly supports continuous monitoring and analysis of network traffic, making it a correct choice for defense-in-depth.

  • ✗

    Host-based firewall on each employee workstation.

    Why it's wrong here

    A host-based firewall controls inbound and outbound traffic on individual workstations, but it does not provide continuous monitoring and analysis of network traffic or endpoint activities across the enterprise. It is a preventive control, not a detection or analysis tool. While useful for defense-in-depth, it does not fulfill the requirement for monitoring and analysis.

  • ✓

    Security information and event management (SIEM) system aggregating logs from multiple sources.

    Why this is correct

    A SIEM aggregates and correlates logs from various sources such as firewalls, IDS, and endpoints, enabling continuous monitoring and analysis of security events. It helps detect complex attacks that might otherwise go unnoticed. By centralizing log data and applying analytics, the SIEM provides the required visibility and response capability, making it a correct choice.

  • ✗

    Uninterruptible power supply (UPS) for network devices.

    Why it's wrong here

    A UPS provides backup power to network devices during outages, ensuring availability, but it has no role in detecting or analyzing malicious activities. It is an availability control, not a monitoring or detection control. Therefore, it does not satisfy the requirement for continuous monitoring and analysis of network traffic and endpoint activities.

  • ✗

    Data loss prevention (DLP) endpoint agent.

    Why it's wrong here

    A DLP endpoint agent monitors and controls sensitive data transfers, but its primary focus is preventing data exfiltration, not detecting malicious network activities or analyzing endpoint behavior for intrusions. It does not provide the broad continuous monitoring and analysis of network traffic and endpoint activities that the scenario requires.

About these practice questions

This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.